SOC 2 Privacy Criteria
Version: 2017 TSC with revised points of focus (2022)
The additional AICPA Trust Services Criteria for privacy, tested in a SOC 2 examination when privacy is in scope. Covers how a service organization gives notice, obtains consent, and collects, uses, retains, discloses, corrects, and disposes of personal information.
Where we stand
Controls
87%
Evidence
12%
Policies
25%
8 of 18 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| P1 Notice and communication of objectives related to privacy | |||||
| P1.1 | Privacy notice Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| P2 Choice and consent | |||||
| P2.1 | Communication of choices and consent | Unmapped | Unmapped | Unmapped | Not yet |
| P3 Collection | |||||
| P3.1 | Collection limited to privacy objectives | Unmapped | Unmapped | Unmapped | Not yet |
| P3.2 | Explicit consent before collection | Unmapped | Unmapped | Unmapped | Not yet |
| P4 Use, retention, and disposal | |||||
| P4.1 | Use limited to identified purposes | Unmapped | Unmapped | Unmapped | Not yet |
| P4.2 | Retention of personal information Controls: DATA-04, DATA-14 | Passing | Not current | Not approved | (29 d ago) |
| P4.3 | Disposal of personal information Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| P5 Access | |||||
| P5.1 | Data subject access | Unmapped | Unmapped | Unmapped | Not yet |
| P5.2 | Correction of personal information | Unmapped | Unmapped | Unmapped | Not yet |
| P6 Disclosure and notification | |||||
| P6.1 | Disclosure to third parties with consent | Unmapped | Unmapped | Unmapped | Not yet |
| P6.2 | Record of authorized disclosures | Unmapped | Unmapped | Unmapped | Not yet |
| P6.3 | Record of unauthorized disclosures Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
| P6.4 | Third-party privacy commitments Controls: VEND-02, VEND-03, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| P6.5 | Third-party notification of unauthorized disclosure Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| P6.6 | Breach and incident notification Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| P6.7 | Accounting of personal information and disclosures | Unmapped | Unmapped | Unmapped | Not yet |
| P7 Quality | |||||
| P7.1 | Accuracy and completeness of personal information | Unmapped | Unmapped | Unmapped | Not yet |
| P8 Monitoring and enforcement | |||||
| P8.1 | Privacy inquiries, complaints, and compliance monitoring Controls: CUST-01 | Passing | Not current | Approved | (4 mo ago) |
