Generally Accepted Privacy Principles
Generally Accepted Privacy Principles (GAPP) was a privacy framework developed jointly by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA) to help organizations build and manage a comprehensive privacy program. It was intended to assist accounting professionals in creating and evaluating privacy practices. GAPP was superseded when the AICPA released the Privacy Management Framework (PMF) in 2020 as an update to the former 2009 GAPP.
GAPP is an internationally recognized privacy framework developed by the AICPA and CICA, with a 2009 edition later updated in early 2010, providing a structured set of principles to guide certified public accountants and chartered accountants in designing, implementing, and assessing an organization's privacy program. The framework was created to support the establishment and evaluation of privacy management practices rather than serving as a certification or attestation standard in itself. GAPP was retired and replaced by the AICPA Privacy Management Framework (PMF), published in 2020 as its successor; practitioners should note that GAPP is distinct from the SOC 2 Trust Services Criteria Privacy category, and the evidence provided does not detail the internal structure or number of principles.
Why it matters
Generally Accepted Privacy Principles (GAPP) matters primarily as a historical foundation for how the accounting profession approached privacy program design and evaluation. Developed jointly by the AICPA and CICA, GAPP gave certified public accountants and chartered accountants a structured framework for helping organizations build and assess comprehensive privacy practices at a time when formalized privacy guidance from the profession was still maturing. Understanding GAPP helps GRC professionals interpret older privacy documentation, legacy program references, and prior assessments that may still cite the framework.
For practitioners today, the most important point is that GAPP has been retired. The AICPA released the Privacy Management Framework (PMF) in 2020 as an update to the former 2009 GAPP, meaning organizations relying on the older framework should transition their reference point to the PMF. Treating GAPP as current guidance risks anchoring privacy program design to a superseded standard.
GAPP should also not be confused with the Privacy category within the SOC 2 Trust Services Criteria. Although both originate from the AICPA and address privacy, they are distinct instruments serving different purposes: GAPP was a framework to guide the creation and evaluation of a privacy program, whereas the SOC 2 Privacy category is one of the optional Trust Services Criteria categories evaluated within an attestation examination. Conflating the two can lead to scoping errors in engagements where privacy is in question.
Who it's relevant to
Inside GAPP
Common questions
Answers to the questions practitioners most commonly ask about GAPP.