A/79/173
quality, responsibility and security. She also highlighted the common aspects of the
international documents in relation to the principles in order to build bridges between
those documents and establish points of contact so as to facilitate harmonization a t
the global level.
19.
She drew the following conclusions in that report:
• The guiding principles underpinning privacy and personal data protection are a
structural part of the legal systems relating to those issues. Those principles
serve as guidelines for interpretation, help to fill gaps in the law and require
controllers and processors to act appropriately in processing personal data.
• Legality must be the foundation for all processing activities throughout the life
cycle of personal data and is based on the existence of legitimate grounds, as
established in the applicable regulations.
• The principle of consent is closely linked to the principle of legality, as it is the
most common internationally recognized permissible grounds for the processing
of personal data.
• The principle of transparency must be observed regardless of the legal basis for
the processing.
• The principle of purpose is established in all the regulatory documents analysed.
The purpose must be explicit, specific, legitimate and relevant. It functions as a
delimiter of the processing activities that the personal data will undergo.
• The principle of fairness requires that personal information be processed in
faithful compliance with all the terms and conditions that provided grounds for
its collection and using processing methods that facilitate this objective.
• In accordance with the principle of proportionality, the use of personal data, and
the processing activities that such data undergo, must be solely for the fulfilment
of the legitimate purposes for which the data were collected.
• The quality of the personal information being processed is vital for the proper
achievement of the purposes that provided grounds for the collection of that
information, as well as for its subsequent processing.
• The principle of responsibility tends to strengthen compliance with principles
and regulations, and ensure that objective elements underpin genuine
compliance and the fulfilment of legitimate purposes, in a climate of trust and
respect for the fundamental rights involved.
• There can be neither data protection nor respect for privacy without security.
Ensuring the integrity, availability and confidentiality of personal data is an
essential task and a major responsibility. The variety of technologies and their
dynamic transformation must be taken into account in order to evaluate risks
and appropriate security measures in a responsible and ethical manner.
• There are many commonalities in how the international regulatory documents
address the principles of privacy and personal data protection.
• The common elements identified could serve as a basis for moving towards a
global consensus that will make it possible to address, in a concerted and
appropriate manner, the various challenges that arise in the processing of
personal data, such as international data transfers, the use of information and
communications technology and artificial intelligence; human rights deserve
equal respect in virtual and in face-to-face environments.
24-13146
7/23