Webinar: Comparing the APEC CBPR with the European GDPR
In March 2021, the firm delivered a webinar for members of the Inter-Pacific Bar Association (IPBA) comparing the Cross-Border Privacy Rules (CBPR) developed in the APEC region with the European Union’s General Data Protection Regulation (GDPR).
The objective was to contrast two different approaches to personal data protection and international data transfers, at a time when businesses are increasingly operating on a global scale.
Two data protection frameworks based on different approaches
The GDPR is based on a regulatory framework that applies directly within the European Union and imposes specific obligations on data controllers and processors, together with an enforcement system overseen by national data protection authorities, including the CNIL in France.
The APEC CBPR system, by contrast, is based on a certification mechanism designed to facilitate cross-border data flows between participating countries and businesses, on the basis of common privacy principles.
Comparing the two frameworks made it possible to examine their main differences in areas such as accountability, international data transfers, individual rights, and oversight mechanisms.
Anticipating the challenges of international data flows
For international businesses, the coexistence of multiple personal data protection frameworks is a significant operational issue.
A company may need to comply simultaneously with several regulatory regimes depending on the countries in which it operates, the individuals whose data it processes, and the data flows between its different entities or service providers.
The IPBA webinar was therefore designed to provide practitioners with a comparative framework for identifying the main similarities, differences, and areas of concern between data protection regimes in Europe and the Asia-Pacific region.
* * * * * * * * * * *
Bénédicte DELEPORTE
Avocat
Deleporte Wentz Avocat
March 2021