International Standards US / Global

SOC 2 Privacy Criteria: What the Privacy Category Requires

The AICPA Trust Services privacy criteria explained: notice, choice and consent, collection, use and retention, access, disclosure, quality, and monitoring, and what examiners test.

Regulation

AICPA Trust Services Criteria (2017, with 2022 revised points of focus), privacy category; examinations performed under AICPA attestation standards (SSAE)

Max Penalty

None statutory; qualified opinions and exceptions have commercial consequences, and misdescribing your practices to an examiner compounds into fraud exposure

Enforcing Authority

Licensed CPA firms conduct the examinations; the AICPA sets criteria and peer-review discipline; no regulator enforces SOC 2 itself

Official Source

www.aicpa-cima.com

Executive Summary

  • The privacy category is one of five Trust Services Criteria (with security, availability, processing integrity, confidentiality); security is mandatory in every SOC 2, the others are elected, and privacy is elected least often.
  • Its criteria cover the personal-information lifecycle: notice; choice and consent; collection; use, retention, and disposal; access; disclosure and notification; quality; and monitoring and enforcement.
  • The distinctive mechanism: your own privacy commitments (chiefly the privacy notice) become the audit criteria; the examiner tests whether the controls deliver what you promised.
  • Type II examinations test controls across an observation period (commonly 12 months); exceptions appear in the report for customers to read.
  • Privacy differs from confidentiality: confidentiality protects designated information generally; privacy governs personal information against lifecycle commitments, adding rights, consent, and notice machinery.

SOC 2’s privacy category runs on an elegant and slightly ruthless idea: the audit criteria are your own promises. Security examinations test you against the AICPA’s expectations; privacy examinations test you against your notice, your DPAs, and your marketing page, which is why the category is both rarely elected and highly credible when present. The preparation is mostly a truth-reconciliation project, what did we promise, what do we actually do, and which one moves, followed by a year of operating cleanly under your own internal monitoring. Companies that pass discover the byproduct is the real prize: a privacy program whose commitments, controls, and evidence actually agree with each other.

Category statusElected, rare; security is the only mandatory TSC
Criteria areasNotice, choice/consent, collection, use/retention/disposal, access, disclosure, quality, monitoring
Defining mechanicYour commitments (notice, DPAs) become the audit criteria
Type IIControls tested across ~12-month period; exceptions published in report
Runway15-21 months to first privacy-inclusive Type II
SourceAICPA SOC 2

Preparing for the category

Reconcile promises with practice first. The notice is the criteria; amend practice or prose before the period opens.

Instrument for period testing. Continuous evidence and internal monitoring; see how SaaS processors structure this.

Decide against the alternatives deliberately. 27701 vs SOC 2 is a buyer-geography question; HIPAA-combined examinations serve health-data processors.

Map the disclosure surface. Third-party flows versus notice statements is the highest-yield pre-audit check.

Your notice versus your site’s actual behavior is testable today: run a free scan.

Frequently Asked Questions

What do the privacy criteria actually cover, area by area?

Eight areas tracing the personal-information lifecycle. Notice: the entity provides notice about its privacy practices to data subjects, current, accessible, covering purposes, and updated when practices change. Choice and consent: choices are communicated and consent obtained (explicit or implicit as commitments and law require) for collection, use, and disclosure, including changes of purpose. Collection: personal information is collected consistent with the purposes identified in the notice, the criterion that makes over-collection an audit finding. Use, retention, and disposal: use limited to noticed purposes; retention bounded to fulfillment of purposes or legal requirements; disposal actually performed and evidenced. Access: data subjects can access their information for review and correction, with identity authentication and denial-handling procedures. Disclosure and notification: third-party disclosures happen only per commitments, with equivalent-protection expectations of recipients, and unauthorized disclosures (breaches) trigger notification procedures. Quality: personal information is accurate, complete, and relevant for its purposes. Monitoring and enforcement: compliance with commitments is monitored, disputes and complaints are addressed, and issues remediated. Each area decomposes into criteria with points of focus, and the examiner designs tests per criterion against your system description and commitments, the criteria are stable; what varies per engagement is what you promised.

How do our own commitments become the audit standard?

This is the privacy category's defining mechanic and its sharpest edge. The examination evaluates whether controls provide reasonable assurance that the entity met its privacy commitments and the applicable criteria, and 'commitments' means what you told data subjects and customers: the privacy notice foremost, plus DPAs, contract exhibits, and public statements. Consequences follow. Your notice is testable: 'we delete your data within 30 days of account closure' converts to a control the examiner samples, closures from the period, deletion evidence per system, and the marketing flourish your growth team added ('we never share your data') becomes a criterion your ad-tech integrations promptly fail. Vagueness does not save you: commitments must still meet the criteria's substance, so a notice that promises nothing specific fails the notice criteria themselves. Alignment work is therefore the pre-engagement priority: inventory every externally stated privacy commitment, reconcile against actual practice, and amend either the practice or the statement before the observation period opens, not during it, mid-period notice changes complicate testing and read poorly. The upside of the mechanic: a clean privacy-inclusive SOC 2 is uniquely persuasive evidence, a CPA tested your actual promises against your actual behavior for a year, which is precisely what a privacy-diligence reviewer wants to know and what no policy binder demonstrates.

What does the examiner test, and what do exceptions look like?

In a Type II, the examiner tests operating effectiveness across the observation period: inquiry (interviews), inspection (records sampling), observation, and reperformance, applied per control. Concretely, expect: consent-record sampling against collection events (was consent captured before processing, with the promised granularity); DSAR samples traced end-to-end (request, authentication, data location, response content, timeliness against committed deadlines); retention and disposal evidence (deletion job outputs, disposal certificates, sampled against the schedule and closure events); disclosure testing (third-party data flows reconciled against the notice's disclosure statements and DPA terms, onward-transfer contract inspection); breach-procedure walkthroughs and, if incidents occurred, their handling against notification commitments; accuracy and complaint-handling samples. Exceptions are deviations found in testing, a sampled DSAR answered late, a deletion job that missed a datastore, consent records missing for a cohort, and they appear in the report's test-results section with management's response; enough of them, or systemic ones, push the opinion from unqualified to qualified. Two realities to internalize: customers read the exceptions table first, a clean opinion with three material exceptions is not clean to a buyer; and exceptions are period-locked, you cannot remediate January's failure out of a January-December report, which is why continuous internal monitoring (your own mini-examination, monthly) is the only comfortable way to live with a Type II.

How does the privacy category differ from confidentiality, and do we need both?

They answer different questions and are frequently confused, including by buyers. Confidentiality: protects information designated confidential, customer business data, trade secrets, whatever the agreements define, through access restriction, encryption, and disposal controls; its subject is designated information of any kind, and its beneficiary is typically the customer who designated it. Privacy: governs personal information specifically, against the full lifecycle commitments, notice, consent, collection limits, use limits, subject access, disclosure rules, quality, and its beneficiaries include the individuals the data describes, who are not your customers and never signed your MSA. A processor can be flawlessly confidential and fail privacy comprehensively: encrypting everything, restricting access tightly, and still over-collecting, using data beyond notice, denying subject access, and retaining forever. Do you need both? If you handle personal information and elect privacy, confidentiality usually rides along cheaply, the protective controls overlap heavily. The realistic decision is whether to add privacy to a security-plus-confidentiality report: add it when customers process consumer personal data through you and their diligence asks lifecycle questions (consent, deletion, subject rights) that confidentiality reports cannot answer; skip it when your service touches only business-contact or pseudonymous operational data and contracts treat everything as confidential information, where the privacy category adds cost without answering a question anyone is asking. And if you operate under GDPR-family laws with EU enterprise buyers, weigh whether ISO 27701 answers the same diligence more recognizably in that market.

What preparation does adding the privacy category require, and on what timeline?

For an organization already running SOC 2 (security, probably availability or confidentiality), a realistic runway to a privacy-inclusive Type II report is 15-21 months, because the observation period is inside it. Quarter one: commitment inventory and reconciliation, every notice, DPA, and public statement versus actual practice; extend the system description to cover personal-information flows; gap-assess against the privacy criteria (the usual gaps: consent-record quality, DSAR machinery coverage, retention execution evidence, disclosure mapping, complaint handling). Quarters two and three: control build and remediation, instrument consent capture, wire DSAR workflows with deadline tracking, implement and evidence disposal, paper the onward-transfer expectations, stand up the monitoring criterion's machinery (your internal testing of the privacy controls); amend the notice where practice will not reach the promise. Then open the observation period, twelve months during which the controls must operate cleanly while your internal monitoring catches deviations early enough to remediate and document (remediated deviations with management responses read far better than discovered-by-examiner exceptions). Add examiner readiness (a Type I at period start is an optional confidence point), fieldwork, and reporting. Cost drivers: examiner fees rise modestly with the added category; the real cost is the control build and the evidence hygiene, and the recurring reality that every subsequent year re-tests the whole period. The efficiency play for those also holding ISO 27701: one control set, dual-mapped, with evidence designed for period-testing, which satisfies both regimes at the stricter standard.

Regulatory Crosswalk

ISO/IEC 27701NIST Privacy FrameworkGDPRGAPP heritage

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.