UNHRDB › Special Procedures reports › SR Privacy

A/HRC/52/37

Implementation of the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in the processing of personal data collected by public entities in the context of the COVID-19 pandemic

SR Privacy · 27 December 2022 · Mandate-holder: Ana Brian Nougrères · 32 paragraphs

Search and read in the UNHRDB app · Official text (UN Documents)

I. Introduction

¶1

On 11 March 2020, the World Health Organization (WHO) declared a state of pandemic in view of the rapid spread and severity of the coronavirus disease (COVID-19). The announcement signified that the epidemic had spread to multiple countries and continents throughout the world and was affecting large numbers of people.1

  1. Pan American Health Organization, “WHO characterizes COVID-19 as a pandemic”. Available at: https://www.paho.org/en/news/11-3-2020-who-characterizes-covid-19-pandemic. ↩
¶2

The declaration of the pandemic prompted States to establish and implement emergency response mechanisms to curb the spread of COVID-19, among other actions.

¶3

As part of this action, public entities in different countries of the world collected data from millions of people with a view to implementing measures for detecting and combating COVID-19 and tracking its spread, and thus protecting public health and preventing its transmission. In addition to contact and personal identification data, the information collected included health-related data such as details of symptoms, test results and diagnoses, all of which are considered sensitive personal data.

¶4

Additionally, biosecurity protocols were adopted to mitigate and control the risks associated with the COVID-19 pandemic and ensure an appropriate response in different activities, services, sectors, processes, establishments and locations. The implementation of such measures also entailed the collection and processing of personal data.

¶5

According to WHO, as at 24 November 2022, 636,089,587 confirmed cases of severe acute respiratory syndrome coronavirus-2 (SARS-CoV-2)2 had been recorded worldwide. The breakdown of these cases by region is shown in Table 1 below.

  1. See https://covid19.who.int/ (accessed 25 November 2022). ↩

Table 1 Number of confirmed cases of COVID-19 in different regions of the world (as at 24 November 2022)

¶6

Data processing regulations allow, among other things, for personal information to be collected and used in the event of a medical or health emergency. However, such a situation does not rescind the fundamental right to personal data protection, and compliance with the regulations protecting this right is obligatory for all entities that control and/or process personal data.

¶7

Data collected for the purpose of combating COVID-19 may be used for this purpose only, and may be stored only for as long as is reasonable and necessary for said purpose. Once the purpose has been achieved, the data must be deleted or anonymized in accordance with the data processing regulations of each country.

¶8

A set of general principles that provides a basis for the fair and transparent processing of personal data has been established at the international level. These principles consist of a series of rules intended to ensure that the collection and use of personal information does not affect or harm the rights of individuals. By determining whether or not the principles have been respected, it is possible to verify whether, in any given case, the data processing is being carried out fairly and lawfully.

¶9

The following sections examine three of the principles relevant to the processing of data in the context of the fight against COVID-19, namely, purpose limitation, deletion of data and demonstrated or proactive accountability.

II. Principle of purpose limitation for the processing of data collected to combat the COVID-19 pandemic

¶10

A number of texts drawn up by organizations in different parts of the world3 provide that personal data may be collected for specific, clear and lawful purposes. The principle of purpose limitation:
(a) Limits the purposes for which the personal data may be used;
(b) Prevents personal information from being used arbitrarily by persons or entities holding the personal data of third parties;
(c) Requires that data be used only for purposes permitted by law or for which the data subjects have given their consent;
(d) Allows data to be used for purposes compatible with those permitted by law or for which the data subjects have given their consent. The subsequent processing of personal data for scientific and historical research purposes or for statistical ends, all in the public interest, is not usually considered incompatible with initial purposes, provided that States establish appropriate safeguards.

  1. Organisation for Economic Co-operation and Development (OECD), Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, 23 September 1980 and July 2013 update; Council of Europe, Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, No. 108 of 28 January 1981; United Nations, Guidelines for the regulation of computerized personal data files, 14 December 1990; Council of Europe, Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, regarding supervisory authorities and transborder data flows, 8 November 2001; Asia-Pacific Economic Cooperation Forum, Asia-Pacific Economic Cooperation Privacy Framework, 2004; Spanish Data Protection Agency, Joint Proposal for a Draft of International Standards on the Protection of Privacy with regard to the Processing of Personal Data, Madrid, 5 November 2009; European Parliament and Council of the European Union, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation); Ibero-American Data Protection Network, Guidelines for Harmonization of Data Protection in the Ibero-American Community, 2017; Council of Europe, Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, October 2018; and Organization of American States, Inter-American Juridical Committee, Updated Principles on Privacy and Personal Data Protection, 2021. ↩

III. Principle of deletion of data collected in the context of the COVID-19 pandemic

¶11

Not only must data be processed for a specific, clear and lawful purpose; it must also be processed for a period no longer than is necessary to achieve the intended purpose. In other words, as a general rule, the processing of data should be subject to a time limit and should not be permitted to continue indefinitely or ad infinitum.

¶12

Once the time limit has expired, the data must be either definitively deleted or else anonymized in such a way that, beyond the period of time necessary to achieve the purposes for which the data were collected, it is impossible to identify the data subject.

¶13

At the international level, this principle generally means that:
(a) Data cannot be retained indefinitely or in a form that allows for individual data subjects to be identified;
(b) Personal data may be retained no longer than is necessary to achieve the intended purpose;
(c) Provided the regulations establish appropriate safeguards, personal data may be retained for a longer period for historical, statistical or scientific purposes;
(d) Data must be either deleted or, where appropriate, converted into an anonymous form that can continue to be processed without the data subjects being identified.

IV. Principle of demonstrated or proactive accountability in the processing of data collected to combat the COVID-19 pandemic

¶14

The term “accountability” comes from the Anglo-Saxon world4 and, despite the varying interpretations that may be attributed to it, as far as data protection is concerned, the term is understood to refer to the action that entities should take to comply with the relevant regulations in practice and what they should do to demonstrate that the action taken is appropriate, relevant and effective.

  1. European Commission, Article 29 Data Protection Working Party, Opinion 3/2010 on the principle of accountability, paras. 21–23. Available at: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2010/wp173_en.pdf. ↩
¶15

Ensuring that data protection regulations are effectively applied in practice is an ongoing challenge for any entity. Although it is important to adopt regulations, adoption alone is insufficient since regulations are not automatically effective; measures to give them effect are also necessary. Efforts should therefore be focused on ensuring that data processing regulations set specific, tangible goals rather than purely theoretical ones, and are thus of genuine benefit.

¶16

The principle of accountability is of paramount importance to achieving this end. This principle requires those who control and/or process data to implement appropriate, effective and verifiable measures through which to demonstrate that they have duly complied with personal data processing regulations. Such measures should be subject to ongoing review and evaluation in order to gauge how effective they are in terms of ensuring compliance and protecting the rights of data subjects.

¶17

The principle of accountability calls for less rhetoric and more action in fulfilling the obligations established under personal data processing regulations. It requires entities to take specific action to ensure that personal data are processed fairly and lawfully.

¶18

The challenges that entities face in ensuring respect for the principle of accountability extend beyond the simple issuance of documents since, in the exercise of their duties, they are required to demonstrate genuine and effective compliance in practice. The purpose of the principle of accountability is to ensure that constitutional and legal obligations related to personal data processing are verifiably upheld and genuinely serve to protect the rights of individuals.

¶19

From the various international documents consulted,5 it can be concluded that demonstrated responsibility, which is also referred to as proactive accountability:
(a) Requires entities to implement appropriate, relevant, timely and effective measures and procedures to demonstrate compliance with personal data processing regulations;
(b) Entails implementing and supervising verification procedures to ensure that the measures adopted not only exist on paper but are implemented and work in practice (internal or external audits, etc.).6

  1. A detailed study of the principle of demonstrated accountability in the field of international regulation and of the various guides published on the subject can be found in: Nelson Remolina, Manuel Tenorio and Gustavo Quintero, De la responsabilidad demostrada en las funciones misionales de la Registraduría Nacional del Estado Civil: hacia un programa de gestión de datos personales y la consolidación de un buen gobierno corporativo en el tratamiento de esa clase de información (Bogotá, Temis, 2018). Available at: https://habeasdatacolombia.uniandes.edu.co/?p=2836. ↩
  2. European Commission, Article 29 Data Protection Working Party, Opinion 3/2010 on the principle accountability, paras. 21–23. Available at: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2010/wp173_en.pdf. ↩

V. Findings

¶20

The following paragraphs describe the methodology used to establish whether the principles of purpose limitation, deletion of data and demonstrated accountability are being respected in practice.

¶21

Firstly, questionnaires were sent to 186 countries asking, among other questions,7 when personal data collected for the purpose of combating COVID-19 would be deleted and whether States had incorporated the concept of “post-pandemic” in their regulations for purposes of the deletion of this information.

  1. Question 7 of the questionnaire asks: “When will the personal data concerning COVID-19 be deleted from the databases?” Question 8 asks: “Has your country regulated the post-pandemic concept from the point of view of the removal of personal data from databases?” ↩
¶22

The following 18 countries are thanked for their responses: Albania, Algeria, Austria, Bermuda, Chile, Costa Rica, Croatia, Cyprus, Czechia, Honduras, Ireland, Mauritius, Morocco, Poland, Qatar, Romania, Saudi Arabia and Uruguay.

¶23

Although not all countries responded to all the questions, it can be concluded from the responses received that there is no specific guidance for the retention of COVID-19-related data in the countries in question and that the general principles and regulations for the protection of personal data therefore apply – specifically, the principle of purpose limitation, which means that data may be kept until the lawful purpose for which they were collected has been achieved, taking into consideration health sector-specific standards. Information may also be kept for scientific or statistical purposes, provided it is in a form in which the data subjects can no longer be identified.

¶24

Secondly, checks were carried out to corroborate information about the applications and web pages created by the public authorities of a representative sample of 20 countries – selected from Africa, the Americas, Asia, Europe and Oceania – for the purpose of collecting and processing personal data for use in detecting and/or combating COVID-19 and tracking its spread with a view to protecting public health and preventing the transmission of the virus.

¶25

To establish whether these applications and web pages took account of the principles of purpose limitation, deletion of data and demonstrated responsibility, the following questions were asked:
Question 1 (purpose limitation): Are users informed of the purpose for which their personal data are being collected and processed?
Question 2 (deletion or anonymization): Are users expressly informed that their data will be deleted or anonymized as soon as the purpose for which they were collected is achieved?
Question 3 (accountability in general): Are any measures for ensuring demonstrated or proactive accountability in respect of the processing of personal data mentioned?
Question 4 (accountability and deletion): Have you committed to implementing demonstrated or proactive accountability measures to comply with the principle of deletion of data?
Question 5 (verification): Is there any mention of a verification procedure for demonstrating or proving that personal data have been deleted or anonymized?
Question 6 (audit): Is the use of an external auditor to certify that personal data have been effectively deleted or anonymized envisaged?
The results are shown in Table 2 below.

VI. Conclusions

¶26

After verification of the information provided about the policies adopted by the public authorities in 20 countries8 in Africa, the Americas, Asia, Europe and Oceania and the terms and conditions of the applications and/or web pages created by the entities responsible for collecting and processing personal data with a view to detecting and/or combating COVID-19, tracking its spread and thus protecting public health and preventing transmission, the following conclusions were drawn:
All of the public entities applied the principle of purpose limitation in the processing of personal data. Accordingly, all of the policies and/or terms and conditions for the applications and/or web pages contained information about the purpose for which the personal data were being collected and processed.
Not all the public entities provided information about the deletion or anonymization of data once they ceased to be useful for the purposes for which they were collected. Specifically, 20 per cent did not expressly state that the data would be deleted or anonymized as soon as the purpose had been achieved, 70 per cent stated that the information would be deleted and 10 per cent indicated that it would be either deleted or anonymized as soon as the purpose for which it was collected had been achieved.
As regards application of the principle of demonstrated or proactive accountability, the survey revealed that 55 per cent of entities envisaged in their policies the adoption of general demonstrated or proactive accountability measures for processing the data collected, while the remaining 45 per cent made no mention of this aspect.
Only 15 per cent of the entities had committed to implementing demonstrated or proactive accountability measures to comply with the principle of deletion of data.
Notwithstanding the foregoing, very few, if any, entities had established transparent mechanisms for verifying whether personal data had been deleted or anonymized. In fact, only one public authority (equivalent to 5 per cent of the total number of entities surveyed) had established a verification procedure for demonstrating or proving that personal data had been deleted or anonymized, and none of them envisaged using an external auditor to certify that personal data had effectively been deleted or anonymized.

  1. Argentina, Australia, Belgium, Brazil, Colombia, France, Germany, India, Ireland, Italy, Japan, Latvia, Mauritius, Mexico, the Netherlands, New Zealand, Singapore, South Africa, Spain and the United Kingdom. ↩

VII. Recommendations

¶27

The Special Rapporteur urges States to ensure that they are genuinely and effectively complying with the principles of purpose limitation, deletion of data and demonstrated or proactive accountability in respect of the data of millions of people that were collected for the purpose of detecting and/or combating COVID-19 and tracking its spread with a view to protecting public health and preventing its transmission.

¶28

The Special Rapporteur calls on States to reinforce the application of the principle of demonstrated or proactive responsibility in all programmes and policies involving the processing of personal data. This requires them, among other things, to adopt relevant, appropriate, timely and effective measures to comply with the legal obligations established in personal data processing regulations. Such measures should be subject to ongoing review and evaluation in order to gauge how effective they are in terms of ensuring compliance and the protection of personal data.

¶29

States should implement processes and use tools that demonstrate and provide evidence of due compliance with their obligations. Such processes and tools should be transparent and easily verifiable by the competent public authorities and the public in general.

¶30

It is suggested that, before commencing the design and development of applications and software that involve processing personal data for the purpose of carrying out State functions, States should take proactive, preventive measures with a view to establishing a risk monitoring and management system that will ensure that data are processed fairly and lawfully.

¶31

States should also work to cement a public culture that fosters transparent and ethical processing of personal data, with all due safeguards, so as to ensure that transparency becomes an essential component in the design and implementation of all public programmes and policies that involve the processing of personal data.

¶32

The Special Rapporteur urges States to build and consolidate levels of public confidence in the programmes of public entities that involve the processing of personal data by implementing transparent, publicly accessible mechanisms that allow citizens to verify, through a simple process and at any time, that public entities comply in practice with the procedures and commitments set forth in their policy notices and/or terms and conditions for activities that involve the collection, use and exchange of personal data or any other activity in which personal data are processed.