Civil society groups call for safeguards in commercial cyber intrusion guidelines

More than 25 civil society organisations and independent experts have urged the Pall Mall Process to include stronger human rights, oversight and accountability safeguards in its forthcoming guidelines for commercial cyber intrusion capabilities.

More than 25 civil society organisations and independent experts have submitted recommendations to the Pall Mall Process, a UK- and France-led initiative developing Industry Guidelines for Commercial Cyber Intrusion Capabilities (CCICs). The guidelines, expected to be finalised in November 2026, will address commercial spyware and other targeted surveillance technologies.

The submission argues that the guidelines should establish clear requirements for companies involved in the development, sale and transfer of these capabilities. The organisations say the tools can facilitate serious human rights violations and that their risks extend beyond government use, as increasingly accessible intrusion technologies can also reach non-state actors.

Among the proposed measures is a prohibition on supplying CCICs to non-state actors, except for legitimate state or public-interest research, as well as restrictions on transfers to states with documented patterns of abuse or inadequate safeguards. The organisations also call for human rights due diligence before and throughout procurement relationships, including criteria for excluding companies presenting unacceptable risks.

The submission further argues that participation in a voluntary industry code should not by itself demonstrate that a company has fulfilled its human rights responsibilities. It stresses that government regulation and corporate responsibility should operate alongside each other rather than serve as substitutes.

Specific protections are proposed for journalists, human rights defenders, political opponents, lawyers, judges, academics and civil society organisations. The groups also call for independent oversight mechanisms, including auditable records and licensing controls, with the ability to suspend or terminate access when misuse is identified.

The recommendations also cover access to remedy across borders. They include accessible complaint mechanisms, notification of affected individuals and safeguards against retaliation. The organisations argue that accountability mechanisms should remain available to people affected by the misuse of commercial cyber intrusion tools regardless of where the technology provider or user is based.

The submission also addresses the development process itself. It calls for sustained civil society participation, meaningful engagement with communities and individuals affected by spyware, and safeguards to prevent companies or individuals with documented involvement in abuses from influencing standards that would govern their own industry.

The Pall Mall Process previously developed a Code of Practice for States on commercial cyber intrusion capabilities. The forthcoming industry guidelines are intended to build on that work and are expected to be finalised in November 2026.

Go to Top