Global Cross-Border Privacy Rules (CBPR) Framework
Overview
Dakota Performance Solutions recognizes and respects the importance of protecting personal information as it flows across international borders. As a business process outsourcing and federal services organization that may handle data originating from or transmitted to jurisdictions outside the United States, DPS is committed to upholding the principles of the Global Cross-Border Privacy Rules (CBPR) Framework, administered through the Global CBPR Forum.
The Global CBPR Framework is an internationally recognized data privacy certification system that establishes baseline standards for the protection of personal information transferred between participating economies. It was developed from the Asia-Pacific Economic Cooperation (APEC) CBPR System and expanded into a global framework open to all economies committed to interoperable privacy protections.
Scope of Application
This section applies to all personal information that Dakota Performance Solutions collects, processes, stores, transfers, or otherwise handles on behalf of clients, partners, or individuals located outside the United States, including but not limited to:
Core CBPR Principles We Uphold
Dakota Performance Solutions aligns its data handling practices with the nine foundational principles of the Global CBPR Framework:
1. Preventing Harm DPS takes reasonable steps to identify foreseeable harms that could result from the collection, use, or transfer of personal information and implements safeguards proportionate to the likelihood and severity of such harm.
2. Notice Individuals whose personal data is collected are provided with clear, accessible, and timely notice regarding the purposes of collection, the types of information collected, and how that information will be used, shared, and protected — including when data is transferred internationally.
3. Collection Limitation DPS collects only the personal information that is necessary, relevant, and proportionate to the identified purpose. We do not collect personal data through unlawful or unfair means.
4. Uses of Personal Information Personal information is used only for the purposes disclosed at the time of collection or for purposes that are compatible with and not materially different from those disclosed, unless additional consent is obtained or legal authority permits otherwise.
5. Choice Where practicable and required by applicable law or the CBPR Framework, individuals are offered meaningful choices regarding the collection, use, and disclosure of their personal information — including opt-out mechanisms for non-essential uses and opt-in consent for sensitive data.
6. Integrity of Personal Information DPS maintains reasonable practices and procedures to ensure that personal information is accurate, complete, and current for the purposes for which it is to be used, and takes reasonable steps to correct inaccurate or outdated information upon request.
7. Security Safeguards Dakota Performance Solutions implements physical, technical, and administrative security safeguards appropriate to the sensitivity of the personal information held and the risks of unauthorized access, collection, use, disclosure, copying, modification, disposal, or destruction.
8. Access and Correction Individuals have the right to request access to their personal information held by DPS and to request correction of inaccurate or incomplete data, subject to applicable legal limitations. Requests may be submitted to privacy@dakotaperformance.com.
9. Accountability Dakota Performance Solutions takes responsibility for all personal information under its control, including data transferred to third-party agents or service providers. We require all recipients of personal data acting on our behalf to provide equivalent levels of protection consistent with these principles.
International Data Transfers
When personal information is transferred across borders, Dakota Performance Solutions employs one or more of the following safeguards to ensure continued protection:
DPS does not transfer personal information to countries or recipients that cannot provide an adequate level of protection without first implementing appropriate contractual, technical, or organizational safeguards.
Sensitive Personal Information
Dakota Performance Solutions treats the following categories of information as sensitive and applies heightened protection and, where required, explicit consent prior to collection or cross-border transfer:
Your Rights Under This Framework
Individuals whose personal data is subject to the Global CBPR Framework may have the following rights, subject to applicable law and any overriding federal contract requirements:
To exercise any of these rights, please contact us at privacy@dakotaperformance.com. We will respond within 30 days of receiving a verifiable request.
Accountability Agent & Dispute Resolution
Dakota Performance Solutions is committed to resolving privacy-related complaints in a timely and transparent manner. If you believe your personal information has been handled in a manner inconsistent with this section or the Global CBPR Framework principles, you may:
We will acknowledge complaints within 5 business days and provide a substantive response within 30 days. Where a complaint cannot be resolved internally, DPS will cooperate with applicable regulatory authorities or accountability agents designated under the Global CBPR Framework.
Relationship to Other Privacy Laws
This section supplements and does not replace DPS's obligations under other applicable privacy laws, including but not limited to:
In the event of a conflict between this section and a stricter applicable legal requirement, the stricter requirement shall control.
Updates to This Section
Dakota Performance Solutions reviews and updates this Cross-Border Privacy disclosure periodically to reflect changes in applicable law, business operations, and evolving global privacy standards. Material changes will be posted to this page with an updated effective date.
For questions specific to cross-border data transfers or to submit a data subject request, contact: privacy@dakotaperformance.com
Reminder — fill in before publishing:
12. Global Cross-Border Privacy Rules (CBPR) Framework & International Data Privacy
Overview
Dakota Performance Solutions recognizes and respects the importance of protecting personal information as it flows across international borders. As a business process outsourcing and federal services organization that may handle data originating from or transmitted to jurisdictions outside the United States, DPS is committed to upholding the principles of the Global Cross-Border Privacy Rules (CBPR) Framework, administered through the Global CBPR Forum, as well as all other applicable international privacy regulations — including the General Data Protection Regulation (GDPR).
The Global CBPR Framework is an internationally recognized data privacy certification system that establishes baseline standards for the protection of personal information transferred between participating economies. It was developed from the Asia-Pacific Economic Cooperation (APEC) CBPR System and expanded into a global framework open to all economies committed to interoperable privacy protections.
Scope of Application
This section applies to all personal information that Dakota Performance Solutions collects, processes, stores, transfers, or otherwise handles on behalf of clients, partners, or individuals located outside the United States, including but not limited to:
Core CBPR Principles We Uphold
Dakota Performance Solutions aligns its data handling practices with the nine foundational principles of the Global CBPR Framework:
1. Preventing Harm DPS takes reasonable steps to identify foreseeable harms that could result from the collection, use, or transfer of personal information and implements safeguards proportionate to the likelihood and severity of such harm.
2. Notice Individuals whose personal data is collected are provided with clear, accessible, and timely notice regarding the purposes of collection, the types of information collected, and how that information will be used, shared, and protected — including when data is transferred internationally.
3. Collection Limitation DPS collects only the personal information that is necessary, relevant, and proportionate to the identified purpose. We do not collect personal data through unlawful or unfair means.
4. Uses of Personal Information Personal information is used only for the purposes disclosed at the time of collection or for purposes that are compatible with and not materially different from those disclosed, unless additional consent is obtained or legal authority permits otherwise.
5. Choice Where practicable and required by applicable law or the CBPR Framework, individuals are offered meaningful choices regarding the collection, use, and disclosure of their personal information — including opt-out mechanisms for non-essential uses and opt-in consent for sensitive data.
6. Integrity of Personal Information DPS maintains reasonable practices and procedures to ensure that personal information is accurate, complete, and current for the purposes for which it is to be used, and takes reasonable steps to correct inaccurate or outdated information upon request.
7. Security Safeguards Dakota Performance Solutions implements physical, technical, and administrative security safeguards appropriate to the sensitivity of the personal information held and the risks of unauthorized access, collection, use, disclosure, copying, modification, disposal, or destruction.
8. Access and Correction Individuals have the right to request access to their personal information held by DPS and to request correction of inaccurate or incomplete data, subject to applicable legal limitations. Requests may be submitted to privacy@dakotaperformance.com.
9. Accountability Dakota Performance Solutions takes responsibility for all personal information under its control, including data transferred to third-party agents or service providers. We require all recipients of personal data acting on our behalf to provide equivalent levels of protection consistent with these principles.
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is the European Union's comprehensive data protection law, effective May 25, 2018. It governs the collection, processing, storage, and transfer of personal data belonging to individuals located in the European Union and European Economic Area (EEA), regardless of where the processing organization is located. The United Kingdom maintains a parallel framework known as the UK GDPR following its departure from the EU.
To the extent that Dakota Performance Solutions processes personal data of individuals located in the EU, EEA, or United Kingdom — whether directly or on behalf of a client under a data processing agreement — DPS is committed to meeting its obligations under the GDPR and UK GDPR.
Lawful Basis for Processing
Under the GDPR, all processing of personal data must be based on a valid lawful basis. Dakota Performance Solutions relies on one or more of the following lawful bases depending on the nature of the processing activity:
Data Subject Rights Under the GDPR
Individuals located in the EU, EEA, or United Kingdom whose personal data is processed by Dakota Performance Solutions have the following rights under the GDPR, subject to applicable exemptions and limitations:
To exercise any of the above rights, please submit a written request to privacy@dakotaperformance.com. We will respond within 30 days of receipt of a verifiable request. Where requests are complex or numerous, we may extend this period by an additional two months, with notice provided to you within the initial 30-day window.
Data Protection Officer (DPO)
Where required by the GDPR, Dakota Performance Solutions designates a Data Protection Officer responsible for overseeing compliance with data protection law and serving as the point of contact for data subjects and supervisory authorities. DPO inquiries may be directed to: privacy@dakotaperformance.com.
International Transfers of EU/EEA Personal Data
Transfers of personal data from the EU, EEA, or United Kingdom to the United States or other third countries are conducted only where an adequate level of protection is ensured through one or more of the following mechanisms:
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Dakota Performance Solutions will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to individuals, affected data subjects will be notified without undue delay in accordance with Article 34.
Retention of EU Personal Data
Personal data of EU, EEA, and UK individuals is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law or contract. Upon expiration of the applicable retention period, data is securely deleted, anonymized, or returned to the data controller in accordance with the terms of any applicable data processing agreement.
Supervisory Authority
If you are located in the EU or EEA and believe that DPS has not handled your personal data in compliance with the GDPR, you have the right to lodge a complaint with the supervisory authority in your EU member state of residence or place of work. A list of EU supervisory authorities is available at: edpb.europa.eu/about-edpb/about-edpb/members_en. If you are located in the United Kingdom, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.
International Data Transfers — General
When personal information is transferred across borders, Dakota Performance Solutions employs one or more of the following safeguards to ensure continued protection:
DPS does not transfer personal information to countries or recipients that cannot provide an adequate level of protection without first implementing appropriate contractual, technical, or organizational safeguards.
Sensitive Personal Information
Dakota Performance Solutions treats the following categories of information as sensitive and applies heightened protection and, where required, explicit consent prior to collection or cross-border transfer:
Your Rights Under This Framework
Individuals whose personal data is subject to the Global CBPR Framework, the GDPR, or other applicable international privacy law may have the following rights, subject to applicable legal requirements and any overriding federal contract obligations:
To exercise any of these rights, please contact us at privacy@dakotaperformance.com. We will respond within 30 days of receiving a verifiable request.
Accountability Agent & Dispute Resolution
Dakota Performance Solutions is committed to resolving privacy-related complaints in a timely and transparent manner. If you believe your personal information has been handled in a manner inconsistent with this section, the Global CBPR Framework, or the GDPR, you may:
We will acknowledge complaints within 5 business days and provide a substantive response within 30 days. Where a complaint cannot be resolved internally, DPS will cooperate with applicable regulatory authorities or accountability agents designated under the Global CBPR Framework or GDPR.
Relationship to Other Privacy Laws
This section supplements and does not replace DPS's obligations under other applicable privacy laws, including but not limited to:
In the event of a conflict between this section and a stricter applicable legal requirement, the stricter requirement shall control.
Updates to This Section
Dakota Performance Solutions reviews and updates this Cross-Border Privacy and GDPR disclosure periodically to reflect changes in applicable law, business operations, and evolving global privacy standards. Material changes will be posted to this page with an updated effective date.
For questions specific to cross-border data transfers, GDPR rights requests, or to submit a data subject access request, contact: privacy@dakotaperformance.com
General Data Protection Regulation (GDPR)