Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complexity for businesses with multi-state operations. (a) CALIFORNIA CCPA (Cal Civ Code 1798.140(p)) + CPRA - recognizes binding/enforceable cross-border programs; CPPA (California Privacy Protection Agency) enforcement consideration of CBPR certification + APEC CBPR; (b) VIRGINIA VCDPA - recognizes binding cross-border privacy programs as adequate; (c) COLORADO CPA - similar recognition; (d) CONNECTICUT CTDPA - similar recognition + active engagement; (e) FLORIDA FDBR - similar (2024 effective); (f) TENNESSEE TIPA - similar (2025 effective); (g) MONTANA MCDPA + IOWA IPA + UTAH UCPA + DELAWARE DPDPA + NEW HAMPSHIRE NHDPA + KENTUCKY KCDPA + RHODE ISLAND RIDTPPA + INDIANA ICDPA + ORGEON OCPA + WASHINGTON WDPA + others - similar recognition pattern. CBPR AS COMPLIANCE EVIDENCE: organizations leverage CBPR certification to demonstrate compliance with multi-state laws + reduce per-state compliance complexity + simplify cross-border data flows. RECIPROCAL RECOGNITION: California + multiple states recognize CBPR for businesses with multi-state customers + Northern California Privacy Forum + state DPA bilateral engagement. SECTORAL US LAWS: HIPAA + GLBA + COPPA + FERPA - separate covered-entity scope but CBPR provides supplementary accountability evidence + bridge for sector-internal cross-border transfers (e.g. multi-national health insurers + financial services + educational institutions).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.