Global Cross-Border Privacy Rules (Global CBPR) Forum
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Global CBPR Forum: 2024-2025 Pipeline, UK Accession, New Jurisdictions, AI and PEP Integration
Global CBPR Forum 2024-2025 status + pipeline. UK ACCESSION 2024: United Kingdom acceded April 2024 + first non-APEC member; ICO + DSIT signed accession; first wave of UK-certified Accountability Agents accredited; UK companies leverage CBPR for transfers to/from US + Japan + Korea + Singapore + Canada + Philippines + Taiwan; UK Data Protection Bill reform may further integrate CBPR adequacy mechanism. ACCESSION PIPELINE 2025-2026: Mexico (active discussions with US Commerce + Mexico CONDUSEF/INAI) + Australia (OAIC dialogue) + New Zealand (Office of the Privacy Commissioner) + Bahrain (PDPA) + Dubai DIFC (DIFC Data Protection Law) + Argentina + Brazil (LGPD) + others; the Forum aims to expand to 15+ members by 2027. AI INTEGRATION: 2024-2025 working group on AI-specific privacy guidance under CBPR; ASEAN AI Guide + Singapore AI Verify + Japan AI Governance Guidelines + Korea AI Privacy
- Pipeline-tracking + impact assessment
- AI + PET readiness for certification
- Multi-stakeholder participation
- Pipeline not tracked
- AI + PET readiness gaps
- Multi-stakeholder participation absent
Global CBPR Forum implementation roadmap. ROLES (organization side): (a) CHIEF PRIVACY OFFICER (CPO) or DPO - strategic ownership of certification + program; (b) PROGRAM MANAGER - day-to-day certification management + AA relationship + remediation; (c) PRIVACY ENGINEERING - technical privacy controls + DPIA + tooling; (d) LEGAL - cross-border + statutory + contractual review; (e) INFOSEC + CISO - safeguards (principle 6); (f) PRODUCT/ENGINEERING - product-level privacy + transparency + choice mechanisms; (g) MARKETING/COMMUNICATIONS - notice + consent + Privacy Choices; (h) HR - employee data + training; (i) PROCUREMENT - vendor management + sub-processor flow-down + PRP. ROLES (AA side): (a) AA Director + Accreditation Manager + Assessor + Compliance Officer + Dispute Resolution Manager. TOOLING: (a) PRIVACY MANAGEMENT PLATFORMS (OneTrust + TrustArc + Securiti + WireWheel + BigID + Priv
- Role inventory + RACI
- Tooling adoption + vendor selection
- Metrics + management review
- Annual cycle documentation
- Roles undefined
- Tooling fragmented
- Metrics gaps
- Annual cycle ad-hoc
Global CBPR Forum industry adoption + sectoral application. INDUSTRY ADOPTION: 100+ certified organizations across Forum members + growing rapidly post-2022 launch + UK 2024 accession; major certified organizations include (a) TECHNOLOGY + SOFTWARE - Apple + Google + Microsoft + Amazon + Meta + Salesforce + Workday + Adobe + IBM + Cisco + ServiceNow + Oracle + Lenovo + HP + Hewlett Packard Enterprise + many SaaS + cloud providers; (b) TELECOMMUNICATIONS - AT&T + Verizon + Comcast + Cox Communications + Charter + various; (c) FINANCIAL SERVICES - JPMorgan + Bank of America + Wells Fargo + Citi + Goldman Sachs + Morgan Stanley + payments providers; (d) CONSUMER GOODS + RETAIL - Walmart + Target + Costco + various; (e) HEALTHCARE - UnitedHealth + Anthem + HCA + various health insurance + hospital systems + life sciences; (f) MEDIA + ADVERTISING - Disney + Comcast NBCUniversal + Adobe Advert
- Industry case studies + sectoral application
- Certified organizations directory
- Growth tracking + competitive analysis
- Industry adoption tracking gaps
- Sectoral application unclear
- Competitive analysis absent
Global CBPR Forum status + operations + future roadmap. ANNUAL MEETING: Forum Assembly meets at least annually; 2024 + 2025 meetings include UK formal accession + program updates + AI + PET working group outputs + new member accession + Global PRP expansion + APEC CBPR evolution discussions. WORKING GROUPS: (a) ACCESSION WORKING GROUP - manages prospective member onboarding; (b) PROGRAM REQUIREMENTS WORKING GROUP - updates to 50 Program Requirements + AI + PET integration; (c) ACCOUNTABILITY AGENT WORKING GROUP - AA accreditation + oversight + sanctions; (d) CROSS-BORDER COOPERATION WORKING GROUP - DPA cooperation + dispute resolution + enforcement; (e) GLOBAL PRP WORKING GROUP - processor program evolution + Controller-Processor linkage; (f) ASEAN MCC + BRIDGE-MECHANISM WORKING GROUP - cross-recognition exploration; (g) UK INTEGRATION WORKING GROUP - UK accession-specific + UK-EU + UK D
- Working group participation
- Roadmap tracking + impact
- Industry engagement + IAPP/FPF/CIPL
- Working group participation absent
- Roadmap not tracked
- Industry engagement weak
Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)
Global CBPR Forum is based on the 9 APEC PRIVACY PRINCIPLES adopted in 2004 + revised 2015 + carried forward into Global CBPR Program Requirements (~50 detailed). (1) NOTICE - clear + accessible privacy statements identifying purposes of collection + use + disclosure + collection practices; (2) COLLECTION LIMITATION - limited to information relevant to purposes + obtained by lawful + fair means; (3) USES OF PERSONAL INFORMATION - use limited to purposes for which collected + compatible purposes + with consent or by law; (4) CHOICE - mechanisms for individuals to opt-out or opt-in to collection + use + disclosure; (5) INTEGRITY OF PERSONAL INFORMATION - accurate + complete + up-to-date; (6) SECURITY SAFEGUARDS - administrative + physical + technical safeguards proportionate to sensitivity + risks; (7) ACCESS AND CORRECTION - individuals can confirm holdings + access + correct/amend; reaso
- Privacy policy + practices documentation
- Privacy program operationalisation per principle
- Continuous compliance evidence
- Privacy principles not operationalised
- Program Requirements gaps
- Continuous compliance documentation missing
Global CBPR Forum: Accountability Agents, Program Requirements, Certification Process
Global CBPR Forum certification operates through ACCREDITED ACCOUNTABILITY AGENTS (AAs). AAs are third-party private-sector organizations accredited by the Forum to certify Controllers (Global CBPR) + Processors (Global PRP); accreditation is jurisdiction-specific (an AA may operate in multiple member jurisdictions but must be accredited per jurisdiction); AAs subject to oversight + audit + sanctions for non-compliance with accreditation standards. ACCREDITED AAs (as of 2026): (a) TRUSTARC (largest by certifications) - operates in US + Canada + Japan + Korea + Philippines + Singapore + Taiwan; (b) SCHELLMAN - US + Canada + Japan + Singapore; (c) BBB NATIONAL PROGRAMS (Better Business Bureau) - US + Canada; (d) JIPDEC (Japan Information Processing Development Center) - Japan (national); (e) others in accreditation pipeline. CERTIFICATION PROCESS: (1) ORGANIZATION SELF-ASSESSMENT against 5
- AA contract + assessment report
- Self-assessment + remediation evidence
- Recertification + monitoring reports
- Breach notifications to AA
- AA selection gaps
- Self-assessment incomplete
- Recertification skipped
- Breach notification gaps
Global CBPR Forum: Coordination with GDPR + UK + Japan APPI + Korea PIPA + Singapore PDPA + US State Laws
Global CBPR Forum coordination with adjacent privacy regimes. EU GDPR + GDPR ADEQUACY: no formal EU adequacy decision recognizing CBPR + ongoing European Commission dialogue; some EU companies use CBPR as supplementary measure + accountability evidence; bridge-mechanism aspirations + GDPR Art. 46 + Art. 47 (Binding Corporate Rules) coordination + EDPB engagement; no immediate adequacy expected 2026. UK GDPR: UK acceded 2024 + first non-APEC member; UK ICO + DSIT participating; UK Department for Science Innovation and Technology + Information Commissioners Office endorsement; UK companies can use CBPR for transfers to other Forum members; UK Data Protection Bill (Data (Use and Access) Bill 2024) reform may further integrate CBPR. JAPAN APPI (Act on Protection of Personal Information): Japan founding member + APPI cross-border provisions recognize CBPR-certified recipients; PPC (Personal I
- Multi-jurisdictional compliance program
- CBPR certification + cross-border evidence
- State-by-state adequacy evidence
- Bridge-mechanism + EU communication
- Multi-jurisdictional coordination gaps
- CBPR not leveraged as state adequacy
- Bridge-mechanism status unclear
Global CBPR Forum crosswalk to adjacent privacy frameworks. (a) EU GDPR - 9 APEC principles map to GDPR Articles 5-25 + 32 + 33-34 + 35 with bridge gaps in (i) Lawful Basis (GDPR Art. 6) - CBPR uses 'compatible purposes' + consent + business purpose model rather than 6 lawful bases; (ii) Data Subject Rights (GDPR Art. 12-22) - CBPR covers access + correction; doesn't explicitly include right to erasure + portability + restriction + objection + ADM safeguards (UK CBPR may evolve); (iii) DPIA + DPO - CBPR more flexible than mandated; (iv) breach notification - CBPR principle but no 72-hour bright line; (v) lawful international transfers - CBPR IS one mechanism but not equivalent to adequacy decision. (b) UK GDPR + UK DATA PROTECTION ACT 2018 + UK DATA (USE AND ACCESS) BILL 2024 - similar to EU GDPR plus UK adequacy assessment context. (c) US STATE PRIVACY LAWS - CBPR explicitly recognized
- Multi-framework certification + mapping
- Cross-mapping documentation
- Sectoral application evidence
- Multi-framework alignment ad-hoc
- Cross-mapping not maintained
- Sectoral coordination gaps
Global CBPR Forum: Cross-Border Transfer Recognition, Dispute Resolution, Enforcement
Global CBPR Forum dispute resolution + enforcement + cross-border recognition. DISPUTE RESOLUTION MECHANISM (DRM): when a data subject complaint cannot be resolved by the certified organization or its Accountability Agent + the data subject can escalate; ULTIMATE ESCALATION to the national DPA or competent authority of the certified organization. ACCOUNTABILITY AGENT COMPLAINT HANDLING: AAs maintain complaint procedures + dispute resolution mechanisms + record-keeping; failure to handle complaints can trigger AA accreditation review + sanctions. CROSS-BORDER COOPERATION: participating DPAs commit to mutual cooperation + information-sharing + joint investigations; coordination with international networks (GPEN - Global Privacy Enforcement Network + APEC CPEA - Cross-border Privacy Enforcement Arrangement + ICDPPC International Conference of Data Protection and Privacy Commissioners). ENFO
- DRM procedures + complaint records
- Cross-border cooperation evidence
- Transfer recognition documentation per state
- DRM gaps
- Cross-border cooperation absent
- Transfer recognition not leveraged
Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complexity for businesses with multi-state operations. (a) CALIFORNIA CCPA (Cal Civ Code 1798.140(p)) + CPRA - recognizes binding/enforceable cross-border programs; CPPA (California Privacy Protection Agency) enforcement consideration of CBPR certification + APEC CBPR; (b) VIRGINIA VCDPA - recognizes binding cross-border privacy programs as adequate; (c) COLORADO CPA - similar recognition; (d) CONNECTICUT CTDPA - similar recognition + active engagement; (e) FLORIDA FDBR - similar (2024 effective); (f) TENNESSEE TIPA - similar (2025 effective); (g) MONTANA MCDPA + IOWA IPA + UTAH UCPA + DELAWARE DPDPA + NEW HAMPSHIRE NHDPA + KENTUCKY KCDPA
- Multi-state compliance program leveraging CBPR
- State recognition evidence per business
- Sectoral US compliance bridge
- Multi-state CBPR not leveraged
- State recognition not evidenced
- Sectoral US coordination gaps
Global CBPR Forum: Global PRP (Privacy Recognition for Processors) + Controller-Processor Linkage
Global PRP (Privacy Recognition for Processors) is the Forum's certification program for DATA PROCESSORS - organizations that process personal data on behalf of Controllers (rather than determining purposes/means themselves). PURPOSE: bridges Controller-Processor compliance gap in cross-border data transfers + provides Controllers a vetted vendor list + simplifies Controller-Processor agreements + reduces Controller burden assessing each Processor individually. PROCESSORS COVERED: cloud service providers (AWS + Azure + Google Cloud + Oracle Cloud + Alibaba Cloud) + SaaS providers (Salesforce + Workday + ServiceNow + Adobe + HubSpot + Zendesk + many others) + analytics platforms (Mixpanel + Amplitude + Segment + Heap + Adobe Analytics) + customer service (Zendesk + Intercom + Salesforce Service) + marketing automation (Marketo + HubSpot + Mailchimp + ConvertKit) + identity platforms (Auth
- Processor certification + contract evidence
- Sub-processor flow-down + audit
- Controller-Processor agreement template + DPAs
- Processor certification not pursued
- Sub-processor management gaps
- Controller-Processor agreement weak
Global CBPR Forum: Governance, Membership and Relationship to APEC CBPR Predecessor
Global CBPR Forum governance + membership. ESTABLISHMENT: launched 21 April 2022 via the GLOBAL CROSS-BORDER PRIVACY RULES DECLARATION signed by 7 founding members (United States + Canada + Japan + Republic of Korea + Philippines + Singapore + Taiwan/Chinese Taipei) + announced by US Department of Commerce; serves as international successor to the APEC CBPR System (which continues in parallel for non-Forum APEC economies). UK ACCESSION: United Kingdom acceded 2024 + first non-APEC member; ICO + DSIT participating. GOVERNANCE STRUCTURE: (a) GLOBAL FORUM ASSEMBLY - intergovernmental coordinating body comprising one representative per member jurisdiction (typically a national DPA or government agency); meets annually; sets policy + admits new members + amends program; (b) GLOBAL FORUM STEERING COMMITTEE - smaller operational body overseeing day-to-day; (c) US DEPARTMENT OF COMMERCE serves a
- Forum membership status documentation
- Accession evidence + Assembly endorsement
- DPA participation evidence
- Forum membership unclear
- Accession process not understood
- DPA participation gaps
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Global Cross-Border Privacy Rules (Global CBPR) Forum framework page.