We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SOC 2 Trust Services Criteria · Optional category

SOC 2 Privacy (P1–P8)

The largest optional category: eight criteria tracking personal information from notice to enforcement. Scoped in when you make privacy commitments about personal data you collect directly. For Indian entities the mapping to DPDP duties is close — notice, consent, retention, access and erasure all have statutory twins.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit

The criteria that decide your examination

P1.1
Notice

Notice to data subjects about privacy practices — what is collected, why, how used and retained.

P2.1
Choice and consent

Choices communicated and consent obtained for collection, use and disclosure — the DPDP s.6 twin.

P3.1–P3.2
Collection

Personal information collected consistent with objectives; explicit consent where required for sensitive data.

P4.1–P4.3
Use, retention and disposal

Use limited to purposes; retention limited; disposal executed — the criteria that pair with DPDP s.8(7) erasure duties.

P5.1–P5.2
Access

Data subjects can access and correct their personal information.

P6.x
Disclosure to third parties

Disclosures with consent, processor commitments, breach notification obligations — the largest P-block.

P7.1
Quality

Personal information kept accurate, complete and relevant.

P8.1
Monitoring and enforcement

Complaints and disputes addressed; compliance monitored.

Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).

Where examinations produce exceptions

Scoping Privacy when you are a processor

Privacy criteria centre on commitments to data subjects — usually the controller’s role. Processors typically serve privacy through Confidentiality + contractual commitments; scoping P1–P8 wrongly doubles the work.

Notice and consent that drifted from reality

The privacy notice promises X; telemetry collects Y. Auditors read the notice and trace actual flows — the gap is the exception.

Deletion rights promised, unexecutable

P4.3/P5 commitments require operational deletion/access workflows with records — the same machinery DPDP requires, which is why building it once for both is the efficient path.

Evidence auditors sample

  • Privacy notice versions and publication records (P1.1)
  • Consent capture and withdrawal records (P2.1)
  • Data inventory/mapping supporting collection and use limits (P3/P4)
  • DSAR workflow samples: access, correction, deletion with timestamps (P5, P4.3)
  • Processor agreements and disclosure records (P6)
  • Complaint-handling records (P8.1)

Privacy FAQ

Should we add Privacy or is Confidentiality enough?

If you make commitments to data subjects about personal information you collect (controller-like role), Privacy fits. If you process customer data under their instructions, Confidentiality plus contractual privacy commitments is usually the right scope.

Does SOC 2 Privacy overlap with DPDP compliance?

Substantially — notice, consent, retention/erasure, access and grievance handling all have DPDP statutory twins, so Indian entities can build one operational layer that serves both.

Is SOC 2 Privacy a substitute for a privacy law programme?

No — it attests controls against your commitments and the criteria; statutory duties under DPDP/GDPR exist independently and need their own compliance basis.

Confidentiality (C1)

Privacy in your SOC 2 scope

We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.