Auditen
Home / Frameworks / SOC 2 / The Privacy criterion
SOC 2 · P

The Privacy criterion

The Privacy criterion requires a service organization to handle personal information in accordance with the commitments and notices it has provided to its users. It focuses on ensuring that the collection, use, retention, disclosure, and disposal of personally identifiable information (PII) are transparent and consistent with stated policies.

What it means

While the Security criterion focuses on protecting data from unauthorized access, the Privacy criterion focuses on the legal and ethical handling of personal information based on a "promise" made to the user. The core intent is transparency; if your privacy notice says you do not sell data or that you delete it after three years, you must prove those specific promises are kept.

In practice, this means mapping the entire lifecycle of PII within your organization. You must identify what personal information is collected, why it is being collected (the purpose), who has access to it, and how it is eventually destroyed.

Scope typically includes any data that can be used to distinguish or trace an individual's identity. This extends beyond just the internal team to include third-party vendors who process this data on your behalf.

How to meet it

Evidence an auditor asks for

  • The current, public-facing Privacy Policy and version history showing when it was updated.
  • A data map or inventory documenting the flow of PII through your systems and where it is stored.
  • Screenshots or logs demonstrating how user consent is captured and stored (e.g., checkbox timestamps).
  • Tickets or records proving that requests for data deletion or access were fulfilled within the promised timeframe.
  • Signed contracts with sub-processors containing specific privacy and confidentiality clauses.

Common pitfalls

  • Maintaining a "template" Privacy Notice that describes practices the company does not actually follow in reality.
  • Confusing security controls (like encryption) with privacy controls (like consent management); encryption protects data, but it doesn't justify why you collected it.
  • Collecting "shadow data" or additional PII for analytics and marketing without updating the Privacy Notice to reflect these new uses.
  • Lack of a formal process for purging old user data, leading to indefinite retention that violates stated disposal policies.