United Nations Mandate Source RegistryBeta Version
UN Secretariat MandatesUN System Mandates
United Nations (opens in new tab)
(opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab)
Donate (opens in new tab)
  • A-Z Site Index (opens in new tab)
  • Contact (opens in new tab)
  • Copyright (opens in new tab)
  • FAQ (opens in new tab)
  • Fraud Alert (opens in new tab)
  • Privacy Notice (opens in new tab)
  • Terms of Use (opens in new tab)

Right to Privacy in the Digital Age

A/HRC/RES/54/21View PDF

Who created this mandate?

A Resolution of the Human Rights Council, under agenda item 3Promotion and protection of all human rights, civil, political, economic, social and cultural rights, including the right to development, published in 2023.

What other versions does this mandate have?

2 versions · 2021–2023
  • 2023A/HRC/RES/54/21Right to privacy in the digital ageLatestCompare with previous version
  • 2021A/HRC/RES/48/4Right to privacy in the digital age

iVersions are identified automatically by matching titles within the same organ (~97% accuracy on a manual audit).

What subjects does this mandate have?

9 topics
Corporate Social ResponsibilityData ProtectionDigital TechnologyDiscriminationElectronic SurveillanceHuman Rights PolicyInternational ObligationsNew TechnologiesRight to Privacy

What does this mandate say?

44 operative paragraphs
1
Reaffirms the right to privacy, according to which no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, and the right to the protection of the law against such interference, as set out in article 12 of the Universal Declaration of Human Rights and article 17 of the International Covenant on Civil and Political Rights;
2
Recalls that States should ensure that any interference with the right to privacy is consistent with the principles of legality, necessity and proportionality;
3
Also recalls the increasing impact of new and emerging technologies, such as those developed in the fields of surveillance, artificial intelligence, automated decision-making and machine-learning, and of profiling, tracking and biometrics, including facial recognition, without human rights safeguards, present to the full enjoyment of the right to privacy and other human rights, and acknowledges that some applications may not be compatible with international human rights law;
4
Affirms that the same rights that people have offline must also be protected online, including the right to privacy;
5
Also affirms that, in order to protect, respect and promote the right to privacy, personal data should only be collected for specified, explicit and legitimate purposes and must be processed lawfully, fairly and in a transparent manner;
6
Highlights that every person should be able to ascertain which public authorities or private individuals or bodies control or may control their personal data, and that any interference with data protection must be lawful, in accordance with international human rights law, including the principles of legality, proportionality, necessity and non-discrimination;
7
Acknowledges that risks to the right to privacy and other human rights can and should be minimized by adopting adequate regulations or other appropriate mechanisms, in accordance with applicable obligations under international human rights law, in the conception, design, use, acquisition, transfer, sale, deployment and further development of new and emerging digital technologies, such as artificial intelligence, by ensuring a safe, secure and high-quality data infrastructure, by exercising due diligence to assess, prevent and mitigate adverse human rights impacts, and by establishing human oversight, as well as redress mechanisms;
8
Stresses that States must comply with their human rights obligations and that business enterprises, including technology companies, should respect the right to privacy and other human rights when collecting, processing, sharing and storing personal data by, inter alia, adopting data protection policies and safeguards;
9
Also stresses that remote biometric surveillance systems, including facial recognition, raise serious concerns with regard to their proportionality, given their highly intrusive nature and broad impact on large numbers of people;
10
Calls upon all States:
a
To respect and protect the right to privacy, including in the context of digital communications and new and emerging digital technologies;
b
To take measures to end violations and abuses of the right to privacy and to create the conditions to prevent such violations and abuses, including by ensuring that relevant national legislation complies with their obligations under international human rights law, especially in the case of persons in vulnerable situations or marginalized groups;
c
To review, on a regular basis, their procedures, practices and legislation regarding the surveillance of communications, including mass surveillance and the interception and collection of personal data, as well as regarding the use of profiling, automated decision-making, machine learning and biometric technologies, with a view to upholding the right to privacy by ensuring the full and effective implementation of all their obligations under international human rights law;
d
To respect international human rights obligations, including the right to privacy, when States intercept digital communications of individuals and/or collect personal data, when they share or otherwise provide access to data collected through, inter alia, information- and intelligence-sharing agreements and when they require disclosure of personal data from third parties, including business enterprises;
e
To ensure that any measures taken to counter terrorism and violent extremism conducive to terrorism that interfere with the right to privacy are consistent with the principles of legality, necessity and proportionality and comply with their obligations under international law;
f
To ensure that biometric identification and recognition technologies, including facial recognition technologies by public and private actors, do not enable arbitrary or unlawful surveillance, including of those exercising their right to freedom of peaceful assembly;
g
To ensure that digital or biometric identity programmes are designed, implemented and operated after appropriate technical, regulatory, legal and ethical safeguards are in place and in full compliance with the obligations of States under international human rights law;
h
To develop or maintain and implement adequate legislation, with effective sanctions and remedies, that protects individuals against violations and abuses of the right to privacy, namely through the collection, processing, retention or use of personal data by individuals, Governments, business enterprises or private organizations without the individual’s free, explicit and informed consent or unless otherwise lawful, in accordance with international human rights law;
i
To consider adopting or maintaining data protection legislation, regulations and policies, including on digital communication data, that comply with their international human rights obligations and that could include provisions on sensitive personal data protection and the establishment of national independent authorities with the powers and resources to monitor data privacy practices, investigate violations and abuses and receive communications from individuals and organizations, and to provide appropriate effective remedies;
j
To consider adopting or reviewing legislation, regulations or policies to ensure that all business enterprises, including social media enterprises and other online platforms, fully incorporate the right to privacy and other relevant human rights into the design, development, deployment and evaluation of technologies, including artificial intelligence, to take appropriate steps to improve and encourage corporate accountability, and to provide individuals whose rights may have been violated or abused with access to an effective remedy, including reparation and guarantees of non-repetition;
k
To further develop or maintain in this regard preventive measures and remedies for violations and abuses regarding the right to privacy in the digital age that may affect all individuals, including where there are particular effects for women, children, persons in vulnerable situations or marginalized groups;
l
To develop, review, implement and strengthen gender-responsive policies and programmes that contribute to the empowerment of all women and girls and promote and protect the right of all individuals to privacy in the digital age;
m
To provide effective and up-to-date guidance to business enterprises on how to respect human rights by advising on appropriate methods, including human rights due diligence, and on how to consider effectively issues of gender, vulnerability and/or marginalization, and to consider appropriate measures that would enable business enterprises to adopt adequate voluntary transparency measures with regard to requests by State authorities for access to private user data and information;
n
To refrain from the use of surveillance technologies in a manner that is not compliant with international human rights obligations, including when used against human rights defenders, journalists and other media workers, and to take specific actions to protect against violations of the right to privacy, including by regulating the sale, transfer, use and export of surveillance technologies;
o
To promote accessible, inclusive quality education and lifelong education opportunities for all to foster, inter alia, digital and data literacy and the technical skills, including by providing online safety training, guidance and awareness-raising, required to protect effectively their privacy, and to ensure the availability of appropriate training for relevant stakeholders in this area;
p
To refrain from requiring business enterprises to take steps that interfere with the right to privacy in an arbitrary or unlawful way, and to protect individuals from harm, including that caused by business enterprises through data collection, processing, storage and sharing and profiling, and the use of automated processes and machine learning;
q
To enhance efforts to combat discrimination resulting from the use of artificial intelligence systems, including by exercising due diligence to assess, prevent and mitigate the adverse human rights impacts of their deployment;
11
Encourages all business enterprises, in particular business enterprises that collect, store, use, share and process data:
a
To review their business models and ensure that their design and development processes, business operations, data collection and data processing practices are in line with the Guiding Principles on Business and Human Rights: Implementing the United Nations “Protect, Respect and Remedy” Framework, and to emphasize the importance of conducting human rights due diligence of their products, in particular of the role of algorithms and ranking systems;
b
To inform users, in a clear and age-appropriate way that is easily accessible, including for persons with disabilities, about the collection, use, sharing and retention of their data that may affect their right to privacy, to refrain from doing so without their consent or a legal basis, and to establish transparency and policies that allow for the free, informed and meaningful consent of users;
c
To integrate the right to privacy and other relevant human rights into internal policymaking, product engineering, business development, staff training and other relevant internal processes;
d
To implement administrative, technical and physical safeguards to ensure that data are processed lawfully, to ensure that such processing is necessary in relation to the purposes of the processing and that the legitimacy of such purposes, and the accuracy, integrity and confidentiality of the processing are ensured, and to prevent the unauthorized disclosure or use of data;
e
To ensure that individuals have access to their data and the possibility to amend, correct, update, delete and withdraw consent for the use of their data, in particular if the data are incorrect or inaccurate or if the data were obtained illegally or used for discriminatory purposes;
f
To ensure that respect for the right to privacy and other relevant human rights is incorporated into the design, operation, evaluation and regulation of automated decision-making and machine-learning technologies, and to provide effective remedies, including compensation, for human rights abuses that they have caused or to which they have contributed or been linked;
g
To put in place adequate safeguards that seek to prevent or mitigate adverse human rights impacts that are directly linked to their operations, products or services, including where necessary through contractual clauses, and to promptly inform relevant domestic, regional or international oversight bodies of abuses or violations when misuse of their products and services is detected;
h
To enhance efforts to combat discrimination resulting from the use of artificial intelligence systems, including through human rights due diligence and monitoring and evaluation of artificial intelligence systems across their life cycle, and the human rights impact of their deployment;
i
To promote the transparency and adequate explainability of algorithmic decision-making, automated systems and human-in-the-loop systems, and to ensure that data used for the training of algorithms are representative and legally collected;
j
To put in place appropriate safeguard measures to ensure that the distribution and transfer of data within and among organizations and/or the rearrangement of data, including through cloud computing, unstructured datasets, blockchain technology, augmented reality and the Internet of things, are compatible with data protection and the right to privacy;
k
To take appropriate measures throughout the life cycle of artificial intelligence systems and digital technologies, including before commencing the design and development of applications and software that involve processing personal data, with a view to establishing a risk monitoring and management system to ensure that data are processed fairly and lawfully;
12
Encourages business enterprises, including communications service providers, to work towards enabling solutions to secure and protect the confidentiality of digital communications and transactions, including measures for encryption, pseudonymization and anonymity, and to ensure the implementation of human-rights compliant safeguards, and calls upon States to promote measures and technical solutions for strong encryption, pseudonymization and anonymity, not to interfere with the use of such technical solutions, with any restrictions thereon complying with States’ obligations under international human rights law, and to enact policies that protect the privacy of individuals’ digital communications;
13
Encourages States and, where applicable, business enterprises to systematically conduct human rights due diligence throughout the life cycle of the artificial intelligence systems that they conceptualize, design, develop, deploy or sell or obtain and operate, including through regular and comprehensive human rights impact assessments and the participation of all relevant stakeholders;
14
Encourages all relevant stakeholders to mainstream a gender perspective into the conceptualization, development and implementation of digital technologies and related policies and to promote the participation of women in order to address violence and discrimination against all women and girls that occur through or are amplified by the use of technology by, inter alia, encouraging digital technology companies, including Internet service providers, to respect standards and implement transparent and accessible reporting mechanisms;
15
Requests the Office of the United Nations High Commissioner for Human Rights to prepare a report on challenges and risks with regard to discrimination and unequal enjoyment of the right to privacy associated with the collection and processing of data, including those addressed in the present resolution, to identify and clarify related human rights principles, safeguards and best practices, and to present the report to the Human Rights Council at its fifty-seventh session, to be followed by an interactive dialogue;
16
Also requests the Office of the High Commissioner, when preparing the above-mentioned report, to seek input from and to take into account the work already done by relevant stakeholders from diverse geographical regions, including States, international and regional organizations, the special procedures of the Human Rights Council, the treaty bodies, other relevant United Nations offices, agencies, funds and programmes, within their respective mandates, national human rights institutions, civil society, the private sector, the technical community and academic institutions.

iParagraph content is machine-extracted from UN documents. For authoritative content, please refer to the official UN document.

Table of contents

No headings found in this document.