A/79/173 and would happen to the data collected from millions of people from all countries in the world in order to combat the pandemic. 35. The Special Rapporteur drew a number of conclusions and made the following recommendations on the basis of an analysis of 20 countries in Africa, the Americas, Asia, Europe and Oceania: • Ensure [genuine and effective compliance] with the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in respect of the data of millions of people that were collected for the purpose of detecting and/or combating COVID-19 and tracking its spread with a view to protecting public health and preventing its transmission. • Reinforce the application of the principle of demonstrated or proactive responsibility in all programmes and policies involving the processing of personal data. This requires [States], among other things, to adopt relevant, appropriate, timely and effective measures to comply with the legal obligations established in personal data processing regulations. Such measures should be subject to ongoing review and evaluation in order to gauge how effective they are in terms of ensuring compliance and the protection of personal data. • Implement processes and use tools that demonstrate and provide evidence of due compliance with [national] obligations. Such processes and tools should be transparent and easily verifiable by the competent public authorities and the public in general. • It is suggested that, before commencing the design and development of applications and software that involve processing personal data for the purpose of carrying out State functions, States should take proactive, preventive measures with a view to establishing a risk monitoring and management system that will ensure that data are processed fairly and lawfully. • Cement a public culture that fosters transparent and ethical processing of personal data, with all due safeguards, so as to ensure that transparency becomes an essential component in the design and implementation of all public programmes and policies that involve the processing of personal data. • Build and consolidate levels of public confidence in the programmes of public entities that involve the processing of personal data by implementing transparent, publicly accessible mechanisms that allow citizens to verify, through a simple process and at any time, that public entities comply in practice with the procedures and commitments set forth in their policy notices and/or terms and conditions for activities that involve the collection, use and exchange of personal data or any other activity in which personal data are processed. 27 III. Some thematic gaps in General Assembly resolution 45/95 as compared with international documents on personal data processing 36. Because General Assembly resolution 45/95 was adopted in 1990, its content is outdated compared with that of subsequent international documents. This can be seen from a comparative analysis of the resolution and the following documents: • APEC Privacy Framework, 2004 __________________ 27 12/23 Ibid., paras. 27–32. 24-13146

Select target paragraph3