SOC 2 Privacy (P1–P8)
The largest optional category: eight criteria tracking personal information from notice to enforcement. Scoped in when you make privacy commitments about personal data you collect directly. For Indian entities the mapping to DPDP duties is close — notice, consent, retention, access and erasure all have statutory twins.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit
The criteria that decide your examination
Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).
Where examinations produce exceptions
Privacy criteria centre on commitments to data subjects — usually the controller’s role. Processors typically serve privacy through Confidentiality + contractual commitments; scoping P1–P8 wrongly doubles the work.
The privacy notice promises X; telemetry collects Y. Auditors read the notice and trace actual flows — the gap is the exception.
P4.3/P5 commitments require operational deletion/access workflows with records — the same machinery DPDP requires, which is why building it once for both is the efficient path.
Evidence auditors sample
- Privacy notice versions and publication records (P1.1)
- Consent capture and withdrawal records (P2.1)
- Data inventory/mapping supporting collection and use limits (P3/P4)
- DSAR workflow samples: access, correction, deletion with timestamps (P5, P4.3)
- Processor agreements and disclosure records (P6)
- Complaint-handling records (P8.1)
Privacy FAQ
Should we add Privacy or is Confidentiality enough?
If you make commitments to data subjects about personal information you collect (controller-like role), Privacy fits. If you process customer data under their instructions, Confidentiality plus contractual privacy commitments is usually the right scope.
Does SOC 2 Privacy overlap with DPDP compliance?
Substantially — notice, consent, retention/erasure, access and grievance handling all have DPDP statutory twins, so Indian entities can build one operational layer that serves both.
Is SOC 2 Privacy a substitute for a privacy law programme?
No — it attests controls against your commitments and the criteria; statutory duties under DPDP/GDPR exist independently and need their own compliance basis.
Privacy in your SOC 2 scope
We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.
