The Bleak Future of Human Rights Impact Assessments in the Technology Sector 

For some time now, CELE has been researching the use of "Human Rights Impact Assessments" (HRIAs) in the field of digital rights. This is a diagnostic tool that transnational companies providing internet services can adopt to ensure that they comply with their responsibility (which is not a legal obligation) to respect human rights, within the framework of the voluntary business and human rights model developed by the UN in recent years. We began by studying the conceptual history of impact assessments and their relationship to other efforts aimed at measuring human activity and seeking to anticipate its consequences in order to reduce foreseeable and preventable harm. We then analyzed how these impact assessments were adopted by companies in the telecommunications sector, in the context of a growing pessimism towards the internet, a shift in perception that moved away from viewing it as an inherently democratic technology and instead began to frame it as one that poses risks to democracy itself. Subsequently, we sought to bring the discussion to Latin Americain order to examine whether the region was in a good position to develop this corporate practice, given the fact that the vast majority of internet service providers being called upon to evaluate and mitigate negative human rights impacts online are transnational companies headquartered outside the region. 

A few years later, we can take stock of what we observed at the time and of the predictions we made. As we stated in 2023, for the tool to be adopted in Latin America, it would have to address enormous challenges that remain unaddressed, and its adoption by companies in the region continues to be an unresolved issue. On the other hand, the voluntary framework of the United Nations' business and human rights model remains an obstacle that limits the scope of those rights in relation to the practices of transnational corporations. The voluntary scheme is easy to explain: it exists because states failed, for decades, to reach an agreement on a binding human rights treaty for corporations. What we have is the only thing that could be achieved. Better than nothing, but still quite insufficient. The transformative potential of human rights as discursive resources to be mobilized politically and legally is contained and limited by a framework that offers no clear accountability mechanisms and depends on a global commitment to human rights which—at best—is currently going through a very weak moment.

The question I would like to address here is the following: Can HRIAs survive in the tech world after the European Union's Digital Services Act (DSA)? The question is pertinent because the DSA adopts a risk-based framework which requires companies to monitor their activities, assess their risks, mitigate them, and report on them to regional and national regulators. What the DSA is calling for is in part similar to what some companies were already doing under the business and human rights paradigm. This overlap will have consequences, as it merges previously distinct corporate practices into a single, unified process. The DSA has the potential to absorb the teams and professionals who used to carry out human rights impact assessments and convert or merge them into legal compliance and confidentiality teams. This is an argument recently and extensively developed by Daphne Keller. The DSA exerts that gravitational pull because it imposes, through formal legal requirements, demands similar to those previously articulated—though never legally binding—by the UN’s business and human rights framework. From an organizational perspective, it makes sense for different teams to consolidate efforts or for a single team to take on both functions. In that scenario, the HRIAs are at a disadvantage, because mistakes made during their development are only subject to weak and indirect forms of accountability, such as naming and shaming characteristic of the horizontal accountability mechanisms in the human rights field. Legal compliance and confidentiality failures under the DSA, by contrast, are measured in millions of dollars. 

Keller also argues that this shift is being driven by specific compliance and confidentialityrequirements, such as the need to document everything that is done in order to demonstrate it before administrative or judicial authorities. As Keller

« compliance and confidentiality teams typically do things like build oversight systems to avoid violating anti-corruption laws, tax laws, or securities regulations. Platforms and other companies can apply this approach to relatively predictable rules, like those under privacy and data protection laws such as the General Data Protection Regulation (GDPR). Building these systems to reduce complexity and risk—and to err on the side of overcompliance —often makes sense. Doing more than the law requires might cost a bit more money, but it's worth it to avoid trouble.» 

The problem with this approach, typical of the corporate legal world, is that overcompliance with rules related to user speech is far more problematic than overzealous protection of personal data. The incentives are aligned for companies to "err" on the safe side, restricting far more speech than necessary to avoid falling into the gray zone of corporate liability in the eyes of powerful regulators. We have already pointed out these issues when discussing the limitations of the DSA’s risk-based approach, which relegate rights to a secondary, marginal role. The future of HRIAs in the tech world looks, at the very least, complicated. On the one hand, the informal mechanisms of social and peer pressure that were supposed to lead companies to adopt human rights commitments have failed. Meta's alignment with the United States government, announced in January 2025, and the public statements by senior U.S. officials opposing European regulatory efforts seem to curtail the influence of the voluntary framework—at least in the short term. The world seems to be heading in contradictory directions, none of which place human rights at the center as a guiding paradigm. On the other hand, the legal codification of actions typically associated with HRIAs under the DSA—such as risk identification, assessment, and mitigation—draws HRIA practices closer to the realm of legal compliance and confidentiality with the already-mentioned risk of overcompliance.

The defense of human rights online will require, I fear, new and stronger arguments that overcome both limitations: the constraints of the United Nations’ voluntary framework and the loss of focus on rights inherent in the DSA’s risk-based approach. The challenge is to place rights, once again, at the center of the conversation.