Back to Frameworks

APEC Cross-Border Privacy Rules (CBPR) System

Asia-Pacific (APEC)
v2011 (updated)
17 domains
59 controls

The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary accountability-based framework for facilitating cross-border data flows among APEC economies while protecting personal information. Participating companies self-certify compliance with programme requirements, verified by APEC-recognised accountability agents. Based on the APEC Privacy Framework. Participating economies include US, Japan, Canada, South Korea, Australia, Singapore, and others. Being transitioned to the Global CBPR Forum.

Verified

APEC Cross-Border Privacy Rules (CBPR) System is a compliance framework from Asia-Pacific (APEC) with 17 domains and 59 controls that map to 20 other frameworks. The largest domains are CBPR Program Requirements: Accountability (12 controls), CBPR Program Requirements: Security Safeguards (10 controls), CBPR Program Requirements: Choice (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit cbprs.org

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

CBPR Program Requirements: Access and Correction

3 controls
Controls in the CBPR Program Requirements: Access and Correction domain of APEC Cross-Border Privacy Rules (CBPR) System3 controls
CodeTitle
CBPR-PR-36Confirmation of holding
CBPR-PR-37Access to personal information
CBPR-PR-38Challenge and rectification

CBPR Program Requirements: Accountability

12 controls
Controls in the CBPR Program Requirements: Accountability domain of APEC Cross-Border Privacy Rules (CBPR) System12 controls
CodeTitle
CBPR-PR-39Measures to ensure compliance
CBPR-PR-40Responsible individual appointed
CBPR-PR-41Complaint handling procedures
CBPR-PR-42Timely complaint response
CBPR-PR-43Remedial action explained
CBPR-PR-44Employee privacy training
CBPR-PR-45Response to legal demands
CBPR-PR-46Mechanisms with processors to meet obligations
CBPR-PR-47Processor agreement content
CBPR-PR-48Processor self-assessments
CBPR-PR-49Spot checking and monitoring of processors
CBPR-PR-50Disclosure where due diligence is impractical

CBPR Program Requirements: Choice

7 controls
Controls in the CBPR Program Requirements: Choice domain of APEC Cross-Border Privacy Rules (CBPR) System7 controls
CodeTitle
CBPR-PR-14Choice over collection
CBPR-PR-15Choice over use
CBPR-PR-16Choice over disclosure
CBPR-PR-17Choices clear and conspicuous
CBPR-PR-18Choices clearly worded
CBPR-PR-19Choices accessible and affordable
CBPR-PR-20Mechanisms to honour choices

CBPR Program Requirements: Collection Limitation

3 controls
Controls in the CBPR Program Requirements: Collection Limitation domain of APEC Cross-Border Privacy Rules (CBPR) System3 controls
CodeTitle
CBPR-PR-05Collection methods identified
CBPR-PR-06Collection limited to relevant information
CBPR-PR-07Lawful and fair collection

CBPR Program Requirements: Integrity of Personal Information

5 controls
Controls in the CBPR Program Requirements: Integrity of Personal Information domain of APEC Cross-Border Privacy Rules (CBPR) System5 controls
CodeTitle
CBPR-PR-21Accuracy verification
CBPR-PR-22Correction mechanism
CBPR-PR-23Corrections communicated after transfer
CBPR-PR-24Corrections communicated after disclosure
CBPR-PR-25Processor obligation to report data quality issues

CBPR Program Requirements: Notice

4 controls
Controls in the CBPR Program Requirements: Notice domain of APEC Cross-Border Privacy Rules (CBPR) System4 controls
CodeTitle
CBPR-PR-01Privacy statement published
CBPR-PR-02Notice at the time of collection
CBPR-PR-03Purposes stated at collection
CBPR-PR-04Notice of sharing with third parties

CBPR Program Requirements: Security Safeguards

10 controls
Controls in the CBPR Program Requirements: Security Safeguards domain of APEC Cross-Border Privacy Rules (CBPR) System10 controls
CodeTitle
CBPR-PR-26Information security policy
CBPR-PR-27Physical, technical and administrative safeguards
CBPR-PR-28Safeguards proportional to risk
CBPR-PR-29Employee security awareness
CBPR-PR-30Specific proportional safeguards in place
CBPR-PR-31Secure disposal policy
CBPR-PR-32Detection, prevention and response measures
CBPR-PR-33Testing the effectiveness of safeguards
CBPR-PR-34Risk assessments and third party certifications
CBPR-PR-35Processor protection obligations

CBPR Program Requirements: Uses of Personal Information

6 controls
Controls in the CBPR Program Requirements: Uses of Personal Information domain of APEC Cross-Border Privacy Rules (CBPR) System6 controls
CodeTitle
CBPR-PR-08Use limited to stated purposes
CBPR-PR-09Grounds for unrelated use
CBPR-PR-10Disclosure to other controllers identified
CBPR-PR-11Transfers to processors identified
CBPR-PR-12Disclosure consistent with original purpose
CBPR-PR-13Grounds for other disclosure

Consent

1 controls
Controls in the Consent domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-04Choice

Data Minimization

1 controls
Controls in the Data Minimization domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-02Collection Limitation

Data Quality

1 controls
Controls in the Data Quality domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-05Integrity of Personal Information

Governance

1 controls
Controls in the Governance domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-08Accountability

Individual Rights

1 controls
Controls in the Individual Rights domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-07Access and Correction

Purpose Limitation

1 controls
Controls in the Purpose Limitation domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-03Uses of Personal Information

Risk

1 controls
Controls in the Risk domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-09Preventing Harm

Security

1 controls
Controls in the Security domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-06Security Safeguards

Transparency

1 controls
Controls in the Transparency domain of APEC Cross-Border Privacy Rules (CBPR) System1 controls
CodeTitle
CBPR-01Notice

Your Compliance Coverage

If you comply with APEC Cross-Border Privacy Rules (CBPR) System, you already cover:

+ 17 more: Australia Consumer Data Right - Banking (CDR) (76%), Australian Privacy Principles (APPs) (75%)

See all 20 mapped frameworks ↓

Maps to 20 other frameworks

59 total controls
GDPR
59 source controls mapped|28 target controls covered
100%
ISO 27701:2019
54 source controls mapped|39 target controls covered
92%
APPI
50 source controls mapped|23 target controls covered
85%
Australia Consumer Data Right - Banking (CDR)
45 source controls mapped|23 target controls covered
76%
Australian Privacy Principles (APPs)
44 source controls mapped|11 target controls covered
75%
CCPA/CPRA
40 source controls mapped|24 target controls covered
68%
SOC 2
36 source controls mapped|15 target controls covered
61%
NIST SP 800-53 Rev 5
35 source controls mapped|18 target controls covered
59%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
34 source controls mapped|41 target controls covered
58%
NIST SP 800-161 Rev 1
33 source controls mapped|35 target controls covered
56%
Australia My Health Records Act 2012
29 source controls mapped|17 target controls covered
49%
C5 (Germany)
20 source controls mapped|33 target controls covered
34%
NIST SP 800-53 Rev 5 MODERATE
20 source controls mapped|31 target controls covered
34%
FedRAMP Moderate
20 source controls mapped|33 target controls covered
34%
NIST SP 800-53 Revision 5.1 HIGH
20 source controls mapped|32 target controls covered
34%
FedRAMP High
20 source controls mapped|33 target controls covered
34%
NIST SP 800-53 Rev 5 LOW
18 source controls mapped|25 target controls covered
31%
HIPAA Security Rule
17 source controls mapped|22 target controls covered
29%
NIST SP 800-66 Rev 2
17 source controls mapped|20 target controls covered
29%
Azure Security Benchmark
10 source controls mapped|21 target controls covered
17%

What is APEC Cross-Border Privacy Rules (CBPR) System and who does it apply to?

APEC Cross-Border Privacy Rules (CBPR) System is a compliance framework from Asia-Pacific (APEC) with 17 domains and 59 controls. The APEC Cross-Border Privacy Rules (CBPR) System is a voluntary accountability-based framework for facilitating cross-border data flows among APEC economies while protecting personal information. Participating companies self-certify compliance with programme requirements, verified by APEC-recognised accountability agents. Based on the APEC Privacy Framework. Participating economies include US, Japan, Canada, South Korea, Australia, Singapore, and others. Being transitioned to the Global CBPR Forum. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does APEC Cross-Border Privacy Rules (CBPR) System actually require?

APEC Cross-Border Privacy Rules (CBPR) System has 59 controls organised across 17 domains. The largest domains are CBPR Program Requirements: Accountability (12 controls), CBPR Program Requirements: Security Safeguards (10 controls), CBPR Program Requirements: Choice (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of APEC Cross-Border Privacy Rules (CBPR) System do I already cover?

APEC Cross-Border Privacy Rules (CBPR) System maps to 20 other compliance frameworks. The top mapping partners are GDPR (100% coverage), ISO 27701:2019 (92% coverage), APPI (85% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement APEC Cross-Border Privacy Rules (CBPR) System?

Start your APEC Cross-Border Privacy Rules (CBPR) System compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APEC Cross-Border Privacy Rules (CBPR) System requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 59 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required