Global Cross-Border Privacy Rules (Global CBPR) Forum
Global CBPR Forum: Coordination with GDPR + UK + Japan APPI + Korea PIPA + Singapore PDPA + US State Laws

Global Cross-Border Privacy Rules (Global CBPR) Forum CBPR-Crosswalk-GDPR-StateLaws-ISO27701-NIST: Global CBPR Forum: Crosswalk to GDPR, US State Laws, ISO/IEC 27701 and NIST Privacy Framework

Global CBPR Forum crosswalk to adjacent privacy frameworks. (a) EU GDPR - 9 APEC principles map to GDPR Articles 5-25 + 32 + 33-34 + 35 with bridge gaps in (i) Lawful Basis (GDPR Art. 6) - CBPR uses 'compatible purposes' + consent + business purpose model rather than 6 lawful bases; (ii) Data Subject Rights (GDPR Art. 12-22) - CBPR covers access + correction; doesn't explicitly include right to erasure + portability + restriction + objection + ADM safeguards (UK CBPR may evolve); (iii) DPIA + DPO - CBPR more flexible than mandated; (iv) breach notification - CBPR principle but no 72-hour bright line; (v) lawful international transfers - CBPR IS one mechanism but not equivalent to adequacy decision. (b) UK GDPR + UK DATA PROTECTION ACT 2018 + UK DATA (USE AND ACCESS) BILL 2024 - similar to EU GDPR plus UK adequacy assessment context. (c) US STATE PRIVACY LAWS - CBPR explicitly recognized in California CCPA + Virginia VCDPA + Colorado CPA + Connecticut CTDPA + Florida FDBR + Tennessee TIPA + many others as adequacy/binding-program mechanism; coordinates with state-specific transparency + access + correction + opt-out + sale + sharing definitions. (d) HIPAA Privacy + Security Rules - separate covered-entity scope but coordination via Business Associate Agreements + privacy program. (e) FERPA - student education records; coordination via educational sector applications. (f) GLBA - financial services NPI; coordination via FTC Safeguards Rule (verified) + Privacy Rule. (g) ISO/IEC 27701:2019 - Privacy Information Management System extension to ISO 27001; many CBPR-certified organizations also pursue ISO 27701 + integrated PIMS approach; ISO 27701 + CBPR are complementary not duplicative. (h) NIST PRIVACY FRAMEWORK v1.0 (January 2020) - voluntary risk-based privacy management; cross-mapping to CBPR 9 principles + 50 Program Requirements; NIST Privacy Framework + CBPR commonly used together by US organizations. (i) ISO/IEC 27018 (PII protection in public cloud) - applicable to Processors + complements Global PRP. (j) ASEAN MCC (Model Contractual Clauses) - cross-recognition exploration. (k) APEC CBPR (predecessor) - continues for non-Forum APEC economies + Global CBPR supersedes for Forum members.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Global CBPR Forum: Coordination with GDPR + UK + Japan APPI + Korea PIPA + Singapore PDPA + US State Laws

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.