SOC 2 Trust Services Criteria

SOC 2 Privacy Criterion

Privacy covers the collection, use, retention, disclosure, and disposal of personal information in line with the organisation's privacy notice and applicable laws (GDPR, CCPA, Australian Privacy Principles).

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILSOC 2 Privacy EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Common control areas

Notice and consent

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Choice and consent mechanisms

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Collection limitations

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Data quality and integrity

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Access and correction rights

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Disclosure and consent

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Retention and disposal

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Privacy incident response

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Evidence to keep

  • Control owner and review cadence
  • Policy or procedure approved by management
  • System export, ticket, report, or log sample
  • Exception record and remediation evidence

Privacy policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Back to all SOC 2 criteria, or open the SOC 2 template pack.