apac-transfers skill
Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
Is the apac-transfers skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the apac-transfers skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/apac-transfers ~/.claude/skills/apac-transfers
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Managing APAC Cross-Border Transfers
Overview
The Asia-Pacific region encompasses diverse data protection regimes with varying cross-border transfer mechanisms. Unlike the GDPR's unified framework, APAC transfers require navigating multiple overlapping systems: the APEC Cross-Border Privacy Rules (CBPR), ASEAN Model Contractual Clauses (MCCs), and country-specific mechanisms under Japan's APPI, South Korea's PIPA, Thailand's PDPA, and Singapore's PDPA. This skill provides a jurisdiction-by-jurisdiction guide to managing cross-border data flows across the APAC region.
APEC Cross-Border Privacy Rules (CBPR) System
Framework
The APEC CBPR system is a voluntary, accountability-based mechanism enabling participating organisations to demonstrate compliance with internationally recognised privacy protections for cross-border data flows within the APEC region.
Participating economies (as of March 2026): Australia, Canada, Japan, South Korea, Mexico, Philippines, Singapore, Chinese Taipei, United States.
Key features:
- Organisations self-certify compliance with the APEC Privacy Framework principles
- Certification is conducted by an APEC-recognised Accountability Agent (e.g., TRUSTe/TrustArc for the US, JIPDEC for Japan)
- CBPR certification covers only the data flows of the specific certified organisation, not the entire economy
- The Global CBPR Forum (established April 2022) aims to expand the system beyond APEC membership
CBPR Principles
CBPR and EU Interoperability
- CBPR certification is not recognised as an adequate safeguard under GDPR Chapter V.
- For EU-to-APAC transfers, EU SCCs remain required even if the APAC recipient is CBPR-certified.
- However, CBPR certification can serve as evidence of the recipient's data protection maturity in a TIA assessment.
ASEAN Model Contractual Clauses (MCCs)
Framework
The ASEAN Model Contractual Clauses were adopted by the ASEAN Telecommunications and IT Ministers in 2021 to facilitate cross-border data flows within the ASEAN Economic Community while maintaining data protection standards.
ASEAN Member States: Brunei, Cambodia, Indonesia, Laos, Malaysia, Myanmar, Philippines, Singapore, Thailand, Vietnam.
Key features:
- Model clauses for controller-to-controller and controller-to-processor transfers
- Non-binding guidance — Member States may adopt or adapt the MCCs
- Designed to be compatible with other international transfer mechanisms (EU SCCs, APEC CBPR)
- Implementation varies by Member State; Singapore and Philippines have been early adopters
MCC Structure
Japan — APPI Cross-Border Transfer Provisions
Act on the Protection of Personal Information (APPI) — Amended 2022
Art. 28 (Cross-Border Transfer):
- Transfer of personal data to a third party in a foreign country requires one of:
- Consent: The individual's consent, after being provided with information about the foreign country's data protection regime, the receiving party's privacy protections, and other relevant information per PPC Rules Art. 17
- Adequate country: The foreign country has been recognised by the PPC as providing equivalent data protection standards (currently: EU/EEA countries and the UK)
- Equivalent measures: The recipient has established an equivalent system of measures for handling personal information in conformity with APPI standards, including internal rules and an independent oversight mechanism
PPC Supplementary Rules for EU Adequacy:
- Applied reciprocally under the EU-Japan adequacy mutual recognition
- Japanese operators receiving EU-origin data must treat all such data as "requiring special care"
- Additional retention limitations and onward transfer restrictions apply
Athena Global Logistics implementation (Japan operations):
- Transfers from Japan to Germany: rely on PPC adequate country recognition of the EU
- Transfers from Japan to Hong Kong: obtain individual consent per Art. 28 after providing foreign country information
- Transfers from EU to Japan: rely on EU adequacy decision (Decision 2019/419) with supplementary rules
South Korea — PIPA Cross-Border Provisions
Personal Information Protection Act (PIPA) — Amended 2023
Art. 28-2 (Cross-Border Transfer):
- Transfer permitted when:
- Consent: The data subject's consent after being informed of the recipient, purpose, categories of data, retention period, and the right to refuse
- Adequacy recognition: Transfer to a country recognised by the Personal Information Protection Commission (PIPC) as having an equivalent level of protection
- Contractual safeguards: The recipient has provided contractual safeguards equivalent to PIPA standards
- PIPC-approved certification: The recipient holds a certification recognised by the PIPC
EU-Korea interoperability:
- The EU has adopted an adequacy decision for South Korea (Decision 2022/254)
- South Korea has recognised the EU as providing equivalent protection
- This creates a bilateral mutual recognition framework similar to the EU-Japan arrangement
Athena Global Logistics implementation (Korea operations):
- Transfers from Korea to Germany: rely on PIPC adequacy recognition of the EU
- Transfers from EU to Korea: rely on EU adequacy decision for Korea
- Transfers from Korea to non-adequate countries: obtain consent per Art. 28-2 with full information disclosure
Thailand — PDPA Cross-Border Provisions
Personal Data Protection Act B.E. 2562 (2019) — Effective 1 June 2022
Section 28 (Cross-Border Transfer):
- Transfer to a foreign country permitted when:
- The destination country has adequate data protection standards as prescribed by the PDPC (Personal Data Protection Committee)
- Compliance with Binding Corporate Rules approved by the PDPC Office
- The transfer is subject to a data protection policy of the same group of business, inspected and certified by the PDPC Office
- The transfer is subject to contractual safeguards between the transferor and transferee
- The transfer is necessary for contract performance, vital interests, important public interest, legal claims, or with the data subject's explicit consent (derogation conditions similar to GDPR Art. 49)
PDPC Notification on Adequacy (pending):
- As of March 2026, the PDPC has not yet published the list of adequate countries.
- In the interim, organisations rely on contractual safeguards or consent for cross-border transfers.
Athena Global Logistics implementation (Thailand operations):
- Transfers from Thailand to Germany: contractual safeguards (data processing agreement with PDPA-aligned clauses)
- Transfers from EU to Thailand: EU SCCs Module 2 (no EU adequacy decision for Thailand)
- Domestic processing: Pinnacle Data Services Co Ltd (Bangkok) operates under Thai PDPA with contractual safeguards from TransPacific Freight Solutions
Singapore — PDPA Cross-Border Provisions
Personal Data Protection Act 2012 (PDPA) — Amended 2021
Section 26 (Transfer Limitation Obligation):
- An organisation must not transfer personal data outside Singapore unless it takes appropriate steps to ensure the recipient is bound by legally enforceable obligations to provide a standard of protection at least comparable to the PDPA.
Mechanisms for compliance:
- Contractual arrangements: Contract with the recipient obligating them to meet PDPA-equivalent standards
- Binding corporate rules: Intra-group policies providing equivalent protection
- PDPC-approved frameworks: Compliance with APEC CBPR or other PDPC-recognised certification
- Consent: The individual consents to the transfer after being informed of the non-comparable standard
- Prescribed exceptions: Necessary for contract performance, public interest, vital interests, or legal proceedings
PDPC enforcement:
- The PDPC actively enforces the transfer limitation obligation.
- Fines up to SGD 1 million per breach (increased under 2021 amendments to up to 10% of annual turnover for organisations with annual turnover exceeding SGD 10 million).
Athena Global Logistics implementation (Singapore operations):
- CloudVault Asia Pte Ltd (sub-processor in Singapore): PDPA-compliant; transfers to EU governed by PDPA contractual arrangements
- Transfers from Singapore to Germany: contractual safeguards in the data processing agreement
- Transfers from EU to Singapore: EU SCCs Module 3 (P2P, as CloudVault is a sub-processor of TransPacific)
Cross-Jurisdictional Transfer Matrix
Practical Implementation Considerations
- Multi-mechanism compliance: A single data flow from the EU through Japan to Singapore may require EU adequacy reliance (EU→JP), Japan Art. 28 adequate country (JP→SG equivalent measures), and Singapore PDPA contractual safeguards — three mechanisms for one flow.
- Contractual harmonisation: Use a single data processing agreement with jurisdiction-specific addenda to cover GDPR, APPI, PIPA, PDPA (Thailand), and PDPA (Singapore) requirements simultaneously.
- Consent fatigue: Where multiple jurisdictions require consent for cross-border transfer, coordinate consent collection to avoid multiple consent requests for the same transfer chain.
- Monitoring burden: Each APAC jurisdiction's transfer rules evolve independently; maintain a monitoring programme covering all applicable laws.
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway
- Aarckit-at-dsgvo[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Austrian enforcement practice