The Global CBPR Forum is updating the Global CBPR System Program Requirements (PRs) to better align data protection and privacy requirements among Global CBPR Forum Members and Associates and to enhance data privacy and protection for individuals.

With the updates, the Global CBPR certification will expand from 50 PRs to 57 PRs, and 3 PRs will be updated as described below. The new PRs are available in full on the Global CBPR Forum website.

New Program Requirements
For the first time, the Global CBPR System PRs enumerate specific requirements companies must take to implement the Preventing Harm principle, a key principle of the Global CBPR Privacy Framework. These new requirements:
– Increase accountability for processing sensitive (PR 1) and children’s data (PRs 2&3)
– Mandate procedures for risk assessment and mitigation (PR 4)
– Mandate processes for breach notification to affected individuals (PR 5)

Choice has been strengthened to:
– Require companies to provide choice to individuals about whether to receive direct marketing
(PR 22)
– Require individuals’ choice to be recorded (PR 26)
– Mandate that companies provide mechanisms for individuals to withdraw consent for the processing of their personal data when the data is no longer needed by the company for the purposes for which consent was provided (PR 27)

Accountability has been enhanced to:
– Require companies to maintain records of processing activities (PR 46)
– Emphasize that individuals responsible for compliance with a company’s data protection program must have qualifications appropriate to the nature of the data processing activities (PR 47)

Timeline to Implement the new Program Requirements
From April 1, 2027, companies certifying for the first time and those recertifying must certify to the updated PRs upon their recertification date. Companies certified under the current PRs will have until then to review their processes and implement the updated PRs before seeking recertification.

Relationship between the Global CBPR and APEC CBPR Systems
Until April 1, 2027, the Global CBPR System and APEC CBPR System PRs will continue to be the same, and companies can continue to participate in both Systems.