Skip to navigation Skip to main content Skip to footer

APEC CBPR / PRP and
Global CBPR / PRP Certifications

Strengthen, verify, and certify your commitment to robust data privacy protection.

Take your data privacy compliance efforts further with NCC Group.

Take your data privacy compliance efforts further with NCC Group.

US based NCC Group Security Services Inc. is approved through the US Department of Commerce Accountability Agent program for both:

  • the Asia-Pacific Economic Cooperation (APEC) Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP)
  • and the Global Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP)

From this position, we are able to assess the privacy programs of US companies and certify their alignment with the comprehensive CBPR and PRP compliance requirements of both certification offerings.


What are the differences between the two sets of certifications?

There are some differences between the Global CPBR / PRP and the APEC CBP /PRP to be aware of.

The Asia Pacific Economic Cooperation created the Cross Border Privacy Rules System and the Privacy Recognition for Processors System to support trusted, accountable cross border data flows across APEC economies.

The Global CBPR and PRP systems are essentially the internationalized successor to the APEC CBPR and PRP systems—retaining the same privacy principles and certification model while expanding participation beyond the Asia-Pacific region. 

These programs operationalize an agreed Privacy Framework, offering a consistent, enforceable approach for companies to demonstrate privacy compliance and reduce friction in international commerce.

APEC CBPR/PRP vs Global CBPR/PRP Comparison 

 

Category APEC CBPR / PRP Global CBPR / PRP
Purpose Facilitate trusted cross-border data transfers among APEC economies while protecting personal information. Extend the CBPR/PRP concept beyond APEC to create a globally scalable, interoperable privacy certification framework.
Geographic Scope Limited to participating APEC economies. Open to jurisdictions worldwide, including non-APEC participants.
Governing Body APEC governance structure. Global CBPR Forum (established in 2022).
Launch/Evolution CBPR endorsed in 2011; PRP added later. Established in 2022 as an evolution of the APEC system.
Privacy Framework APEC Privacy Framework

Website - Cross Border Privacy Rules System
Global CBPR Framework derived from APEC and aligned to OECD principles.

Website - https://www.globalcbpr.org/
Certification for Controllers and Requirements CBPR certification.

Read the official CBPR requirements from APEC
Global CBPR certification.

Until 31 MAR 2027 - Global CBPR System Program Requirements (Valid until 31 March 2027)

After 01 APR 2027 - Global CBPR System Program Requirements (Effective from 1 April 2027)
Certification for Processors and Requirements PRP certification

Learn more about APEC PRP
Global PRP certification.

Global PRP System Program Requirements
Program Requirements Comparison APEC certification requirements. Initially, substantively the same as APEC requirements.
Links to Program Requirements APEC Website Global CBPR PRP Website
Accountability Agents Independent Accountability Agents certify organizations. Recognized Accountability Agents under Global Forum governance.
Regulatory Objective Interoperability among APEC privacy regimes. Interoperability across global privacy regimes.
Business Impact Recognition primarily for Asia-Pacific data transfers. Broader international recognition.

 

What Global CBPR / PRP and APEC CBPR /PRP  have in common: 

The CBPR System is a voluntary, certification based framework for personal information controllers (organizations that determine purposes and means of processing). It allows organizations to demonstrate compliance with the germane Privacy Framework principles and is implemented through accredited Accountability Agents.

CBPR program requirements:  

  • Notice
  • Collection Limitation
  • Uses of Personal Information
  • Choice
  • Integrity of Personal Information
  • Security Safeguards
  • Access and Correction
  • Accountability

PRP System

The PRP System is designed for personal information processors—organizations that process data on behalf of controllers. Introduced in 2015, PRP helps processors demonstrate the capacity to implement a controller’s privacy obligations and robust security and operational controls.
 
PRP focus areas:

  • Data security and incident management
  • Operational capacity to implement controller instructions
  • Support for controller compliance obligations (e.g., access requests)
  • Organizational accountability and oversight

APEC and Global - CBPR vs. PRP side-by-side details

Category APEC CBPR (Controllers) APEC PRP (Processors) Global CBPR (Controllers) Global PRP (Processors)
Who it applies to Personal information controllers that determine purposes and means of processing. Personal information processors acting on behalf of controllers. Personal information controllers that determine purposes and means of processing in participating Global CBPR Forum jurisdictions. Personal information processors acting on behalf of controllers in participating Global CBPR Forum jurisdictions.
Program intent Demonstrate comprehensive privacy governance aligned to APEC principles. Demonstrate ability to implement controller instructions and strong security/operations. Demonstrate accountable privacy governance and trusted international data transfers under the Global CBPR Framework. Demonstrate processor capability to implement controller requirements and maintain effective privacy and security controls globally.
Core requirements 50 program requirements across notice, choice, access, integrity, security, accountability, etc. Streamlined requirements emphasizing security, operational controls, and support for controller obligations. Program requirements aligned to the Global CBPR Privacy Principles covering notice, choice, accountability, security, access, integrity, and risk management. Requirements focused on processor accountability, security safeguards, operational controls, subcontractor management, and support for controller compliance obligations.
Assessment body APEC-recognized Accountability Agents certify and monitor. APEC-recognized Accountability Agents recognize and monitor. Global CBPR Forum-recognized Accountability Agents certify and monitor compliance. Global CBPR Forum-recognized Accountability Agents certify and monitor compliance.
Onward transfers Requires ensuring recipients provide comparable protections and contractual controls. Requires managing sub-processors and following controller-approved terms and flows. Requires ensuring downstream recipients provide comparable privacy protections and appropriate contractual safeguards. Requires oversight of sub-processors and adherence to controller-approved processing terms and transfer requirements.
Individual rights Direct obligations for access and correction; notice and choice mechanisms. Support functions to help controllers fulfill individual rights. Direct responsibility for providing mechanisms supporting notice, access, correction, and complaint handling. Supports controllers in fulfilling data subject rights and regulatory obligations.
Use cases B2C and B2B controllers; intra-group and external transfers. Service providers, cloud/SaaS, BPO, hosting, and data processing vendors. Global organizations seeking a recognized privacy certification for international data transfers and privacy governance. Cloud providers, SaaS vendors, outsourcing firms, hosting providers, and other service providers operating internationally.
Business value Reduces cross-border friction; signals a robust privacy program to regulators and customers. Eases controller due diligence; differentiates processors in procurement. Provides globally recognized privacy certification, facilitates trusted cross-border data flows, and demonstrates accountability across multiple jurisdictions. Simplifies customer due diligence, improves trust with controllers, and demonstrates processor maturity in global procurement and compliance reviews.

Key Obligations for Potential Program Members

For CBPR (Controllers):

  • Publish transparent privacy notices and define purposes of processing.
  • Limit collection and use to what is necessary and compatible with purposes.
  • Provide choice mechanisms where required (e.g., opt out/opt in).
  • Implement security safeguards proportionate to risk and data sensitivity.
  • Offer individual access and correction.
  • Establish internal accountability (governance, training, oversight).
  • Manage onward transfers to ensure comparable protections by recipients.

For PRP (Processors):

  • Maintain robust security and incident response.
  • Document and implement controller instructions and data handling playbooks.
  • Support controller compliance (e.g., access, correction, deletion support).
  • Demonstrate operational readiness, record keeping, and auditability.

Key steps for either program

  1.  Apply through an APEC or Global CBPR/PRP recognized Accountability Agent such as NCC Group
  2. Undergo assessment of policies, practices, and technical/organizational measures against program requirements.
  3. Implement corrective actions to close gaps identified by the Accountability Agent.
  4. Maintain ongoing compliance via periodic reviews and monitoring; certification may be suspended or revoked for non compliance.

Key benefits

Certification strengthens global interoperability, reduces barriers to data transfers within participating economies, supports due diligence expectations, and aligns with other global privacy standards.

 


 

Customer intake form comparison

   

Customer Intake form comparison for both programs

Category CBPR Intake Questionnaire PRP Intake Questionnaire
Links to Required Forms APEC CBPR System Intake Questionnaire

Global CBPR System Intake Questionnaire
APEC PRP Intake Questionnaire

Global PRP System Intake Questionnaire
Applies To Controllers (determine purposes of processing). Processors (process on behalf of controllers).
Purpose Assess compliance with CBPR requirements. Assess ability to implement controller instructions.
Key Sections General, Notice, Collection, Uses, Choice, Integrity, Security, Access, Accountability. General, Security Safeguards, Accountability Measures.
Use Case Pre-assessment for CBPR certification. Pre-assessment for PRP recognition.

   

Companies we've recently assessed:

 

Organization Name APEC Assessment Global Assessment (New)
BrightInsight, Inc. Yes - CBPR and PRP No
Hopper, Inc. Yes - CBPR and PRP No
Medallia, Inc. Yes - CBPR and PRP No
Yardi Systems, Inc. Yes - CBPR and PRP No
Thoropass, Inc. Yes - CBPR No

Make privacy compliance simpler and stronger.

Our CBPR & PRP specialists are ready to support you today.

 

Complaint process:

US organizations only 

If warranted, use the form or alternative contact methods below to submit a complaint concerning NCC Groups APEC and Global CBPR or PRP service for US companies. We take great care to ensure any legitimate complaints are quickly addressed per the APEC rules.

Complaint Form

CBPR and PRP complaint process

Contact

Attention: NCC Group C&I North American Lead 

Mailing Address

NCC Group Security Services, Inc.

11 E Adams St Suite 400
Chicago, IL 60603

Email Address

APEC-CBPR-PRP@nccgroup.com

Global-CBPR-PRP@nccgroup.com

Phone Number 

T: +1 (800) 813 3523

 

 

Federal Trade Commission

Contact Info

600 Pennsylvania Avenue, NW
Washington, DC 20580

(202) 326-2222

FTC Website

https://www.ftc.gov/

Certification service inquires:

By submitting this form, I understand the information provided by me will be used for the purpose of fulfilling my request. For more information check out our Privacy Notice