Mmcp.market

apec-cbpr-cert skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.

A100/100content scan

Is the apec-cbpr-cert skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the apec-cbpr-cert skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/apec-cbpr-cert ~/.claude/skills/apec-cbpr-cert
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

APEC Cross-Border Privacy Rules Certification

Overview

The APEC Cross-Border Privacy Rules (CBPR) system is a government-backed data privacy certification that enables the free flow of personal information across APEC economies while ensuring effective protection of that information. Established in 2011, the CBPR system implements the nine APEC Privacy Framework principles (updated in 2015) through a certifiable set of program requirements that organizations self-assess against and submit to an APEC-recognized Accountability Agent for review and certification.

As of 2024, the CBPR system has evolved into the Global Cross-Border Privacy Rules (Global CBPR) Forum, expanding beyond APEC member economies. The Global CBPR Forum was established in April 2022 by Canada, Japan, the Republic of Korea, the Philippines, Singapore, Chinese Taipei, and the United States, with additional economies joining subsequently. Organizations certified under the APEC CBPR system are transitioning to Global CBPR certification.

Sentinel Compliance Group holds CBPR certification through TRUSTe (TrustArc), the US-recognized Accountability Agent, covering its customer data processing operations across APEC economies.

APEC Privacy Framework Principles

The CBPR system is built on the nine principles of the APEC Privacy Framework (2015 revision):

Principle 1: Preventing Harm

The organization develops policies and procedures to prevent misuse of personal information and to mitigate the risk of harm to individuals. Harm includes physical, financial, reputational, psychological, and other forms of damage arising from the collection, use, or disclosure of personal information.

CBPR Requirements:

  • Conduct privacy risk assessments proportionate to the sensitivity and volume of personal information processed
  • Implement technical and organizational safeguards to prevent unauthorized access, use, or disclosure
  • Establish incident response procedures for data breaches
  • Maintain privacy complaint resolution mechanisms

Principle 2: Notice

The organization provides clear, conspicuous, and accessible notice of its privacy practices.

CBPR Requirements:

  • Publish a privacy policy that describes: categories of personal information collected, purposes of collection and use, categories of recipients, data subject rights, complaint mechanisms, policy effective date
  • Provide notice prior to or at the point of collection
  • Notify individuals of material changes to privacy practices before the changes take effect
  • Make the privacy policy available in an easily understandable format

Principle 3: Collection Limitation

Personal information collection is limited to that which is relevant to the purposes of collection and obtained by lawful and fair means with the knowledge or consent of the individual.

CBPR Requirements:

  • Limit collection to personal information relevant to identified purposes
  • Obtain personal information by lawful means
  • Obtain consent for collection of sensitive personal information (health, financial, children's data)
  • Document the categories of personal information collected and the purposes for each

Principle 4: Uses of Personal Information

Personal information is used only to fulfill the purposes of collection and other compatible purposes.

CBPR Requirements:

  • Use personal information only for purposes identified in the privacy notice or compatible purposes
  • Obtain consent before using personal information for materially different purposes
  • Document the uses of personal information and ensure consistency with disclosed purposes
  • Implement purpose limitation controls in data systems

Principle 5: Choice

Individuals are provided with choice regarding the collection, use, and disclosure of their personal information.

CBPR Requirements:

  • Provide opt-out mechanisms for marketing communications and non-essential processing
  • Provide opt-in mechanisms for collection and use of sensitive personal information
  • Ensure that opt-out mechanisms are clear, conspicuous, and easy to use
  • Honor choice preferences in a timely manner

Principle 6: Integrity of Personal Information

Personal information is accurate, complete, and kept up-to-date to the extent necessary for the purposes of use.

CBPR Requirements:

  • Implement data quality processes at the point of collection
  • Provide mechanisms for individuals to request correction of inaccurate information
  • Process correction requests in a timely manner
  • Maintain audit trails for corrections

Principle 7: Security Safeguards

Personal information is protected by reasonable security safeguards against unauthorized access, use, modification, disclosure, or destruction.

CBPR Requirements:

  • Implement technical safeguards proportionate to the sensitivity of the data (encryption, access controls, logging)
  • Implement organizational safeguards (security policies, employee training, background checks)
  • Implement physical safeguards (access-controlled facilities, secure disposal)
  • Conduct periodic security assessments
  • Maintain incident response and breach notification procedures

Principle 8: Access and Correction

Individuals have the ability to access and correct their personal information.

CBPR Requirements:

  • Provide mechanisms for individuals to access their personal information
  • Verify the identity of individuals making access requests
  • Respond to access requests within a reasonable timeframe
  • Provide mechanisms for individuals to request correction
  • Communicate reasons for denying access or correction requests

Principle 9: Accountability

The organization is accountable for complying with measures that give effect to the above principles.

CBPR Requirements:

  • Designate a privacy contact person or office
  • Implement privacy training for employees who handle personal information
  • Develop and implement privacy policies and procedures
  • Conduct periodic privacy assessments
  • Ensure that processors and third parties provide equivalent protection
  • Cooperate with supervisory authorities and accountability agents

Self-Assessment Process

Step 1: Eligibility Determination

Determine eligibility for CBPR certification:

  • The organization must be located in or subject to the jurisdiction of a CBPR-participating economy
  • The organization must process personal information of individuals in APEC economies
  • The organization must be willing to submit to the jurisdiction of an Accountability Agent
  • The organization must be willing to cooperate with cross-border enforcement actions

Participating Economies (APEC CBPR as of 2024): United States, Mexico, Japan, Canada, Republic of Korea, Singapore, Chinese Taipei, Philippines, Australia

Global CBPR Forum Members (expanding): United States, Canada, Japan, Republic of Korea, Philippines, Singapore, Chinese Taipei, Bermuda, Jersey, United Kingdom (observer)

Step 2: Accountability Agent Selection

Select an APEC-recognized Accountability Agent for the relevant economy:

Step 3: Intake Questionnaire Completion

The Accountability Agent provides an intake questionnaire based on the APEC CBPR Program Requirements. The questionnaire maps to the nine Privacy Framework principles and requires the organization to:

Section A: Organization Information

  • Legal entity name, address, and jurisdiction
  • Contact information for privacy officer
  • Description of business activities involving personal information
  • Economies where personal information is collected, processed, and transferred
  • Number of individuals whose personal information is processed
  • Categories of personal information processed
  • Categories of sensitive personal information processed

Section B: Privacy Practices Self-Assessment

For each of the 50 CBPR program requirements, the organization must:

  1. Describe its current practice
  2. Identify the policy, procedure, or technical control that implements the requirement
  3. Provide evidence of implementation
  4. Identify any gaps and planned remediation

Key Self-Assessment Questions (representative subset):

Step 4: Accountability Agent Review

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway
  • Aarckit-at-dsgvo[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Austrian enforcement practice

All agent skills → · MCP servers