Skip to main content
Category: Trust Services Criteria

Generally Accepted Privacy Principles

Also known as: GAPP, AICPA/CICA Generally Accepted Privacy Principles
Simply put

Generally Accepted Privacy Principles (GAPP) was a privacy framework developed jointly by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA) to help organizations build and manage a comprehensive privacy program. It was intended to assist accounting professionals in creating and evaluating privacy practices. GAPP was superseded when the AICPA released the Privacy Management Framework (PMF) in 2020 as an update to the former 2009 GAPP.

Formal definition

GAPP is an internationally recognized privacy framework developed by the AICPA and CICA, with a 2009 edition later updated in early 2010, providing a structured set of principles to guide certified public accountants and chartered accountants in designing, implementing, and assessing an organization's privacy program. The framework was created to support the establishment and evaluation of privacy management practices rather than serving as a certification or attestation standard in itself. GAPP was retired and replaced by the AICPA Privacy Management Framework (PMF), published in 2020 as its successor; practitioners should note that GAPP is distinct from the SOC 2 Trust Services Criteria Privacy category, and the evidence provided does not detail the internal structure or number of principles.

Why it matters

Generally Accepted Privacy Principles (GAPP) matters primarily as a historical foundation for how the accounting profession approached privacy program design and evaluation. Developed jointly by the AICPA and CICA, GAPP gave certified public accountants and chartered accountants a structured framework for helping organizations build and assess comprehensive privacy practices at a time when formalized privacy guidance from the profession was still maturing. Understanding GAPP helps GRC professionals interpret older privacy documentation, legacy program references, and prior assessments that may still cite the framework.

For practitioners today, the most important point is that GAPP has been retired. The AICPA released the Privacy Management Framework (PMF) in 2020 as an update to the former 2009 GAPP, meaning organizations relying on the older framework should transition their reference point to the PMF. Treating GAPP as current guidance risks anchoring privacy program design to a superseded standard.

GAPP should also not be confused with the Privacy category within the SOC 2 Trust Services Criteria. Although both originate from the AICPA and address privacy, they are distinct instruments serving different purposes: GAPP was a framework to guide the creation and evaluation of a privacy program, whereas the SOC 2 Privacy category is one of the optional Trust Services Criteria categories evaluated within an attestation examination. Conflating the two can lead to scoping errors in engagements where privacy is in question.

Who it's relevant to

Privacy and GRC Professionals
Those managing privacy programs may encounter GAPP references in legacy documentation or prior assessments. Recognizing that GAPP was superseded by the AICPA Privacy Management Framework (PMF) in 2020 helps ensure current program design draws on up-to-date guidance rather than a retired framework.
CPAs and Chartered Accountants
GAPP was originally created to assist certified public accountants and chartered accountants in designing, implementing, and assessing privacy programs. Accounting professionals working in privacy advisory or evaluation roles should be aware of the framework's history and its replacement by the PMF.
SOC 2 Practitioners and Auditors
Practitioners scoping engagements that include privacy should note that GAPP is distinct from the SOC 2 Trust Services Criteria Privacy category. Keeping these instruments separate helps avoid scoping and reference errors when the optional Privacy category is selected in a SOC 2 examination.
Compliance Managers Reviewing Legacy Materials
Those inheriting older privacy documentation or evaluating historical program artifacts benefit from understanding that GAPP was a framework, not a certification or attestation standard, and that it was retired in favor of the PMF. This context supports accurate interpretation of dated references.

Inside GAPP

Management
The component addressing the definition, documentation, communication, and assignment of accountability for an organization's privacy policies and procedures. It establishes who owns privacy governance and how policies are maintained.
Notice
The component covering how an organization informs individuals about its privacy policies and practices, typically at or before the point of collecting personal information.
Choice and Consent
The component describing the choices available to individuals regarding the collection, use, and disclosure of their personal information, and the mechanisms for obtaining consent where required.
Collection
The component addressing that personal information is collected only for the purposes identified in the notice, limiting collection to what is disclosed to the individual.
Use, Retention, and Disposal
The component covering the limitation of use of personal information to identified purposes, the retention of information only as long as needed, and secure disposal when no longer required.
Access
The component providing individuals the ability to access their personal information for review and, where appropriate, correction, amendment, or deletion.
Disclosure to Third Parties
The component addressing that personal information is disclosed to third parties only for the purposes identified in the notice and with appropriate consent.
Security for Privacy
The component covering the protection of personal information against unauthorized access, both physical and logical. Note that this intersects with, but is not identical to, the Security (Common Criteria) category under the Trust Services Criteria.
Quality
The component addressing the maintenance of accurate, complete, and relevant personal information for the purposes for which it is used.
Monitoring and Enforcement
The component covering how an organization monitors compliance with its privacy policies and procedures and handles inquiries, complaints, and disputes.

Common questions

Answers to the questions practitioners most commonly ask about GAPP.

Is GAPP the same as the Privacy category in the SOC 2 Trust Services Criteria?
No. GAPP was a separate AICPA privacy framework and should not be conflated with the Privacy category of the Trust Services Criteria used in current SOC 2 examinations. In a SOC 2 engagement, Privacy is one of the optional Trust Services Criteria categories selected based on scope, alongside Security (the required Common Criteria), Availability, Processing Integrity, and Confidentiality. While both address privacy concepts, they are distinct constructs, and you should refer to the Trust Services Criteria when scoping a SOC 2 report rather than assuming GAPP terminology applies directly.
Does adopting GAPP mean my organization satisfies ISO 27001 privacy requirements?
No. GAPP is an AICPA privacy framework and does not automatically satisfy any ISO/IEC 27001 requirements. ISO 27001 certifiable requirements are in clauses 4 through 10 (the ISMS requirements), with reference controls listed in Annex A and selected via a Statement of Applicability informed by risk assessment. Privacy-specific extensions such as ISO 27018 or a privacy information management system approach are addressed through different mechanisms. Mapping between a privacy framework and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other.
How should we map GAPP-based privacy controls to a SOC 2 Privacy examination?
In most engagements, mapping legacy GAPP-based controls to a SOC 2 Privacy examination requires reconciling them against the Privacy category of the current Trust Services Criteria rather than assuming a one-to-one correspondence. Because the frameworks are distinct, the exercise is typically partial and depends on your scope and the criteria selected. Work with your CPA firm to confirm which of your existing privacy controls align to the applicable criteria, and identify gaps where the Trust Services Criteria expect coverage not addressed by your prior framework.
Can our privacy program documentation built on GAPP support an ISO 27001 certification effort?
Existing privacy documentation may provide useful input, but it does not substitute for the ISMS requirements that an accredited certification body assesses. For ISO 27001, you would typically need to demonstrate the clause 4 through 10 requirements and select applicable Annex A reference controls through a Statement of Applicability informed by risk assessment. Depending on scope, privacy-focused controls can inform that selection, but the certification covers only the defined scope of the ISMS and requires the specific documentation and evidence the standard calls for.
Which privacy framework should we align to if we are pursuing both a SOC 2 report and ISO 27001 certification?
Because SOC 2 is an attestation examination performed under the AICPA standard and ISO 27001 is a certification issued by an accredited certification body against a management system standard, the two follow different structures. In most engagements, organizations pursuing both align privacy activities to the SOC 2 Privacy category of the Trust Services Criteria for the report and to the relevant ISO requirements and reference controls for the certification, then look for partial overlaps. The appropriate approach depends on your scope, the criteria selected, and the guidance of your CPA firm and certification body.
Does relying on a GAPP-derived privacy program guarantee we won't experience a privacy breach?
No. No privacy framework guarantees freedom from breaches. A SOC 2 report attests only to the controls and the period covered by the examination and does not guarantee that no incidents will occur, and an ISO 27001 certificate covers only the defined scope of the ISMS. Any privacy program, regardless of the framework it draws on, establishes controls and processes but cannot provide an absolute assurance against incidents. Treat framework alignment as one component of risk management rather than a guarantee of outcomes.

Common misconceptions

GAPP is the same as the Privacy category within the SOC 2 Trust Services Criteria.
GAPP was a distinct AICPA/CICA privacy framework that predates and informed later privacy criteria. The Privacy category is one of the optional Trust Services Criteria categories selected based on scope, and it should not be treated as interchangeable with GAPP. Practitioners should confirm which current criteria set applies to their engagement rather than assuming equivalence.
Addressing GAPP's privacy principles satisfies the requirements of ISO 27001 or its privacy-related standards.
GAPP originates from the AICPA/CICA tradition and is not part of the ISO 27001 management system requirements (clauses 4 through 10) or its Annex A reference controls. Mapping between privacy frameworks and ISO standards such as ISO 27018 is at most partial, and satisfying one does not automatically satisfy another.
GAPP's Security for Privacy component makes a separate security assessment unnecessary.
The Security for Privacy component addresses protection of personal information specifically, but it is not equivalent to a full security examination. Under SOC 2, Security (the Common Criteria) is the only required category and is assessed on its own terms; privacy-focused security measures do not replace that broader coverage.

Best practices

Map each GAPP component to your organization's documented privacy policies and assign clear accountability under the Management component, so ownership and maintenance responsibilities are explicit.
Confirm which current privacy criteria set applies to your engagement rather than assuming GAPP language is interchangeable with the Privacy category of the Trust Services Criteria, and document that scoping decision.
Limit collection, use, retention, and disclosure of personal information to the purposes stated in your notice, and maintain records demonstrating that consent mechanisms match those stated purposes.
Establish access, correction, and secure disposal processes for personal information so individuals can review their data and information is not retained beyond its identified need.
Treat Security for Privacy as complementary to, not a substitute for, a broader security assessment, since satisfying one framework does not automatically satisfy another and mappings between frameworks are typically partial.
Implement monitoring and enforcement procedures, including handling of complaints and disputes, and clearly document the scope covered so stakeholders understand what is and is not addressed.