Data Protection in Humanitarian Action

Written by

Introduction 

To mark ten years of progress in data protection in humanitarian action, this post is part of a special blog series accompanying the recently published Routledge volume Data Protection in Humanitarian Action: Responding to Crises in a Data-Driven World. A joint initiative of the Data Protection Office of the International Committee of the Red Cross (ICRC), the Data Protection Office of the United Nations High Commissioner for Refugees (UNHCR) and the Global Privacy Assembly (GPA), the book reflects on a decade of experience since the adoption of the ICRC’s and UNHCR’s data protection regulatory frameworks and the GPA Resolution on Privacy and International Humanitarian Action.  

Through years of collaboration with humanitarian organisations, I came to realize that personal data protection in times of crisis is, more than in any other sector, not just a matter of regulatory compliance; it is about humanity, dignity and trust. It is in this spirit that this initiative and the reflections it gathers hold particular significance.  

Personal data in humanitarian actions 

Contemporary humanitarian action increasingly relies on the processing of vast information resources—primary and secondary data collection, analysis and exchange. A significant portion of this data is linked to specific individuals: aid beneficiaries, aid workers or intermediaries. Where once physical presence and goodwill were sufficient, today information systems, the identification of aid beneficiaries and a precise mapping of their needs are necessary. In this dynamic environment, the underlying question of the publication becomes more and more pressing: How do we effectively protect the personal data of the people we want to help? 

Processing the personal data of refugees, or victims of conflict or natural disasters carries enormous risks. Such data can become a tool of oppression or discrimination. Humanitarian organisations and other actors involved must therefore not only provide assistance, but also act responsibly and in accordance with the principles stemming from law, the internal arrangements of international organisations and the ethics of data processing.  

We all seem to know what humanitarian action is. It comprises organised efforts to help people affected by natural disasters, armed conflicts, refugee crises, epidemics and other emergencies that threaten life, health, safety or human dignity. However, we are not fully aware of the practical challenges of carrying out humanitarian operations, particularly those that extend beyond the jurisdiction of a single state. 

Enlightenment 

When I first encountered the topic of data protection and privacy in humanitarian action, serving as assistant European Data Protection Supervisor at the time, I simply approached it as yet another field—or sector—of social activity in which we implement the same data protection and privacy principles, perhaps with some specificities. 

How wrong I was! 

Working for several years as a lawyer and for more than four years as a national data protection supervisor in Poland, I had become accustomed to working with various charities, public administrations, law enforcement agencies and the military in dealing with natural disasters and catastrophes. Humanitarian actions in the EU and humanitarian actions organised in the remotest regions of the world have the same goal —to save lives and alleviate suffering. However, they differ significantly in terms of context, scale, resources and types of needs. In EU countries, humanitarian action most often occurs in response to natural disasters (e.g. floods, fires, pandemics), mass influxes of refugees or social crises. In Europe’s neighbouring Africa, humanitarian actions in response to armed conflict, famine, epidemics, drought, lack of infrastructure and structural poverty are far more prevalent. 

Differences in infrastructure relate not only to hospitals, roads, emergency services, transport, health care and clean water, but also—very significantly—to IT infrastructure and the Internet. The differences are not always about the level of infrastructural development. For example, differences in the role of mobile internet in Africa and Europe, or differences in ownership of networks on the two continents, can result in the need to build quite different logistical and legal structures for humanitarian action.  

In the GDPR countries, most crises and actions are of a short-term nature, which encourages various types of short-term derogations and special measures for data processing. More attention is paid to ensuring the temporariness of these measures, the erasure of data resources created on an ad hoc basis and the evaluation of the performance of the system, while of course taking care to protect the ‘essence’ of the rights to privacy and data protection. These are usually the jurisdictions where civil law and specific branches of law—such as constitutional law or administrative law—can assist as well. In different regions of the world, humanitarian actors must often take into account that many measures will be long-term, humanitarian and developmental at the same time—and that the assistance will often last for years. 

I learned all these truths, which I should have already known before, from the group of experts who have contributed to the Handbook on Data Protection in Humanitarian Action, the first edition of which was published in 2015. I learned from them in the context of the workshops dedicated to data protection with international organisations which are co-organised, on a regular basis, by European Data Protection Supervisor. These workshops, initiated in 2005, are an opportunity for all international organisations to exchange their experiences and views on the most pressing issues they are facing.  

Reading 

Today, after a decade of promoting data protection in humanitarian action together, experts in the field, law, technology, crisis management and ethics, share their knowledge and experience with us. They analyse real cases, point out best practices and caution against mistakes. Together, we consider how to build trust in extreme situations, where data protection may not be a luxury, but a foundation. This book is an invitation to reflect on how to combine operational effectiveness with respect for human dignity. 

Undoubtedly, there is much to discuss and write about. As humanitarian organisations target various—sometimes very distant—regions of the world, one has to acknowledge that the protection of personal data poses a number of legal, technological and ethical challenges. One of the greatest risks is the potential for data security breaches. In situations of armed conflict or humanitarian crises, information can end up in the wrong hands—e.g. of armed groups or repressive regimes. This can lead to persecution, discrimination and even violence against aid beneficiaries. In addition, humanitarian organisations are increasingly becoming targets of cyber-attacks because they store sensitive data, such as information on health status, ethnicity, religion or refugee status. 

Complying with a variety of legal frameworks is another major challenge. Organisations operating internationally have to adapt to the legal systems of different countries, such as the GDPR in the European Union or the Health Insurance Portability and Accountability Act in the United States. The lack of consistent data protection standards in many countries is also an issue, even today when most countries in the world theoretically have comprehensive data protection laws in place. Actual protection, however, does not boil down to just the letter of the law. 

The collection of personal data in crisis situations exacerbates the challenges encountered. Faced with the lack of stable technical infrastructure, data has to be collected anyway—often in a hurry, without fully informing those affected. The trust of the people affected is the foundation of effective humanitarian action. However, many people, especially refugees, may be distrustful of having their data collected, especially if they have had traumatic experiences with authorities. Moreover, there is sometimes a need for rapid intervention—using for example medical data—which can present further challenges. Collaborating and sharing data with partners such as the United Nations, local NGOs or state institutions, can also be a challenge.  

In conclusion, responsible data management in the humanitarian sector requires not only robust technological safeguards, but also ethical sensitivity, knowledge of the law and measures that promote trust among the communities being helped. Only then is it possible to provide support that truly protects rather than puts at risk those most in need. 

Heroes 

The authors of this book are the heroes of this difficult daily struggle for data protection in conflict zones or politically unstable states, which involves risks not only for the people targeted by humanitarian action but also for the humanitarian workers themselves. They have to work with local leaders, informal structures and sometimes with authorities with—to put it mildly—limited legitimacy, from whom accountability cannot be exacted and who will certainly want to become data controllers. 

The group of professionals promotes data protection standards in organisations that are sometimes the only real source of support for local populations. In their work, they keep in mind that the key characteristics of humanitarian action are neutrality (aid is provided without taking sides in a conflict), impartiality (aid goes to all those in need, regardless of nationality, religion, gender or opinion), humanitarianism (the main objective is to save lives and alleviate suffering) and independence (humanitarian organisations act autonomously from governments and political groups). 

Let’s embark on a journey to uncover the fruits of their labour. 

 

In related posts this week, Mariana Salazar Albornoz will provide a view from the Americas and Tatjana Grote will examine military personal data processing.

Leave a Comment

Comments for this post are closed

Comments