Data Protection & Privacy
DETAIL

APEC Cross-Border Privacy Rules (CBPR) System

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary, accountability-based certification that lets organizations demonstrate that their privacy practices meet the APEC Privacy Framework so they can move personal information across participating economies. A certified organization commits to a published set of program requirements, is assessed by an independent Accountability Agent, and is subject to enforcement by a privacy regulator in its home jurisdiction.

APEC Leaders endorsed the CBPR System in 2011, and nine APEC economies participate: the United States, Mexico, Japan, Canada, Singapore, the Republic of Korea, Australia, Chinese Taipei, and the Philippines. In 2022 those economies established the Global CBPR Forum, which now administers the Global CBPR and Global Privacy Recognition for Processors (PRP) certifications as the successor to the APEC systems and has since admitted the Dubai International Financial Centre as a member and Bermuda, Mauritius, Nigeria, and the United Kingdom as associates. The certification binds personal information controllers (CBPR) and processors (PRP) that choose to be certified; it does not replace domestic privacy law.

Organizations implement the CBPR System by mapping their privacy program to the 50 program requirements grouped under the Global CBPR Privacy Principles, completing the intake questionnaire, and submitting policies and evidence to a Forum-recognized Accountability Agent for review, certification, and annual recertification. Compliance programs typically integrate CBPR with GDPR, ISO/IEC 27701, and national privacy laws so one set of controls supports several transfer mechanisms.

Why it Matters

The APEC CBPR System gives organizations an internationally recognized way to prove accountable handling of personal data and to keep cross-border data flows lawful where participating economies recognize the certification.

Key benefits include:

  • Enable lawful cross-border data transfers

Certification is recognized by participating economies as a mechanism for transferring personal information, reducing reliance on bespoke contracts.

  • Demonstrate accountability to regulators and customers

Independent assessment and a published certification mark show that privacy commitments are verified rather than self-declared.

  • Harmonize privacy controls across jurisdictions

One set of program requirements aligned with the APEC Privacy Framework and the OECD Privacy Guidelines supports compliance in several markets at once.

  • Extend assurance to processors

The companion PRP certification lets processors show controllers that they can meet CBPR obligations on their behalf.

  • Reduce enforcement and reputational risk

Backstopped enforcement by privacy authorities through the Cross-Border Privacy Enforcement Arrangement gives the certification credibility with consumers and partners.

How it Works

The CBPR System is built on nine Global CBPR Privacy Principles carried over from the APEC Privacy Framework: Preventing Harm, Notice, Collection Limitation, Uses of Personal Information, Choice, Integrity of Personal Information, Security Safeguards, Access and Correction, and Accountability. The program requirements translate these principles into 50 assessable questions grouped under eight headings, each with assessment criteria that an Accountability Agent verifies. Accountability Agents are recognized by the Forum against published criteria, and privacy enforcement authorities cooperate through the Cross-Border Privacy Enforcement Arrangement.

Organizations implement the system by completing the intake questionnaire, attaching privacy statements, policies, and procedures as evidence, and working with the Accountability Agent to close gaps before certification. Ongoing activities include maintaining a personal information inventory, honoring notice and choice commitments, managing onward transfers to third parties and processors, running security safeguards proportionate to risk, handling access and correction requests, and responding to complaints and annual recertification reviews.

Within SmartSuite, teams can operationalize the CBPR System by loading the 50 program requirements as a control library, assigning owners and review cadences, attaching the privacy statements and procedures an Accountability Agent will ask for, and tracking recertification, complaints, and third-party transfers in one workspace with dashboards for privacy leadership.

Key Elements

  • Global CBPR Privacy Principles

Nine principles derived from the APEC Privacy Framework that define what a certified organization must commit to.

  • Program requirements and intake questionnaire

Fifty questions with assessment criteria that applicants answer and evidence, replicated in the intake questionnaire.

  • Accountability Agents

Independent, Forum-recognized bodies that assess applicants, certify them, monitor compliance, and handle disputes.

  • Privacy Recognition for Processors (PRP)

A parallel certification that lets processors demonstrate they can implement a controller's CBPR obligations.

  • Enforcement backstop

Privacy enforcement authorities in each participating jurisdiction can act on a certified organization's failure to honor its commitments, cooperating through the Cross-Border Privacy Enforcement Arrangement.

  • Global CBPR Forum governance

The Forum, established by the 2022 Global CBPR Declaration, sets the Framework, program requirements, and recognition criteria and admits members and associates.

Framework Scope

The CBPR System applies to personal information controllers headquartered in a participating jurisdiction that seek certification, and through PRP to processors acting on a controller's instructions. It covers the collection, use, disclosure, transfer, and safeguarding of personal information about identified or identifiable individuals, and it is typically adopted by multinational organizations that transfer customer or employee data among Asia-Pacific and Global CBPR Forum jurisdictions.

Framework Objectives

The APEC CBPR System aims to protect personal information while keeping trusted cross-border data flows open among participating economies.

Give individuals clear notice, choice, and access rights wherever their data travels

Hold certified organizations accountable through independent assessment and regulator enforcement

Provide a single recognized transfer mechanism that bridges differing national privacy laws

Extend verified privacy assurance to processors through the PRP certification

Promote interoperability with the OECD Privacy Guidelines, GDPR, and other frameworks

Support small and medium-sized businesses with a practical, scalable certification path

Framework in Context

The CBPR System operationalizes the APEC Privacy Framework and is consistent with the OECD Privacy Guidelines; the Global CBPR Framework of 2023 restates both as the basis for the global certifications. Organizations commonly run it alongside GDPR and UK GDPR transfer mechanisms, the EU-US Data Privacy Framework, ISO/IEC 27701, and the national privacy laws of the participating economies.

Common Framework Mappings

Organizations map the CBPR program requirements to regional privacy laws and privacy management standards so that one privacy program supports certification, statutory compliance, and international transfers.

Mapped frameworks include:

APEC PF

APEC Privacy Recognition for Processors (PRP)

OECD Privacy Guidelines

GDPR

UK GDPR

EU-US DPF

Convention 108+

ISO 27701

ISO 29100

NIST Privacy Framework v1.0

Privacy Act 1988 (APPs)

APPI

PIPA (South Korea)

Singapore PDPA

Philippines DPA (RA 10173)

At a Glance
APEC Cross-Border Privacy Rules (CBPR) System
  • Classification
    Category
    Data Protection & Privacy
    Domain
    Privacy
    Framework Family
    APEC Privacy Framework
  • Regulatory Context
    Type
    Certification / Assurance Program
    Legal Instrument
    Certification Program
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Asia-Pacific
    Region Detail
    APEC economies and Global CBPR Forum members
    Publisher
    Asia-Pacific Economic Cooperation (APEC); Global CBPR Forum
  • Versioning
    Version
    APEC CBPR System (2011); Global CBPR Framework (2023) and program requirements (valid to 31 March 2027; September 2025 update effective 1 April 2027)
    Effective Date
    2011
    Issue Date
    2011
  • Adoption
    Adoption Model
    Certification
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

The CBPR Framework, program requirements, and intake questionnaire are published free of charge by the Global CBPR Forum and APEC; SmartSuite does not include the text within the platform.

Framework text is licensed by its publisher and is included only where stated above.

SMARTSUITE

How SmartSuite Supports APEC CBPR

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Manage CBPR certification by holding the 50 program requirements, the intake questionnaire evidence, Accountability Agent findings, and annual recertification tasks in one accountable privacy workspace.

CBPR Program Requirements Library

Load the 50 program requirements under their nine privacy principles and link each to policies and procedures.

Ownership, Cadence, and Recertification

Assign requirement owners, schedule reviews, and track the annual recertification cycle with the Accountability Agent.

Evidence Collection and Audit Trail

Attach privacy statements, contracts, and training records to each requirement with timestamps and reviewers.

Assessment and Gap Remediation

Record intake questionnaire answers, Accountability Agent findings, and remediation tasks through to closure.

Third-Party Transfer and Processor Oversight

Track onward transfers, processor contracts, and PRP status for the vendors that handle certified data.

Privacy Program Reporting

Report certification status, open findings, complaints, and transfer inventories to privacy leadership and regulators.

Related frameworks

APEC PF

APEC Privacy Framework helps organizations manage cross-border privacy risks and facilitate data flows among Asia-Pacific economies.

OECD Privacy Guidelines

OECD Privacy Guidelines provide international principles for protecting personal data and enabling safe cross-border data flows.

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

EU-US DPF

The EU-US Data Privacy Framework enables lawful transfers of EU personal data to US organizations by requiring adequate privacy protections.

ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Singapore PDPA

Singapore's Personal Data Protection Act sets rules for how organizations collect, use, and disclose individuals' personal data.

Philippines DPA (RA 10173)

Philippines Data Privacy Act of 2012 is a national law governing personal data collection, processing, and protection to safeguard privacy.

Convention 108+

Convention 108 is the only binding international data protection treaty; Convention 108+ modernizes it with GDPR-style principles, breach notification, and stronger supervisory authorities.

ONBOARDING FAQS

Frequently Asked Questions For APEC CBPR

No items found.

Operationalize APEC CBPR System with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.