A/HRC/39/29
rights law to the greatest extent possible and mitigate as much as possible any adverse
impact, for example by interpreting government demands as narrowly as possible. 57
45.
The responsibility to respect human rights requires business enterprises to have in
place policies and processes appropriate to their size and circumstances, including:
(a)
Making a publicly available policy commitment at the most senior level and
embedding responsibility to respect human rights throughout operational policies and
procedures;58
(b)
Carrying out human rights due diligence processes, which entails:
(i)
Conducting human rights impact assessments to identify and assess any
actual or potentially adverse human rights impacts;
(ii)
Integrating those assessments and taking appropriate action to prevent and
mitigate adverse human rights impacts that have been identified;
(iii)
Tracking the effectiveness of their efforts;
(iv)
Reporting formally on how they have addressed their human rights impacts;59
(c)
Providing remediation or cooperating in remediation of abuse where the
company identifies adverse impacts that it has caused or to which it has contributed. 60
46.
According to the Guiding Principles, all companies have a responsibility to
undertake human rights due diligence to identify and address any human rights impacts of
their activities. Taking a concrete example, companies selling surveillance technology
should carry out, as part of their due diligence, a thorough human rights impact assessment
prior to any potential transaction. Risk mitigation should include clear end-use assurances
being stipulated in contractual agreements with strong human rights safeguards that prevent
arbitrary or unlawful use of the technology and periodic reviews of the use of technology
by States.61 Companies collecting and retaining user data need to assess the privacy risks
connected to potential State requests for such data, including the legal and institutional
environment of the States concerned. They must provide for adequate processes and
safeguards to prevent and mitigate potential privacy and other human rights harms. Human
rights impact assessments also need to be conducted, as part of the adoption of the terms of
service and design and engineering choices that have implications for security and privacy,
and decisions taken to provide or terminate services in a particular context (see
A/HRC/32/38, para. 11).
47.
As part of the human rights due diligence process, the Guiding Principles stipulate
that business enterprises should account for how they address their human rights impacts
and be prepared to communicate that externally, particularly when concerns are raised by or
on behalf of affected stakeholders. 62 In the digital environment, that entails disclosing
which personal data are collected, how long they are stored for, for what purpose, how they
are used and with whom and under what circumstances they are shared. That includes
requests received by States for access to user data. In instances where national laws and
regulations hinder such reporting, companies should use to the greatest extent possible any
leverage they may have and are encouraged to advocate for the possibility to release such
information.
48.
As part of the operationalization of their policy commitments under the Guiding
Principles, the ICT sector has developed guidance on how to implement human rights
policies. Such initiatives include the Principles on Freedom of Expression and Privacy of
57
58
59
60
61
62
Guiding Principle 23.
Guiding Principle 16.
Guiding Principles 17– 21.
Guiding Principle 22 and section VI of the present report.
See Privacy International, submission to the Special Rapporteur on the promotion and protection of
the right to freedom of opinion and expression (January 2016), available at
www.ohchr.org/Documents/Issues/Expression/PrivateSector/PrivacyInternational.pdf.
Guiding Principle 21.
13