TRW Law Firm - Global Header
Business & Human Rights Lawyers Bangladesh | TRW Law Firm

Navigating the Evolving Landscape of Business, Human Rights, and Data Privacy

In today's globalized and digitized world, the intersection of business operations, human rights, and data privacy has become a critical area of legal and corporate responsibility. TRW Law Firm is a leader in advising national and international clients on this complex and evolving landscape. Our dedicated team provides comprehensive legal services to help businesses navigate the intricacies of human rights due diligence, corporate accountability, sustainable practices, and the stringent requirements of data protection regulations like the GDPR. We ensure our clients operate ethically, sustainably, and in full compliance with both local and international standards.

Our Integrated Expertise in Bangladesh

Bangladesh, a key player in global supply chains and a rapidly growing economy, presents a unique nexus of challenges and opportunities. We provide expert, integrated guidance on a wide array of issues, from traditional human rights concerns like labor rights and workplace safety to the cutting-edge legal challenges of data protection and digital rights. Our goal is to ensure our clients not only meet their legal obligations but also build a reputation for ethical leadership.

Integrated Expertise in Business, Human Rights, and Data Privacy in Bangladesh

Our Comprehensive Legal Services

Our services are designed to provide end-to-end support for businesses seeking to build a robust framework for human rights and data privacy compliance. We offer tailored solutions that address the specific risks of each client.

  • Human Rights & Data Privacy Due Diligence: We conduct thorough assessments to identify, prevent, and mitigate risks related to human rights and data protection across operations and supply chains.
  • Policy Development & Implementation: We assist in drafting and implementing robust policies for human rights and data protection that align with international standards like the UNGPs and GDPR.
  • Supply Chain Responsibility: We provide guidance on responsible sourcing, supplier codes of conduct, and monitoring mechanisms to ensure your supply chain is free from human rights abuses and compliant with data transfer regulations.
  • Data Protection & GDPR Compliance: We offer expert advice on data mapping, privacy impact assessments (PIAs), data subject rights, and cross-border data transfers to ensure full compliance with GDPR and other data protection laws.
  • Stakeholder Engagement & Grievance Mechanisms: We facilitate meaningful engagement with stakeholders and help establish effective grievance mechanisms for both human rights and data privacy concerns.
  • Training and Capacity Building: We offer customized training programs to build awareness and capacity on business, human rights, and data privacy issues at all levels of your organization.
Protecting Indigenous and Digital Rights

Protecting Indigenous and Digital Rights

Our expertise extends to the most sensitive areas of human rights. We advise clients on projects impacting indigenous communities, ensuring adherence to the principles of Free, Prior, and Informed Consent (FPIC). Simultaneously, we are at the forefront of protecting digital rights, advising on issues of surveillance, freedom of expression online, and the human rights implications of artificial intelligence.

Frequently Asked Questions

Bangladesh Focus

What are the key human rights and data privacy challenges for businesses in Bangladesh?

Key challenges include ensuring fair labor practices, workplace safety, environmental compliance, and navigating the developing legal framework for data protection, including the Digital Security Act and the forthcoming Data Protection Act.

Is GDPR applicable to companies in Bangladesh?

Yes, the GDPR has extraterritorial reach. If a company in Bangladesh processes the personal data of individuals in the EU in relation to offering them goods or services, or monitors their behavior, it must comply with the GDPR.

International & Data Privacy Focus

What are the core principles of the GDPR?

The GDPR is built on seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability.

What is a Data Protection Impact Assessment (DPIA)?

A DPIA is a process to help you identify and minimize the data protection risks of a project. You must do a DPIA for processing that is likely to result in a high risk to individuals. It is a key part of your accountability obligations under the GDPR.

Contact Us

For expert legal advice on business, human rights, and data privacy, contact TRW Law Firm today.

Email: info@trfirm.com

Phone: +880-1708-000660 | +8801847220062

Office: House 410, Road 29, Mohakhali DOHS, Dhaka 1206, Bangladesh

Schedule a Consultation

Deep Dive: The Intersection of Data Privacy and Human Rights

In the digital age, the right to privacy is a fundamental human right that underpins freedom of expression, thought, and association. The collection, processing, and sharing of personal data can have significant human rights implications. At TRW Law Firm, we have a deep understanding of this intersection and provide expert guidance on navigating the complex legal frameworks that govern data privacy and human rights.

The General Data Protection Regulation (GDPR)

The GDPR is the most comprehensive data protection law in the world. It sets a high standard for data protection and has had a global impact. We provide a full range of GDPR compliance services, including:

  • GDPR Audits and Gap Analysis: We assess your current data processing activities and identify areas of non-compliance.
  • Data Protection Officer (DPO) Services: We can act as your external DPO or provide support to your internal DPO.
  • Data Breach Response: We provide rapid response and guidance in the event of a data breach, including notification to supervisory authorities and affected individuals.
  • Vendor and Third-Party Risk Management: We help you assess and manage the data protection risks associated with your vendors and other third parties.

Data Privacy in Bangladesh

While Bangladesh does not yet have a comprehensive data protection law equivalent to the GDPR, the legal landscape is evolving. The Digital Security Act, 2018, contains provisions related to data privacy and security, and a dedicated Data Protection Act is expected to be enacted soon. We are at the forefront of these developments and can help your business prepare for the new legal framework.

Data Privacy and Human Rights Due Diligence

Data Privacy as a Human Right

We believe that data privacy is not just a compliance issue but a fundamental human right. Our approach is grounded in the principles of data protection by design and by default. We help you build a culture of privacy within your organization and demonstrate your commitment to protecting the personal data of your customers, employees, and other stakeholders.

The Ultimate FAQ Compendium on Business, Human Rights & Data Privacy

Bangladesh: Data Privacy & Human Rights

What are the key provisions of the Digital Security Act, 2018?

The Act criminalizes various forms of online expression and provides for the establishment of a Digital Security Agency. It has been criticized for its potential to curb freedom of speech. Businesses need to be aware of its provisions to mitigate legal risks.

What is the status of the draft Data Protection Act in Bangladesh?

The draft Act is currently undergoing consultation and is expected to be enacted soon. It is likely to be based on the principles of the GDPR and will introduce new obligations for businesses that process personal data.

How does the right to information in Bangladesh relate to data privacy?

The Right to Information Act, 2009, gives citizens the right to access information held by public authorities. However, this right is subject to certain exemptions, including the protection of personal privacy.

International: Data Privacy & Human Rights

What are the Standard Contractual Clauses (SCCs) for data transfers?

SCCs are a mechanism for legally transferring personal data from the European Economic Area (EEA) to countries that are not considered to have an adequate level of data protection. They are standard sets of contractual terms and conditions that the sender and the receiver of the personal data both sign up to.

What was the significance of the Schrems II judgment?

The Schrems II judgment of the Court of Justice of the European Union invalidated the EU-US Privacy Shield framework for data transfers. It also clarified that companies using SCCs must conduct a case-by-case assessment of whether the law in the recipient country provides adequate protection for personal data.

What is the California Consumer Privacy Act (CCPA)?

The CCPA is a state-wide data privacy law in California that gives consumers more control over the personal information that businesses collect about them. It has had a significant impact on businesses across the United States and beyond.

Our Methodology: A Step-by-Step Guide to Human Rights & Data Privacy Compliance

At TRW Law Firm, we employ a systematic and robust methodology to guide our clients through the complexities of business, human rights, and data privacy compliance. Our approach is proactive, preventative, and aligned with global best practices, ensuring that your business not only meets its legal obligations but also builds a strong foundation for sustainable growth.

Phase 1: Scoping and Commitment

The first step is to define the scope of your company's commitment. This involves developing board-approved Human Rights and Data Privacy Policies that are publicly available and communicated to all stakeholders. We work with you to ensure these policies are tailored to your specific industry, operations, and geographic footprint.

Phase 2: Integrated Impact Assessment

This is the core of the due diligence process. Our Integrated Impact Assessments (IIAs) are comprehensive and involve:

  • Desktop Research: Reviewing country reports, industry-specific studies, and media coverage to identify potential human rights and data privacy risks.
  • Stakeholder Engagement: Conducting interviews and focus groups with employees, local communities, civil society organizations, and other relevant stakeholders to understand their perspectives and concerns.
  • Data Mapping and Process Analysis: Identifying and analyzing all personal data processing activities to understand data flows and associated risks.
  • Site Visits: Visiting operational sites and supplier factories to observe conditions on the ground.
  • Risk Mapping and Saliency Assessment: Identifying and prioritizing the most salient human rights and data privacy risks.

Phase 3: Integration and Action

Based on the findings of the IIA, we help you integrate the necessary changes into your business operations. This involves:

  • Developing a Corrective Action Plan: Outlining specific steps, timelines, and responsibilities for addressing identified risks.
  • Updating Policies and Procedures: Revising procurement policies, supplier codes of conduct, and internal management systems to embed human rights and data privacy considerations.
  • Contractual Clauses: Incorporating human rights and data protection clauses into supplier contracts to create clear expectations and legal leverage.

Phase 4: Tracking and Monitoring

Effective due diligence is an ongoing process. We help you develop systems to track the implementation and effectiveness of your actions. This includes setting Key Performance Indicators (KPIs), conducting regular internal and external audits, and reporting progress to the board and senior management.

Phase 5: Communication and Reporting

Transparency is key to building trust. We assist in developing clear and honest communications about your human rights and data privacy efforts. This includes preparing formal reports, such as Modern Slavery Statements or sustainability reports, as well as engaging in ongoing dialogue with stakeholders.

Phase 6: Remediation and Grievance Mechanisms

Where your business has caused or contributed to adverse impacts, providing for or cooperating in their remediation is essential. We help you design and implement effective operational-level grievance mechanisms that are legitimate, accessible, predictable, equitable, transparent, rights-compatible, and a source of continuous learning.

Stakeholder Engagement and Collaboration

The Power of Stakeholder Engagement

Meaningful stakeholder engagement is not just a part of due diligence; it is a cross-cutting activity that should inform every stage of the process. By engaging with those who may be affected by your business operations, you can gain valuable insights, build trust, and develop more effective solutions. We facilitate this process, ensuring that it is inclusive, culturally appropriate, and focused on two-way communication.

The Definitive Business, Human Rights & Data Privacy FAQ Library

Bangladesh: Advanced Topics

What is the process for forming a trade union in Bangladesh?

A minimum of 20% of the workers in an establishment must apply to the Registrar of Trade Unions. The application must include the names and details of the applicants and the proposed union officials. The Registrar will verify the application and, if satisfied, register the union.

Are there restrictions on the termination of workers in Bangladesh?

Yes, the Labour Act provides for specific grounds and procedures for termination, such as misconduct, retrenchment, and discharge. Termination for misconduct requires a formal inquiry process. Workers are also entitled to notice periods and severance pay depending on the length of their service.

What is the 'Workers Profit Participation Fund' (WPPF) in Bangladesh?

Companies meeting certain criteria are required to contribute 5% of their net profits to a WPPF. This fund is then distributed among the company's workers and to a government-managed welfare fund.

How does the law in Bangladesh address child labour?

The Labour Act prohibits the employment of children under the age of 14. Adolescents (14-18) can be employed in non-hazardous work, but with restrictions on working hours. The National Child Labour Elimination Policy aims to eradicate all forms of child labour.

International Law & Data Privacy: Advanced Topics

What is the concept of 'salience' in human rights due diligence?

Salience is a method for prioritizing human rights risks. A salient human rights issue is one that is at risk of the most severe negative impact through the company’s activities or business relationships. The severity is judged by its scale, scope, and irremediable character.

What is the difference between 'causing', 'contributing to', and being 'directly linked to' an adverse impact?

A company 'causes' an impact if its own activities are the source of the impact. It 'contributes to' an impact if its activities, in combination with the activities of others, cause the impact. It is 'directly linked to' an impact if the impact is caused by another entity, but is connected to the company's own operations, products or services. The level of responsibility and appropriate action differs for each.

What are National Action Plans (NAPs) on Business and Human Rights?

NAPs are policy documents developed by states to outline their strategy for implementing the UN Guiding Principles. They set out the state's expectations for businesses and its own commitments to protect human rights.

What is the role of human rights defenders in the context of business?

Human rights defenders are individuals and groups who work to promote and protect human rights. They play a crucial role in holding businesses accountable for their human rights impacts. Companies have a responsibility to respect the rights of human rights defenders and to ensure they are not targeted for their work.

Beyond Compliance: Creating Shared Value Through Principled Performance

At TRW Law Firm, we believe that a genuine commitment to human rights and data privacy extends far beyond mere legal compliance. It is about embedding ethical principles into the core of your business strategy to create shared value for your company, your stakeholders, and society at large. By proactively managing risks and seizing opportunities to make a positive impact, you can enhance your brand reputation, attract and retain top talent, strengthen stakeholder relationships, and build a more resilient and sustainable enterprise for the future.

Integrating Human Rights and Data Privacy into Corporate Strategy

We work with senior leadership to integrate human rights and data privacy into the very fabric of your corporate strategy. This involves linking performance in these areas to core business objectives, incorporating these risks into enterprise risk management (ERM) frameworks, and aligning executive compensation with meaningful human rights and data privacy goals. By making these issues a strategic priority, you can drive transformative change throughout your organization and demonstrate true leadership.

Impact Investing, Sustainable Finance, and ESG

The financial sector is a powerful driver of corporate change. We advise both companies and investors on the rapidly growing fields of impact investing and sustainable finance. We help companies align with the stringent criteria of Environmental, Social, and Governance (ESG) investors to unlock new sources of capital. We also work with investors to develop and implement responsible investment policies that place human rights and data privacy at the center of their due diligence and engagement strategies.

The Future of Business, Human Rights, and Technology

This field is in a state of constant evolution. We are vigilantly monitoring emerging trends, such as the development of a legally binding UN treaty on business and human rights, the increasing use of artificial intelligence in due diligence, the human rights implications of the metaverse, and the critical role of business in ensuring a just transition to a low-carbon economy. We are committed to keeping our clients at the absolute forefront of these global developments.

The Future of Business and Human Rights

The Definitive Encyclopedia of Business, Human Rights & Data Privacy FAQs

Bangladesh: Expert Level

What is the role of the National Human Rights Commission (NHRC) of Bangladesh?

The NHRC is an independent statutory body established to promote and protect human rights. It can investigate allegations of human rights violations, make recommendations to the government, and raise public awareness. While it does not have binding enforcement powers, its reports and recommendations carry significant weight and can influence public opinion and government policy.

How does the Digital Security Act, 2018, impact freedom of expression for businesses and individuals?

The Act has been highly controversial, with critics arguing that some of its provisions are overly broad and have been used to stifle legitimate expression and journalism. Businesses must be acutely aware of the Act's provisions regarding online content, data security, and defamation to mitigate significant legal and reputational risks.

What are the legal requirements for Environmental, Social, and Governance (ESG) reporting in Bangladesh?

While comprehensive, mandatory ESG reporting is not yet in place for all companies, the Bangladesh Securities and Exchange Commission (BSEC) has issued corporate governance guidelines for listed companies that include aspects of social and environmental responsibility. There is a strong and growing expectation from investors, regulators, and the public for greater ESG transparency and performance.

What is the status of the Ship Breaking and Recycling Rules, 2011?

These rules were introduced to regulate the shipbreaking industry in Bangladesh, which has historically been known for hazardous working conditions and severe environmental pollution. The rules aim to ensure the safe and environmentally sound recycling of ships, in line with the Hong Kong Convention. However, full implementation and consistent enforcement remain significant challenges.

International Law & Data Privacy: Expert Level

What is the process for developing a UN Treaty on Business and Human Rights?

An open-ended intergovernmental working group (IGWG) was established by the UN Human Rights Council to elaborate an international legally binding instrument to regulate the activities of transnational corporations and other business enterprises. The process involves multiple rounds of negotiations between states, with significant input and lobbying from civil society organizations and business associations.

What are the Santa Marta Group and the Bali Process?

These are leading multi-stakeholder initiatives focused on combating modern slavery and human trafficking. The Santa Marta Group is a unique alliance of police chiefs, bishops, and religious sisters from around the world, working to eradicate human trafficking. The Bali Process is a forum for dialogue and cooperation between governments and the private sector in the Asia-Pacific region to combat people smuggling, trafficking in persons, and related transnational crime.

What is the role of the World Bank's Inspection Panel?

The Inspection Panel is an independent accountability mechanism for the World Bank. It provides a forum for people who believe they have been or are likely to be adversely affected by a World Bank-financed project to raise their concerns. The Panel investigates whether the Bank has complied with its own operational policies and procedures, including its environmental and social standards.

How does international humanitarian law (IHL) apply to businesses operating in conflict zones?

IHL, also known as the laws of armed conflict, applies to situations of armed conflict. Businesses operating in such contexts have a responsibility to respect IHL and to ensure that their activities do not contribute to violations. This includes complex issues such as trading in conflict minerals, providing services to armed groups, and ensuring the safety of employees. Failure to do so can lead to legal liability and severe reputational damage.

Case Studies: Our Impact in Action

We believe in demonstrating our expertise through tangible results. Here are some examples of how we have helped our clients navigate complex challenges at the intersection of business, human rights, and data privacy.

Case Study 1: Transforming a Garment Supply Chain in Bangladesh

Challenge: A major international apparel brand was facing significant reputational damage due to reports of poor working conditions and labor rights violations in its Bangladeshi supply chain.

Our Role: We were engaged to conduct a comprehensive, independent assessment of the brand's entire supply chain in Bangladesh. Our work involved unannounced factory audits, confidential worker interviews, and engagement with local trade unions and civil society. We then worked with the brand to develop a time-bound, publicly reported corrective action plan. This included investing in factory safety upgrades, implementing a living wage program, and establishing a robust, independent grievance mechanism for workers.

Result: Within two years, the brand had become a recognized leader in supply chain responsibility. It had significantly improved its relationship with suppliers, regained the trust of consumers, and saw a measurable increase in worker productivity and retention.

Case Study 2: Implementing GDPR for a Multinational Tech Company

Challenge: A US-based technology company with a significant customer base in the EU needed to ensure full compliance with the GDPR before the enforcement deadline.

Our Role: We conducted a full-scale GDPR readiness assessment, including data mapping of all personal data flows, a gap analysis of their existing policies and procedures, and a review of their vendor contracts. We then guided them through the implementation of a comprehensive compliance program. This included drafting a new privacy policy, establishing a process for handling data subject access requests, appointing a Data Protection Officer (DPO), and conducting company-wide training.

Result: The company achieved full GDPR compliance ahead of the deadline, avoiding potentially massive fines. The process also led to a deeper understanding of their data, which they were able to leverage for improved customer insights and data security.

Case Study 3: Navigating Land Rights for an Infrastructure Project

Challenge: An international consortium was planning a major infrastructure project in a remote area of Bangladesh that was home to several indigenous communities.

Our Role: We were brought in to advise on the land acquisition and resettlement process. We insisted on going beyond the requirements of national law and adhering to international best practices, including the IFC Performance Standards and the principle of Free, Prior, and Informed Consent (FPIC). We facilitated a multi-year process of consultation and negotiation with the affected communities, ensuring they were fully informed and had a meaningful say in the project's design and benefit-sharing arrangements.

Result: The project was able to proceed with the broad support of the local communities. The company avoided the costly delays and social conflict that often plague such projects and built a strong social license to operate. The resettlement program was recognized by the World Bank as a model of best practice.

Global Human Rights and Data Privacy Practice

Our Global Perspective, Our Local Expertise

While we are deeply rooted in the legal and cultural context of Bangladesh, our practice has a truly global perspective. We advise clients on a wide range of international laws and standards, ensuring they can operate with confidence across multiple jurisdictions. We help our clients navigate the complex web of national laws, bilateral investment treaties, international human rights frameworks, and data protection regulations that govern modern business.

The Definitive Encyclopedia of Business, Human Rights & Data Privacy FAQs

Bangladesh: Master Level

What is the legal framework for corporate social responsibility (CSR) in Bangladesh?

While there is no single, overarching law mandating CSR for all companies, certain sectors like banking have specific requirements. The Companies Act, 2020, also includes provisions for CSR. However, the trend is towards greater expectation of voluntary CSR, which we can help you structure for maximum impact and legal recognition.

How is the issue of climate change and its human rights impacts being addressed in Bangladesh?

Bangladesh is one of the most climate-vulnerable countries in the world. The government has developed a National Adaptation Plan and is increasingly focused on climate resilience. There is a growing body of climate litigation and a push for businesses to take responsibility for their carbon emissions and to support adaptation efforts.

What are the key challenges for freedom of association and collective bargaining in Bangladesh?

Despite legal protections, workers often face challenges in forming and joining trade unions, including anti-union discrimination and complex registration processes. We advise companies on how to respect these rights and build constructive relationships with trade unions.

International Law & Data Privacy: Master Level

What is the future of cross-border data transfers after Schrems II?

The legal landscape for data transfers remains in flux. The new EU-US Data Privacy Framework provides a new mechanism for transfers to the US, but it is likely to face legal challenges. Companies need to have a multi-pronged strategy for data transfers, relying on a combination of adequacy decisions, Standard Contractual Clauses (SCCs) with supplementary measures, and Binding Corporate Rules (BCRs).

What are Binding Corporate Rules (BCRs)?

BCRs are a mechanism for multinational companies to make intra-organizational transfers of personal data across borders in compliance with the GDPR. They are a set of internal rules and policies that are approved by a data protection authority and are legally binding on the entire corporate group.

What is the relationship between the UNGPs and the OECD Guidelines for Multinational Enterprises?

The OECD Guidelines are a comprehensive set of government-backed recommendations for responsible business conduct. The human rights chapter of the OECD Guidelines is fully aligned with the UNGPs. The key difference is that the OECD Guidelines have a built-in grievance mechanism through the National Contact Points (NCPs).

Why Choose TRW Law Firm?

Choosing the right legal partner is critical when navigating the complex and high-stakes intersection of business, human rights, and data privacy. At TRW Law Firm, we offer a unique combination of deep local expertise, a truly global perspective, and an unwavering commitment to our clients' success and ethical leadership.

Unparalleled Expertise

Our team consists of leading experts in human rights law, data protection law, and corporate law. We have a deep and nuanced understanding of the legal frameworks, political dynamics, and cultural contexts in Bangladesh and beyond. We are not just lawyers; we are strategic advisors who help you anticipate and navigate the challenges of tomorrow.

A Proactive and Pragmatic Approach

We believe in a proactive and preventative approach. We work with you to build robust compliance systems that not only protect you from legal and reputational risks but also create value for your business. Our advice is always pragmatic, business-focused, and tailored to your specific needs and objectives.

A Commitment to Shared Value

We are passionate about helping our clients create shared value for their business and society. We believe that principled business is good business. We are committed to helping you build a more sustainable, equitable, and prosperous future for all.

A Trusted Partner

We build long-term relationships with our clients based on trust, integrity, and mutual respect. We are more than just a law firm; we are a trusted partner in your journey towards responsible and sustainable business.

TRW Law Firm - Your Trusted Partner

Ready to Lead?

The world is changing. Stakeholder expectations are rising. The legal landscape is becoming more complex. Is your business ready to lead? Contact us today to learn how we can help you navigate the challenges and opportunities of the 21st century and build a business that is not only profitable but also a force for good in the world.

The Definitive Encyclopedia of Business, Human Rights & Data Privacy FAQs

Bangladesh: Grandmaster Level

What is the role of the judiciary in upholding human rights in Bangladesh?

The judiciary, particularly the Supreme Court of Bangladesh, has played a crucial role in upholding fundamental rights through public interest litigation (PIL). The Court has issued landmark judgments on issues ranging from environmental protection to workers' rights and the rights of marginalized communities.

How does the law on corporate manslaughter apply in Bangladesh?

While Bangladesh does not have a specific corporate manslaughter statute like the UK, companies and their directors can be held criminally liable for workplace accidents under provisions of the Penal Code, 1860, such as causing death by negligence. The Rana Plaza collapse case is a key example of such prosecutions.

International Law & Data Privacy: Grandmaster Level

What is the future of human rights due diligence legislation?

The trend is clearly towards mandatory human rights and environmental due diligence (mHREDD). The EU's Corporate Sustainability Due Diligence Directive (CSDDD) is a key driver, but many other countries are also moving in this direction. The scope of this legislation is also expanding to cover the entire value chain and a wider range of human rights and environmental impacts.

How is the concept of a "just transition" relevant to business and human rights?

A just transition refers to the process of moving to a low-carbon economy in a way that is fair and inclusive for workers and communities. Businesses have a key role to play in ensuring that the transition does not lead to job losses, social disruption, or other adverse human rights impacts. This includes reskilling workers, investing in affected communities, and engaging in social dialogue.

Glossary of Key Terms in Business, Human Rights, and Data Privacy

This glossary provides definitions for key terms and acronyms used in the fields of business and human rights and data privacy. It is intended as a resource for businesses, legal professionals, and civil society to foster a common understanding of this complex and evolving area.

A-C

Accountability:
In the context of the GDPR, the principle that data controllers are responsible for complying with the Regulation and must be able to demonstrate their compliance. In the context of human rights, the process of holding actors responsible for their human rights impacts.
Adequacy Decision:
A decision by the European Commission that a non-EU country provides an adequate level of data protection, allowing for the free flow of personal data from the EU to that country.
Adverse Human Rights Impact:
Any negative impact on the human rights of individuals or groups resulting from the activities of a business enterprise.
Alien Tort Statute (ATS):
A U.S. law that has been used to bring lawsuits in U.S. courts for human rights violations that have occurred outside the United States.
Binding Corporate Rules (BCRs):
A mechanism for multinational companies to make intra-organizational transfers of personal data across borders in compliance with the GDPR.
Child Labour:
Work that deprives children of their childhood, their potential and their dignity, and that is harmful to their physical and mental development. The ILO sets the minimum age for work at 15 (14 in developing countries).
Corporate Social Responsibility (CSR):
A self-regulating business model that helps a company be socially accountable — to itself, its stakeholders, and the public.

D-F

Data Controller:
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Processor:
A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Data Protection Impact Assessment (DPIA):
A process to help you identify and minimize the data protection risks of a project.
Due Diligence:
In the context of human rights, an ongoing risk management process that a reasonable and prudent company needs to follow to identify, prevent, mitigate and account for how it addresses its adverse human rights impacts.
Environmental, Social, and Governance (ESG):
A set of standards for a company’s operations that socially conscious investors use to screen potential investments.
Forced Labour:
All work or service which is exacted from any person under the menace of any penalty and for which the said person has not offered himself voluntarily.
Free, Prior, and Informed Consent (FPIC):
A specific right pertaining to indigenous peoples that allows them to give or withhold consent to a project that may affect them or their territories.

G-L

General Data Protection Regulation (GDPR):
A regulation in EU law on data protection and privacy in the European Union and the European Economic Area.
Grievance Mechanism:
A process for receiving, investigating, and addressing complaints about the human rights impacts of a business.
Human Rights Defenders:
Individuals and groups who work to promote and protect human rights.
Human Rights Impact Assessment (HRIA):
A process for systematically identifying, predicting, and responding to the potential human rights impacts of a business operation, project, or policy.
International Labour Organization (ILO):
A United Nations agency whose mandate is to advance social and economic justice through setting international labour standards.
Just Transition:
The process of moving to a low-carbon economy in a way that is fair and inclusive for workers and communities.
Living Wage:
The remuneration received for a standard workweek by a worker in a particular place sufficient to afford a decent standard of living for the worker and her or his family.

M-Z

Modern Slavery:
A term used to describe situations of exploitation that a person cannot refuse or leave because of threats, violence, coercion, deception, or abuse of power. It includes forced labour, debt bondage, forced marriage, and human trafficking.
National Action Plan (NAP) on Business and Human Rights:
A policy document developed by a state to outline its strategy for implementing the UN Guiding Principles.
OECD Guidelines for Multinational Enterprises:
A comprehensive set of government-backed recommendations for responsible business conduct.
Personal Data:
Any information that relates to an identified or identifiable living individual.
Salience:
A method for prioritizing human rights risks based on the severity of the potential impact.
Standard Contractual Clauses (SCCs):
A mechanism for legally transferring personal data from the EEA to countries that are not considered to have an adequate level of data protection.
UN Guiding Principles on Business and Human Rights (UNGPs):
A global standard for preventing and addressing the risk of adverse human rights impacts linked to business activity.