APEC Cross-Border Privacy Rules (CBPR) System
Evidence request list. 59 controls, 59 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CBPR Program Requirements: Access and Correction
On request, the applicant confirms whether or not it holds personal information about the requesting individual.
- procedure for handling confirmation requests
- request log with response times
- identity verification steps applied before responding
- confirmation bundled with a full access request so simple queries are slow
- no log so timeliness is unevidenced
- identity verification demanding more data than necessary
On request, the applicant provides individuals with access to the personal information it holds about them, within a reasonable timeframe, in an understandable form and at a reasonable charge if any.
- access request procedure covering timeframe, format and charges
- request log with dates, outcomes and any fee applied
- evidence the response is intelligible to the individual
- identity confirmation steps
- access provided as a raw system export the individual cannot read
- charges applied that deter requests
- some data stores excluded from the search
The applicant permits individuals to challenge the accuracy of their information and to have it rectified, completed, amended or deleted.
- procedure covering challenge, rectification, completion, amendment and deletion
- request log with outcomes and reasons for any refusal
- evidence of the explanation given where a request is refused
- evidence changes propagate to all copies
- deletion offered only where the law compels it
- refusals given with no reason
- changes applied in one system while other copies retain the old value
CBPR Program Requirements: Accountability
The applicant maintains measures to ensure compliance with the APEC Information Privacy Principles, such as internal guidelines or policies and the arrangements that implement them.
- internal privacy guidelines or policies
- description of how each is implemented in practice
- evidence of monitoring compliance with them
- policies published with no implementation described
- measures listed as intentions rather than operating controls
- no monitoring so compliance is assumed
The applicant has appointed an individual or individuals responsible for its overall compliance with its privacy policies and practices.
- appointment record naming the individual and the scope of responsibility
- the individual's reporting line and authority
- evidence the appointment is communicated internally and externally
- responsibility assigned to a role that is vacant
- appointee with no authority to change practice
- appointment not communicated so nobody escalates to them
The applicant has procedures to receive, investigate and respond to privacy-related complaints.
- complaint handling procedure
- complaint log with receipt, investigation and outcome
- the channels through which complaints can be received
- complaints handled through general customer service with no privacy escalation
- log not maintained so trends are invisible
- only one channel offered for complaints
The applicant has procedures to ensure individuals receive a timely response to their complaints.
- defined response timeframes
- measured response times against those timeframes
- escalation route where the timeframe is at risk
- timeframe defined but never measured
- clock started at triage rather than receipt
- no escalation so overdue complaints simply age
Responses to complaints include an explanation of the remedial action relating to the complaint.
- template or examples of complaint responses showing remedial action explained
- records of remedial actions taken
- evidence the remedy is tracked to completion
- responses acknowledging the complaint without describing any remedy
- remedy promised and not tracked
- explanation given verbally with no record
The applicant has procedures for training employees on its privacy policies and procedures.
- privacy training content
- attendance records by role including refresher cycles
- role-specific training for staff handling personal information
- one generic module for all roles
- no refresher so training decays
- attendance not tracked for contractors
The applicant has procedures for responding to judicial or other government subpoenas, warrants or orders, including those requiring disclosure of personal information.
- procedure for handling legal demands
- log of demands received and how each was handled
- legal review step before disclosure
- criteria for challenging or narrowing a demand
- demands handled ad hoc by whoever receives them
- no log so the volume and pattern of demands is unknown
- disclosure made without legal review
The applicant has mechanisms with processors, agents, contractors and other service providers, covering the personal information they process on its behalf, to ensure its obligations to the individual will be met.
- contracts or arrangements covering processing on the applicant's behalf
- provisions ensuring obligations to individuals can be met, including access and correction
- records showing individual requests can be fulfilled through the processor
- contract silent on how an access request reaching the processor is handled
- obligations imposed with no mechanism to exercise them
- arrangements absent for processors engaged before the programme
The agreements with processors, agents, contractors and other service providers generally require them to act consistently with the applicant's obligations.
- representative agreements showing the required provisions
- checklist of required provisions applied to new contracts
- review of legacy contracts against the checklist
- required provisions present in new contracts only
- provisions varying by vendor negotiating strength
- no checklist so contract review is inconsistent
The applicant requires processors, agents, contractors and other service providers to provide self-assessments confirming compliance with its instructions, agreements and contracts.
- self-assessment requirement in the contract
- completed self-assessments received and their dates
- review records showing the assessments were evaluated
- action taken where an assessment showed a gap
- self-assessments requested and never chased
- assessments filed without review
- requirement applied to a small subset of providers
The applicant carries out regular spot checking or monitoring of processors, agents, contractors and other service providers to ensure compliance with its instructions, agreements and contracts.
- spot check or monitoring schedule and its risk basis
- completed check records with findings
- remediation tracking for findings
- evidence the programme covers higher risk providers more often
- monitoring limited to reviewing the provider's own certificate
- checks scheduled but not performed
- findings recorded with no remediation owner
Where due diligence and reasonable steps to ensure the recipient's compliance are impractical or impossible, the applicant handles such disclosures under the conditions the programme requirements permit.
- register of disclosures where due diligence was impractical
- justification recorded for each
- the alternative safeguard or condition relied on
- approval records for these disclosures
- impracticality asserted for convenience
- no register so these disclosures are invisible
- no alternative safeguard applied once due diligence was set aside
CBPR Program Requirements: Choice
The applicant provides a mechanism for individuals to exercise choice in relation to the collection of their personal information.
- description and screenshots of the choice mechanism for collection
- evidence the mechanism is operative and honoured
- qualification relied on where choice is not offered, with justification
- choice offered for marketing only
- mechanism present but the setting has no effect
- qualification claimed with no justification recorded
The applicant provides a mechanism for individuals to exercise choice in relation to the use of their personal information.
- description of the choice mechanism for use
- evidence choices propagate to the systems that perform the use
- records of choices exercised and honoured
- choice recorded in one system and ignored by others
- use continues after the individual opts out
- no record of choices so honouring cannot be evidenced
The applicant provides a mechanism for individuals to exercise choice in relation to the disclosure of their personal information.
- description of the choice mechanism for disclosure
- evidence choices are communicated to recipients
- records of choices exercised and honoured
- choice honoured internally but recipients not informed
- disclosure choice not offered at all where a processor is involved
- choices not retained so they are lost at the next migration
Where choices are offered over collection, use or disclosure, they are displayed or provided in a clear and conspicuous manner.
- screenshots or copies showing how the choice is presented
- placement evidence relative to the point of decision
- review confirming the presentation is not obscured by design
- choice hidden in a settings submenu
- pre-ticked boxes presented as choice
- choice presented in colour or size that de-emphasises it
Where choices are offered, they are clearly worded and easily understandable.
- the wording of each choice as presented
- readability or comprehension assessment
- evidence of translation where the audience requires it
- double negatives making the effect of the choice unclear
- legal drafting reused as user-facing choice text
- wording untranslated for a substantial part of the audience
Where choices are offered, they are easily accessible and affordable to the individual.
- description of how the choice is reached and any cost involved
- accessibility evidence for the mechanism
- records of any charge applied
- choice available only by postal letter
- a fee applied to exercise choice
- mechanism inaccessible to users of assistive technology
The applicant has mechanisms so that choices, where appropriate, can be honoured in an effective and expeditious manner.
- description of the systems and processes that give effect to choices
- time taken from choice to effect, measured
- reconciliation confirming no processing continues against a recorded choice
- escalation route where a choice is not honoured
- choices honoured manually with long lags
- no reconciliation so failures go undetected
- batch processes that ignore recorded choices
CBPR Program Requirements: Collection Limitation
The applicant identifies how it obtains personal information, whether directly from the individual or from third parties collecting on its behalf.
- documented inventory of collection channels
- identification of third parties collecting on the applicant's behalf
- contracts or instructions governing those third parties
- indirect collection channels omitted from the inventory
- third party collectors treated as out of scope
- inventory maintained once and not updated as channels change
The applicant limits collection to information relevant to the purposes for which it is collected or to other compatible or related purposes.
- data element inventory mapped to the purpose each element serves
- relevance assessment for each element collected
- records of elements removed as unnecessary
- fields collected because they might be useful later
- relevance never assessed after the form was designed
- optional fields presented as mandatory
The applicant collects personal information by lawful and fair means consistent with the requirements of the jurisdiction governing the collection.
- legal basis analysis per collection channel and jurisdiction
- evidence that consent, where relied on, is obtained as the jurisdiction requires
- review of collection practices against deceptive or covert methods
- single legal analysis applied across jurisdictions with different rules
- covert collection through tracking not disclosed anywhere
- legal basis asserted with no analysis behind it
CBPR Program Requirements: Integrity of Personal Information
The applicant takes steps to verify that the personal information it holds is up to date, accurate and complete to the extent necessary for the purposes of use.
- documented accuracy verification steps by data set
- frequency of verification and its rationale
- records of verification performed and corrections made
- accuracy assumed because the individual supplied the data
- verification applied to contact data only
- no defined standard for what accurate enough means
The applicant has a mechanism for correcting inaccurate, incomplete and out of date personal information to the extent necessary for the purposes of use.
- description of the correction mechanism
- correction request log with outcomes and timescales
- evidence corrections propagate to all copies
- correction applied in the front-end system only
- no log so timeliness cannot be evidenced
- corrections require the individual to prove the error unaided
Where corrections are made after the information has been transferred, and the inaccuracy affects the purposes of use, the applicant communicates the corrections to the recipients.
- procedure for notifying recipients of post-transfer corrections
- recipient contact register
- records of correction notifications sent
- no recipient register so notification is impossible
- procedure exists but is never triggered
- notification limited to current recipients, omitting past ones still holding the data
Where corrections are made after the information has been disclosed, and the inaccuracy affects the purposes of use, the applicant communicates the corrections to the third parties concerned.
- procedure for notifying third parties of post-disclosure corrections
- disclosure register identifying who received what
- records of notifications sent and acknowledged
- disclosure register incomplete so third parties cannot be identified
- notification sent with no confirmation of action
- procedure covers processors but not other controllers
The applicant requires processors, agents and other service providers acting on its behalf to inform it when they become aware that information is inaccurate, incomplete or out of date.
- contract clauses imposing the obligation
- records of notifications received from processors
- evidence the obligation is included in new and renewed contracts
- clause absent from legacy contracts
- obligation in the contract with no route for the processor to report
- notifications received but not acted on
CBPR Program Requirements: Notice
The applicant publishes clear and easily accessible statements of the practices and policies governing the personal information it holds.
- privacy statement as published, with its effective date
- location evidence showing it is on the website and easy to find
- confirmation it applies to information collected online and offline
- statement buried behind several clicks
- separate statements for product lines with gaps between them
- no effective date so versions cannot be distinguished
The applicant gives notice that personal information is being collected at the time of collection, whether it collects directly or through third parties acting on its behalf.
- collection notice text as displayed at each collection point
- inventory of collection points including those operated by third parties on the applicant's behalf
- evidence the notice appears at or before collection
- notice given only in the general privacy statement, not at the collection point
- third party collection points with no notice
- notice shown after collection has occurred
The applicant states at the time of collection the purposes for which the personal information is being collected.
- purpose statements at each collection point
- mapping of collection points to the purposes declared
- review evidence that stated purposes match actual processing
- purposes described so broadly they state nothing
- purposes stated in the policy but not at the point of collection
- actual use drifted from the purpose declared
The applicant notifies individuals at the time of collection that their personal information will be or may be shared with third parties.
- sharing notice text
- list of third party categories or named recipients disclosed
- evidence the notice is given at the time of collection
- sharing disclosed only after a request
- categories described so vaguely the recipient cannot be identified
- notice omitted where a processor is involved
CBPR Program Requirements: Security Safeguards
The applicant has implemented an information security policy.
- the information security policy as approved
- approval and review dates
- evidence of communication to staff
- policy adopted from a template and never tailored
- policy approved years ago and never reviewed
- policy not communicated so staff are unaware of it
The applicant has implemented physical, technical and administrative safeguards protecting personal information against loss, unauthorised access, destruction, use, modification or disclosure.
- description of safeguards in each of the three categories
- configuration or implementation evidence for the technical safeguards
- evidence the safeguards cover all systems holding personal information
- technical safeguards described while physical and administrative are omitted
- safeguards described for the main platform only
- description with no implementation evidence behind it
The applicant can show that its safeguards are proportional to the likelihood and severity of the harm threatened, the sensitivity of the information and the context in which it is held.
- risk assessment linking harm, sensitivity and context to the safeguards selected
- sensitivity classification of the information held
- record of safeguards strengthened where sensitivity is higher
- uniform safeguards regardless of sensitivity
- proportionality asserted with no assessment
- assessment performed once and not revisited as processing changed
The applicant makes employees aware of the importance of maintaining the security of personal information, for example through regular training and oversight.
- training content covering personal information security
- attendance records including new starters and refreshers
- oversight arrangements such as supervision or monitoring
- training delivered at induction only
- attendance not recorded so coverage is unknown
- contractors and temporary staff excluded
The applicant has implemented the specific safeguards the programme requirements enumerate, proportional to the likelihood and severity of harm, the sensitivity of the information and the context in which it is held.
- evidence of each enumerated safeguard being in place
- mapping from each safeguard to the risk it addresses
- gaps identified and their remediation plans
- some enumerated safeguards missing with no compensating control
- evidence provided as policy text rather than implementation
- safeguards implemented in production but not in test environments holding real data
The applicant has implemented a policy for the secure disposal of personal information.
- secure disposal policy and the methods it mandates
- disposal records or certificates
- evidence disposal covers backups, archives and physical media
- disposal policy covering paper only
- backups retained after the live copy is disposed of
- disposal performed with no record
The applicant has implemented measures to detect, prevent and respond to attacks, intrusions and other security failures.
- detection and prevention tooling in place and its coverage
- incident response procedure
- incident log with detection source and response taken
- detection deployed with no one monitoring the alerts
- response procedure untested
- coverage limited to the perimeter
The applicant has processes to test the effectiveness of the detection, prevention and response measures it has implemented.
- testing schedule and scope
- test results including penetration test or exercise reports
- remediation tracking for issues found
- testing limited to automated vulnerability scanning
- results received but findings not tracked
- tests scoped to avoid the systems that hold personal information
The applicant uses risk assessments or third party certifications in support of its security safeguards.
- risk assessment reports covering personal information processing
- third party certification reports and their scope statements
- evidence the scope covers the systems holding personal information
- tracking of findings to closure
- certification relied on whose scope excludes the relevant systems
- certificate held with the report never read
- risk assessments performed with no follow-up
The applicant requires processors, agents, contractors and other service providers to whom it transfers personal information to protect it against loss, unauthorised access, destruction, use, modification and disclosure.
- contract clauses imposing the protection obligations
- due diligence records for each provider
- evidence the obligations flow down to subprocessors
- obligations in the master agreement but absent from order forms actually used
- due diligence performed at onboarding only
- subprocessors engaged with no flow-down
CBPR Program Requirements: Uses of Personal Information
The applicant limits use of the personal information it collects to the purposes identified in its privacy statement or in the notice given at the time of collection.
- mapping of processing activities to the purposes declared
- controls preventing use outside those purposes
- review records confirming use has not drifted
- analytics or model training added without revisiting the declared purpose
- no mapping so drift is undetectable
- purpose compatibility asserted without assessment
Where the applicant uses personal information for unrelated purposes, it does so only on a permitted ground such as express consent of the individual or another circumstance recognised in the programme requirements.
- register of unrelated uses and the ground relied on for each
- consent records where express consent is the ground
- assessment supporting any other ground relied on
- unrelated use with the ground chosen after the fact
- consent bundled with terms of service and not separable
- no register so unrelated uses are invisible
The applicant identifies whether it discloses the personal information it collects to other personal information controllers.
- register of disclosures to other controllers
- description of what is disclosed to each and why
- evidence the register is kept current
- disclosures made by business units and never registered centrally
- recipients recorded by category only so accountability is unclear
- register not refreshed when new recipients are added
The applicant identifies whether it transfers personal information to personal information processors.
- register of processors and the information transferred to each
- contracts or arrangements governing each transfer
- evidence the register covers subprocessors
- subprocessors engaged by processors not tracked
- register limited to major vendors
- transfers made under a contract that predates the privacy commitments
Disclosures and transfers are undertaken to fulfil the original purpose of collection or another compatible or related purpose.
- purpose justification recorded for each disclosure or transfer
- compatibility assessment where the purpose differs from the original
- approval records for disclosures
- compatibility asserted without an assessment
- disclosure approved commercially with no privacy review
- original purpose not recorded so compatibility cannot be tested
Where a disclosure or transfer does not fulfil the original or a compatible purpose, it takes place only under a permitted circumstance such as the express consent of the individual.
- register of such disclosures and the circumstance relied on
- consent records where consent is the circumstance
- assessment supporting any other circumstance
- ground identified after the disclosure has been made
- consent relied on without evidence it was obtained
- no register so these disclosures are untracked
Consent
Provide clear, prominent, accessible, and affordable mechanisms for individuals to exercise choice over collection, use, and disclosure.
- Mechanisms for individuals to exercise choice over collection/use/disclosure
- No choice mechanism
Data Minimization
Limit collection of personal information to what is relevant to identified purposes and obtain it by lawful and fair means.
- Collection limited to relevant, lawful & fair means
- Excessive/unfair collection
Data Quality
Maintain personal information that is accurate, complete, and kept up to date to the extent necessary for purposes of use.
- Processes keeping PI accurate, complete, up to date
- Inaccurate PI not corrected
Governance
Be accountable for complying with measures that give effect to privacy principles and for onward transfers to other personal information controllers and processors.
- Accountability measures incl. onward-transfer obligations
- No accountability for transferred PI
Individual Rights
Provide individuals reasonable ability to access, confirm, challenge accuracy, and obtain correction or deletion of their personal information.
- Access & correction request handling
- No access/correction mechanism
Purpose Limitation
Use personal information only for purposes of collection or compatible/related purposes, except with consent or as authorized by law.
- Use limited to collection purposes / compatible uses
- Incompatible secondary use
Risk
Design protections to prevent misuse of personal information taking into account risks of harm to individuals.
- Remedies proportionate to likelihood & severity of harm
- No harm-prevention design
Security
Protect personal information with reasonable safeguards proportionate to likelihood and severity of harm, sensitivity, and context.
- Physical, technical & administrative safeguards proportionate to risk
- Inadequate safeguards
Transparency
Provide clear, accessible notice describing personal information practices including collection, use, disclosure, and choices.
- Privacy notice covering collection, purposes, disclosure, contact
- No privacy notice provided
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APEC Cross-Border Privacy Rules (CBPR) System framework page.