The Privacy criterion
The Privacy criterion requires a service organization to handle personal information in accordance with the commitments and notices it has provided to its users. It focuses on ensuring that the collection, use, retention, disclosure, and disposal of personally identifiable information (PII) are transparent and consistent with stated policies.
What it means
While the Security criterion focuses on protecting data from unauthorized access, the Privacy criterion focuses on the legal and ethical handling of personal information based on a "promise" made to the user. The core intent is transparency; if your privacy notice says you do not sell data or that you delete it after three years, you must prove those specific promises are kept.
In practice, this means mapping the entire lifecycle of PII within your organization. You must identify what personal information is collected, why it is being collected (the purpose), who has access to it, and how it is eventually destroyed.
Scope typically includes any data that can be used to distinguish or trace an individual's identity. This extends beyond just the internal team to include third-party vendors who process this data on your behalf.
How to meet it
- Publish a clear, accessible Privacy Notice that accurately describes how personal information is collected, used, disclosed, and disposed of.
- Implement mechanisms to obtain and record user consent for the collection and use of PII, ensuring users can opt-in or opt-out as promised.
- Establish a formal data classification scheme to identify which data elements are considered "personal information."
- Create a documented process for responding to Data Subject Access Requests (DSARs), such as requests to view, correct, or delete personal data.
- Define and implement a data retention and disposal schedule that ensures PII is not kept longer than necessary or promised.
- Execute data processing agreements (DPAs) with all third-party vendors to ensure they adhere to your privacy commitments.
Evidence an auditor asks for
- The current, public-facing Privacy Policy and version history showing when it was updated.
- A data map or inventory documenting the flow of PII through your systems and where it is stored.
- Screenshots or logs demonstrating how user consent is captured and stored (e.g., checkbox timestamps).
- Tickets or records proving that requests for data deletion or access were fulfilled within the promised timeframe.
- Signed contracts with sub-processors containing specific privacy and confidentiality clauses.
Common pitfalls
- Maintaining a "template" Privacy Notice that describes practices the company does not actually follow in reality.
- Confusing security controls (like encryption) with privacy controls (like consent management); encryption protects data, but it doesn't justify why you collected it.
- Collecting "shadow data" or additional PII for analytics and marketing without updating the Privacy Notice to reflect these new uses.
- Lack of a formal process for purging old user data, leading to indefinite retention that violates stated disposal policies.