Global Cross-Border Privacy Rules (Global CBPR) Forum
Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

Global Cross-Border Privacy Rules (Global CBPR) Forum CBPR-9-APEC-Privacy-Principles: Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

Global CBPR Forum is based on the 9 APEC PRIVACY PRINCIPLES adopted in 2004 + revised 2015 + carried forward into Global CBPR Program Requirements (~50 detailed). (1) NOTICE - clear + accessible privacy statements identifying purposes of collection + use + disclosure + collection practices; (2) COLLECTION LIMITATION - limited to information relevant to purposes + obtained by lawful + fair means; (3) USES OF PERSONAL INFORMATION - use limited to purposes for which collected + compatible purposes + with consent or by law; (4) CHOICE - mechanisms for individuals to opt-out or opt-in to collection + use + disclosure; (5) INTEGRITY OF PERSONAL INFORMATION - accurate + complete + up-to-date; (6) SECURITY SAFEGUARDS - administrative + physical + technical safeguards proportionate to sensitivity + risks; (7) ACCESS AND CORRECTION - individuals can confirm holdings + access + correct/amend; reasonable cost + delay; (8) ACCOUNTABILITY - controller is responsible for compliance + must enforce with third-party processors + downstream recipients; (9) PREVENTING HARM - recognize the potential harm from misuse + minimize likelihood + magnitude. PROGRAM REQUIREMENTS: ~50 detailed requirements operationalising the 9 principles; certification requires demonstrating compliance with each. AAs assess against these. EVOLUTION FROM APEC: same 9 principles + same scope + same accountability-based approach + updated for cross-border digital economy + AI + emerging tech.

What else in your programme already covers this

This control maps to 116 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 5 controls

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

FedRAMP Rev 5 · 2 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • CA-10 Selects and Develops Control Activities

GLBA · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 116 it maps to, and the evidence behind each claim, over MCP and REST.