A/HRC/39/29 Rights (OHCHR). More generally, efforts should be made to develop sector-specific guidance tools on business responsibilities to respect the right to privacy. 61. The High Commissioner recommends that States: (a) Recognize the full implications of new technologies, in particular datadriven technologies for the right to privacy but also for all other human rights; (b) Adopt strong, robust and comprehensive privacy legislation, including on data privacy, that complies with international human rights law in terms of safeguards, oversight and remedies to effectively protect the right to privacy; (c) Ensure that data-intensive systems, including those involving the collection and retention of biometric data, are only deployed when States can demonstrate that they are necessary and proportionate to achieve a legitimate aim; (d) Establish independent authorities with powers to monitor State and private sector data privacy practices, investigate abuses, receive complaints from individuals and organizations, and issue fines and other effective penalties for the unlawful processing of personal data by private and public bodies; (e) Ensure, through appropriate legislation and other means that any interference with the right to privacy, including by communications surveillance and intelligence-sharing, complies with international human rights law, including the principles of legality, legitimate aim, necessity and proportionality, regardless of the nationality or location of the individuals affected, and clarify that authorization of surveillance measures requires reasonable suspicion that a particular individual has committed or is committing a criminal offence or is engaged in acts amounting to a specific threat to national security; (f) Strengthen mechanisms for the independent authorization and oversight of State surveillance and ensure that those mechanisms are competent and adequately resourced to monitor and enforce the legality, necessity and proportionality of surveillance measures; (g) Review laws to ensure that they do not impose requirements of blanket, indiscriminate retention of communications data on telecommunications and other companies; (h) Take steps in order to enhance transparency and accountability in the acquisition of surveillance technologies by States; (i) Fully implement their duty to protect against abuses of the right to privacy by business enterprises in all relevant sectors, including the ICT sector, by taking appropriate steps to prevent, investigate, punish and redress such abuse through effective policies, legislation, regulations and adjudication; (j) Ensure that all victims of violations and abuses of the right to privacy have access to effective remedies, including in cross-border cases. 62. The High Commissioner recommends that business enterprises: (a) Make all efforts to meet their responsibility to respect the right to privacy and all other human rights. At a minimum, business enterprises should fully operationalize the Guiding Principles on Business and Human Rights, which implies conducting effective human rights due diligence across their operations and in relation to all human rights, including the right to privacy, and taking appropriate action to prevent, mitigate and address actual and potential impacts; (b) Seek to ensure a high level of security and confidentiality of any communications they transmit and personal data they collect, store or otherwise process. Conduct assessments on how best to design and update the security of products and services on an ongoing basis; (c) Comply with the key privacy principles referred to in paragraphs 29–31 of the present report and ensure the greatest possible transparency in their internal policies and practices that implicate the right to privacy of their users and customers; 16

Select target paragraph3