Personal information is collected consistent with the entity's privacy objectives.
Also written as P 3.1, TSC P3.1, SOC2 P3.1, SOC 2 Type 2 P3.1.
Collection limited to identified purposes is one of 18 criteria in the Privacy (P) series of the Privacy category. Personal information is collected consistent with the entity's privacy objectives. Because this sits outside the Common Criteria, it is only tested when Privacy is in the scope of your engagement — check your report scope before building evidence for it.
When preparing for a SOC 2 audit against P3.1, gather artefacts such as:
P3.1 has no clean one-to-one ISO 27001:2022 Annex A equivalent — it is largely a governance or reporting expectation that ISO 27001 handles through the management-system clauses (4–10) rather than an Annex A control. Treat it as its own requirement rather than assuming ISMS evidence covers it.
Only if the Privacy category is in scope. The Common Criteria (CC1–CC9) are mandatory for every SOC 2, but P criteria are tested only when you elect to include Privacy in the engagement. Scope is your choice, usually driven by customer contracts.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet P3.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.