Asia-Pacific (APEC)

APEC Cross-Border Privacy Rules (CBPR) System

59 controls. 20 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

59 controls 20 frameworks share controls with it Asia-Pacific (APEC) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

APEC Cross-Border Privacy Rules (CBPR) Evidence & Implementation Kit

59 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CBPR-01Notice9
CBPR-02Collection Limitation8
CBPR-03Uses of Personal Information10
CBPR-04Choice8
CBPR-05Integrity of Personal Information9
CBPR-06Security Safeguards18
CBPR-07Access and Correction9
CBPR-08Accountability16
CBPR-09Preventing Harm17
CBPR-PR-01Privacy statement published9
CBPR-PR-02Notice at the time of collection9
CBPR-PR-03Purposes stated at collection8
CBPR-PR-04Notice of sharing with third parties9
CBPR-PR-05Collection methods identified9
CBPR-PR-06Collection limited to relevant information7
CBPR-PR-07Lawful and fair collection8
CBPR-PR-08Use limited to stated purposes10
CBPR-PR-09Grounds for unrelated use9
CBPR-PR-10Disclosure to other controllers identified11
CBPR-PR-11Transfers to processors identified13
CBPR-PR-12Disclosure consistent with original purpose10
CBPR-PR-13Grounds for other disclosure8
CBPR-PR-14Choice over collection8
CBPR-PR-15Choice over use6
CBPR-PR-16Choice over disclosure7
CBPR-PR-17Choices clear and conspicuous5
CBPR-PR-18Choices clearly worded4
CBPR-PR-19Choices accessible and affordable5
CBPR-PR-20Mechanisms to honour choices7
CBPR-PR-21Accuracy verification14
CBPR-PR-22Correction mechanism9
CBPR-PR-23Corrections communicated after transfer6
CBPR-PR-24Corrections communicated after disclosure8
CBPR-PR-25Processor obligation to report data quality issues4
CBPR-PR-26Information security policy16
CBPR-PR-27Physical, technical and administrative safeguards17
CBPR-PR-28Safeguards proportional to risk18
CBPR-PR-29Employee security awareness16
CBPR-PR-30Specific proportional safeguards in place10
CBPR-PR-31Secure disposal policy18
CBPR-PR-32Detection, prevention and response measures15
CBPR-PR-33Testing the effectiveness of safeguards14
CBPR-PR-34Risk assessments and third party certifications16
CBPR-PR-35Processor protection obligations16
CBPR-PR-36Confirmation of holding7
CBPR-PR-37Access to personal information8
CBPR-PR-38Challenge and rectification8
CBPR-PR-39Measures to ensure compliance18
CBPR-PR-40Responsible individual appointed10
CBPR-PR-41Complaint handling procedures7
CBPR-PR-42Timely complaint response6
CBPR-PR-43Remedial action explained6
CBPR-PR-44Employee privacy training16
CBPR-PR-45Response to legal demands6
CBPR-PR-46Mechanisms with processors to meet obligations19
CBPR-PR-47Processor agreement content17
CBPR-PR-48Processor self-assessments12
CBPR-PR-49Spot checking and monitoring of processors14
CBPR-PR-50Disclosure where due diligence is impractical4

Tell me when APEC Cross-Border Privacy Rules (CBPR) System files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • The training programme content and its approval
  • Completion records covering all employees
  • The refresh cycle and evidence it is met
  • Follow-up for non-completers
  • Annual privacy training completion reports
  • Role specific training modules

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for APEC Cross-Border Privacy Rules (CBPR) System, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition