United Nations Mandate Source RegistryBeta Version
UN Secretariat MandatesUN System Mandates
United Nations (opens in new tab)
(opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab)
Donate (opens in new tab)
  • A-Z Site Index (opens in new tab)
  • Contact (opens in new tab)
  • Copyright (opens in new tab)
  • FAQ (opens in new tab)
  • Fraud Alert (opens in new tab)
  • Privacy Notice (opens in new tab)
  • Terms of Use (opens in new tab)

The Right to Privacy in the Digital Age

A/RES/77/211View PDF

Who created this mandate?

A Resolution of the General Assembly, under agenda item 68bHuman rights questions, including alternative approaches for improving the effective enjoyment of human rights and fundamental freedoms, published in 2022.

What other versions does this mandate have?

11 versions · 2014–2024
This is an older version — the most recent is A/RES/79/175
  • 2024A/RES/79/175The right to privacy in the digital ageLatestCompare with previous version
  • 2023A/RES/77/211The right to privacy in the digital ageCompare with previous version
  • 2020A/RES/75/176The right to privacy in the digital ageCompare with previous version
  • 2019A/RES/73/179The right to privacy in the digital ageCompare with previous version
  • 2019A/HRC/RES/42/15The right to privacy in the digital ageCompare with previous version

iVersions are identified automatically by matching titles within the same organ (~97% accuracy on a manual audit).

Who cites this mandate in the budget?

1 entity

A dot marks an entity citing this document in its “Mandates and background” narrative rather than only its Legislative mandates list. Many do both.

iExtracted automatically from each entity’s budget submission.

What subjects does this mandate have?

5 topics
Communication TechnologyCybercrimeData ProtectionDigital TechnologyRight to Privacy

What does this mandate say?

39 operative paragraphs
1
Reaffirms the right to privacy, according to which no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, and the right to the protection of the law against such interference, as set out in article 12 of the Universal Declaration of Human Rights and article 17 of the International Covenant on Civil and Political Rights;
2
Recognizes the global and open nature of the Internet and the rapid advancement in information and communications technologies as a driving force in accelerating progress towards development in its various forms, including in achieving the Sustainable Development Goals;
3
Affirms that the same rights that people have offline must also be protected online, including the right to privacy, with special regard given to the protection of children;
4
Recalls that States should ensure that any interference with the right to privacy is consistent with the principles of legality, necessity and proportionality;
5
Encourages all States to promote an open, secure, stable, accessible and peaceful information and communications technology environment based on respect for international law, including the obligations enshrined in the Charter of the United Nations and human rights instruments;
6
Acknowledges that the conception, design, use, deployment and further development of new and emerging technologies, such as those that involve artificial intelligence, may have an impact on the enjoyment of the right to privacy and other human rights, and that the risks to these rights can and should be avoided and minimized by adapting or adopting adequate regulation or other appropriate mechanisms, in accordance with applicable obligations under international human rights law, for the conception, design, development and deployment of new and emerging technologies, including artificial intelligence, by taking measures to ensure a safe, transparent, accountable, secure and high quality data infrastructure and by developing human rights-based auditing mechanisms and redress mechanisms and establishing human oversight;
7
Calls upon all States:
a
To respect and protect the right to privacy, both online and offline, including in the context of digital communications and new and emerging technologies;
b
To invite all relevant stakeholders to further discuss how emerging phenomena, such as the push for widespread adoption of blockchain, expanded and virtual reality technologies and the development of increasingly powerful neurotechnology, without proper safeguards, have an impact on the enjoyment of the right to privacy and the right to freedom of opinion and expression;
c
To take measures to put an end to violations of the right to privacy and to create the conditions to prevent such violations, including by ensuring that relevant national legislation complies with their obligations under international human rights law;
d
To review, on a regular basis, their procedures, practices and legislation regarding the surveillance of communications, their interception and the collection of personal data, including mass surveillance, interception and collection, as well as regarding the use of profiling, automated decision-making, machine learning and biometric technologies, with a view to upholding the right to privacy by ensuring the full and effective implementation of all their obligations under international human rights law;
e
To establish or maintain existing independent, effective, adequately resourced and impartial judicial, administrative and/or parliamentary domestic oversight mechanisms capable of ensuring transparency, as appropriate, and accountability for State surveillance of communications, their interception and the collection of personal data;
f
To provide individuals whose right to privacy has been violated by unlawful or arbitrary surveillance with access to an effective remedy, consistent with international human rights obligations;
g
To consider developing or maintaining and implementing adequate legislation, in consultation with all relevant stakeholders, including business enterprises, international organizations and civil society, with effective sanctions and appropriate remedies, that protects individuals against violations and abuses of the right to privacy, namely through the unlawful and arbitrary collection, processing, retention, sharing or use of personal data by individuals, Governments, business enterprises and private organizations;
h
To consider developing or maintaining and implementing legislation, regulations and policies to ensure that all business enterprises, including social media enterprises and other online platforms, fully respect the right to privacy and other relevant human rights in the design, development, deployment and evaluation of technologies, including artificial intelligence, and to provide individuals whose rights may have been violated or abused with access to an effective remedy, including compensation and guarantees of non-repetition;
i
To consider adopting or maintaining data protection legislation, regulation and policies, including on digital communication data, that comply with their international human rights obligations, which could include the establishment of national independent authorities with powers and resources to monitor data privacy practices, investigate violations and abuses and receive communications from individuals and organizations, and to provide appropriate remedies;
j
To further develop or maintain, in this regard, preventive measures and remedies for violations and abuses of the right to privacy in the digital age that may affect all individuals, including where there are particular effects for women, as well as children;
k
To consider developing, reviewing, implementing and strengthening gender-responsive policies that promote and protect the right of all individuals to privacy in the digital age;
l
To provide effective and up-to-date guidance to business enterprises on how to respect human rights by advising on appropriate methods, including human rights due diligence, and on how to consider effectively issues of gender, vulnerability and/or marginalization;
m
To promote quality education and lifelong educational opportunities for all to foster, inter alia, digital literacy and technical skills to effectively protect their privacy;
n
To refrain from requiring business enterprises to take steps that interfere with the right to privacy in an arbitrary or unlawful way;
o
To protect individuals from violations or abuses of the right to privacy, including those which are caused by arbitrary or unlawful data collection, processing, storage and sharing, profiling and the use of automated processes and machine learning;
p
To take steps to enable business enterprises to adopt adequate voluntary transparency measures with regard to requests by State authorities for access to private user data and information;
q
To consider developing or to maintain legislation, preventive measures and remedies addressing harm from the processing, use, sale or multiple resale or other corporate sharing of personal data without the individual’s free, explicit, meaningful and informed consent;
r
To ensure that digital or biometric identity programmes are designed, implemented and operated after appropriate technical, regulatory, legal and ethical safeguards are in place and in full compliance with the obligations of States under international human rights law;
8
Calls upon all business enterprises, in particular those that collect, store, use, share and process data:
a
To meet their responsibility to respect human rights in accordance with the Guiding Principles on Business and Human Rights: Implementing the United Nations “Protect, Respect and Remedy” Framework, including the right to privacy in the digital age, and to enhance efforts in this regard;
b
To inform users in a clear, easily accessible and age-appropriate way about the collection, use, sharing and retention of their data that may affect their right to privacy, to refrain from doing so without their consent or a legal basis and to establish and to apply transparency policies that allow for the free, informed and meaningful consent of users, as appropriate;
c
To implement administrative, technical and physical safeguards to ensure that data are processed lawfully and to ensure that such processing is limited to what is necessary in relation to the purposes of the processing and that the legitimacy of such purposes, as well as the accuracy, integrity and confidentiality of the processing, is ensured;
d
To ensure that respect for the right to privacy and other international human rights is incorporated into the design, operation, evaluation and regulation of automated decision-making and machine-learning technologies and to provide for compensation for the human rights abuses that they may cause or to which they may contribute;
e
To ensure that individuals have access to their personal data and to adopt appropriate measures for the possibility to amend, correct, update, delete and withdraw consent for the data, in particular if the data are incorrect or inaccurate, or if the data were obtained illegally;
f
To put in place adequate safeguards that seek to prevent or mitigate adverse human rights impacts that are directly linked to their operations, products or services, including where necessary through contractual clauses or notification of any relevant entities of abuses or violations when misuse of their products and services is detected;
g
To enhance efforts to combat discrimination resulting from the use of artificial intelligence systems, including by exercising due diligence in assessing, preventing and mitigating the adverse human rights impacts of their deployment;
9
Encourages business enterprises to work towards enabling technical solutions to secure and protect the confidentiality of digital communications, which may include measures for encryption, pseudonymization and anonymity, and calls upon States not to interfere with the use of such technical solutions, with any restrictions thereon complying with the obligations of States under international human rights law, and to enact policies that recognize and protect the privacy of individuals’ digital communications;
10
Encourages States and, where applicable, business enterprises to systematically conduct human rights due diligence throughout the life cycle of the artificial intelligence systems that they conceptualize, design, develop, deploy, sell, obtain or operate, including regular and comprehensive human rights impact assessments and the participation of all relevant stakeholders;
11
Encourages all relevant stakeholders to mainstream a gender perspective into the conceptualization, development and implementation of digital technologies and related policies and promote the participation of women in order to address violence and discrimination against women and girls in digital contexts, inter alia, by encouraging digital technology companies, including Internet service providers, to respect standards and implement transparent and accessible reporting mechanisms;
12
Emphasizes that, in the digital age, encryption and anonymity tools have become vital for many journalists and media workers to freely exercise their work and their enjoyment of human rights, in particular their rights to freedom of expression and to privacy, including to secure their communications and to protect the confidentiality of their sources, and calls upon States not to interfere with the use by journalists and media workers of such technologies and to ensure that any restrictions thereon comply with the obligations of States under international human rights law;
13
Encourages all relevant stakeholders to participate in informal dialogues about the right to privacy, and takes note with appreciation of the contribution of the Special Rapporteur of the Human Rights Council on the right to privacy to this process;
14
Decides to continue its consideration of the question at its seventy-ninth session.

iParagraph content is machine-extracted from UN documents. For authoritative content, please refer to the official UN document.

Table of contents

No headings found in this document.