Understanding the Pall Mall Process
Canva Pro: Hailshadow
It is estimated that over 100 countries, more than half of the world’s governments, now have access to commercial spyware. This means the risk of spyware affecting companies, investors, non-profit organizations, government officials, judges, journalists, and even critical public infrastructure is higher than ever.
The Pall Mall Process represents the first serious multilateral attempt to govern the commercial spyware and cyber intrusion market through voluntary codes of practice and state cooperation. However, experts warn that soft-law approaches to such a hard, urgent problem risk legitimizing spyware use. Furthermore, civil society argues that deliberations are moving forward without adequately addressing the crux of the issue: the technology itself may be incompatible with international human rights law by design.
Human rights organizations and the private sector alike are eager for Pall Mall to correct its course, given that democracy, rule of law, national security, and commercial interests such as the protection of intellectual property and consumer protection are at stake.
What is the Pall Mall Process, and why does it matter?
The Pall Mall Process is a voluntary, non-binding international initiative launched by the United Kingdom and France in February 2024 to respond to the growing misuse of commercial cyber intrusion tools (CCICs), including spyware. The initiative emerged after numerous discoveries that spyware had been deployed against journalists, activists, opposition figures, lawyers, executives and financial institutions, and government officials across multiple countries. Although some governments have long been hesitant to regulate the design, development and deployment of this technology, others have put guardrails in place to stop the proliferation of commercial spyware. Revelations of spyware abuse have elevated spyware from a technical cybersecurity issue into a broader debate about human rights, democratic accountability, and national security.
The Pall Mall Declaration sets out that the process aims to, amongst other things:
- Address the national security, human rights, and international stability risks posed by the commercial spyware and intrusion market
- Develop guiding principles and policy options for the development, purchase, transfer, and use of CCICs
- This includes the Code of Practice for States (which was adopted to establish a framework for responsible state activity in April 2025) and the impending Code of Practice for Industry (or industry guidelines)
- Encourage responsible state and corporate behavior in cyberspace in line with international law and UN norms
- Support cyber resilience and capacity-building, including defensive security research and vulnerability disclosure practices
What is spyware, exactly? Why is this technology so dangerous for democracy?
Spyware is a highly invasive form of malicious software that enables covert surveillance by secretly gaining access to a target’s device and extracting data without the user’s knowledge or consent. Unlike ordinary malware, advanced spyware can provide near-total control over a phone or computer, including access to encrypted messages, emails, contacts, location data, photos, microphones, and cameras. Some spyware uses “zero-click” exploits, allowing infection without any interaction from the target (i.e. no need to even click a malicious phishing link), making detection extremely difficult.
Investigations by Citizen Lab, Amnesty International, Access Now and other civil society organizations have uncovered evidence that governments and private actors have been using spyware as a key vector for violating rights. There are mounting cases of abuse, demonstrating the acute potential for spyware to facilitate transnational repression and undermine rights including privacy, free expression, press freedom, due process, freedom from arbitrary detention, freedom from gender-based violence, freedom from torture, and even the right to life.
Which governments have signed up to the voluntary initiative to combat the proliferation of spyware?
As of June 2026, 27 governments have signed a voluntary Code of Practice for States encouraging measures such as improved export controls, procurement restrictions, sanctions, support for spyware victims, and human rights due diligence for companies. The Code explicitly cites the United Nations Guiding Principles on Business and Human Rights twice, as well as a suggestion to “encourage CCIC vendors to conduct human rights due diligence, in order to identify, prevent and mitigate their adverse human rights impacts”. Investors are also mentioned as important actors within the CCIC ecosystem.
Supporting States include: Austria, Belgium, Denmark, Estonia, Finland, France, Germany, Ghana, Greece, Hungary, Ireland, Italy, Japan, Kosovo, Latvia, Luxembourg, Moldova, Netherlands, Poland, Republic of Korea, Romania, Slovakia, Slovenia, Sweden, Switzerland, United Kingdom of Great Britain and Northern Ireland, United States of America.
Notably, many states where spyware companies domiciled and/or where there have been reports of potential abuse (including Azerbaijan, Cyprus, India, Israel, Mexico, Morocco, Spain, and Saudi Arabia) are not signatories.
What has been said about the main benefits of the Pall Mall process thus far? Have governments made any changes in the name of Pall Mall?
The main benefit of the Pall Mall Process is that it has, for the first time, created sustained multilateral political attention on commercial spyware and broader cyber intrusion capabilities. The Pall Mall Process is an attempt to move the issue from fragmented national debates to a coordinated international forum. It also aims to improve internal coordination among government actors by connecting intelligence, national security, cybersecurity, and export control bodies, thereby breaking down silos to address this highly cross-cutting issue.
Now more than ever, governments are discussing the risks of commercial spyware proliferation, export control evasion, and the clear drawbacks for their own national interests rather than denying or minimizing the scale of the problem. To date, however, there is not yet clear evidence that the Pall Mall Process has acted as a driver of concrete policy change or enforcement outcomes, including reforms to state laws or regulatory interpretations, increased budgets or resources for civil society support or victim remediation, new or expanded prosecutorial action against spyware companies or officials implicated in abuse, or improvements in export controls, sanctions regimes, procurement restrictions, new accountability agencies or mechanisms, visa bans, and strengthened due diligence requirements in government technology procurement.
We have contacted the Pall Mall team to request more information about positive developments and will update this page accordingly if information is shared.
What are the main critiques of the Pall Mall process?
A number of civil society organizations have expressed concern that the process is:
Diluting existing state obligations - The Pall Mall Process relies on non-binding soft law, which has no oversight or enforcement mechanisms. Spyware abuses are already well documented and often carried out by states themselves. In this context, voluntary compliance depends on political will from the very actors who may benefit from weak oversight. Without binding standards, transparency requirements, stricter controls, judicial authorization, or independent investigations, there is little to prevent governments from invoking national security to justify unlawful surveillance. Critics argue this process risks normalizing spyware as a legitimate state tool rather than confronting whether using such technologies can ever be deployed in a rights-respecting manner. This normalization risks undermining legality, necessity, proportionality, democratic accountability, and civic space. Government obligations are accompanied by heavily qualified language -- such as “where applicable”-- which frames existing legally binding obligations as suggestions.
At grave risk of corporate capture - Although the process is formally multi-stakeholder, in practice participation and influence are uneven across governments, civil society, “offensive” CICCs companies and “defensive” industry working to protect IT infrastructure. This raises concerns that input is not meaningfully reflected in outcomes and that engagement may be more symbolic than substantive. The criteria for which companies can participate in shaping the process are seen as overly minimalistic, potentially allowing spyware companies with credible allegations of abuse or ongoing legal proceedings to engage directly in self-regulating. This has led to concerns that involvement in Pall Mall may function as a form of reputation laundering, where companies gain legitimacy through participation without demonstrating meaningful accountability or reform.
Quotes from civil society:
“Without credible monitoring, benchmarking, and public reporting, it is difficult to assess whether [Pall Mall] commitments translate into meaningful changes in the behaviour of states or commercial cyber intrusion vendors. In parallel, the Process should ensure meaningful and diverse civil society participation and create avenues to raise concerns about recurring abuses and implementation failures.” Stephane Duguin, Protect.ngo
What has been the timeline of the Pall Mall Process?
February 2024: The UK and France formally launch the Pall Mall Process
August to October 2024: The UK and France ran a public consultation, inviting views from stakeholders on good practices relating to constraining irresponsible activity across the cyber intrusion market
January 2025: The UK and France publish a report outlining their main findings from the consultation process
April 2025: A non-binding Code of Practice for States is formally adopted
November 2025 to January 2026: UK and France ran a consultation on commercial cyber intrusion industry practices
June 2026: The UK and France published a report summarizing key findings of the consultation on the Code of Practice for Industry
August to October 2026: Negotiations on the Code of Practice for Industry
November 2026: Projected launch of the Code of Practice for Industry
What are the next steps for the Pall Mall Process?
As described by the Pall Mall team, the next steps are the following:
- Finalize the Code of Practice for CCICs – The convening governments are currently working on a draft, which will be negotiated over the coming months, and the launch is scheduled for 10-11 November in Paris.
- Implement the Pall Mall Code of Practice for States – France and the UK are reportedly hosting a series of workshops for States to improve national governance frameworks in line with the Code of Practice for States and improve information sharing between governments.
- Awareness Raising and Outreach to Governments – France and the UK are hosting private convenings at conferences around the globe to raise awareness of the growing challenge posed by CCIC irresponsible use, familiarize stakeholders with the Pall Mall Process, and encourage new state signatories.
The Business and Human Rights Centre is keeping track of the evolution of the Pall Mall Process, and will update this page with additional materials periodically.