Introduction
About this Guideline
These Guidelines provides practical advice on key things National Human Rights Institution (NHRIs)
should do to protect personal information of and about Human Rights Defenders (HRDs).
Who is it for?
All NHRIs may benefit from these Guidelines. NHRIs who have deep frontline engagement with
individual HRDs or Civil Society Organisations (CSOs) and who do not have the resources to employ
dedicated data security, governance or cyber security staff may benefit the most from these Guidelines.
Why do we need it?
Protecting personal information of HRDs from unauthorised use or disclosure is a core responsibility
of NHRIs. It is also crucial to enabling HRDs to do their work. Some HRDs may refrain from important
work or not report violations of their rights due to fear that they will be targeted for reprisals.
The Implementation Guidelines for APF Regional Action Plan on Human Rights Defenders (RAP on
HRDs) identified the importance of secure management of information from HRDs. This was seen as
crucial to monitoring and also reporting on violations against HRDs (RAP on HRDs National Actions 5
and 6).
Approach taken in this Guideline
Most privacy laws around the world have broadly similar principles on how personal information should
be handled based on the information lifecycle shown below.
Retention
and deletion
Collection
Use
Storage
and security
Disclosure
Data Protection Guidelines for NHRIs Toolkit
5