The Privacy category is the largest optional set, covering notice, choice, collection, use, retention, disclosure, quality, monitoring and enforcement across the personal-information lifecycle. It overlaps heavily with GDPR and similar regimes, so organisations already running a privacy programme usually have most of the evidence — the work is mapping it to the P-series structure rather than creating it.
P Privacy contains 18 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
No. P is only tested when you elect to include the Privacy category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.