A/RES/79/175 The right to privacy in the digital age (k) To consider developing, reviewing, implementing and strengthening gender-responsive policies and programmes that contribute to the empowerment of all women and girls and promote and protect the right of all individuals to privacy in the digital age; (l) To provide effective and up-to-date guidance to business enterprises on how to respect human rights by advising on appropriate methods, including human rights due diligence, and on how to consider effectively issues of gender, vulnerability and/or marginalization; (m) To promote quality education and lifelong educational opportunities for all to foster, inter alia, digital literacy and technical skills to effectively protect their privacy; (n) To refrain from requiring business enterprises to take steps that interfere with the right to privacy in an arbitrary or unlawful way; (o) To protect individuals from violations or abuses of the right to privacy, including those which are caused by arbitrary or unlawful data collection, processing, storage and sharing, profiling and the use of automated processes and machine learning; (p) To take steps to enable business enterprises to adopt adequate voluntary transparency measures with regard to requests by State authorities for access to private user data and information; (q) To consider developing or to maintain legislation, preventive measures and remedies addressing harm from the processing, use, sale or multiple resale or other corporate sharing of personal data without the individual’s free, explicit, meaningful and informed consent; (r) To ensure that digital or biometric identity programmes are designed, implemented and operated after appropriate technical, regulatory, legal and ethical safeguards are in place and in full compliance with the obligations of States under international human rights law; (s) To ensure that established national independent authorities dedicated to data protection include proper oversight mechanisms; 9. Calls upon all business enterprises, in particular those that collect, store, use, share and process data: (a) To review their business models and ensure that their design and development processes, business operations, data collection and data processing practices are in line with the Guiding Principles on Business and Human Rights: Implementing the United Nations “Protect, Respect and Remedy” Framework, and to emphasize the importance of conducting human rights due diligence of their products, in particular of the role of algorithms and ranking systems; (b) To inform users, in a clear and age-appropriate way that is easily accessible, including for persons with disabilities, about the collection, use, sharing and retention of their data that may affect their right to privacy, to refrain from doing so without their consent or a legal basis and to establish and to apply transparency policies that allow for the free, informed and meaningful consent of users, as appropriate; (c) To implement administrative, technical and physical safeguards to ensure that data are processed lawfully and to ensure that such processing is limited to what is necessary in relation to the purposes of the processing and that the legitimacy of such purposes, as well as the accuracy, integrity and confidentiality of the processing, is ensured; 10/12 24-24216

Select target paragraph3