SOC 2 Privacy Criterion
Privacy covers the collection, use, retention, disclosure, and disposal of personal information in line with the organisation's privacy notice and applicable laws (GDPR, CCPA, Australian Privacy Principles).
Common control areas
Notice and consent
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Choice and consent mechanisms
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Collection limitations
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Data quality and integrity
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Access and correction rights
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Disclosure and consent
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Retention and disposal
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Privacy incident response
Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.
Evidence to keep
- Control owner and review cadence
- Policy or procedure approved by management
- System export, ticket, report, or log sample
- Exception record and remediation evidence
Privacy policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Back to all SOC 2 criteria, or open the SOC 2 template pack.