P Privacy · 18 criteria

SOC 2 P — Privacy

The Privacy category is the largest optional set, covering notice, choice, collection, use, retention, disclosure, quality, monitoring and enforcement across the personal-information lifecycle. It overlaps heavily with GDPR and similar regimes, so organisations already running a privacy programme usually have most of the evidence — the work is mapping it to the P-series structure rather than creating it.

All 18 P criteria

P1.1 Privacy notice
Notice is provided to data subjects about the entity's privacy practices and objectives.
P2.1 Choice and consent
Choices regarding collection, use, retention, disclosure, and disposal of personal information are communicated and consent obtained.
P3.1 Collection limited to identified purposes
Personal information is collected consistent with the entity's privacy objectives.
P3.2 Explicit consent for sensitive information
Explicit consent is obtained for sensitive personal information when required.
P4.1 Use limited to identified purposes
Use of personal information is limited to the purposes identified in the entity's privacy objectives.
P4.2 Retention of personal information
Personal information is retained consistent with the entity's privacy objectives.
P4.3 Secure disposal of personal information
Personal information is securely disposed of to meet the entity's privacy objectives.
P5.1 Access to personal information
Data subjects are provided access to their personal information for review and correction.
P5.2 Correction of personal information
Requests for correction of personal information are managed and data subjects informed.
P6.1 Disclosure with consent
Personal information is disclosed to third parties only with consent or as otherwise permitted by the entity's privacy objectives.
P6.2 Recording authorized disclosures
Authorized disclosures of personal information are recorded.
P6.3 Recording unauthorized disclosures
Unauthorized disclosures of personal information are recorded.
P6.4 Third-party privacy commitments
Third parties with access to personal information commit to appropriate privacy practices.
P6.5 Third-party breach notification obligations
Third parties are obligated to notify the entity of actual or suspected unauthorized disclosures.
P6.6 Breach notification to data subjects
Data subjects are notified of breaches and incidents affecting their personal information when required.
P6.7 Accounting of disclosures
An accounting of personal information disclosures is provided to data subjects upon request.
P7.1 Data quality
Personal information is maintained accurate, complete, and relevant for the purposes identified.
P8.1 Privacy inquiries, complaints and disputes
A process exists to receive, address, and resolve inquiries, complaints, and disputes regarding privacy practices.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC7 CC8 CC9 A1 C1 PI1
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 P?

P Privacy contains 18 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is P required in every SOC 2 report?

No. P is only tested when you elect to include the Privacy category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.

What is the difference between a Type 1 and Type 2 report for P?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.