APEC Cross-Border Privacy Rules (CBPR) System

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary, accountability-based certification that lets organizations demonstrate that their privacy practices meet the APEC Privacy Framework so they can move personal information across participating economies. A certified organization commits to a published set of program requirements, is assessed by an independent Accountability Agent, and is subject to enforcement by a privacy regulator in its home jurisdiction.
APEC Leaders endorsed the CBPR System in 2011, and nine APEC economies participate: the United States, Mexico, Japan, Canada, Singapore, the Republic of Korea, Australia, Chinese Taipei, and the Philippines. In 2022 those economies established the Global CBPR Forum, which now administers the Global CBPR and Global Privacy Recognition for Processors (PRP) certifications as the successor to the APEC systems and has since admitted the Dubai International Financial Centre as a member and Bermuda, Mauritius, Nigeria, and the United Kingdom as associates. The certification binds personal information controllers (CBPR) and processors (PRP) that choose to be certified; it does not replace domestic privacy law.
Organizations implement the CBPR System by mapping their privacy program to the 50 program requirements grouped under the Global CBPR Privacy Principles, completing the intake questionnaire, and submitting policies and evidence to a Forum-recognized Accountability Agent for review, certification, and annual recertification. Compliance programs typically integrate CBPR with GDPR, ISO/IEC 27701, and national privacy laws so one set of controls supports several transfer mechanisms.
Why it Matters
The APEC CBPR System gives organizations an internationally recognized way to prove accountable handling of personal data and to keep cross-border data flows lawful where participating economies recognize the certification.
Key benefits include:
- Enable lawful cross-border data transfers
Certification is recognized by participating economies as a mechanism for transferring personal information, reducing reliance on bespoke contracts.
- Demonstrate accountability to regulators and customers
Independent assessment and a published certification mark show that privacy commitments are verified rather than self-declared.
- Harmonize privacy controls across jurisdictions
One set of program requirements aligned with the APEC Privacy Framework and the OECD Privacy Guidelines supports compliance in several markets at once.
- Extend assurance to processors
The companion PRP certification lets processors show controllers that they can meet CBPR obligations on their behalf.
- Reduce enforcement and reputational risk
Backstopped enforcement by privacy authorities through the Cross-Border Privacy Enforcement Arrangement gives the certification credibility with consumers and partners.
How it Works
The CBPR System is built on nine Global CBPR Privacy Principles carried over from the APEC Privacy Framework: Preventing Harm, Notice, Collection Limitation, Uses of Personal Information, Choice, Integrity of Personal Information, Security Safeguards, Access and Correction, and Accountability. The program requirements translate these principles into 50 assessable questions grouped under eight headings, each with assessment criteria that an Accountability Agent verifies. Accountability Agents are recognized by the Forum against published criteria, and privacy enforcement authorities cooperate through the Cross-Border Privacy Enforcement Arrangement.
Organizations implement the system by completing the intake questionnaire, attaching privacy statements, policies, and procedures as evidence, and working with the Accountability Agent to close gaps before certification. Ongoing activities include maintaining a personal information inventory, honoring notice and choice commitments, managing onward transfers to third parties and processors, running security safeguards proportionate to risk, handling access and correction requests, and responding to complaints and annual recertification reviews.
Within SmartSuite, teams can operationalize the CBPR System by loading the 50 program requirements as a control library, assigning owners and review cadences, attaching the privacy statements and procedures an Accountability Agent will ask for, and tracking recertification, complaints, and third-party transfers in one workspace with dashboards for privacy leadership.
Key Elements
- Global CBPR Privacy Principles
Nine principles derived from the APEC Privacy Framework that define what a certified organization must commit to.
- Program requirements and intake questionnaire
Fifty questions with assessment criteria that applicants answer and evidence, replicated in the intake questionnaire.
- Accountability Agents
Independent, Forum-recognized bodies that assess applicants, certify them, monitor compliance, and handle disputes.
- Privacy Recognition for Processors (PRP)
A parallel certification that lets processors demonstrate they can implement a controller's CBPR obligations.
- Enforcement backstop
Privacy enforcement authorities in each participating jurisdiction can act on a certified organization's failure to honor its commitments, cooperating through the Cross-Border Privacy Enforcement Arrangement.
- Global CBPR Forum governance
The Forum, established by the 2022 Global CBPR Declaration, sets the Framework, program requirements, and recognition criteria and admits members and associates.
Framework Scope
The CBPR System applies to personal information controllers headquartered in a participating jurisdiction that seek certification, and through PRP to processors acting on a controller's instructions. It covers the collection, use, disclosure, transfer, and safeguarding of personal information about identified or identifiable individuals, and it is typically adopted by multinational organizations that transfer customer or employee data among Asia-Pacific and Global CBPR Forum jurisdictions.
Framework Objectives
The APEC CBPR System aims to protect personal information while keeping trusted cross-border data flows open among participating economies.
Give individuals clear notice, choice, and access rights wherever their data travels
Hold certified organizations accountable through independent assessment and regulator enforcement
Provide a single recognized transfer mechanism that bridges differing national privacy laws
Extend verified privacy assurance to processors through the PRP certification
Promote interoperability with the OECD Privacy Guidelines, GDPR, and other frameworks
Support small and medium-sized businesses with a practical, scalable certification path
Framework in Context
The CBPR System operationalizes the APEC Privacy Framework and is consistent with the OECD Privacy Guidelines; the Global CBPR Framework of 2023 restates both as the basis for the global certifications. Organizations commonly run it alongside GDPR and UK GDPR transfer mechanisms, the EU-US Data Privacy Framework, ISO/IEC 27701, and the national privacy laws of the participating economies.
Common Framework Mappings
Organizations map the CBPR program requirements to regional privacy laws and privacy management standards so that one privacy program supports certification, statutory compliance, and international transfers.
Mapped frameworks include:
APEC PF
APEC Privacy Recognition for Processors (PRP)
OECD Privacy Guidelines
GDPR
UK GDPR
EU-US DPF
Convention 108+
ISO 27701
ISO 29100
NIST Privacy Framework v1.0
Privacy Act 1988 (APPs)
APPI
PIPA (South Korea)
Singapore PDPA
Philippines DPA (RA 10173)
- ClassificationCategoryData Protection & PrivacyDomainPrivacyFramework FamilyAPEC Privacy Framework
- Regulatory ContextTypeCertification / Assurance ProgramLegal InstrumentCertification ProgramSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionAsia-PacificRegion DetailAPEC economies and Global CBPR Forum membersPublisherAsia-Pacific Economic Cooperation (APEC); Global CBPR Forum
- VersioningVersionAPEC CBPR System (2011); Global CBPR Framework (2023) and program requirements (valid to 31 March 2027; September 2025 update effective 1 April 2027)Effective Date2011Issue Date2011
- AdoptionAdoption ModelCertificationImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The CBPR Framework, program requirements, and intake questionnaire are published free of charge by the Global CBPR Forum and APEC; SmartSuite does not include the text within the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports APEC CBPR
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Manage CBPR certification by holding the 50 program requirements, the intake questionnaire evidence, Accountability Agent findings, and annual recertification tasks in one accountable privacy workspace.
CBPR Program Requirements Library
Load the 50 program requirements under their nine privacy principles and link each to policies and procedures.
Ownership, Cadence, and Recertification
Assign requirement owners, schedule reviews, and track the annual recertification cycle with the Accountability Agent.
Evidence Collection and Audit Trail
Attach privacy statements, contracts, and training records to each requirement with timestamps and reviewers.
Assessment and Gap Remediation
Record intake questionnaire answers, Accountability Agent findings, and remediation tasks through to closure.
Third-Party Transfer and Processor Oversight
Track onward transfers, processor contracts, and PRP status for the vendors that handle certified data.
Privacy Program Reporting
Report certification status, open findings, complaints, and transfer inventories to privacy leadership and regulators.
Related frameworks

APEC Privacy Framework helps organizations manage cross-border privacy risks and facilitate data flows among Asia-Pacific economies.

OECD Privacy Guidelines provide international principles for protecting personal data and enabling safe cross-border data flows.

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

The EU-US Data Privacy Framework enables lawful transfers of EU personal data to US organizations by requiring adequate privacy protections.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Singapore's Personal Data Protection Act sets rules for how organizations collect, use, and disclose individuals' personal data.
Frequently Asked Questions For APEC CBPR
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

