This post follows on from Wojciech Wiewiórowski‘s introduction to Data Protection in Humanitarian Action.

 

Personal Data at the Core of Humanitarian Action 

According to the UN, by the end of May 2025, nearly 300 million people around the world were in urgent need of humanitarian assistance and protection. Many of the emergency response services provided nowadays by humanitarian organizations worldwide involve or require personal data collection, processing and transfers. For example, humanitarian operations frequently process personal data when registering and verifying displaced persons for shelter or cash and voucher assistance, tracing and reuniting separated family members, identifying missing persons or human remains, managing health and medical data, or coordinating protection services. 

The long-standing international recognition of the human right to privacy (among others, in Article 12 of the Universal Declaration of Human Rights and Article 17 of the International Covenant on Civil and Political Rights) has been accompanied in recent years by the adoption of numerous regional and national laws that delineate and specify its correlated right to personal data protection. To date, 155 States across the globe have adopted some sort of national legislation on personal data protection. The adoption in 2015, and entry into force in 2018, of the European General Data Protection Regulation (GDPR)—with its unique extraterritoriality provisions (Article 3  and corresponding Recitals 22, 23, 24, and 25)—has caused a spillover effect beyond European-operating actors, with many multinational companies and organizations opting to adopt the strict data protection standards contained in the GDPR in order to avoid the burden of having to manage disparate regulatory systems. In turn, data protection laws around the world are, slowly but steadily, adapting to this reality through amendments and updates that seek to align them with this trend while preserving their national priorities.  

Humanitarian organizations face special challenges in protecting personal data when providing emergency response to protect individuals from the dangers of armed conflict, other situations of violence, natural disasters, pandemics and other humanitarian emergencies.  Not all humanitarian organizations share the same legal status: while some are NGOs subject to national and regional laws (see here), others have the status of international organizations, which grants them privileges and immunities that exempt them from the requirement of complying with certain regional and national legislation (see here, here and here for a more detailed analysis). However, as stressed by the ICRC in its Handbook on Data Protection in Humanitarian Action,

[r]espect for privacy and data protection rules is nevertheless, in many cases, a prerequisite for them to receive personal data from other entities and, therefore, to do their work,” and thus, even when not a legal obligation for those that are international organizations, “implementation of Data Protection standards […] should be a priority for all [h]umanitarian [o]rganizations, considering that the main objective of their activities is to work for the safety and dignity of individuals.  

In order to effectively carry out their humanitarian action, humanitarian organizations need to collect and process the personal data of individuals affected by emergencies. At the same time, protecting such personal data is often essential to safeguarding those individuals’ lives, security and work. The ICRC’s Handbook provides useful and practical guidance to help humanitarian organizations navigate the respect for data protection principles while carrying out their activities, under the premise that “particular care and flexibility is required when applying data protection principles in the humanitarian sector.”   

The GDPR refers to humanitarian action in three of its recitals, reaffirming that

when processing is necessary for humanitarian purposes, including for monitoring epidemics and their spread or in situations of humanitarian emergencies, in particular in situations of natural and man-made disasters,

this type of processing “may serve both important grounds of public interest and the vital interests of the data subject” (Recital 46). In the same sense, it adds that

[a]ny transfer to an international humanitarian organisation of personal data of a data subject who is physically or legally incapable of giving consent, with a view to accomplishing a task incumbent under the Geneva Conventions or to complying with international humanitarian law applicable in armed conflicts, could be considered to be necessary for an important reason of public interest or because it is in the vital interest of the data subject. (Recital 112; see here for a detailed analysis on transferring personal data to international organizations under the GDPR)

The GDPR also recognizes that humanitarian purposes may justify lawful restrictions on specific data protection rights and principles (Recital 73). 

Moreover, the Explanatory Report of the Council of Europe’s Convention 108+, which is open to ratification by both European and non-European States, also includes a specific reference to humanitarian action, stating that

[d]ata processing may serve both a ground of public interest and the vital interests of the data subject as, for instance, in the case of data processed for humanitarian purposes including monitoring a life-threatening epidemic and its spread or in humanitarian emergencies. The latter may occur in situations of natural disasters where processing of personal data of missing persons may be necessary for a limited time or purpose related to the emergency context—which is to be evaluated on a case-by-case basis. It can also occur in situations of armed conflicts or other violence.

Evolving Legal Framework in the Americas 

Unlike Europe, the region of the Americas does not have, to this date, a uniform binding regional instrument like the GDPR, imposing data protection obligations on its 35 States from North, South and Central America and the Caribbean.  Only three States of the Americas are parties to the Council of Europe’s Convention 108, and two of them are parties to its Convention 108+. At the level of domestic legislation, after a first wave of laws adopted in the late 1990s and a second wave in the first decade of the 2000s, to this date most States of the Americas have already adopted some sort of domestic law regarding data protection (see here). However, there are significant variations in the types and contents of those laws: not all are comprehensive data protection laws, and many still require updating to reflect recent trends. 

To further promote the uniformity of data protection laws in the continent, in 2012 the Inter-American Juridical Committee (IAJC), at the request of the Organization of American States’ (OAS) General Assembly, drafted and adopted a set of Inter-American Principles on Privacy and Data Protection. In 2015 it updated and broadened these to include detailed “Annotations” to serve as a guide for States. In turn, in 2017 the Ibero-American Data Protection Network, whose members include data protection authorities and private actors from many—yet not all—States of the Americas, adopted a set of Ibero-American Data Protection Standards, aligned to a great extent with the GDPR.  

In light of these latest significant normative developments, the IAJC again undertook the task of updating the Inter-American Principles on Privacy and Data Protection, with Annotations, as a result of a new request made to it by the OAS General Assembly.  Following extensive consultations with States and other stakeholders, in 2021 the IAJC adopted the Updated Principles on Privacy and Data Protection, with Annotations (for the Annotated Principles as adopted by the IAJC, see here and here; for the drafting history, see here). Moreover, the Principles themselves (without the annotations) were also adopted by the OAS General Assembly in October 2021. 

For the first time in their drafting history, the IAJC’s 2021 Updated Principles on Privacy and Data Protection, with Annotations contain references to humanitarian action in two paragraphs of their annotations, correlating it with grounds of public interest and of vital interests of data subjects: 

  • First, regarding the principle of consent, the annotations indicate that: “[i]n some situations, and more specifically in the framework of humanitarian action, obtaining consent might prove very difficult and therefore, it may be necessary and legitimate to rely on other legal basis, such as public interest or the vital interest of the Data Subject. The possibility of relying on public interest grounds is particularly important for humanitarian organizations, which, due to the nature of their activities and the emergency situations in which they usually operate, may find it difficult to fulfil the basic conditions of valid consent, particularly that it is informed and freely given. This may be the case, for example, where consenting to the processing of Personal Data is a precondition to receiving assistance or where it may be necessary to collect the data of a missing person. In these cases, humanitarian organizations should clearly substantiate and motivate their collection.” (pp. 10-11) 
  • Second, regarding trans-border personal data flows, they state that “OAS Member States are encouraged to ensure that the transfer of Personal Data across borders between humanitarian organizations and other entities with the specific purpose of providing humanitarian services remains as unrestricted as possible and as legally permissible. Consequently, domestic legislation should consider that humanitarian organizations may need to share Personal Data across borders to safeguard the vital interests of Data Subjects or for important grounds of public interest, based on the humanitarian organization’s mandate.” (p. 24) 

These guiding references are particularly relevant, bearing in mind that the existing data protection laws in the Americas contain general principles but do not make specific mention of humanitarian action. To guide their humanitarian practice in the Americas— which is largely focused on migration and forensics—States and humanitarian organizations in the region can benefit from the guidance of these annotations and of the ICRC’s Handbook. For example, in October 2024 the Mexican Prosecutors of Justice and the Honduran authorities, facilitated by the ICRC, agreed to share fingerprint information of unidentified deceased persons in order to assist in the identification of missing migrants (see here).  

The evolving legal frameworks and operational practices across the Americas reveal how regional approaches can shape and strengthen global standards for ensuring personal data protection in crises. They make clear that data protection is far more than a technical or legal requirement: it is a crucial enabler of humanitarian action, directly tied to the safety, dignity and rights of people affected by crises. These insights resonate throughout the recently published Routledge publication Data Protection in Humanitarian Action: Responding to Crises in a Data-Driven World, which brings together diverse perspectives to highlight both the progress achieved and the gaps that remain, while encouraging continued collaboration and responsible innovation that uphold humanitarian principles in an increasingly data-driven age. 

 

In a related post, Tatjana Grote will examine military personal data processing.