A/HRC/41/35/Add.4 of the technology is not the only concern; governments that purchase such tools also pose a threat to freedom of expression and should hold responsibility as well. 27. The effect of legislation was questioned by multiple participants. Two distinct concerns were raised: (i) States have difficult implementing laws and (ii) companies can bypass State laws. One participant provided Hacking Team as an example where after they were exposed and regulated in Italy, they moved operations and continued operating in the same manner. 28. Participants generally noted that technology has played a role in developing surveillance tools, particularly over the last ten years. However, one participant observed that the sophistication of the targeted surveillance tools is usually low. 29. Participants focused discussion on what a legal framework should look like. A lot of problems were highlighted with the Wassenaar Arrangement including the fact it is nonbinding, lacks transparency, and vaguely formulated. One participant noted that even members of the Wassenaar Arrangement fail to internalize the terms. Suggestions on improving the Wassenaar Arrangement included export controls criteria based on human rights concerns. One participant suggested that there is a lack of standards because there is no information sharing among States. Switzerland was used an example to demonstrate how a state can increase transparency by listing the licenses they approve and deny. However, this begged the question of whether more transparency is always better. It also raises concerns regarding capacity because the more items that the State controls, the more people will be needed to process. One participant expressed concerns regulating software or services like hacking under an export controls regime, since hacking software is already widely available and the service provided is intangible. A participant also stated that before regulating dualuse technology, we need to clearly define it. 30. The European Union has created ambitious goals to create firmer rules on surveillance technologies. However, one participant noted that there are internal clashes between different branches of government within the European Union and internally the EU has outdated frameworks. Participants agreed that the frameworks that exist are lacking an enforcement mechanism and do not cover all relevant technologies. However, there is a lot of information hidden in private-government relationships that hinder civil society’s ability to close the gap. Some participants raised concerns that export-control debate is very westernized and fails to account for the acquisition and use of the technology by importing States. 31. Most participants agreed on the lack of enforcement of human rights standards when it comes to surveillance. Pressures coming from the private industry and IT sector, the lack of common standards for technologies and countries, broad and non-binding international soft law standards were all been mentioned as important issues. 32. The discussion raised important questions, including: (i) who are the targets of espionage, (ii) what are the ideal requirements for law enforcement, (iii) to what extent can the private surveillance industry be analyzed from a consumer rights perspective, and (iv) what is the ideal level of transparency in this industry. D. Session 4: company responsibility: norms and enforcement 33. Almost all participants recognized the importance of the UN Guiding Principles on Business and Human Rights in establishing minimum baseline standards for corporates to respect human rights. Yet, most participants acknowledged that the industry is resistant to change and considered the legal framework for holding private surveillance industry accountable insufficient and unsatisfactory. 34. As possible further normative development, it was suggested that we look to other industries where there is an inherent state function or “service” of the state. One participant suggested analyzing private military contractors. One question here is whether surveillance would be categorized as a service of the state. 35. Additionally, a participant suggested we focus on technical standards and we view security and privacy as consumer needs. A participant raised the possibility of an ethics-based 6

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents