Compare with different regulatory event:

Description

Updated APEC Cross-Border Privacy Rules (CBPR) System outlining data transfer measures

On 4 November 2019, the Cross-Border Privacy Rules (CBPR) system is updated to include provisions endorsed by the Asia-Pacific Economic Cooperation (APEC) leaders in the APEC Privacy Framework 2015. The CBPR system represents a data privacy certification to which companies can adhere in order to demonstrate compliance with data protection measures and transfer data to the countries that endorsed the certification scheme. Under the CBPR system data controllers are required to obtain the consent of individuals where applicable to transfer personal data to another organization domestically or internationally. Furthermore, data controllers have to exercise due diligence and implement the necessary measures to ensure the protection of the data by the organization receiving it. The updated CBPR extends the certification scheme to data processing organizations. Data processors will be able to apply and receive accreditation from recognized accountability agents.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
bi- or plurilateral agreement
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2011-11-13
adopted

On 13 November 2011, the states of the Asia-Pacific Economic Cooperation (APEC) endorsed the establ…

2019-11-04
adopted

On 4 November 2019, the Cross-Border Privacy Rules (CBPR) system is updated to include provisions e…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): transfer: cross-border
Regulatory tool
User consent: Permit user opt-out
Registration requirement
Standard contractual clauses requirement
Regulator approval requirement
Technical standard adherence
Regulator cooperation requirements
Audit requirement
Sanctions
Regulated subjects
1
personal data (all forms): data collection
Regulatory tool
User consent: Permit user opt-out
Registration requirement
Regulator approval requirement
Technical standard adherence
Regulator cooperation requirements
Audit requirement
Sanctions
Regulated subjects
1
personal data (all forms): data processing

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): transfer: cross-border

personal data (all forms): data collection

personal data (all forms): data processing