These Guidelines are intended to be a best practice guide for NHRIs operating in different countries.
We have therefore taken the requirements of the European Union General Data Protection Regulation
(GDPR), generally considered one of the most rigorous privacy frameworks, as our reference point for
the advice in this resource.
(!) Protecting personal information should be an integral part of NHRIs’ data
protection practices.
HRDs are among the most sensitive or high-risk groups of people to whom NHRIs owe a duty of
care when it comes to information management and privacy protection. An organisation’s data
protection practices are therefore particularly important to the safety and well-being of HRDs.
Background: What is personal information?
Personal information is a key concept in privacy and data protection.
Although its exact definition varies between jurisdictions, the term “personal information” generally
refers to any information which is about a person who it is reasonably possible to identify.
What exactly constitutes personal information is more than direct identifiers like a name, address and
phone number – it is determined by context. For example, if you have a car’s registration number, that
number by itself is not personal information. However, if you have the ability to look up the number in
a database and find out who the car belongs to – then that number is personal information in your (or
your organisation’s) hands.
Personal information can include opinions about a person, even if they are incorrect.
* The terms “personal data” and “personal information” have largely similar meanings. Although
the GDPR uses the term “personal data”, we have adopted the term “personal information” in
these Guidelines.
Data Protection Guidelines for NHRIs Toolkit
6