Global CBPR Forum is based on the 9 APEC PRIVACY PRINCIPLES adopted in 2004 + revised 2015 + carried forward into Global CBPR Program Requirements (~50 detailed). (1) NOTICE - clear + accessible privacy statements identifying purposes of collection + use + disclosure + collection practices; (2) COLLECTION LIMITATION - limited to information relevant to purposes + obtained by lawful + fair means; (3) USES OF PERSONAL INFORMATION - use limited to purposes for which collected + compatible purposes + with consent or by law; (4) CHOICE - mechanisms for individuals to opt-out or opt-in to collection + use + disclosure; (5) INTEGRITY OF PERSONAL INFORMATION - accurate + complete + up-to-date; (6) SECURITY SAFEGUARDS - administrative + physical + technical safeguards proportionate to sensitivity + risks; (7) ACCESS AND CORRECTION - individuals can confirm holdings + access + correct/amend; reasonable cost + delay; (8) ACCOUNTABILITY - controller is responsible for compliance + must enforce with third-party processors + downstream recipients; (9) PREVENTING HARM - recognize the potential harm from misuse + minimize likelihood + magnitude. PROGRAM REQUIREMENTS: ~50 detailed requirements operationalising the 9 principles; certification requires demonstrating compliance with each. AAs assess against these. EVOLUTION FROM APEC: same 9 principles + same scope + same accountability-based approach + updated for cross-border digital economy + AI + emerging tech.
This control maps to 116 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 116 it maps to, and the evidence behind each claim, over MCP and REST.