A/RES/79/175
The right to privacy in the digital age
(k) To consider developing, reviewing, implementing and strengthening
gender-responsive policies and programmes that contribute to the empowerment of
all women and girls and promote and protect the right of all individuals to privacy in
the digital age;
(l) To provide effective and up-to-date guidance to business enterprises on
how to respect human rights by advising on appropriate methods, including human
rights due diligence, and on how to consider effectively issues of gender, vulnerability
and/or marginalization;
(m) To promote quality education and lifelong educational opportunities for
all to foster, inter alia, digital literacy and technical skills to effectively protect their
privacy;
(n) To refrain from requiring business enterprises to take steps that interfere
with the right to privacy in an arbitrary or unlawful way;
(o) To protect individuals from violations or abuses of the right to privacy,
including those which are caused by arbitrary or unlawful data collection, processing,
storage and sharing, profiling and the use of automated processes and machine learning;
(p) To take steps to enable business enterprises to adopt adequate voluntary
transparency measures with regard to requests by State authorities for access to
private user data and information;
(q) To consider developing or to maintain legislation, preventive measures and
remedies addressing harm from the processing, use, sale or multiple resale or other
corporate sharing of personal data without the individual’s free, explicit, meaningful
and informed consent;
(r) To ensure that digital or biometric identity programmes are designed,
implemented and operated after appropriate technical, regulatory, legal and ethical
safeguards are in place and in full compliance with the obligations of States under
international human rights law;
(s) To ensure that established national independent authorities dedicated to
data protection include proper oversight mechanisms;
9.
Calls upon all business enterprises, in particular those that collect, store,
use, share and process data:
(a) To review their business models and ensure that their design and
development processes, business operations, data collection and data processing
practices are in line with the Guiding Principles on Business and Human Rights:
Implementing the United Nations “Protect, Respect and Remedy” Framework, and to
emphasize the importance of conducting human rights due diligence of their products,
in particular of the role of algorithms and ranking systems;
(b) To inform users, in a clear and age-appropriate way that is easily
accessible, including for persons with disabilities, about the collection, use, sharing
and retention of their data that may affect their right to privacy, to refrain from doing
so without their consent or a legal basis and to establish and to apply transparency
policies that allow for the free, informed and meaningful consent of users, as
appropriate;
(c) To implement administrative, technical and physical safeguards to ensure
that data are processed lawfully and to ensure that such processing is limited to what
is necessary in relation to the purposes of the processing and that the legitimacy of
such purposes, as well as the accuracy, integrity and confidentiality of the processing,
is ensured;
10/12
24-24216