APEC Privacy Framework
The Data Privacy Sub-Group developed the APEC Privacy Framework. In developing the Framework the Sub-Group took as its starting point the 1980 OECD Guidelines on the Protection of Privacy and Trans-Border Flows of Personal Data, which also underpins the Privacy Act 1988. The Framework contains nine high level Privacy Principles, as follows:
- Preventing Harm
- Notice
- Collection Limitations
- Uses of Personal Information
- Choice
- Integrity of Personal Information
- Security Safeguards
- Access and Correction
- Accountability
The Principles represent a minimum standard and it is expected that standards will generally rise as new economies develop privacy laws. The Framework, containing the Privacy Principles, explanatory material, and guidance on domestic and international implementation, was endorsed by APEC Ministers in Santiago, Chile, in November 2004.
Ways to implement the Framework were also considered by the Sub-Group. Prescribing the way the Privacy Principles should be implemented was not an option given the diversity of economies in APEC. Instead, it was recognised that the aim should be to encourage consistent implementation of the Privacy Principles across the APEC region.
To this end, the Framework contains guidance on a range of factors that should be considered in the domestic implementation of the Principles within member economies, which was the initial focus of the Sub-Group’s work after 2004. The Framework also contains guidance on international implementation between member economies and this is the subject of the Sub-Group’s current work. Three key issues were identified for international implementation: information sharing between economies on privacy issues; developing arrangements for cross-border cooperation in investigation and enforcement; and the cooperative development of a system for the use by business of Cross-Border Privacy Rules (CBPRs). While work has been ongoing on all three of these issues, a system for CBPRs is the current priority.
- APEC Privacy Framework - PDF 188KB
- Guidelines on the Protection of Privacy and Trans-Border Flows of Personal Data
Top