A/HRC/28/39 effective control. If surveillance involved the exercise of power or effective control by a State in relation to digital communications infrastructure, then wherever it might be taking place, that surveillance might engage the human rights obligations of the State. That would include, for example, direct tapping or penetration of a communications infrastructure and exercise by the State of regulatory jurisdiction over a third party which physically controlled the data. 13. The report recalled that international human rights law was also explicit on the principle of non-discrimination and that States must take measures to ensure that any interference with the right to privacy complied with the principles of legality, proportionality and necessity, regardless of the ethnicity, nationality, location or other status of the people whose communications it was monitoring. 14. The report also referred to the essential nature of procedural safeguards and effective oversight to safeguard the right to privacy in law and in practice. A lack of effective oversight had contributed to impunity for arbitrary or unlawful intrusions on the right to privacy in the digital environment. Internal safeguards devoid of independent oversight had been demonstrably ineffective against unlawful or arbitrary surveillance methods. Appropriate safeguards must include independent civilian oversight and participation from all branches of Government, in order to ensure the effective protection of the law. States also had a legal obligation to provide effective remedies for violations of privacy through digital surveillance, in judicial, legislative or administrative forms, with procedures that were known and accessible. 15. Finally, the Deputy High Commissioner referred to the role of the private sector, an issue also addressed in the report of the High Commissioner. Governments increasingly relied on corporations to conduct and facilitate digital surveillance. In some cases there might be legitimate reasons for a company to provide user data. But when the request was in violation of human rights law, or where the information was used in violation of human rights law, that company risked being complicit in human rights abuses. The Guiding Principles on Business and Human Rights, endorsed by the Human Rights Council in resolution 17/4 of 16 June 2011, provided a global standard for preventing and addressing adverse the human rights effects of business activity. They made clear that the responsibility to protect human rights applied throughout a company’s global operations, regardless of where its users were located, and independently of whether a State met its own human rights obligations. Many corporations appeared to be insufficiently aware of those issues. 16. The Deputy High Commissioner concluded by noting that the lack of government transparency regarding the measures that they had adopted that might impact on the right to privacy, often rendered attempts to address the gaps and exercise accountability extremely arduous. She concluded that there was a clear need for further discussion and in-depth analysis as information regarding those measures became public. III. Contributions of panellists 17. In response to questions from the moderator, the initial remarks of the panellists focused on issues linked to the international human rights law framework with respect to the right to privacy, including procedural safeguards, effective oversight and right to a remedy, as well as the role of the business sector. 18. The Legal Director at Privacy International highlighted the importance of privacy in any democratic society and stressed the links between privacy and the concept of human dignity. She noted that the right to privacy was a fundamental precondition to, and guarantor of, other rights, as it enabled individuals to independently develop thoughts and 5

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents