Global CBPR Forum launches certification for cross-border data transfers
Around 100 companies are expected to benefit.
The Global CBPR Forum will launch a new Global Cross-Border Privacy Rules (CBPR) Certification on 2 June 2025, allowing organisations to transfer data more easily across participating economies.
The certification is designed to give businesses and the public greater assurance in international data flows, demonstrating compliance with internationally recognised data protection standards. Around 100 companies, including IBM, Mastercard and OCBC, and their 2,000 subsidiaries are expected to benefit.
The new framework builds on the Asia-Pacific Economic Cooperation (APEC) CBPR system and initially covers nine economies with a combined market size of approximately US$40t. It is grounded in the Global CBPR Privacy Principles, which align with the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data.
Organisations only need certification in one country to operate across all member economies. Certification must be obtained through third-party Accountability Agents recognised by the forum.
In Singapore, the Infocomm Media Development Authority (IMDA) will serve as the official agent and main point of contact for organisations seeking certification.