A/HRC/39/29
28.
There is a growing global consensus on minimum standards that should govern the
processing of personal data by States, business enterprises and other private actors.
International instruments and guidelines reflecting this development include the 1990
Guidelines for the Regulation of Computerized Personal Data Files; the Council of Europe
1981 Convention for the Protection of Individuals with regard to Automatic Processing of
Personal Data and its modernized version, which sets a global high level of protection; 35 the
1980 Organization for Economic Cooperation and Development Privacy Guidelines,
updated in 2013; the 2014 African Union Convention on Cyber Security and Personal Data
Protection (Malabo Convention); the Madrid resolution of the International Conference of
Data Protection and Privacy Commissioners; and the 2015 Asia-Pacific Economic
Coordination Privacy Framework, among others. Those standards, particularly the
Convention for the Protection of Individuals with regard to Automatic Processing of
Personal Data, have informed the data privacy frameworks of many States and can direct
the design of adequate policy instruments. 36
29.
The instruments and guidelines mentioned above contain a range of key principles,
rights and obligations that ensure a minimum level of protection of personal data. First,
processing of personal data should be fair, lawful and transparent. The individuals whose
personal data are being processed should be informed about the data processing, its
circumstances, character and scope, including through transparent data privacy policies. In
order to prevent the arbitrary use of personal information, the processing of personal data
should be based on the free, specific, informed and unambiguous consent of the individuals
concerned, or another legitimate basis laid down in law. 37 Personal data processing should
be necessary and proportionate to a legitimate purpose that should be specified by the
processing entity. Consequently, the amount and type of data and the retention period need
to be limited, data must be accurate and anonymization and pseudonymization techniques
used whenever possible. Changes of purpose without the consent of the person concerned
should be avoided and when undertaken, should be limited to purposes compatible with the
initially specified purpose. Considering the vulnerability of personal data to unauthorized
disclosure, modification or deletion, it is essential that adequate security measures be taken.
Moreover, entities processing personal data should be accountable for their compliance
with the applicable data processing legal and policy framework. Finally, sensitive data
should enjoy a particularly high level of protection. 38
30.
In all the instruments and guidelines mentioned above, it is recognized that certain
rights need to be afforded to the persons whose data is being processed. At a minimum, the
persons affected have a right to know that personal data has been retained and processed, to
have access to the data stored, to rectify data that is inaccurate or outdated and to delete or
rectify data unlawfully or unnecessarily stored. Newer instruments have added important
additional rights, in particular, a right to object to personal data processing, at least for
cases where the processing entity does not demonstrate legitimate, overriding grounds for
the processing. 39 States should pay particular attention to providing strong protection
against interference with the right to privacy by means of profiling and automated decisionmaking. The rights described above should also apply to information derived, inferred and
predicted by automated means, to the extent that the information qualifies as personal data.
It is important that the legal framework ensures that those rights do not unduly limit the
35
36
37
38
39
In addition to the 47 member States of the Council of Europe, the Convention has been ratified by
Mauritius, Senegal, Tunisia and Uruguay, and several other States are in the process of accession.
For detailed guidance, see https://privacyinternational.org/advocacy-briefing/2165/guide-policyengagement-data-protection and Access Now, “Creating a data protection framework: a do’s and
don’ts guide for lawmakers. Lessons from the EU general data protection regulation” (2018).
See article 5 (2) of the modernized Convention for the Protection of Individuals with regard to
Automatic Processing of Personal Data; article 13 (1) of the Malabo Convention; and principle 12 of
the Madrid resolution.
See article 6 of the modernized Convention for the Protection of Individuals with regard to Automatic
Processing of Personal Data.
Ibid., art. 9 (1) (d). See also article 21 of the general data protection regulation and article 18 (1) of
the Malabo Convention.
9