UNHRDB › Special Procedures reports › SR Privacy

A/79/173

Proposal for the updating of General Assembly resolution 45/95 of 14 December 1990, entitled “Guidelines for the regulation of computerized personal data files”

SR Privacy · 17 July 2024 · Mandate-holder: Ana Brian Nougrères · 37 paragraphs

Search and read in the UNHRDB app · Official text (UN Documents)

I. Background and justification

¶1

In accordance with the Charter of the United Nations, signed on 26 June 1945,1 one of the objectives of the United Nations is “to achieve international co-operation ... in promoting and encouraging respect for human rights and for fundamental freedoms for all without distinction as to race, sex, language or religion”.2 The rights of individuals with respect to the processing of their personal data are therefore also among the concerns of the United Nations.

  1. The official text of the Charter of the United Nations is available on the Organization’s website: www.un.org/about-us/un-charter. ↩
  2. Article 1, paragraph 3, of the Charter of the United Nations. Other purposes of the United Nations set forth in Article 1 are: “1. To maintain international peace and security ...; 2. To develop friendly relations among nations based on respect for the principle of equal rights and self-determination of peoples, and to take other appropriate measures to strengthen universal peace; 3. To achieve international co-operation in solving international problems of an economic, social, cultural, or humanitarian character, and in promoting and encouraging respect for human rights and for fundamental freedoms for all without distinction as to race, sex, language, or religion; and 4. To be a centre for harmonizing the actions of nations in the attainment of these common ends”. ↩
¶2

By its resolution 45/95 of 14 December 1990, the General Assembly3 adopted the Guidelines for the regulation of computerized data files.4 This resolution was preceded by Commission on Human Rights resolution 1990/42 of 6 March 1990 and Economic and Social Council resolution 1990/38 of 25 May 1990, entitled “Guidelines on the use of computerized personal files”. These guidelines are not legally binding on States but have been very important and have been incorporated by Governments into their domestic regulations and cited by judges and academics.

  1. The General Assembly is the chief deliberative, policymaking and representative organ of the United Nations (www.un.org/en/ga/about/background.shtml). ↩
  2. The principles apply to the computerized files of public and private entities. They can also be applied, subject to certain adjustments, to manual files (see para. 10 of the Guidelines). ↩
¶3

Resolution 45/95 was adopted in 1990 in response to the socio-technological realities of that time. Since then, new technological phenomena have arisen and advancements have been made that have transformed our society and are part of our daily lives. For example:
• The emergence and expansion of public use of the Internet have revolutionized the way in which we gain access to and share information from all over the world.
• Smartphones have become essential for communication, work, education and entertainment.
• Digital social networks have transformed online communication and social connection.
• Cloud computing has changed the way in which businesses and individuals manage information, as it allows them to gain access to and store online data and applications from around the world, from anywhere in the world.
• Big data has enabled sophisticated analysis and decision-making based on the processing of large quantities of data.
• Artificial intelligence is generating enormous expectations and changes owing to its advanced algorithms and its production of information.
• The Internet of things enables the interconnection of physical devices through the Internet and the sharing of information in order to automate and remotely control various systems.
• Virtual reality and augmented reality have made it possible to create new digital experiences, including games, training applications and simulations.
• Advancements in artificial intelligence and sensors have enabled cars to operate independently, thereby transforming the transportation industry and the way in which people travel.
• Neurotechnology has led to detailed knowledge of the brain and information on the neural systems of individuals (highly sensitive data).

¶4

None of these technological developments had taken place when General Assembly resolution 45/95 was adopted. It is therefore necessary to update them in order to bring them into line with the socio-technological reality of the twenty-first century. In addition, current technology allows data to be collected anywhere in the world from individuals domiciled or residing in other countries. This phenomenon, known as “international data collection”,5 is not envisaged in General Assembly resolution 45/95. As the means by which data are most frequently collected from individuals worldwide, it should be incorporated into international documents.

  1. Nelson Remolina Angarita, Recolección internacional de datos personales: un reto del mundo post-internet (Madrid, Spain, Official Gazette, 2015). ↩
¶5

Information is also essential to the functioning of technological tools, such as artificial intelligence, given that an algorithm, by itself, is not sufficient to produce a result; the result comes from the processing and analysis of information.

¶6

Personal data is a specific category of information. Such data are so valuable that they have been referred to as the “currency of the digital economy”. For example, at the end of December 2022, the Organisation for Economic Co-operation and Development (OECD) adopted the Declaration on a Trusted, Sustainable and Inclusive Digital Future,6 which highlights, among other things, “the outcomes of the OECD Horizontal Project on Data Governance for Growth and Well-being … which recognise the importance of data as a driver of the global economy” (emphasis added).

  1. Organisation for Economic Co-operation, “Declaration on a Trusted, Sustainable and Inclusive Digital Future”. The Declaration was the outcome of the meeting held on the island of Gran Canaria, Spain, on 14 and 15 December 2022. The official text is available at https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0488. ↩
¶7

OECD has committed itself to, among other things, “advancing a human-centric and rights-oriented digital transformation that includes promoting the enjoyment of human rights, both offline and online, strong protections for personal data, laws and regulations fit for the digital age, and trustworthy, secure, responsible and sustainable use of emerging digital technologies and artificial intelligence”.7

  1. Ibid. ↩
¶8

On 23 January 2023, the European Parliament, the Council of the European Union and the European Commission adopted the European Declaration on Digital Rights and Principles for the Digital Decade,8 in whose chapter III, entitled “Freedom of choice”, under the subheading “A fair digital environment”, they committed themselves to, among other things, “ensuring a safe and secure digital environment based on fair competition, where fundamental rights are protected, users’ rights and consumer protection in the Digital Single Market are ensured, and responsibilities of platforms, especially large players and gatekeepers, are well defined”.

  1. European Parliament, Council of the European Union and European Commission, European Declaration on Digital Rights and Principles for the Digital Decade (2023/C 23/01), 23 January 2023. The official text is available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri= OJ%3AJOC_2023_023_R_0001. ↩
¶9

All of the above has led to a review, across the world, of relevant international documents on data processing and of local laws, with a view to modernizing them. In that regard, in October 2023, the Global Privacy Assembly (GPA) adopted a resolution aimed at achieving global data protection standards, in which it set forth principles to ensure high levels of data protection and privacy worldwide and emphasized a decades-old idea, namely, that there should be global standards on data protection and privacy. In the resolution, GPA therefore promoted certain principles, rights and other elements as important for achieving high levels of data protection and privacy, and resolved to advocate, promulgate and promote the principles, rights and other elements set out in the resolution, to ensure that they could be effectively implemented and applied in all contexts, particularly in the processing of data with new and emerging technologies and innovations.9

  1. GPA, resolution entitled “Achieving global data protection standards: Principles to ensure high levels of data protection and privacy worldwide”, October 2023. Available at https://globalprivacyassembly.org/document-archive/adopted-resolutions/. ↩
¶10

In the resolution, GPA emphasized the importance of providing for the protection of personal data across borders with a range of transfer mechanisms, such as adequacy, model clauses, certifications and administrative arrangements, to ensure that protection travels with the data when the data cross borders. It also noted the benefits of building on commonalities, complementarities and elements of convergence in order to foster future interoperability between existing regulatory approaches and mechanisms enabling safe, trustworthy cross-border data flows.10

  1. Ibid. ↩
¶11

Such international regulatory harmonization began in the twentieth century, with the Council of Europe, OECD, the United Nations, the European Parliament and the Council of the European Union as the main stakeholders. In the twenty-first century, they were joined by the Asia-Pacific Economic Cooperation forum (APEC), the Ibero-American Data Protection Network and GPA, formerly known as the International Conference of Data Protection and Privacy Commissioners.

¶12

In that connection, the Ibero-American Data Protection Network has stated that the “establishment of a harmonized framework for data protection at the global level has been the main basis for the adoption of the various current international instruments on data protection. The aim is to ensure that the development of global commerce is compatible with the protection of the rights of individuals, especially with regard to the protection of information concerning them”.11

  1. Ibero-American Data Protection Network, “Guidelines for Harmonization of Data Protection in the Ibero-American Community”, p. 1 (2007). The Ibero-American Data Protection Network goes on to state that “therefore, the establishment of a homogeneous framework for the regulation of the right to data protection, either through the adoption of binding supranational instruments or of national laws enshrining the essential content of that right, will ensure the development of commerce in the area, facilitating the exchange of information between the various operators located in the Ibero-American States and between those States and third countries, in particular the States members of the European Union, without restrictions resulting from differences in the level of protection of the fundamental right to the protection of personal data”. ↩
¶13

Lastly, mention should be made of cyberspace as the milieu in which millions of people in the world coexist.

¶14

Personal data circulate daily in cyberspace. However, the regulation of data processing arose in an environment in which cyberspace was not yet being discussed. In other words, the current socio-technological reality is not the socio-technological reality that existed when the first regulations on personal data protection were issued.

¶15

However, information and personal data are a central and indispensable part of cyberspace. Although there are different definitions of cyberspace, it should be understood as comprising the following aspects:
• Technological infrastructure (technological resources) composed of countless pieces of equipment (servers, computers, cell phones, tablets, etc.) located in many parts of the world
• A worldwide platform for communications (global communications network), information and interconnected networks (Internet), known as “global information infrastructure”
• Millions of people and organizations of diverse nationalities that are based in countries with dissimilar legal systems and that, from anywhere in the world, use technology, communications and information to interact with other people, and utilize the services available on the Internet
• Huge amounts of information (including personal data) that are constantly circulating within countries and across borders

¶16

Little by little, we are witnessing a shift from a physical world demarcated by geographical borders to a technological cyberspace without borders, in which the number of people interacting at any one time is gradually increasing.

¶17

The global, international and cross-border nature of many activities conducted through the Internet, such as e-commerce, has been a key aspect that has led to the need for appropriate regulations in order to promote development and innovation, and to sufficiently protect the right of individuals whose information is collected and used by companies, people and Governments throughout the world. In the Declaration on the Use of Scientific and Technological Progress in the Interests of Peace and for the Benefit of Mankind,12 the General Assembly recognizes not only that “scientific and technological progress is of great importance in accelerating the social and economic development of developing countries”, but also that, while such developments “provide ever-increasing opportunities to better the conditions of life of peoples and nations, in a number of instances they can give rise to social problems, as well as threaten the human rights and fundamental freedoms of the individual”. For this reason, the Assembly continues, there is a “need to make full use of scientific and technological developments for the welfare of man and to neutralize the present and possible future harmful consequences of certain scientific and technological achievements”. Consequently, the Assembly agreed, among other things, that: “all States shall take effective measures, including legislative measures, to prevent and preclude the utilization of scientific and technological achievements to the detriment of human rights and fundamental freedoms and the dignity of the human person”.13

  1. General Assembly resolution 3384 (XXX) of 10 November 1975. ↩
  2. Ibid., para. 8. ↩

II. Reports of the Special Rapporteur on the right to privacy on issues relevant to the updating of General Assembly resolution 45/95

¶18

In a 2022 report,14 the Special Rapporteur conducted a comparative study of seven international documents in order to determine the scope of the following principles relating to the processing of personal data: legality, lawfulness and legitimacy, consent, transparency, purpose, fairness, proportionality, minimization, quality, responsibility and security. She also highlighted the common aspects of the international documents in relation to the principles in order to build bridges between those documents and establish points of contact so as to facilitate harmonization at the global level.

  1. “Principles underpinning privacy and the protection of personal data”, report of the Special Rapporteur on the right to privacy (A/77/196, 20 July 2022). ↩
¶19

She drew the following conclusions in that report:
• The guiding principles underpinning privacy and personal data protection are a structural part of the legal systems relating to those issues. Those principles serve as guidelines for interpretation, help to fill gaps in the law and require controllers and processors to act appropriately in processing personal data.
• Legality must be the foundation for all processing activities throughout the life cycle of personal data and is based on the existence of legitimate grounds, as established in the applicable regulations.
• The principle of consent is closely linked to the principle of legality, as it is the most common internationally recognized permissible grounds for the processing of personal data.
• The principle of transparency must be observed regardless of the legal basis for the processing.
• The principle of purpose is established in all the regulatory documents analysed. The purpose must be explicit, specific, legitimate and relevant. It functions as a delimiter of the processing activities that the personal data will undergo.
• The principle of fairness requires that personal information be processed in faithful compliance with all the terms and conditions that provided grounds for its collection and using processing methods that facilitate this objective.
• In accordance with the principle of proportionality, the use of personal data, and the processing activities that such data undergo, must be solely for the fulfilment of the legitimate purposes for which the data were collected.
• The quality of the personal information being processed is vital for the proper achievement of the purposes that provided grounds for the collection of that information, as well as for its subsequent processing.
• The principle of responsibility tends to strengthen compliance with principles and regulations, and ensure that objective elements underpin genuine compliance and the fulfilment of legitimate purposes, in a climate of trust and respect for the fundamental rights involved.
• There can be neither data protection nor respect for privacy without security. Ensuring the integrity, availability and confidentiality of personal data is an essential task and a major responsibility. The variety of technologies and their dynamic transformation must be taken into account in order to evaluate risks and appropriate security measures in a responsible and ethical manner.
• There are many commonalities in how the international regulatory documents address the principles of privacy and personal data protection.
• The common elements identified could serve as a basis for moving towards a global consensus that will make it possible to address, in a concerted and appropriate manner, the various challenges that arise in the processing of personal data, such as international data transfers, the use of information and communications technology and artificial intelligence; human rights deserve equal respect in virtual and in face-to-face environments.
• It is necessary to continue making progress towards finding a balance between the different interests involved in the processing of personal data in the current global and digital era, in pursuit of regulatory cooperation and harmonization.15

  1. Ibid., paras. 138–150. ↩
¶20

In a 2021 report on artificial intelligence and privacy, and children’s privacy,16 the Special Rapporteur provided the information described below.

  1. “Artificial intelligence and privacy, and children’s privacy”, report of the Special Rapporteur on the right to privacy (A/HRC/46/37, 25 January 2021). ↩
¶21

First, with respect to children’s privacy, he concluded that it was necessary, among other things, to adopt policies, laws and standards which:
• Cast children as the bearers of human rights where their rights to privacy, autonomy and equality are inalienable.
• Incorporate the broad scope of privacy, not solely data protection, to enable the full development of children’s potential.
• Incorporate children’s views, children’s strategies for privacy, findings of child-focused research and/or child privacy impact assessments in public policy settings.
• Provide independent means to conciliate, arbitrate and remedy individual or systemic human rights violations against children and ensure that enforcement measures are taken in case of infringements.17

  1. Ibid., para. 126. ↩
¶22

He also made the following recommendations:
• Ensure that biometric data is not collected from children, unless as an exceptional measure only when lawful, necessary, proportionate and fully in line with the rights of the child.
• Ensure that children’s personal data is processed fairly, accurately, securely, for a specific purpose in accordance with a legitimate legal basis utilizing data protection frameworks representing best practice, such as the General Data Protection Regulation and Convention 108+.
• Ensure that those who process personal data, including parents or carers and educators, are made aware of children’s right to privacy and data protection.
• Ensure that information is available to children on exercising their rights on, for example, the websites of data protection authorities, and ensure the provision of counselling, complaint mechanisms and remedies specifically for children, including for cyberbullying.
• Prohibit automated processing of personal data that profiles children for decision-making concerning the child or to analyse or predict personal preferences, behaviour and attitudes, with exemption only in exceptional circumstances in the best interests of the child or an overriding public interest, with appropriate legal safeguards.18

  1. Ibid., para. 127. ↩
¶23

Second, the Special Rapporteur made recommendations on the protection of privacy in the development and implementation of artificial intelligence-based solutions, in order to “provide guiding principles concerning the use of personal and non-personal information in the context of artificial intelligence (AI) solutions developed as part of applied information and communications technologies (ICTs), and to emphasize the importance of a legitimate basis for AI data processing by Governments and corporations within the overarching framework of the human right to privacy”.19

  1. Ibid., para. 1. ↩
¶24

He highlighted in the report that both the processing of data through artificial intelligence-based tools and the decision made as a result of such processing have potential risks for the data subject. Therefore, he considered it important to set forth a number of principles that should be taken into account in the planning, development and implementation of artificial intelligence-based solutions, namely: (a) jurisdiction; (b) ethical and lawful basis; (c) data fundamentals; (d) responsibility and oversight; (e) control; (f) transparency and “explainability”; (g) rights of the data subject; and (h) safeguards.

¶25

In a subsequent report, the Special Rapporteur referred to the principles of transparency and explainability in the processing of personal data in artificial intelligence and emphasized the importance of these principles in that context.20

  1. “Principles of transparency and explainability in the processing of personal data in artificial intelligence”, report of the Special Rapporteur on the right to privacy (A/78/310, 30 August 2023). ↩
¶26

These principles are relevant because transparency and explainability not only help to build trust and reliability in artificial intelligence, but also contribute to the protection of human rights. These principles allow individuals affected by artificial intelligence to be informed in a timely, comprehensive, simple and clear manner about basic issues concerning the use of their personal information in artificial intelligence processes or projects and the consequences thereof, and about the specific reasons why they have been affected. This makes it possible for them to exercise their rights, such as the right to due process and to a defence when faced with decisions made using artificial intelligence tools or technologies.

¶27

In the report, the Special Rapporteur indicated that artificial intelligence involved different types of risk. The contingencies that should be considered include the risks inherent in operating with algorithms (human bias, technical flaws, security vulnerabilities and failures in their implementation), in their design and in the processing of personal data.

¶28

The Special Rapporteur also pointed out that personal data were an input processed by algorithms to produce results. Data input can be affected mainly by bias (incorporation of partial, insufficient, outdated or manipulated data) and pertinence (relevance, inconsistency or completeness of the data). If high-quality and pertinent data are not used, the results will be erroneous. Algorithms, for their part, can be affected by patterns (programming logic bias, including unforeseen functions and inherent failures of the functions used for their codification), and errors (operating conditions that reflect a method of operation that differs from the method of operation planned and goes against the premise of the proposed design). These issues have an impact on the results obtained using artificial intelligence-based tools, which are related to the pertinence and precision of the execution of the algorithms and are a result of the analysis of the data input.

¶29

The following were among the conclusions drawn in the report:
(a) Transparency and explainability help to build trust in artificial intelligence and to respect human rights;
(b) Developers of artificial intelligence must be transparent about how data are processed (how they are collected, stored and used), and about how decisions based on artificial intelligence are made, the reliability of such decisions and the security of the information;
(c) Persons affected by decisions made on the basis of artificial intelligence deserve a clear, simple, complete, truthful and understandable explanation of the reasons for that decision. In that regard, the principle of explainability is of cardinal importance not only because it aligns with the principle of transparency, but also because it will make it possible to uphold such persons’ right to a defence and due process;
(d) Explainability and transparency demand clarity, completeness, truthfulness, impartiality and publicity of the decisions made using artificial intelligence and of the logic, method or reasoning for making decisions about human beings based on information, particularly personal data. Explainability and transparency are, of course, the opposite of opacity, obscurity, deceit, lies and abuse of computing power, which are some of the symptoms of illegal and unethical processing that reflects a lack of respect for human beings and their dignity.21

  1. Ibid., para. 63. ↩
¶30

In addition, the Special Rapporteur made the following recommendations:
(a) Promote transparency in artificial intelligence in order to mitigate the risks that opacity may generate in society, especially with respect to the protection of human rights;
(b) Incorporate into [national] laws the principle of explainability, not only to enable people to understand how the decisions that affect them were made, but also to provide them with the tools to defend their human rights in the face of artificial intelligence;
(c) Promote ethical practices that ensure transparency and explainability in the processing of personal data in artificial intelligence projects or processes;
(d) Foster, support and facilitate education and digital literacy to enable citizens to better understand the concepts relating to artificial intelligence, transparency and explainability, in order to be able to demand that their rights be respected.22

  1. Ibid., para. 64. ↩
¶31

In a 2024 report,23 the Special Rapporteur conducted a comparative study of the legal safeguards for personal data protection and privacy in the digital age. She also examined the legal mechanisms that are available to data subjects for the protection and restitution of their rights and, where necessary, for the reparation of damage caused by the improper use of information concerning them.

  1. “Legal safeguards for personal data protection and privacy in the digital age”, report of the Special Rapporteur on the right to privacy (A/HRC/55/46, 18 January 2024). ↩
¶32

The following were among the conclusions drawn in the report:
(a) Countries from five continents have expressly recognized in their legislation the different rights that data subjects enjoy and that allow them to control their personal information;
(b) Some countries are moving forward by legislating to recognize new rights, including those that are linked to automated and digitalized data processing or are exercised in the context of the Internet or of social media and similar services. This progress can also be seen from the more detailed express recognition of certain rights;
(c) Data subjects exercise personal data protection rights vis-à-vis data controllers through regulated procedures in each legal system that possess similarities and particular features;
(d) Regulated aspects of these procedures include, depending on the law in question, the ability of the data subject or his or her representative to submit requests for the exercise of a right; the types of possible response; the medium of the response; the deadline for responding; whether the procedure is free of charge; and, if a rights request is refused, the duty to inform the data subject of the possibility of submitting a complaint to an administrative or judicial authority;
(e) In respect of administrative remedies, which data subjects may pursue if the data controller fails or refuses to protect their rights, there is a degree of regulatory convergence. The laws of certain countries include specific provisions on the submission of complaints free of charge; on time limits for the resolution of procedures; and on the possibility of referral to alternative dispute resolution mechanisms;
(f) In all of the laws considered, provision is made for administrative measures to protect the claimed right, some of which are intended to prevent the continuation of the infringement or repetition of the conduct;
(g) Certain laws clearly establish the possibility of appealing against the decisions of the supervisory authority before a higher administrative body and the possibility of challenging the decisions of the supervisory authority before the courts in accordance with the right to effective judicial protection;
(h) In some countries, the law gives data subjects the option of whether to turn to the administrative supervisory authority or to directly approach the competent judicial body in order to seek a remedy for the protection of personal data that the data controller has refused or failed to protect;
(i) The five countries covered by the analysis regulate, to a greater or lesser extent, aspects of the redress that may be sought by data subjects who have suffered damage or loss as a result of a breach of data protection and privacy legislation.24

  1. Ibid., para. 123. ↩
¶33

In her main recommendations, the Special Rapporteur urged States to:
(a) Establish and bring up to date appropriate legal frameworks, on a multidisciplinary basis and with the support of all stakeholders, in particular through the adoption of laws and regulations that provide accessible and appropriate remedies for the effective protection, reparation and restitution of the right to personal data protection, including compensation for damage caused by violations of the relevant laws and regulations;
(b) Acting in a sovereign capacity, identify and consider adopting aspects of other countries’ data protection and privacy legislation that may offer stronger guarantees for the effective realization of these rights in the digital age;
(c) Promote and foster human rights information and education, particularly in the area of personal data protection and privacy, as a matter of priority, at all levels and in all fields, so that data subjects are aware of, understand and can exercise their rights and, if necessary, can avail themselves of remedies to ensure their effective enjoyment.25

  1. Ibid., para. 124. ↩
¶34

In 2022, the Special Rapporteur submitted a report on the implementation of the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in the processing of personal data collected by public entities in the context of the COVID-19 pandemic,26 with a view to determining what had happened and would happen to the data collected from millions of people from all countries in the world in order to combat the pandemic.

  1. “Implementation of the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in the processing of personal data collected by public entities in the context of the COVID-19 pandemic”, report of the Special Rapporteur on the right to privacy (A/HRC/52/37, 27 December 2022). ↩
¶35

The Special Rapporteur drew a number of conclusions and made the following recommendations on the basis of an analysis of 20 countries in Africa, the Americas, Asia, Europe and Oceania:
• Ensure [genuine and effective compliance] with the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in respect of the data of millions of people that were collected for the purpose of detecting and/or combating COVID-19 and tracking its spread with a view to protecting public health and preventing its transmission.
• Reinforce the application of the principle of demonstrated or proactive responsibility in all programmes and policies involving the processing of personal data. This requires [States], among other things, to adopt relevant, appropriate, timely and effective measures to comply with the legal obligations established in personal data processing regulations. Such measures should be subject to ongoing review and evaluation in order to gauge how effective they are in terms of ensuring compliance and the protection of personal data.
• Implement processes and use tools that demonstrate and provide evidence of due compliance with [national] obligations. Such processes and tools should be transparent and easily verifiable by the competent public authorities and the public in general.
• It is suggested that, before commencing the design and development of applications and software that involve processing personal data for the purpose of carrying out State functions, States should take proactive, preventive measures with a view to establishing a risk monitoring and management system that will ensure that data are processed fairly and lawfully.
• Cement a public culture that fosters transparent and ethical processing of personal data, with all due safeguards, so as to ensure that transparency becomes an essential component in the design and implementation of all public programmes and policies that involve the processing of personal data.
• Build and consolidate levels of public confidence in the programmes of public entities that involve the processing of personal data by implementing transparent, publicly accessible mechanisms that allow citizens to verify, through a simple process and at any time, that public entities comply in practice with the procedures and commitments set forth in their policy notices and/or terms and conditions for activities that involve the collection, use and exchange of personal data or any other activity in which personal data are processed.27

  1. Ibid., paras. 27–32. ↩

III. Some thematic gaps in General Assembly resolution 45/95 as compared with international documents on personal data processing

¶36

Because General Assembly resolution 45/95 was adopted in 1990, its content is outdated compared with that of subsequent international documents. This can be seen from a comparative analysis of the resolution and the following documents:
• APEC Privacy Framework, 2004
• International Standards on the Protection of Personal Data and Privacy: Joint Proposal for a Draft of International Standards on the Protection of Privacy with regard to the Processing of Personal Data (Madrid Resolution), 2009
• Recommendation of the OECD Council concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data, 2013
• Regulation (European Union) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
• Standards for Personal Data Protection for Ibero-American States,28 adopted in 2017
• Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+), Council of Europe, 2018
• Updated Principles on Privacy and Personal Data Protection, Organization of American States (OAS), 202129
• Resolution entitled “Achieving global data protection standards: Principles to ensure high levels of data protection and privacy worldwide”, GPA, 202330

  1. Document adopted at the fifteenth Ibero-American Data Protection Meeting of the Ibero-American Data Protection Network, held in Santiago on 22 June 2017. ↩
  2. The Principles were adopted by the Inter-American Juridical Committee and approved by the General Assembly of the Organization of American States in 2021. ↩
  3. See footnote 9. ↩
¶37

The main results of the comparative analysis are set out below.
First: as indicated in the table below, in its resolution 45/95 the General Assembly does not mention the following principles relating to the processing of personal data: legitimacy, transparency, demonstrated responsibility and confidentiality.