Skip to content

Evidence request lists

Global Cross-Border Privacy Rules (Global CBPR) Forum

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Global CBPR Forum: 2024-2025 Pipeline, UK Accession, New Jurisdictions, AI and PEP Integration

CBPR-2024-2025-UK-NewJurisdictions-AI-PEP
Global CBPR Forum: 2024-2025 Update Pipeline - UK 2024, AI Integration, PEP, ASEAN MCC

Global CBPR Forum 2024-2025 status + pipeline. UK ACCESSION 2024: United Kingdom acceded April 2024 + first non-APEC member; ICO + DSIT signed accession; first wave of UK-certified Accountability Agents accredited; UK companies leverage CBPR for transfers to/from US + Japan + Korea + Singapore + Canada + Philippines + Taiwan; UK Data Protection Bill reform may further integrate CBPR adequacy mechanism. ACCESSION PIPELINE 2025-2026: Mexico (active discussions with US Commerce + Mexico CONDUSEF/INAI) + Australia (OAIC dialogue) + New Zealand (Office of the Privacy Commissioner) + Bahrain (PDPA) + Dubai DIFC (DIFC Data Protection Law) + Argentina + Brazil (LGPD) + others; the Forum aims to expand to 15+ members by 2027. AI INTEGRATION: 2024-2025 working group on AI-specific privacy guidance under CBPR; ASEAN AI Guide + Singapore AI Verify + Japan AI Governance Guidelines + Korea AI Privacy

Artefacts an auditor will ask for
  • Pipeline-tracking + impact assessment
  • AI + PET readiness for certification
  • Multi-stakeholder participation
Where this commonly fails
  • Pipeline not tracked
  • AI + PET readiness gaps
  • Multi-stakeholder participation absent
CBPR-Implementation-Roadmap-Roles-Org
Global CBPR Forum: Implementation Roadmap, Organizational Roles and Certification Management

Global CBPR Forum implementation roadmap. ROLES (organization side): (a) CHIEF PRIVACY OFFICER (CPO) or DPO - strategic ownership of certification + program; (b) PROGRAM MANAGER - day-to-day certification management + AA relationship + remediation; (c) PRIVACY ENGINEERING - technical privacy controls + DPIA + tooling; (d) LEGAL - cross-border + statutory + contractual review; (e) INFOSEC + CISO - safeguards (principle 6); (f) PRODUCT/ENGINEERING - product-level privacy + transparency + choice mechanisms; (g) MARKETING/COMMUNICATIONS - notice + consent + Privacy Choices; (h) HR - employee data + training; (i) PROCUREMENT - vendor management + sub-processor flow-down + PRP. ROLES (AA side): (a) AA Director + Accreditation Manager + Assessor + Compliance Officer + Dispute Resolution Manager. TOOLING: (a) PRIVACY MANAGEMENT PLATFORMS (OneTrust + TrustArc + Securiti + WireWheel + BigID + Priv

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Tooling adoption + vendor selection
  • Metrics + management review
  • Annual cycle documentation
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Metrics gaps
  • Annual cycle ad-hoc
CBPR-IndustryAdoption-MajorCertifiedOrgs-Sectoral
Global CBPR Forum: Industry Adoption, Major Certified Organizations and Sectoral Application

Global CBPR Forum industry adoption + sectoral application. INDUSTRY ADOPTION: 100+ certified organizations across Forum members + growing rapidly post-2022 launch + UK 2024 accession; major certified organizations include (a) TECHNOLOGY + SOFTWARE - Apple + Google + Microsoft + Amazon + Meta + Salesforce + Workday + Adobe + IBM + Cisco + ServiceNow + Oracle + Lenovo + HP + Hewlett Packard Enterprise + many SaaS + cloud providers; (b) TELECOMMUNICATIONS - AT&T + Verizon + Comcast + Cox Communications + Charter + various; (c) FINANCIAL SERVICES - JPMorgan + Bank of America + Wells Fargo + Citi + Goldman Sachs + Morgan Stanley + payments providers; (d) CONSUMER GOODS + RETAIL - Walmart + Target + Costco + various; (e) HEALTHCARE - UnitedHealth + Anthem + HCA + various health insurance + hospital systems + life sciences; (f) MEDIA + ADVERTISING - Disney + Comcast NBCUniversal + Adobe Advert

Artefacts an auditor will ask for
  • Industry case studies + sectoral application
  • Certified organizations directory
  • Growth tracking + competitive analysis
Where this commonly fails
  • Industry adoption tracking gaps
  • Sectoral application unclear
  • Competitive analysis absent
CBPR-Status-AnnualMeeting-Working-Groups-Future
Global CBPR Forum: Status, Annual Meeting, Working Groups and Future Roadmap

Global CBPR Forum status + operations + future roadmap. ANNUAL MEETING: Forum Assembly meets at least annually; 2024 + 2025 meetings include UK formal accession + program updates + AI + PET working group outputs + new member accession + Global PRP expansion + APEC CBPR evolution discussions. WORKING GROUPS: (a) ACCESSION WORKING GROUP - manages prospective member onboarding; (b) PROGRAM REQUIREMENTS WORKING GROUP - updates to 50 Program Requirements + AI + PET integration; (c) ACCOUNTABILITY AGENT WORKING GROUP - AA accreditation + oversight + sanctions; (d) CROSS-BORDER COOPERATION WORKING GROUP - DPA cooperation + dispute resolution + enforcement; (e) GLOBAL PRP WORKING GROUP - processor program evolution + Controller-Processor linkage; (f) ASEAN MCC + BRIDGE-MECHANISM WORKING GROUP - cross-recognition exploration; (g) UK INTEGRATION WORKING GROUP - UK accession-specific + UK-EU + UK D

Artefacts an auditor will ask for
  • Working group participation
  • Roadmap tracking + impact
  • Industry engagement + IAPP/FPF/CIPL
Where this commonly fails
  • Working group participation absent
  • Roadmap not tracked
  • Industry engagement weak

Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

CBPR-9-APEC-Privacy-Principles
Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

Global CBPR Forum is based on the 9 APEC PRIVACY PRINCIPLES adopted in 2004 + revised 2015 + carried forward into Global CBPR Program Requirements (~50 detailed). (1) NOTICE - clear + accessible privacy statements identifying purposes of collection + use + disclosure + collection practices; (2) COLLECTION LIMITATION - limited to information relevant to purposes + obtained by lawful + fair means; (3) USES OF PERSONAL INFORMATION - use limited to purposes for which collected + compatible purposes + with consent or by law; (4) CHOICE - mechanisms for individuals to opt-out or opt-in to collection + use + disclosure; (5) INTEGRITY OF PERSONAL INFORMATION - accurate + complete + up-to-date; (6) SECURITY SAFEGUARDS - administrative + physical + technical safeguards proportionate to sensitivity + risks; (7) ACCESS AND CORRECTION - individuals can confirm holdings + access + correct/amend; reaso

Artefacts an auditor will ask for
  • Privacy policy + practices documentation
  • Privacy program operationalisation per principle
  • Continuous compliance evidence
Where this commonly fails
  • Privacy principles not operationalised
  • Program Requirements gaps
  • Continuous compliance documentation missing

Global CBPR Forum: Accountability Agents, Program Requirements, Certification Process

CBPR-AccountabilityAgents-CertificationProcess
Global CBPR Forum: Accountability Agents (TrustArc, Schellman, BBB, JIPDEC) and Certification Process

Global CBPR Forum certification operates through ACCREDITED ACCOUNTABILITY AGENTS (AAs). AAs are third-party private-sector organizations accredited by the Forum to certify Controllers (Global CBPR) + Processors (Global PRP); accreditation is jurisdiction-specific (an AA may operate in multiple member jurisdictions but must be accredited per jurisdiction); AAs subject to oversight + audit + sanctions for non-compliance with accreditation standards. ACCREDITED AAs (as of 2026): (a) TRUSTARC (largest by certifications) - operates in US + Canada + Japan + Korea + Philippines + Singapore + Taiwan; (b) SCHELLMAN - US + Canada + Japan + Singapore; (c) BBB NATIONAL PROGRAMS (Better Business Bureau) - US + Canada; (d) JIPDEC (Japan Information Processing Development Center) - Japan (national); (e) others in accreditation pipeline. CERTIFICATION PROCESS: (1) ORGANIZATION SELF-ASSESSMENT against 5

Artefacts an auditor will ask for
  • AA contract + assessment report
  • Self-assessment + remediation evidence
  • Recertification + monitoring reports
  • Breach notifications to AA
Where this commonly fails
  • AA selection gaps
  • Self-assessment incomplete
  • Recertification skipped
  • Breach notification gaps

Global CBPR Forum: Coordination with GDPR + UK + Japan APPI + Korea PIPA + Singapore PDPA + US State Laws

CBPR-Coord-GDPR-UK-Japan-Korea-Singapore-Philippines-StateLaws
Global CBPR Forum: Coordination with GDPR + UK GDPR + Japan APPI + Korea PIPA + Singapore PDPA + Philippines DPA + US State Laws

Global CBPR Forum coordination with adjacent privacy regimes. EU GDPR + GDPR ADEQUACY: no formal EU adequacy decision recognizing CBPR + ongoing European Commission dialogue; some EU companies use CBPR as supplementary measure + accountability evidence; bridge-mechanism aspirations + GDPR Art. 46 + Art. 47 (Binding Corporate Rules) coordination + EDPB engagement; no immediate adequacy expected 2026. UK GDPR: UK acceded 2024 + first non-APEC member; UK ICO + DSIT participating; UK Department for Science Innovation and Technology + Information Commissioners Office endorsement; UK companies can use CBPR for transfers to other Forum members; UK Data Protection Bill (Data (Use and Access) Bill 2024) reform may further integrate CBPR. JAPAN APPI (Act on Protection of Personal Information): Japan founding member + APPI cross-border provisions recognize CBPR-certified recipients; PPC (Personal I

Artefacts an auditor will ask for
  • Multi-jurisdictional compliance program
  • CBPR certification + cross-border evidence
  • State-by-state adequacy evidence
  • Bridge-mechanism + EU communication
Where this commonly fails
  • Multi-jurisdictional coordination gaps
  • CBPR not leveraged as state adequacy
  • Bridge-mechanism status unclear
CBPR-Crosswalk-GDPR-StateLaws-ISO27701-NIST
Global CBPR Forum: Crosswalk to GDPR, US State Laws, ISO/IEC 27701 and NIST Privacy Framework

Global CBPR Forum crosswalk to adjacent privacy frameworks. (a) EU GDPR - 9 APEC principles map to GDPR Articles 5-25 + 32 + 33-34 + 35 with bridge gaps in (i) Lawful Basis (GDPR Art. 6) - CBPR uses 'compatible purposes' + consent + business purpose model rather than 6 lawful bases; (ii) Data Subject Rights (GDPR Art. 12-22) - CBPR covers access + correction; doesn't explicitly include right to erasure + portability + restriction + objection + ADM safeguards (UK CBPR may evolve); (iii) DPIA + DPO - CBPR more flexible than mandated; (iv) breach notification - CBPR principle but no 72-hour bright line; (v) lawful international transfers - CBPR IS one mechanism but not equivalent to adequacy decision. (b) UK GDPR + UK DATA PROTECTION ACT 2018 + UK DATA (USE AND ACCESS) BILL 2024 - similar to EU GDPR plus UK adequacy assessment context. (c) US STATE PRIVACY LAWS - CBPR explicitly recognized

Artefacts an auditor will ask for
  • Multi-framework certification + mapping
  • Cross-mapping documentation
  • Sectoral application evidence
Where this commonly fails
  • Multi-framework alignment ad-hoc
  • Cross-mapping not maintained
  • Sectoral coordination gaps

Global CBPR Forum: Cross-Border Transfer Recognition, Dispute Resolution, Enforcement

CBPR-DisputeResolution-Enforcement-CrossBorderRecognition
Global CBPR Forum: Dispute Resolution, Enforcement and Cross-Border Recognition

Global CBPR Forum dispute resolution + enforcement + cross-border recognition. DISPUTE RESOLUTION MECHANISM (DRM): when a data subject complaint cannot be resolved by the certified organization or its Accountability Agent + the data subject can escalate; ULTIMATE ESCALATION to the national DPA or competent authority of the certified organization. ACCOUNTABILITY AGENT COMPLAINT HANDLING: AAs maintain complaint procedures + dispute resolution mechanisms + record-keeping; failure to handle complaints can trigger AA accreditation review + sanctions. CROSS-BORDER COOPERATION: participating DPAs commit to mutual cooperation + information-sharing + joint investigations; coordination with international networks (GPEN - Global Privacy Enforcement Network + APEC CPEA - Cross-border Privacy Enforcement Arrangement + ICDPPC International Conference of Data Protection and Privacy Commissioners). ENFO

Artefacts an auditor will ask for
  • DRM procedures + complaint records
  • Cross-border cooperation evidence
  • Transfer recognition documentation per state
Where this commonly fails
  • DRM gaps
  • Cross-border cooperation absent
  • Transfer recognition not leveraged
CBPR-Implementation-MultiState-AdequacyMechanism
Global CBPR Forum: US Multi-State Adequacy Mechanism, State-by-State Recognition

Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complexity for businesses with multi-state operations. (a) CALIFORNIA CCPA (Cal Civ Code 1798.140(p)) + CPRA - recognizes binding/enforceable cross-border programs; CPPA (California Privacy Protection Agency) enforcement consideration of CBPR certification + APEC CBPR; (b) VIRGINIA VCDPA - recognizes binding cross-border privacy programs as adequate; (c) COLORADO CPA - similar recognition; (d) CONNECTICUT CTDPA - similar recognition + active engagement; (e) FLORIDA FDBR - similar (2024 effective); (f) TENNESSEE TIPA - similar (2025 effective); (g) MONTANA MCDPA + IOWA IPA + UTAH UCPA + DELAWARE DPDPA + NEW HAMPSHIRE NHDPA + KENTUCKY KCDPA

Artefacts an auditor will ask for
  • Multi-state compliance program leveraging CBPR
  • State recognition evidence per business
  • Sectoral US compliance bridge
Where this commonly fails
  • Multi-state CBPR not leveraged
  • State recognition not evidenced
  • Sectoral US coordination gaps

Global CBPR Forum: Global PRP (Privacy Recognition for Processors) + Controller-Processor Linkage

CBPR-Global-PRP-Privacy-Recognition-Processors
Global CBPR Forum: Global PRP (Privacy Recognition for Processors) Controller-Processor Linkage

Global PRP (Privacy Recognition for Processors) is the Forum's certification program for DATA PROCESSORS - organizations that process personal data on behalf of Controllers (rather than determining purposes/means themselves). PURPOSE: bridges Controller-Processor compliance gap in cross-border data transfers + provides Controllers a vetted vendor list + simplifies Controller-Processor agreements + reduces Controller burden assessing each Processor individually. PROCESSORS COVERED: cloud service providers (AWS + Azure + Google Cloud + Oracle Cloud + Alibaba Cloud) + SaaS providers (Salesforce + Workday + ServiceNow + Adobe + HubSpot + Zendesk + many others) + analytics platforms (Mixpanel + Amplitude + Segment + Heap + Adobe Analytics) + customer service (Zendesk + Intercom + Salesforce Service) + marketing automation (Marketo + HubSpot + Mailchimp + ConvertKit) + identity platforms (Auth

Artefacts an auditor will ask for
  • Processor certification + contract evidence
  • Sub-processor flow-down + audit
  • Controller-Processor agreement template + DPAs
Where this commonly fails
  • Processor certification not pursued
  • Sub-processor management gaps
  • Controller-Processor agreement weak

Global CBPR Forum: Governance, Membership and Relationship to APEC CBPR Predecessor

CBPR-Forum-Governance-Membership
Global CBPR Forum Governance, Membership and Relationship to APEC CBPR

Global CBPR Forum governance + membership. ESTABLISHMENT: launched 21 April 2022 via the GLOBAL CROSS-BORDER PRIVACY RULES DECLARATION signed by 7 founding members (United States + Canada + Japan + Republic of Korea + Philippines + Singapore + Taiwan/Chinese Taipei) + announced by US Department of Commerce; serves as international successor to the APEC CBPR System (which continues in parallel for non-Forum APEC economies). UK ACCESSION: United Kingdom acceded 2024 + first non-APEC member; ICO + DSIT participating. GOVERNANCE STRUCTURE: (a) GLOBAL FORUM ASSEMBLY - intergovernmental coordinating body comprising one representative per member jurisdiction (typically a national DPA or government agency); meets annually; sets policy + admits new members + amends program; (b) GLOBAL FORUM STEERING COMMITTEE - smaller operational body overseeing day-to-day; (c) US DEPARTMENT OF COMMERCE serves a

Artefacts an auditor will ask for
  • Forum membership status documentation
  • Accession evidence + Assembly endorsement
  • DPA participation evidence
Where this commonly fails
  • Forum membership unclear
  • Accession process not understood
  • DPA participation gaps
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Global Cross-Border Privacy Rules (Global CBPR) Forum framework page.