These Guidelines are intended to be a best practice guide for NHRIs operating in different countries. We have therefore taken the requirements of the European Union General Data Protection Regulation (GDPR), generally considered one of the most rigorous privacy frameworks, as our reference point for the advice in this resource. (!) Protecting personal information should be an integral part of NHRIs’ data protection practices. HRDs are among the most sensitive or high-risk groups of people to whom NHRIs owe a duty of care when it comes to information management and privacy protection. An organisation’s data protection practices are therefore particularly important to the safety and well-being of HRDs. Background: What is personal information? Personal information is a key concept in privacy and data protection. Although its exact definition varies between jurisdictions, the term “personal information” generally refers to any information which is about a person who it is reasonably possible to identify. What exactly constitutes personal information is more than direct identifiers like a name, address and phone number – it is determined by context. For example, if you have a car’s registration number, that number by itself is not personal information. However, if you have the ability to look up the number in a database and find out who the car belongs to – then that number is personal information in your (or your organisation’s) hands. Personal information can include opinions about a person, even if they are incorrect. * The terms “personal data” and “personal information” have largely similar meanings. Although the GDPR uses the term “personal data”, we have adopted the term “personal information” in these Guidelines. Data Protection Guidelines for NHRIs Toolkit 6

Select target paragraph3