Skip to content

Evidence request lists

APEC Cross-Border Privacy Rules (CBPR) System

Evidence request list. 59 controls, 59 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CBPR Program Requirements: Access and Correction

CBPR-PR-36
Confirmation of holding

On request, the applicant confirms whether or not it holds personal information about the requesting individual.

Artefacts an auditor will ask for
  • procedure for handling confirmation requests
  • request log with response times
  • identity verification steps applied before responding
Where this commonly fails
  • confirmation bundled with a full access request so simple queries are slow
  • no log so timeliness is unevidenced
  • identity verification demanding more data than necessary
CBPR-PR-37
Access to personal information

On request, the applicant provides individuals with access to the personal information it holds about them, within a reasonable timeframe, in an understandable form and at a reasonable charge if any.

Artefacts an auditor will ask for
  • access request procedure covering timeframe, format and charges
  • request log with dates, outcomes and any fee applied
  • evidence the response is intelligible to the individual
  • identity confirmation steps
Where this commonly fails
  • access provided as a raw system export the individual cannot read
  • charges applied that deter requests
  • some data stores excluded from the search
CBPR-PR-38
Challenge and rectification

The applicant permits individuals to challenge the accuracy of their information and to have it rectified, completed, amended or deleted.

Artefacts an auditor will ask for
  • procedure covering challenge, rectification, completion, amendment and deletion
  • request log with outcomes and reasons for any refusal
  • evidence of the explanation given where a request is refused
  • evidence changes propagate to all copies
Where this commonly fails
  • deletion offered only where the law compels it
  • refusals given with no reason
  • changes applied in one system while other copies retain the old value

CBPR Program Requirements: Accountability

CBPR-PR-39
Measures to ensure compliance

The applicant maintains measures to ensure compliance with the APEC Information Privacy Principles, such as internal guidelines or policies and the arrangements that implement them.

Artefacts an auditor will ask for
  • internal privacy guidelines or policies
  • description of how each is implemented in practice
  • evidence of monitoring compliance with them
Where this commonly fails
  • policies published with no implementation described
  • measures listed as intentions rather than operating controls
  • no monitoring so compliance is assumed
CBPR-PR-40
Responsible individual appointed

The applicant has appointed an individual or individuals responsible for its overall compliance with its privacy policies and practices.

Artefacts an auditor will ask for
  • appointment record naming the individual and the scope of responsibility
  • the individual's reporting line and authority
  • evidence the appointment is communicated internally and externally
Where this commonly fails
  • responsibility assigned to a role that is vacant
  • appointee with no authority to change practice
  • appointment not communicated so nobody escalates to them
CBPR-PR-41
Complaint handling procedures

The applicant has procedures to receive, investigate and respond to privacy-related complaints.

Artefacts an auditor will ask for
  • complaint handling procedure
  • complaint log with receipt, investigation and outcome
  • the channels through which complaints can be received
Where this commonly fails
  • complaints handled through general customer service with no privacy escalation
  • log not maintained so trends are invisible
  • only one channel offered for complaints
CBPR-PR-42
Timely complaint response

The applicant has procedures to ensure individuals receive a timely response to their complaints.

Artefacts an auditor will ask for
  • defined response timeframes
  • measured response times against those timeframes
  • escalation route where the timeframe is at risk
Where this commonly fails
  • timeframe defined but never measured
  • clock started at triage rather than receipt
  • no escalation so overdue complaints simply age
CBPR-PR-43
Remedial action explained

Responses to complaints include an explanation of the remedial action relating to the complaint.

Artefacts an auditor will ask for
  • template or examples of complaint responses showing remedial action explained
  • records of remedial actions taken
  • evidence the remedy is tracked to completion
Where this commonly fails
  • responses acknowledging the complaint without describing any remedy
  • remedy promised and not tracked
  • explanation given verbally with no record
CBPR-PR-44
Employee privacy training

The applicant has procedures for training employees on its privacy policies and procedures.

Artefacts an auditor will ask for
  • privacy training content
  • attendance records by role including refresher cycles
  • role-specific training for staff handling personal information
Where this commonly fails
  • one generic module for all roles
  • no refresher so training decays
  • attendance not tracked for contractors
CBPR-PR-45
Response to legal demands

The applicant has procedures for responding to judicial or other government subpoenas, warrants or orders, including those requiring disclosure of personal information.

Artefacts an auditor will ask for
  • procedure for handling legal demands
  • log of demands received and how each was handled
  • legal review step before disclosure
  • criteria for challenging or narrowing a demand
Where this commonly fails
  • demands handled ad hoc by whoever receives them
  • no log so the volume and pattern of demands is unknown
  • disclosure made without legal review
CBPR-PR-46
Mechanisms with processors to meet obligations

The applicant has mechanisms with processors, agents, contractors and other service providers, covering the personal information they process on its behalf, to ensure its obligations to the individual will be met.

Artefacts an auditor will ask for
  • contracts or arrangements covering processing on the applicant's behalf
  • provisions ensuring obligations to individuals can be met, including access and correction
  • records showing individual requests can be fulfilled through the processor
Where this commonly fails
  • contract silent on how an access request reaching the processor is handled
  • obligations imposed with no mechanism to exercise them
  • arrangements absent for processors engaged before the programme
CBPR-PR-47
Processor agreement content

The agreements with processors, agents, contractors and other service providers generally require them to act consistently with the applicant's obligations.

Artefacts an auditor will ask for
  • representative agreements showing the required provisions
  • checklist of required provisions applied to new contracts
  • review of legacy contracts against the checklist
Where this commonly fails
  • required provisions present in new contracts only
  • provisions varying by vendor negotiating strength
  • no checklist so contract review is inconsistent
CBPR-PR-48
Processor self-assessments

The applicant requires processors, agents, contractors and other service providers to provide self-assessments confirming compliance with its instructions, agreements and contracts.

Artefacts an auditor will ask for
  • self-assessment requirement in the contract
  • completed self-assessments received and their dates
  • review records showing the assessments were evaluated
  • action taken where an assessment showed a gap
Where this commonly fails
  • self-assessments requested and never chased
  • assessments filed without review
  • requirement applied to a small subset of providers
CBPR-PR-49
Spot checking and monitoring of processors

The applicant carries out regular spot checking or monitoring of processors, agents, contractors and other service providers to ensure compliance with its instructions, agreements and contracts.

Artefacts an auditor will ask for
  • spot check or monitoring schedule and its risk basis
  • completed check records with findings
  • remediation tracking for findings
  • evidence the programme covers higher risk providers more often
Where this commonly fails
  • monitoring limited to reviewing the provider's own certificate
  • checks scheduled but not performed
  • findings recorded with no remediation owner
CBPR-PR-50
Disclosure where due diligence is impractical

Where due diligence and reasonable steps to ensure the recipient's compliance are impractical or impossible, the applicant handles such disclosures under the conditions the programme requirements permit.

Artefacts an auditor will ask for
  • register of disclosures where due diligence was impractical
  • justification recorded for each
  • the alternative safeguard or condition relied on
  • approval records for these disclosures
Where this commonly fails
  • impracticality asserted for convenience
  • no register so these disclosures are invisible
  • no alternative safeguard applied once due diligence was set aside

CBPR Program Requirements: Choice

CBPR-PR-14
Choice over collection

The applicant provides a mechanism for individuals to exercise choice in relation to the collection of their personal information.

Artefacts an auditor will ask for
  • description and screenshots of the choice mechanism for collection
  • evidence the mechanism is operative and honoured
  • qualification relied on where choice is not offered, with justification
Where this commonly fails
  • choice offered for marketing only
  • mechanism present but the setting has no effect
  • qualification claimed with no justification recorded
CBPR-PR-15
Choice over use

The applicant provides a mechanism for individuals to exercise choice in relation to the use of their personal information.

Artefacts an auditor will ask for
  • description of the choice mechanism for use
  • evidence choices propagate to the systems that perform the use
  • records of choices exercised and honoured
Where this commonly fails
  • choice recorded in one system and ignored by others
  • use continues after the individual opts out
  • no record of choices so honouring cannot be evidenced
CBPR-PR-16
Choice over disclosure

The applicant provides a mechanism for individuals to exercise choice in relation to the disclosure of their personal information.

Artefacts an auditor will ask for
  • description of the choice mechanism for disclosure
  • evidence choices are communicated to recipients
  • records of choices exercised and honoured
Where this commonly fails
  • choice honoured internally but recipients not informed
  • disclosure choice not offered at all where a processor is involved
  • choices not retained so they are lost at the next migration
CBPR-PR-17
Choices clear and conspicuous

Where choices are offered over collection, use or disclosure, they are displayed or provided in a clear and conspicuous manner.

Artefacts an auditor will ask for
  • screenshots or copies showing how the choice is presented
  • placement evidence relative to the point of decision
  • review confirming the presentation is not obscured by design
Where this commonly fails
  • choice hidden in a settings submenu
  • pre-ticked boxes presented as choice
  • choice presented in colour or size that de-emphasises it
CBPR-PR-18
Choices clearly worded

Where choices are offered, they are clearly worded and easily understandable.

Artefacts an auditor will ask for
  • the wording of each choice as presented
  • readability or comprehension assessment
  • evidence of translation where the audience requires it
Where this commonly fails
  • double negatives making the effect of the choice unclear
  • legal drafting reused as user-facing choice text
  • wording untranslated for a substantial part of the audience
CBPR-PR-19
Choices accessible and affordable

Where choices are offered, they are easily accessible and affordable to the individual.

Artefacts an auditor will ask for
  • description of how the choice is reached and any cost involved
  • accessibility evidence for the mechanism
  • records of any charge applied
Where this commonly fails
  • choice available only by postal letter
  • a fee applied to exercise choice
  • mechanism inaccessible to users of assistive technology
CBPR-PR-20
Mechanisms to honour choices

The applicant has mechanisms so that choices, where appropriate, can be honoured in an effective and expeditious manner.

Artefacts an auditor will ask for
  • description of the systems and processes that give effect to choices
  • time taken from choice to effect, measured
  • reconciliation confirming no processing continues against a recorded choice
  • escalation route where a choice is not honoured
Where this commonly fails
  • choices honoured manually with long lags
  • no reconciliation so failures go undetected
  • batch processes that ignore recorded choices

CBPR Program Requirements: Collection Limitation

CBPR-PR-05
Collection methods identified

The applicant identifies how it obtains personal information, whether directly from the individual or from third parties collecting on its behalf.

Artefacts an auditor will ask for
  • documented inventory of collection channels
  • identification of third parties collecting on the applicant's behalf
  • contracts or instructions governing those third parties
Where this commonly fails
  • indirect collection channels omitted from the inventory
  • third party collectors treated as out of scope
  • inventory maintained once and not updated as channels change
CBPR-PR-06
Collection limited to relevant information

The applicant limits collection to information relevant to the purposes for which it is collected or to other compatible or related purposes.

Artefacts an auditor will ask for
  • data element inventory mapped to the purpose each element serves
  • relevance assessment for each element collected
  • records of elements removed as unnecessary
Where this commonly fails
  • fields collected because they might be useful later
  • relevance never assessed after the form was designed
  • optional fields presented as mandatory
CBPR-PR-07
Lawful and fair collection

The applicant collects personal information by lawful and fair means consistent with the requirements of the jurisdiction governing the collection.

Artefacts an auditor will ask for
  • legal basis analysis per collection channel and jurisdiction
  • evidence that consent, where relied on, is obtained as the jurisdiction requires
  • review of collection practices against deceptive or covert methods
Where this commonly fails
  • single legal analysis applied across jurisdictions with different rules
  • covert collection through tracking not disclosed anywhere
  • legal basis asserted with no analysis behind it

CBPR Program Requirements: Integrity of Personal Information

CBPR-PR-21
Accuracy verification

The applicant takes steps to verify that the personal information it holds is up to date, accurate and complete to the extent necessary for the purposes of use.

Artefacts an auditor will ask for
  • documented accuracy verification steps by data set
  • frequency of verification and its rationale
  • records of verification performed and corrections made
Where this commonly fails
  • accuracy assumed because the individual supplied the data
  • verification applied to contact data only
  • no defined standard for what accurate enough means
CBPR-PR-22
Correction mechanism

The applicant has a mechanism for correcting inaccurate, incomplete and out of date personal information to the extent necessary for the purposes of use.

Artefacts an auditor will ask for
  • description of the correction mechanism
  • correction request log with outcomes and timescales
  • evidence corrections propagate to all copies
Where this commonly fails
  • correction applied in the front-end system only
  • no log so timeliness cannot be evidenced
  • corrections require the individual to prove the error unaided
CBPR-PR-23
Corrections communicated after transfer

Where corrections are made after the information has been transferred, and the inaccuracy affects the purposes of use, the applicant communicates the corrections to the recipients.

Artefacts an auditor will ask for
  • procedure for notifying recipients of post-transfer corrections
  • recipient contact register
  • records of correction notifications sent
Where this commonly fails
  • no recipient register so notification is impossible
  • procedure exists but is never triggered
  • notification limited to current recipients, omitting past ones still holding the data
CBPR-PR-24
Corrections communicated after disclosure

Where corrections are made after the information has been disclosed, and the inaccuracy affects the purposes of use, the applicant communicates the corrections to the third parties concerned.

Artefacts an auditor will ask for
  • procedure for notifying third parties of post-disclosure corrections
  • disclosure register identifying who received what
  • records of notifications sent and acknowledged
Where this commonly fails
  • disclosure register incomplete so third parties cannot be identified
  • notification sent with no confirmation of action
  • procedure covers processors but not other controllers
CBPR-PR-25
Processor obligation to report data quality issues

The applicant requires processors, agents and other service providers acting on its behalf to inform it when they become aware that information is inaccurate, incomplete or out of date.

Artefacts an auditor will ask for
  • contract clauses imposing the obligation
  • records of notifications received from processors
  • evidence the obligation is included in new and renewed contracts
Where this commonly fails
  • clause absent from legacy contracts
  • obligation in the contract with no route for the processor to report
  • notifications received but not acted on

CBPR Program Requirements: Notice

CBPR-PR-01
Privacy statement published

The applicant publishes clear and easily accessible statements of the practices and policies governing the personal information it holds.

Artefacts an auditor will ask for
  • privacy statement as published, with its effective date
  • location evidence showing it is on the website and easy to find
  • confirmation it applies to information collected online and offline
Where this commonly fails
  • statement buried behind several clicks
  • separate statements for product lines with gaps between them
  • no effective date so versions cannot be distinguished
CBPR-PR-02
Notice at the time of collection

The applicant gives notice that personal information is being collected at the time of collection, whether it collects directly or through third parties acting on its behalf.

Artefacts an auditor will ask for
  • collection notice text as displayed at each collection point
  • inventory of collection points including those operated by third parties on the applicant's behalf
  • evidence the notice appears at or before collection
Where this commonly fails
  • notice given only in the general privacy statement, not at the collection point
  • third party collection points with no notice
  • notice shown after collection has occurred
CBPR-PR-03
Purposes stated at collection

The applicant states at the time of collection the purposes for which the personal information is being collected.

Artefacts an auditor will ask for
  • purpose statements at each collection point
  • mapping of collection points to the purposes declared
  • review evidence that stated purposes match actual processing
Where this commonly fails
  • purposes described so broadly they state nothing
  • purposes stated in the policy but not at the point of collection
  • actual use drifted from the purpose declared
CBPR-PR-04
Notice of sharing with third parties

The applicant notifies individuals at the time of collection that their personal information will be or may be shared with third parties.

Artefacts an auditor will ask for
  • sharing notice text
  • list of third party categories or named recipients disclosed
  • evidence the notice is given at the time of collection
Where this commonly fails
  • sharing disclosed only after a request
  • categories described so vaguely the recipient cannot be identified
  • notice omitted where a processor is involved

CBPR Program Requirements: Security Safeguards

CBPR-PR-26
Information security policy

The applicant has implemented an information security policy.

Artefacts an auditor will ask for
  • the information security policy as approved
  • approval and review dates
  • evidence of communication to staff
Where this commonly fails
  • policy adopted from a template and never tailored
  • policy approved years ago and never reviewed
  • policy not communicated so staff are unaware of it
CBPR-PR-27
Physical, technical and administrative safeguards

The applicant has implemented physical, technical and administrative safeguards protecting personal information against loss, unauthorised access, destruction, use, modification or disclosure.

Artefacts an auditor will ask for
  • description of safeguards in each of the three categories
  • configuration or implementation evidence for the technical safeguards
  • evidence the safeguards cover all systems holding personal information
Where this commonly fails
  • technical safeguards described while physical and administrative are omitted
  • safeguards described for the main platform only
  • description with no implementation evidence behind it
CBPR-PR-28
Safeguards proportional to risk

The applicant can show that its safeguards are proportional to the likelihood and severity of the harm threatened, the sensitivity of the information and the context in which it is held.

Artefacts an auditor will ask for
  • risk assessment linking harm, sensitivity and context to the safeguards selected
  • sensitivity classification of the information held
  • record of safeguards strengthened where sensitivity is higher
Where this commonly fails
  • uniform safeguards regardless of sensitivity
  • proportionality asserted with no assessment
  • assessment performed once and not revisited as processing changed
CBPR-PR-29
Employee security awareness

The applicant makes employees aware of the importance of maintaining the security of personal information, for example through regular training and oversight.

Artefacts an auditor will ask for
  • training content covering personal information security
  • attendance records including new starters and refreshers
  • oversight arrangements such as supervision or monitoring
Where this commonly fails
  • training delivered at induction only
  • attendance not recorded so coverage is unknown
  • contractors and temporary staff excluded
CBPR-PR-30
Specific proportional safeguards in place

The applicant has implemented the specific safeguards the programme requirements enumerate, proportional to the likelihood and severity of harm, the sensitivity of the information and the context in which it is held.

Artefacts an auditor will ask for
  • evidence of each enumerated safeguard being in place
  • mapping from each safeguard to the risk it addresses
  • gaps identified and their remediation plans
Where this commonly fails
  • some enumerated safeguards missing with no compensating control
  • evidence provided as policy text rather than implementation
  • safeguards implemented in production but not in test environments holding real data
CBPR-PR-31
Secure disposal policy

The applicant has implemented a policy for the secure disposal of personal information.

Artefacts an auditor will ask for
  • secure disposal policy and the methods it mandates
  • disposal records or certificates
  • evidence disposal covers backups, archives and physical media
Where this commonly fails
  • disposal policy covering paper only
  • backups retained after the live copy is disposed of
  • disposal performed with no record
CBPR-PR-32
Detection, prevention and response measures

The applicant has implemented measures to detect, prevent and respond to attacks, intrusions and other security failures.

Artefacts an auditor will ask for
  • detection and prevention tooling in place and its coverage
  • incident response procedure
  • incident log with detection source and response taken
Where this commonly fails
  • detection deployed with no one monitoring the alerts
  • response procedure untested
  • coverage limited to the perimeter
CBPR-PR-33
Testing the effectiveness of safeguards

The applicant has processes to test the effectiveness of the detection, prevention and response measures it has implemented.

Artefacts an auditor will ask for
  • testing schedule and scope
  • test results including penetration test or exercise reports
  • remediation tracking for issues found
Where this commonly fails
  • testing limited to automated vulnerability scanning
  • results received but findings not tracked
  • tests scoped to avoid the systems that hold personal information
CBPR-PR-34
Risk assessments and third party certifications

The applicant uses risk assessments or third party certifications in support of its security safeguards.

Artefacts an auditor will ask for
  • risk assessment reports covering personal information processing
  • third party certification reports and their scope statements
  • evidence the scope covers the systems holding personal information
  • tracking of findings to closure
Where this commonly fails
  • certification relied on whose scope excludes the relevant systems
  • certificate held with the report never read
  • risk assessments performed with no follow-up
CBPR-PR-35
Processor protection obligations

The applicant requires processors, agents, contractors and other service providers to whom it transfers personal information to protect it against loss, unauthorised access, destruction, use, modification and disclosure.

Artefacts an auditor will ask for
  • contract clauses imposing the protection obligations
  • due diligence records for each provider
  • evidence the obligations flow down to subprocessors
Where this commonly fails
  • obligations in the master agreement but absent from order forms actually used
  • due diligence performed at onboarding only
  • subprocessors engaged with no flow-down

CBPR Program Requirements: Uses of Personal Information

CBPR-PR-08
Use limited to stated purposes

The applicant limits use of the personal information it collects to the purposes identified in its privacy statement or in the notice given at the time of collection.

Artefacts an auditor will ask for
  • mapping of processing activities to the purposes declared
  • controls preventing use outside those purposes
  • review records confirming use has not drifted
Where this commonly fails
  • analytics or model training added without revisiting the declared purpose
  • no mapping so drift is undetectable
  • purpose compatibility asserted without assessment
CBPR-PR-09
Grounds for unrelated use

Where the applicant uses personal information for unrelated purposes, it does so only on a permitted ground such as express consent of the individual or another circumstance recognised in the programme requirements.

Artefacts an auditor will ask for
  • register of unrelated uses and the ground relied on for each
  • consent records where express consent is the ground
  • assessment supporting any other ground relied on
Where this commonly fails
  • unrelated use with the ground chosen after the fact
  • consent bundled with terms of service and not separable
  • no register so unrelated uses are invisible
CBPR-PR-10
Disclosure to other controllers identified

The applicant identifies whether it discloses the personal information it collects to other personal information controllers.

Artefacts an auditor will ask for
  • register of disclosures to other controllers
  • description of what is disclosed to each and why
  • evidence the register is kept current
Where this commonly fails
  • disclosures made by business units and never registered centrally
  • recipients recorded by category only so accountability is unclear
  • register not refreshed when new recipients are added
CBPR-PR-11
Transfers to processors identified

The applicant identifies whether it transfers personal information to personal information processors.

Artefacts an auditor will ask for
  • register of processors and the information transferred to each
  • contracts or arrangements governing each transfer
  • evidence the register covers subprocessors
Where this commonly fails
  • subprocessors engaged by processors not tracked
  • register limited to major vendors
  • transfers made under a contract that predates the privacy commitments
CBPR-PR-12
Disclosure consistent with original purpose

Disclosures and transfers are undertaken to fulfil the original purpose of collection or another compatible or related purpose.

Artefacts an auditor will ask for
  • purpose justification recorded for each disclosure or transfer
  • compatibility assessment where the purpose differs from the original
  • approval records for disclosures
Where this commonly fails
  • compatibility asserted without an assessment
  • disclosure approved commercially with no privacy review
  • original purpose not recorded so compatibility cannot be tested
CBPR-PR-13
Grounds for other disclosure

Where a disclosure or transfer does not fulfil the original or a compatible purpose, it takes place only under a permitted circumstance such as the express consent of the individual.

Artefacts an auditor will ask for
  • register of such disclosures and the circumstance relied on
  • consent records where consent is the circumstance
  • assessment supporting any other circumstance
Where this commonly fails
  • ground identified after the disclosure has been made
  • consent relied on without evidence it was obtained
  • no register so these disclosures are untracked

Consent

CBPR-04
Choice

Provide clear, prominent, accessible, and affordable mechanisms for individuals to exercise choice over collection, use, and disclosure.

Artefacts an auditor will ask for
  • Mechanisms for individuals to exercise choice over collection/use/disclosure
Where this commonly fails
  • No choice mechanism

Data Minimization

CBPR-02
Collection Limitation

Limit collection of personal information to what is relevant to identified purposes and obtain it by lawful and fair means.

Artefacts an auditor will ask for
  • Collection limited to relevant, lawful & fair means
Where this commonly fails
  • Excessive/unfair collection

Data Quality

CBPR-05
Integrity of Personal Information

Maintain personal information that is accurate, complete, and kept up to date to the extent necessary for purposes of use.

Artefacts an auditor will ask for
  • Processes keeping PI accurate, complete, up to date
Where this commonly fails
  • Inaccurate PI not corrected

Governance

CBPR-08
Accountability

Be accountable for complying with measures that give effect to privacy principles and for onward transfers to other personal information controllers and processors.

Artefacts an auditor will ask for
  • Accountability measures incl. onward-transfer obligations
Where this commonly fails
  • No accountability for transferred PI

Individual Rights

CBPR-07
Access and Correction

Provide individuals reasonable ability to access, confirm, challenge accuracy, and obtain correction or deletion of their personal information.

Artefacts an auditor will ask for
  • Access & correction request handling
Where this commonly fails
  • No access/correction mechanism

Purpose Limitation

CBPR-03
Uses of Personal Information

Use personal information only for purposes of collection or compatible/related purposes, except with consent or as authorized by law.

Artefacts an auditor will ask for
  • Use limited to collection purposes / compatible uses
Where this commonly fails
  • Incompatible secondary use

Risk

CBPR-09
Preventing Harm

Design protections to prevent misuse of personal information taking into account risks of harm to individuals.

Artefacts an auditor will ask for
  • Remedies proportionate to likelihood & severity of harm
Where this commonly fails
  • No harm-prevention design

Security

CBPR-06
Security Safeguards

Protect personal information with reasonable safeguards proportionate to likelihood and severity of harm, sensitivity, and context.

Artefacts an auditor will ask for
  • Physical, technical & administrative safeguards proportionate to risk
Where this commonly fails
  • Inadequate safeguards

Transparency

CBPR-01
Notice

Provide clear, accessible notice describing personal information practices including collection, use, disclosure, and choices.

Artefacts an auditor will ask for
  • Privacy notice covering collection, purposes, disclosure, contact
Where this commonly fails
  • No privacy notice provided
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APEC Cross-Border Privacy Rules (CBPR) System framework page.