Skip to content

Prohibited Actions Regardless of Counterparty Status

GOVERNANCE.md decides who is a bad actor, and with-bad-actors.md prohibits relationship types with entities so designated. This document covers the gap that leaves: a counterparty that is not a designated bad actor can still misuse a product or service in a way that causes serious human rights harm. Cisco's equipment sales into China are the canonical example — the counterparty (the Chinese government, as a customer of off-the-shelf equipment) was not, at the time of sale, a designated bad actor, but the equipment was later alleged to have been customized to help identify and suppress a specific religious minority. A framework that only screens counterparties misses this case entirely.

These prohibitions apply to every transaction, including with counterparties in good standing.

No end-use blindness on dual-use technology

Before selling or licensing any product with a plausible surveillance, censorship, or biometric-tracking application to a government or security-sector buyer — regardless of that buyer's designation status — conduct and document an end-use human rights review. "The customer didn't ask us to help with repression" is not sufficient diligence if the product's ordinary use would foreseeably enable it.

No silent customization for repression

Do not build custom features, tuning, or configuration for a government or security-sector customer that increases the product's capability to identify, track, or suppress a specific political, ethnic, or religious group — even if the base product is sold to bad actors and non-bad-actors alike. The prohibition is on the customization, not the underlying product.

No contracts without human rights exit rights

Any contract with a government or law-enforcement customer for a product with surveillance, censorship, or data-access capability must include a clause allowing the company to suspend or terminate service if credible evidence emerges of human-rights-abusive use — and that clause must be exercised, not just held on file, when such evidence appears.

No outsourcing the violation

Do not achieve through a subsidiary, reseller, distributor, or contractor what would be prohibited if done directly. This applies whether or not the intermediary itself is a designated bad actor.

No treating "not yet designated" as "cleared"

Absence of a bad-actor designation is not an affirmative finding of good conduct — see Principle 2. It means the entity hasn't been reviewed or hasn't crossed the threshold, not that it has passed a human rights review. High-risk transactions (state security customers, biometric systems, mass-data-access requests) warrant their own due diligence independent of designation status.