Take your data privacy compliance efforts further with NCC Group.
Take your data privacy compliance efforts further with NCC Group.
US based NCC Group Security Services Inc. is approved through the US Department of Commerce Accountability Agent program for both:
- the Asia-Pacific Economic Cooperation (APEC) Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP)
- and the Global Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP)
From this position, we are able to assess the privacy programs of US companies and certify their alignment with the comprehensive CBPR and PRP compliance requirements of both certification offerings.
What are the differences between the two sets of certifications?
There are some differences between the Global CPBR / PRP and the APEC CBP /PRP to be aware of.
The Asia Pacific Economic Cooperation created the Cross Border Privacy Rules System and the Privacy Recognition for Processors System to support trusted, accountable cross border data flows across APEC economies.
The Global CBPR and PRP systems are essentially the internationalized successor to the APEC CBPR and PRP systems—retaining the same privacy principles and certification model while expanding participation beyond the Asia-Pacific region.
These programs operationalize an agreed Privacy Framework, offering a consistent, enforceable approach for companies to demonstrate privacy compliance and reduce friction in international commerce.
APEC CBPR/PRP vs Global CBPR/PRP Comparison
| Category | APEC CBPR / PRP | Global CBPR / PRP |
|---|---|---|
| Purpose | Facilitate trusted cross-border data transfers among APEC economies while protecting personal information. | Extend the CBPR/PRP concept beyond APEC to create a globally scalable, interoperable privacy certification framework. |
| Geographic Scope | Limited to participating APEC economies. | Open to jurisdictions worldwide, including non-APEC participants. |
| Governing Body | APEC governance structure. | Global CBPR Forum (established in 2022). |
| Launch/Evolution | CBPR endorsed in 2011; PRP added later. | Established in 2022 as an evolution of the APEC system. |
| Privacy Framework | APEC Privacy Framework Website - Cross Border Privacy Rules System |
Global CBPR Framework derived from APEC and aligned to OECD principles. Website - https://www.globalcbpr.org/ |
| Certification for Controllers and Requirements | CBPR certification. Read the official CBPR requirements from APEC |
Global CBPR certification. Until 31 MAR 2027 - Global CBPR System Program Requirements (Valid until 31 March 2027) After 01 APR 2027 - Global CBPR System Program Requirements (Effective from 1 April 2027) |
| Certification for Processors and Requirements | PRP certification Learn more about APEC PRP |
Global PRP certification. Global PRP System Program Requirements |
| Program Requirements Comparison | APEC certification requirements. | Initially, substantively the same as APEC requirements. |
| Links to Program Requirements | APEC Website | Global CBPR PRP Website |
| Accountability Agents | Independent Accountability Agents certify organizations. | Recognized Accountability Agents under Global Forum governance. |
| Regulatory Objective | Interoperability among APEC privacy regimes. | Interoperability across global privacy regimes. |
| Business Impact | Recognition primarily for Asia-Pacific data transfers. | Broader international recognition. |
What Global CBPR / PRP and APEC CBPR /PRP have in common:
The CBPR System is a voluntary, certification based framework for personal information controllers (organizations that determine purposes and means of processing). It allows organizations to demonstrate compliance with the germane Privacy Framework principles and is implemented through accredited Accountability Agents.
CBPR program requirements:
- Notice
- Collection Limitation
- Uses of Personal Information
- Choice
- Integrity of Personal Information
- Security Safeguards
- Access and Correction
- Accountability
PRP System
The PRP System is designed for personal information processors—organizations that process data on behalf of controllers. Introduced in 2015, PRP helps processors demonstrate the capacity to implement a controller’s privacy obligations and robust security and operational controls.
PRP focus areas:
- Data security and incident management
- Operational capacity to implement controller instructions
- Support for controller compliance obligations (e.g., access requests)
- Organizational accountability and oversight
APEC and Global - CBPR vs. PRP side-by-side details
| Category | APEC CBPR (Controllers) | APEC PRP (Processors) | Global CBPR (Controllers) | Global PRP (Processors) |
|---|---|---|---|---|
| Who it applies to | Personal information controllers that determine purposes and means of processing. | Personal information processors acting on behalf of controllers. | Personal information controllers that determine purposes and means of processing in participating Global CBPR Forum jurisdictions. | Personal information processors acting on behalf of controllers in participating Global CBPR Forum jurisdictions. |
| Program intent | Demonstrate comprehensive privacy governance aligned to APEC principles. | Demonstrate ability to implement controller instructions and strong security/operations. | Demonstrate accountable privacy governance and trusted international data transfers under the Global CBPR Framework. | Demonstrate processor capability to implement controller requirements and maintain effective privacy and security controls globally. |
| Core requirements | 50 program requirements across notice, choice, access, integrity, security, accountability, etc. | Streamlined requirements emphasizing security, operational controls, and support for controller obligations. | Program requirements aligned to the Global CBPR Privacy Principles covering notice, choice, accountability, security, access, integrity, and risk management. | Requirements focused on processor accountability, security safeguards, operational controls, subcontractor management, and support for controller compliance obligations. |
| Assessment body | APEC-recognized Accountability Agents certify and monitor. | APEC-recognized Accountability Agents recognize and monitor. | Global CBPR Forum-recognized Accountability Agents certify and monitor compliance. | Global CBPR Forum-recognized Accountability Agents certify and monitor compliance. |
| Onward transfers | Requires ensuring recipients provide comparable protections and contractual controls. | Requires managing sub-processors and following controller-approved terms and flows. | Requires ensuring downstream recipients provide comparable privacy protections and appropriate contractual safeguards. | Requires oversight of sub-processors and adherence to controller-approved processing terms and transfer requirements. |
| Individual rights | Direct obligations for access and correction; notice and choice mechanisms. | Support functions to help controllers fulfill individual rights. | Direct responsibility for providing mechanisms supporting notice, access, correction, and complaint handling. | Supports controllers in fulfilling data subject rights and regulatory obligations. |
| Use cases | B2C and B2B controllers; intra-group and external transfers. | Service providers, cloud/SaaS, BPO, hosting, and data processing vendors. | Global organizations seeking a recognized privacy certification for international data transfers and privacy governance. | Cloud providers, SaaS vendors, outsourcing firms, hosting providers, and other service providers operating internationally. |
| Business value | Reduces cross-border friction; signals a robust privacy program to regulators and customers. | Eases controller due diligence; differentiates processors in procurement. | Provides globally recognized privacy certification, facilitates trusted cross-border data flows, and demonstrates accountability across multiple jurisdictions. | Simplifies customer due diligence, improves trust with controllers, and demonstrates processor maturity in global procurement and compliance reviews. |
Key Obligations for Potential Program Members
For CBPR (Controllers):
- Publish transparent privacy notices and define purposes of processing.
- Limit collection and use to what is necessary and compatible with purposes.
- Provide choice mechanisms where required (e.g., opt out/opt in).
- Implement security safeguards proportionate to risk and data sensitivity.
- Offer individual access and correction.
- Establish internal accountability (governance, training, oversight).
- Manage onward transfers to ensure comparable protections by recipients.
For PRP (Processors):
- Maintain robust security and incident response.
- Document and implement controller instructions and data handling playbooks.
- Support controller compliance (e.g., access, correction, deletion support).
- Demonstrate operational readiness, record keeping, and auditability.
Key steps for either program
- Apply through an APEC or Global CBPR/PRP recognized Accountability Agent such as NCC Group
- Undergo assessment of policies, practices, and technical/organizational measures against program requirements.
- Implement corrective actions to close gaps identified by the Accountability Agent.
- Maintain ongoing compliance via periodic reviews and monitoring; certification may be suspended or revoked for non compliance.
Key benefits
Certification strengthens global interoperability, reduces barriers to data transfers within participating economies, supports due diligence expectations, and aligns with other global privacy standards.
Customer intake form comparison
Customer Intake form comparison for both programs
| Category | CBPR Intake Questionnaire | PRP Intake Questionnaire |
|---|---|---|
| Links to Required Forms | APEC CBPR System Intake Questionnaire Global CBPR System Intake Questionnaire |
APEC PRP Intake Questionnaire Global PRP System Intake Questionnaire |
| Applies To | Controllers (determine purposes of processing). | Processors (process on behalf of controllers). |
| Purpose | Assess compliance with CBPR requirements. | Assess ability to implement controller instructions. |
| Key Sections | General, Notice, Collection, Uses, Choice, Integrity, Security, Access, Accountability. | General, Security Safeguards, Accountability Measures. |
| Use Case | Pre-assessment for CBPR certification. | Pre-assessment for PRP recognition. |
Companies we've recently assessed:
| Organization Name | APEC Assessment | Global Assessment (New) |
|---|---|---|
| BrightInsight, Inc. | Yes - CBPR and PRP | No |
| Hopper, Inc. | Yes - CBPR and PRP | No |
| Medallia, Inc. | Yes - CBPR and PRP | No |
| Yardi Systems, Inc. | Yes - CBPR and PRP | No |
| Thoropass, Inc. | Yes - CBPR | No |
Make privacy compliance simpler and stronger.
Our CBPR & PRP specialists are ready to support you today.
Complaint process:
US organizations only
If warranted, use the form or alternative contact methods below to submit a complaint concerning NCC Groups APEC and Global CBPR or PRP service for US companies. We take great care to ensure any legitimate complaints are quickly addressed per the APEC rules.
| Complaint Form | |
|
Contact |
Attention: NCC Group C&I North American Lead |
|
Mailing Address |
NCC Group Security Services, Inc. 11 E Adams St Suite 400 |
|
Email Address |
|
|
Phone Number |
|
|
|
|
|
Federal Trade Commission Contact Info |
600 Pennsylvania Avenue, NW (202) 326-2222 |
|
FTC Website |