Notice

Recognition of the APEC CBPR System as a Certification Mechanism for Overseas Data Transfers (2021-03-02)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Issued 2021-03-02

Current version last checked: 2026-07-30

Summary

This is a notice from the Office of the Privacy Commissioner for Bermuda (PrivCom) recognising the APEC Cross Border Privacy Rules (CBPR) System as a certification mechanism under section 15(4) of the Personal Information Protection Act 2016 (PIPA). It allows organisations transferring personal information to an overseas third party to rely on that third party's CBPR certification as evidence of a comparable level of data protection, satisfying PIPA's overseas transfer requirements.

  • Recognition: PrivCom formally recognises the APEC CBPR System as a certification mechanism organisations may rely on under PIPA section 15(4) when transferring personal information to overseas third parties.
  • Verification expected: Organisations relying on a third party's CBPR certification should verify the claim via the public Compliance Directory at cbprs.org.
  • Contractual embedding: Organisations should ensure CBPR certification is made a material part of their contractual agreement with the overseas third party, potentially using template clauses (such as those developed by Singapore's PDPC).
  • Continuing PIPA duties: Even where reliance on CBPR certification is appropriate, the transferring Bermudian organisation remains responsible to the individual, must provide appropriate notice of the overseas transfer and reliance on the certification mechanism, must ensure PIPA section 6 Conditions are met, and must fulfil all other PIPA obligations.
  • Risk-based assessment: Organisations must assess their specific circumstances to determine whether CBPR certification is a reasonable and appropriate basis for transfer, noting it may not be suitable for sensitive personal information or high-risk transfers.

The notice is informational guidance clarifying an available compliance option rather than imposing new standalone requirements; existing PIPA obligations on overseas transfers, notice, and accountability continue to apply regardless of which certification mechanism is used.

Key obligations

  • Organisations relying on an overseas third party's CBPR certification should verify the certification claim through the public CBPR Compliance Directory (cbprs.org).
  • Organisations should ensure CBPR certification is a material, contractually documented part of their agreement with the overseas third party.
  • Organisations relying on CBPR certification must still provide individuals with appropriate notice of the overseas transfer and of reliance on the certification mechanism.
  • Organisations must ensure PIPA section 6 Conditions are met and fulfil all other PIPA responsibilities even when relying on CBPR certification.
  • Organisations must assess their specific circumstances (e.g. sensitivity of data, risk of harm) to determine whether reliance on CBPR certification is reasonable and appropriate, and may need to add extra contractual controls where warranted.

Applies to

organisations subject to PIPA (Bermuda) that transfer personal information to overseas third parties

Topics

Version history

2026-07-30

source file (current)