Introduction About this Guideline These Guidelines provides practical advice on key things National Human Rights Institution (NHRIs) should do to protect personal information of and about Human Rights Defenders (HRDs). Who is it for? All NHRIs may benefit from these Guidelines. NHRIs who have deep frontline engagement with individual HRDs or Civil Society Organisations (CSOs) and who do not have the resources to employ dedicated data security, governance or cyber security staff may benefit the most from these Guidelines. Why do we need it? Protecting personal information of HRDs from unauthorised use or disclosure is a core responsibility of NHRIs. It is also crucial to enabling HRDs to do their work. Some HRDs may refrain from important work or not report violations of their rights due to fear that they will be targeted for reprisals. The Implementation Guidelines for APF Regional Action Plan on Human Rights Defenders (RAP on HRDs) identified the importance of secure management of information from HRDs. This was seen as crucial to monitoring and also reporting on violations against HRDs (RAP on HRDs National Actions 5 and 6). Approach taken in this Guideline Most privacy laws around the world have broadly similar principles on how personal information should be handled based on the information lifecycle shown below. Retention and deletion Collection Use Storage and security Disclosure Data Protection Guidelines for NHRIs Toolkit 5

Select target paragraph3