This document addresses some commonly asked questions about the APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) systems.
The following questions are addressed in these FAQs:
- What is APEC?
- What are the APEC Cross-Border Privacy Rules (CBPR)?
- Which APEC economies participate in the CBPR?
- What is the APEC Privacy Recognition for Processors (PRP)?
- How can companies become CBPR or PRP certified?
- What are CBPR Program Requirements?
- What is an “Accountability Agent”?
- How do APEC economies join the CBPR and PRP systems?
- Are the CBPR and PRP enforceable?
- What is the APEC Cross-Border Privacy Enforcement Arrangement (CPEA)?
- How do CBPR and PRP interact with domestic privacy laws?
- What happens if companies don’t comply with their certification?
- Why should companies seek CBPR or PRP certification?
- How do CBPR help consumers?
- How do CBPR help data protection authorities?
- Can non-APEC economies join the CBPR and PRP systems?
- Can companies based in non-APEC economies obtain CBPR and PRP certification?
- Could there be interoperability between the CBPR and EU mechanisms like Binding Corporate Rules (BCR) and GDPR certifications?
- Where can I find more information?