Japan Joins the APEC Cross-Border Privacy Rules System
Time 2 Minute Read

On April 30, 2014, the Asia-Pacific Economic Cooperation (“APEC”) released the Findings Report of the Joint Oversight Panel of the APEC Cross-Border Privacy Rules (“CPBR”) system, confirming that Japan has met the conditions for participation in the CBPRs. Accordingly, Japan has now joined the U.S. and Mexico as a participant in the APEC CBPRs. Canada recently expressed its intent to join the system soon, and other APEC economies are in the process determining how and when they may join.

Japan submitted its “Notice of Intent to Participate in the CBPR System” to the Joint Oversight Panel in June of 2013. As required by the applicable CBPR governance rules, Japan included in its Notice of Intent a list of 15 Japanese “Privacy Enforcement Authorities” that are members of the APEC Cross-border Privacy Enforcement Arrangement (“CPEA”), and indicated that it intends to make use of at least one APEC-recognized “Accountability Agent.” Accountability Agents are third party organizations that review and certify businesses for participation in the CBPRs. Finally, Japan also provided a description of its domestic laws and enforcement mechanisms that would apply to a Japanese Accountability Agent’s CBPR-related activities, as well as the required “APEC CBPR System Program Requirements Enforcement Map,” which describes how the CBPRs are enforceable under Japanese law.

The APEC CBPR system is a regional, multilateral cross-border data transfer mechanism and enforceable privacy code of conduct developed for businesses by the 21 APEC member economies. The CBPRs implement the nine high-level APEC Privacy Principles set forth in the APEC Privacy Framework. Although all APEC economies have endorsed the system, in order to participate individual APEC economies must officially express their intent to join and satisfy certain requirements.

You May Also Be Interested In

Time 3 Minute Read

On February 17, 2026, the Federal Aviation Administration (FAA) issued a final rule adopting a new airworthiness directive (AD) for certain Bombardier Inc. airplanes. This new AD requires locking features to be installed on applicable network interfaces to prevent unauthorized network access. FAA seeks 45-day public comment on any written data, views, or arguments associated with this final rule, ending on April 3, 2026.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 3 Minute Read

On September 2, 2025, two class actions were filed in federal district court alleging that defendants digital advertising platforms Xandr, Inc. and Index Exchange, Inc. violated the Electronic Communications Privacy Act by unlawfully intercepting wire communications for the purpose of violating the Department of Justice’s Bulk Data Transfer Rule.

Time 2 Minute Read

On September 3, 2025, the EU’s General Court issued its judgment in the Latombe v. Commission case. The applicant, a member of the French National Assembly, sought the annulment of the adequacy decision adopted by the European Commission with respect to the EU-U.S. Data Privacy Framework.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page