Privacy protection, for example, can be demonstrated through data minimization practices,
regular third-party audits, and transparent consent mechanisms that allow individuals;
especially those with low digital literacy, to meaningfully control how their data is used.
Effective grievance redress systems that track and resolve privacy-related complaints also
serve as critical accountability tools. Meaningful community participation can be assessed
by the degree to which marginalized groups are represented in AI policy design and decisionmaking processes. Evidence that AI systems are advancing development rather than enabling
surveillance can be seen in whether their outputs correlate with more equitable service
delivery, improved welfare targeting, or reductions in bias across socioeconomic and
demographic lines. Transparency and oversight are key: indicators such as the publication of
model documentation, the frequency of fairness audits, and the existence of independent
bodies empowered to review or halt deployments are essential to ensuring that AI supports
development goals while respecting human rights.
Mandate Privacy-by-Design in All Public Digital Infrastructure
Governments must require that all digital systems, particularly those used in public service
delivery, welfare targeting, or digital identification, embed privacy-by-design principles from
the outset. This involves minimizing the collection of personal data, ensuring that only
relevant information is gathered and retained for a limited period, and that systems are built
with user consent, purpose limitation, and data security as default settings. Public digital
platforms should incorporate transparent data governance policies, privacy impact
assessments, and clear channels for grievance redress. By making privacy an architectural
cornerstone rather than an afterthought, states can protect individuals from surveillance
overreach and build long-term public trust in digital transformation initiatives.
To note, this recommendation may face significant political economy challenges, particularly
in contexts where state institutions may benefit from opaque data practices or where
surveillance aligns with broader security or control agendas. Government compliance cannot
be assumed, especially when data centralization serves political or bureaucratic interests. To
shift incentives, compliance could be tied to funding or technical assistance from
international development agencies, many of which now include digital safeguards in their
governance frameworks. Oversight mechanisms should include independent data protection
authorities with enforcement power, backed by legislation that mandates privacy impact
assessments and routine audits for all new digital infrastructure projects. Civil society
organizations (CSOs) can monitor implementation by engaging in technology assessments,
8