Skip to content

Ethical Framework for Human Rights (EFHR)

An open-source framework any organization can adopt, fork, and adapt to govern its relationships and internal conduct with respect to human rights.

Why this exists

"Ethical use of technology" is too broad to act on. This framework narrows the question deliberately: it is not a general ethics or ESG program, and it does not try to adjudicate every moral question a company faces. It answers one question precisely — which relationships, transactions, and internal practices does this organization refuse to engage in because of human rights harm, and who gets to decide?

It was written from a technology company's vantage point but contains nothing technology-specific. Any organization — a bank, a manufacturer, a university, a nonprofit — can adopt it as-is or fork it.

What's in this repo

File Purpose
PRINCIPLES.md The six guiding principles the rest of the framework is derived from
GOVERNANCE.md The mechanism for deciding who counts as a "bad actor" — sourcing, thresholds, review, appeals
prohibited-actions/with-bad-actors.md Relationship types barred with any entity designated a bad actor
prohibited-actions/within-company.md Baseline internal conduct rules, derived from international human rights law
prohibited-actions/with-any-counterparty.md Actions barred regardless of counterparty status — because a "good actor" can still misuse a product
reference/international-instruments.md The international law baseline this framework is anchored to
reference/reference-organizations.md The starting panel of independent human rights organizations the governance mechanism draws on
CONTRIBUTING.md How to propose changes or adapt this for your organization

How the pieces fit together

  1. Principles set the posture: permissive by default, humble about who judges, anchored in international rather than local law.
  2. Governance answers "who decides a counterparty is a bad actor" — without that answered credibly, nothing else in this framework is defensible.
  3. Three prohibited-actions lists cover the three places human rights risk shows up: your counterparties, your own operations, and residual risk that exists even with a clean counterparty.
  4. Reference material documents the legal and institutional basis so the lists in section 3 aren't arbitrary.

Adopting this framework

This is a starting point, not a finished compliance program. An adopting organization should expect to:

  • Substitute its own risk appetite into the thresholds in GOVERNANCE.md (the defaults proposed here are deliberately conservative)
  • Route final designations and prohibited-action calls through legal counsel — this framework states a policy position, not legal advice
  • Publish which version/commit of the framework it has adopted, and any deviations, so the framework stays meaningful as a public commitment rather than a PDF nobody checks against

License

Released under CC BY 4.0 — reuse, adapt, and redistribute freely, with attribution. See LICENSE.md.