Archive
Cross-border privacy rules 2
As a jurisdiction implementing our own privacy law, and as a member economy of the APEC, it is expected that we recognize, but more importantly, operationalize these principles in our data privacy practices
Certification by stakeholders composed of personal information controllers and processors is a vital component of any roadmap towards compliance to data privacy regulations all over the world. Adopting global frameworks for international data transfers, like the Cross-Border Privacy Rules (CBPR) and the General Data Protection Regulation of the European Union, gives a jurisdiction the thumbs-up and proof that it promotes responsible data stewardship in general, that is recognized by other jurisdictions.
As such, the Asia-Pacific Economic Cooperation (APEC) CBPR certification serves as a seal of privacy compliance and accountability, creating a competitive advantage in both local and global markets. It also fosters trust among consumers, assured that their personal data is securely transferred. This, by requiring business entities to observe transparency and streamline the customer complaint process.
This voluntary system allows companies operating within its member economies some degree of confidence when transmitting data to another extraterritorial entity because that processing has met an allowable standard recognized by other enrolled jurisdictions.
This way our own people and the people of Japan, for example, could sleep soundly at night even if their data is being shared across borders to other companies within the APEC economies, knowing fully they are secured with an acceptable level of protection recognized by their own authority as adequate.
The APEC CBPR system is a regional, multilateral cross-border data transfer mechanism and enforceable privacy code of conduct developed for businesses by APEC member economies. The CBPR system also allows for the creation of “accountability agents” that certify businesses as compliant with APEC CBPR standards.
Once a country becomes enrolled to the CBPR system, companies may opt to get their data processing systems certified with a local accountability agent. CBPR certification will allow them to freely transfer data across CBPR-participating countries. This means they don’t have to get certified in those other countries, especially those that require certification before data can cross their borders.
The Framework is comprised of nine, high-level information privacy principles that promote the development of appropriate privacy protections and ensure the free flow of information in the Asia Pacific region.
They are: preventing of harm; notice; collection limitation; use of personal information; choice; integrity of personal information; security and safeguards; access and correction; and accountability.
As a jurisdiction implementing our own privacy law, and as a member economy of the APEC, it is expected that we recognize, but more importantly, operationalize these principles in our data privacy practices. For companies wanting to be certified, they must be able to sufficiently address these data privacy principles to accountability agents approved by the CBPR system.
The Philippines’ membership will give domestic companies the opportunity to compete globally in terms of data privacy and protection and at the same time ensure consumers of a conscious level of data protection recognized internationally. It will open doors for Filipino companies to freely engage in trade across the APEC region without barriers brought about by data privacy issues as the CBPR provides for a baseline privacy framework which can be used in all APEC member economies.
Next week, let’s discuss how Philippine companies can pass certification in the CBPR.
If you have questions, feel free to contact the National Privacy Commission via info@privacy.gov.ph.