A/79/173
and would happen to the data collected from millions of people from all countries in
the world in order to combat the pandemic.
35. The Special Rapporteur drew a number of conclusions and made the following
recommendations on the basis of an analysis of 20 countries in Africa, the Americas,
Asia, Europe and Oceania:
• Ensure [genuine and effective compliance] with the principles of purpose
limitation, deletion of data and demonstrated or proactive accountability in
respect of the data of millions of people that were collected for the purpose of
detecting and/or combating COVID-19 and tracking its spread with a view to
protecting public health and preventing its transmission.
• Reinforce the application of the principle of demonstrated or proactive
responsibility in all programmes and policies involving the processing of
personal data. This requires [States], among other things, to adopt relevant,
appropriate, timely and effective measures to comply with the legal obligations
established in personal data processing regulations. Such measures should be
subject to ongoing review and evaluation in order to gauge how effective they
are in terms of ensuring compliance and the protection of personal data.
• Implement processes and use tools that demonstrate and provide evidence of
due compliance with [national] obligations. Such processes and tools should be
transparent and easily verifiable by the competent public authorities and the
public in general.
• It is suggested that, before commencing the design and development of
applications and software that involve processing personal data for the purpose
of carrying out State functions, States should take proactive, preventive
measures with a view to establishing a risk monitoring and management system
that will ensure that data are processed fairly and lawfully.
• Cement a public culture that fosters transparent and ethical processing of
personal data, with all due safeguards, so as to ensure that transparency becomes
an essential component in the design and implementation of all public
programmes and policies that involve the processing of personal data.
• Build and consolidate levels of public confidence in the programmes of public
entities that involve the processing of personal data by implementing
transparent, publicly accessible mechanisms that allow citizens to verify,
through a simple process and at any time, that public entities comply in practice
with the procedures and commitments set forth in their policy notices and/or
terms and conditions for activities that involve the collection, use and exchange
of personal data or any other activity in which personal data are processed. 27
III. Some thematic gaps in General Assembly resolution 45/95
as compared with international documents on personal
data processing
36. Because General Assembly resolution 45/95 was adopted in 1990, its content is
outdated compared with that of subsequent international documents. This can be seen
from a comparative analysis of the resolution and the following documents:
• APEC Privacy Framework, 2004
__________________
27
12/23
Ibid., paras. 27–32.
24-13146