FintastIQTrust Center
LoginBook a Consultation
Framework

SOC 2 Privacy Criteria

Version: 2017 TSC with revised points of focus (2022)

The additional AICPA Trust Services Criteria for privacy, tested in a SOC 2 examination when privacy is in scope. Covers how a service organization gives notice, obtains consent, and collects, uses, retains, discloses, corrects, and disposes of personal information.

Official source

Summary

Where we stand

Controls
87%
Evidence
12%
Policies
25%

8 of 18 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
P1 Notice and communication of objectives related to privacy
P1.1Privacy notice
Controls: LEGAL-01
PassingNot currentApprovedNot yet
P2 Choice and consent
P2.1Communication of choices and consentUnmappedUnmappedUnmappedNot yet
P3 Collection
P3.1Collection limited to privacy objectivesUnmappedUnmappedUnmappedNot yet
P3.2Explicit consent before collectionUnmappedUnmappedUnmappedNot yet
P4 Use, retention, and disposal
P4.1Use limited to identified purposesUnmappedUnmappedUnmappedNot yet
P4.2Retention of personal information
Controls: DATA-04, DATA-14
PassingNot currentNot approved(29 d ago)
P4.3Disposal of personal information
Controls: DATA-05
PassingNot currentNot approvedNot yet
P5 Access
P5.1Data subject accessUnmappedUnmappedUnmappedNot yet
P5.2Correction of personal informationUnmappedUnmappedUnmappedNot yet
P6 Disclosure and notification
P6.1Disclosure to third parties with consentUnmappedUnmappedUnmappedNot yet
P6.2Record of authorized disclosuresUnmappedUnmappedUnmappedNot yet
P6.3Record of unauthorized disclosures
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)
P6.4Third-party privacy commitments
Controls: VEND-02, VEND-03, VEND-04
Not passingNot currentNot approved(8 h ago)
P6.5Third-party notification of unauthorized disclosure
Controls: VEND-02
PassingNot currentNot approvedNot yet
P6.6Breach and incident notification
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
P6.7Accounting of personal information and disclosuresUnmappedUnmappedUnmappedNot yet
P7 Quality
P7.1Accuracy and completeness of personal informationUnmappedUnmappedUnmappedNot yet
P8 Monitoring and enforcement
P8.1Privacy inquiries, complaints, and compliance monitoring
Controls: CUST-01
PassingNot currentApproved(4 mo ago)