Compare with different regulatory event:

Description

Adoption of APEC Cross-Border Privacy Rules (CBPR) System including data protection measures

On 13 November 2011, the states of the Asia-Pacific Economic Cooperation (APEC) endorsed the establishment of the Cross-Border Privacy Rules (CBPR) system. The CBPR system implements the APEC Privacy Framework of 2005, by providing a voluntary data protection certification for companies that control personal data. Such data controllers can apply with third parties (accountability agents) for a certificate, which demonstrates compliance with the APEC privacy framework and enables data transfers to the APEC countries that participate in the CBPR system. The CBPR system introduces both obligations for data controllers and rights for data subjects. Regarding data protection obligations, the CBPR system requires companies to implement measures to prevent the misuse of personal data and take into consideration the risks to personal data when establishing remedial measures. Data controllers must implement appropriate safeguards against the unauthorised access, loss, destruction or modification of personal data. Regarding data subject rights, data controllers must collect data by lawful and fair means and where appropriate obtain consent from the data subject. Moreover, data subjects should be able to access the personal data collected by data controllers and request rectification and deletion, although these measures can be subject to limitations in instances where it is impossible or impracticable to change, suppress or delete personal data records. Regarding data breaches, the CBPR system does not require notification to competent authorities or data subjects by data controllers. Rather, the CBPR system obliges participating countries to introduce rules which require a contractual obligation for data breach notification between data controllers and agents, contractors and data processors.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
bi- or plurilateral agreement
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2011-11-13
adopted

On 13 November 2011, the states of the Asia-Pacific Economic Cooperation (APEC) endorsed the establ…

2019-11-04
under deliberation

On 4 November 2019, the Cross-Border Privacy Rules (CBPR) system is updated to include provisions e…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
User consent: Opt-in requirement
Duty of care requirement
Technical standard adherence
Other user right
Sanctions
Determined by existing law or regulation
Other structural remedy
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
Responsive security requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
User consent: Opt-in requirement
Duty of care requirement
Technical standard adherence
Other user right
Sanctions
Determined by existing law or regulation
Other structural remedy
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
User consent: Other requirement
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Purpose/processing limitation
User consent: Opt-in requirement
Duty of care requirement
Technical standard adherence
Other user right
Sanctions
Determined by existing law or regulation
Other structural remedy
Regulated subjects
1
personal data (all forms): transfer (any destination)
Regulatory tool
Preventive security requirement
Responsive security requirement
User right to information about third-parties, with which data has been shared
User consent: Opt-in requirement
Duty of care requirement
Technical standard adherence
Other user right
Sanctions
Determined by existing law or regulation
Other structural remedy
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): storage (any form)

personal data (all forms): data processing

personal data (all forms): transfer (any destination)