P6.7 P · Privacy · Privacy

P6.7 — Accounting of disclosures

An accounting of personal information disclosures is provided to data subjects upon request.

Also written as P 6.7, TSC P6.7, SOC2 P6.7, SOC 2 Type 2 P6.7.

What SOC 2 P6.7 requires

Accounting of disclosures is one of 18 criteria in the Privacy (P) series of the Privacy category. An accounting of personal information disclosures is provided to data subjects upon request. Because this sits outside the Common Criteria, it is only tested when Privacy is in the scope of your engagement — check your report scope before building evidence for it.

Audit evidence assessors look for

When preparing for a SOC 2 audit against P6.7, gather artefacts such as:

  • Procedure for providing disclosure accounting to data subjects
  • Disclosure log capable of per-subject reporting
  • Fulfilled accounting request records
  • Retention of disclosure records per policy

ISO 27001 mapping

P6.7 has no clean one-to-one ISO 27001:2022 Annex A equivalent — it is largely a governance or reporting expectation that ISO 27001 handles through the management-system clauses (4–10) rather than an Annex A control. Treat it as its own requirement rather than assuming ISMS evidence covers it.

Map P6.7 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against P6.7 in the Risk Register.

Other Privacy criteria

P1.1 Privacy notice P2.1 Choice and consent P3.1 Collection limited to identified purposes P3.2 Explicit consent for sensitive information P4.1 Use limited to identified purposes P4.2 Retention of personal information P4.3 Secure disposal of personal information P5.1 Access to personal information P5.2 Correction of personal information P6.1 Disclosure with consent P6.2 Recording authorized disclosures P6.3 Recording unauthorized disclosures P6.4 Third-party privacy commitments P6.5 Third-party breach notification obligations P6.6 Breach notification to data subjects P7.1 Data quality P8.1 Privacy inquiries, complaints and disputes

All P Privacy criteria →

Frequently asked questions

Is P6.7 required for a SOC 2 report?

Only if the Privacy category is in scope. The Common Criteria (CC1–CC9) are mandatory for every SOC 2, but P criteria are tested only when you elect to include Privacy in the engagement. Scope is your choice, usually driven by customer contracts.

How does an auditor test P6.7?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet P6.7 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if P6.7 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.