惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
腾讯CDC
D
Docker
The Cloudflare Blog
量子位
爱范儿
爱范儿
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
CIPL Report Discusses Significant Alignment between GDPR ...
2026-04-28 · via Privacy & Cybersecurity Law Blog

The Centre for Information Policy Leadership (“CIPL”) at Hunton has published a report examining the extent to which the European Union’s General Data Protection Regulation (“GDPR”) aligns with the newly updated Program Requirements of the Global Cross-Border Privacy Rules (“Global CBPR”) System.

The Global CBPR System is a certified compliance program that facilitates personal data flows from and between participating jurisdictions and organizations. It is based on formal third-party assessments affirming that certified organizations operating as data controllers adhere to a common set of approved standards, called “Program Requirements.”  The Global Privacy Recognition for Processors (“Global PRP”) System provides analogous certifications for private sector organizations operating as data processors.

The Global CBPR Forum, which administers the Global CBPR and Global PRP Systems, formally adopted a number of revisions to the Global CBPR Program Requirements in March 2026. These revisions addressed topics commonly found in privacy laws but not previously covered by the Global CBPR System, such as sensitive data, children’s data, risk assessments and breach notification.

According to CIPL’s report, there is significant alignment between the GDPR and the Systems’ Program Requirements with more than 70% of Global CBPR Program Requirements, as revised, aligning with provisions of the GDPR, and more than 75% of the Global PRP doing the same. CIPL concludes that inasmuch as the remainder of the Program Requirements appear to find implicit support in the GDPR, EU supervisory authorities would likely be able to enforce the Program Requirements through the GDPR.

GDPR Art. 42 encourages the “establishment of data protection certification mechanisms,” and GDPR Art. 46(2)(f) permits the use of an approved certification mechanism as an “appropriate safeguard” for international transfers. In light of those provisions, CIPL’s report encourages the EU to explore the benefits of participation in the Global CBPR/Global PRP Systems.

CIPL’s full report is available here.

For additional information regarding the Global CBPR and Global PRP Systems, CIPL has published an explanatory Playbook available here.