APEC Cross-Border Privacy Rules (CBPR) System
The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary accountability-based framework for facilitating cross-border data flows among APEC economies while protecting personal information. Participating companies self-certify compliance with programme requirements, verified by APEC-recognised accountability agents. Based on the APEC Privacy Framework. Participating economies include US, Japan, Canada, South Korea, Australia, Singapore, and others. Being transitioned to the Global CBPR Forum.
APEC Cross-Border Privacy Rules (CBPR) System is a compliance framework from Asia-Pacific (APEC) with 17 domains and 59 controls that map to 20 other frameworks. The largest domains are CBPR Program Requirements: Accountability (12 controls), CBPR Program Requirements: Security Safeguards (10 controls), CBPR Program Requirements: Choice (7 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit cbprs.orgFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
CBPR Program Requirements: Access and Correction
| Code | Title |
|---|---|
| CBPR-PR-36 | Confirmation of holding |
| CBPR-PR-37 | Access to personal information |
| CBPR-PR-38 | Challenge and rectification |
CBPR Program Requirements: Accountability
| Code | Title |
|---|---|
| CBPR-PR-39 | Measures to ensure compliance |
| CBPR-PR-40 | Responsible individual appointed |
| CBPR-PR-41 | Complaint handling procedures |
| CBPR-PR-42 | Timely complaint response |
| CBPR-PR-43 | Remedial action explained |
| CBPR-PR-44 | Employee privacy training |
| CBPR-PR-45 | Response to legal demands |
| CBPR-PR-46 | Mechanisms with processors to meet obligations |
| CBPR-PR-47 | Processor agreement content |
| CBPR-PR-48 | Processor self-assessments |
| CBPR-PR-49 | Spot checking and monitoring of processors |
| CBPR-PR-50 | Disclosure where due diligence is impractical |
CBPR Program Requirements: Choice
| Code | Title |
|---|---|
| CBPR-PR-14 | Choice over collection |
| CBPR-PR-15 | Choice over use |
| CBPR-PR-16 | Choice over disclosure |
| CBPR-PR-17 | Choices clear and conspicuous |
| CBPR-PR-18 | Choices clearly worded |
| CBPR-PR-19 | Choices accessible and affordable |
| CBPR-PR-20 | Mechanisms to honour choices |
CBPR Program Requirements: Collection Limitation
| Code | Title |
|---|---|
| CBPR-PR-05 | Collection methods identified |
| CBPR-PR-06 | Collection limited to relevant information |
| CBPR-PR-07 | Lawful and fair collection |
CBPR Program Requirements: Integrity of Personal Information
| Code | Title |
|---|---|
| CBPR-PR-21 | Accuracy verification |
| CBPR-PR-22 | Correction mechanism |
| CBPR-PR-23 | Corrections communicated after transfer |
| CBPR-PR-24 | Corrections communicated after disclosure |
| CBPR-PR-25 | Processor obligation to report data quality issues |
CBPR Program Requirements: Notice
| Code | Title |
|---|---|
| CBPR-PR-01 | Privacy statement published |
| CBPR-PR-02 | Notice at the time of collection |
| CBPR-PR-03 | Purposes stated at collection |
| CBPR-PR-04 | Notice of sharing with third parties |
CBPR Program Requirements: Security Safeguards
| Code | Title |
|---|---|
| CBPR-PR-26 | Information security policy |
| CBPR-PR-27 | Physical, technical and administrative safeguards |
| CBPR-PR-28 | Safeguards proportional to risk |
| CBPR-PR-29 | Employee security awareness |
| CBPR-PR-30 | Specific proportional safeguards in place |
| CBPR-PR-31 | Secure disposal policy |
| CBPR-PR-32 | Detection, prevention and response measures |
| CBPR-PR-33 | Testing the effectiveness of safeguards |
| CBPR-PR-34 | Risk assessments and third party certifications |
| CBPR-PR-35 | Processor protection obligations |
CBPR Program Requirements: Uses of Personal Information
| Code | Title |
|---|---|
| CBPR-PR-08 | Use limited to stated purposes |
| CBPR-PR-09 | Grounds for unrelated use |
| CBPR-PR-10 | Disclosure to other controllers identified |
| CBPR-PR-11 | Transfers to processors identified |
| CBPR-PR-12 | Disclosure consistent with original purpose |
| CBPR-PR-13 | Grounds for other disclosure |
Consent
| Code | Title |
|---|---|
| CBPR-04 | Choice |
Data Minimization
| Code | Title |
|---|---|
| CBPR-02 | Collection Limitation |
Data Quality
| Code | Title |
|---|---|
| CBPR-05 | Integrity of Personal Information |
Governance
| Code | Title |
|---|---|
| CBPR-08 | Accountability |
Individual Rights
| Code | Title |
|---|---|
| CBPR-07 | Access and Correction |
Purpose Limitation
| Code | Title |
|---|---|
| CBPR-03 | Uses of Personal Information |
Risk
| Code | Title |
|---|---|
| CBPR-09 | Preventing Harm |
Security
| Code | Title |
|---|---|
| CBPR-06 | Security Safeguards |
Transparency
| Code | Title |
|---|---|
| CBPR-01 | Notice |
Your Compliance Coverage
If you comply with APEC Cross-Border Privacy Rules (CBPR) System, you already cover:
GDPR
100%
59 controls mapped
Compare →ISO 27701:2019
92%
54 controls mapped
Compare →APPI
85%
50 controls mapped
Compare →+ 17 more: Australia Consumer Data Right - Banking (CDR) (76%), Australian Privacy Principles (APPs) (75%)
See all 20 mapped frameworks ↓Maps to 20 other frameworks
What is APEC Cross-Border Privacy Rules (CBPR) System and who does it apply to?
APEC Cross-Border Privacy Rules (CBPR) System is a compliance framework from Asia-Pacific (APEC) with 17 domains and 59 controls. The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary accountability-based framework for facilitating cross-border data flows among APEC economies while protecting personal information. Participating companies self-certify compliance with programme requirements, verified by APEC-recognised accountability agents. Based on the APEC Privacy Framework. Participating economies include US, Japan, Canada, South Korea, Australia, Singapore, and others. Being transitioned to the Global CBPR Forum. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does APEC Cross-Border Privacy Rules (CBPR) System actually require?
APEC Cross-Border Privacy Rules (CBPR) System has 59 controls organised across 17 domains. The largest domains are CBPR Program Requirements: Accountability (12 controls), CBPR Program Requirements: Security Safeguards (10 controls), CBPR Program Requirements: Choice (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of APEC Cross-Border Privacy Rules (CBPR) System do I already cover?
APEC Cross-Border Privacy Rules (CBPR) System maps to 20 other compliance frameworks. The top mapping partners are GDPR (100% coverage), ISO 27701:2019 (92% coverage), APPI (85% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement APEC Cross-Border Privacy Rules (CBPR) System?
Start your APEC Cross-Border Privacy Rules (CBPR) System compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APEC Cross-Border Privacy Rules (CBPR) System requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 59 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required