Skip to main content
Category: Trust Services Criteria

Privacy

Also known as: Privacy Trust Services Criterion, Privacy category
Simply put

In the SOC 2 context, Privacy is one of the optional categories an organization can choose to include in the scope of its examination. It concerns how personal information is collected, used, retained, disclosed, and disposed of. Because it is optional, Privacy is only assessed when the organization and its auditor decide to include it in the engagement scope.

Formal definition

Privacy is one of the five Trust Services Criteria categories under the AICPA framework used in SOC 2 examinations. Unlike the Security category (the Common Criteria), which is required in every SOC 2 engagement, Privacy is optional and is selected based on scoping decisions. When in scope, it addresses the organization's controls over personal information across its lifecycle, collection, use, retention, disclosure, and disposal, typically aligned with the entity's privacy commitments and system requirements. Privacy in the SOC 2 sense should not be conflated with the broader concept of information confidentiality (the Confidentiality category), nor with ISO/IEC 27001 Annex A controls or standards such as ISO/IEC 27018. A SOC 2 report that includes Privacy attests only to the controls and review period covered and does not guarantee freedom from breaches or comprehensive regulatory compliance.

Why it matters

Privacy matters in the SOC 2 context because personal information carries distinct obligations that go beyond general security safeguards. When an organization collects, uses, retains, discloses, or disposes of personal information, the parties who entrust that information, customers, partners, and the individuals themselves, increasingly expect assurance that it is handled according to the organization's stated commitments. Including the Privacy category in a SOC 2 examination allows an independent CPA firm to attest to the design, and (in a Type II examination) the operating effectiveness, of the controls governing that personal information over the review period.

Because Privacy is optional rather than required, its presence or absence in a report is itself meaningful. A SOC 2 report scoped to Security alone (the Common Criteria) does not address how personal information is managed across its lifecycle, so readers should not assume privacy controls were evaluated unless the Privacy category is explicitly in scope. Compliance managers and auditors therefore need to confirm which Trust Services Criteria categories a given report actually covers before relying on it for privacy-related assurance.

It is also important to understand the limits of what a Privacy-inclusive SOC 2 report conveys. The report attests only to the controls and the specific review period covered; it does not guarantee freedom from breaches, nor does it constitute comprehensive compliance with any particular privacy law or regulation. Privacy in the SOC 2 sense should not be conflated with information confidentiality, with ISO/IEC 27001 Annex A controls, or with standards such as ISO/IEC 27018, each of which addresses personal information from a different angle.

Who it's relevant to

Compliance and GRC managers
Those responsible for scoping a SOC 2 engagement must decide whether Privacy belongs in scope alongside the required Security category, weighing the organization's privacy commitments and the assurance expectations of its stakeholders. They also need to communicate clearly which Trust Services Criteria categories a report covers so that readers do not assume privacy controls were evaluated when they were not.
Auditors and CPA examination teams
Practitioners performing the examination evaluate the design, and, in a Type II engagement, the operating effectiveness, of controls over personal information across its lifecycle, typically against the entity's stated privacy commitments and system requirements. They must keep the Privacy category distinct from the Confidentiality category and from concepts drawn from other frameworks.
Customers and report readers relying on SOC 2 assurance
Organizations reviewing a vendor's SOC 2 report to understand how personal information is handled should confirm that the Privacy category is explicitly in scope, since a Security-only report does not address personal information management. They should also recognize that the report attests only to the controls and period covered and does not guarantee freedom from breaches or comprehensive regulatory compliance.

Inside Privacy

Privacy as a Trust Services Criterion
In SOC 2, Privacy is one of the optional Trust Services Criteria categories, selected based on the engagement scope. It is not part of the required Security (Common Criteria) category and is included only when personal information is relevant to the services being examined.
Focus on personal information
The Privacy category addresses how an organization collects, uses, retains, discloses, and disposes of personal information, distinguishing it from Confidentiality, which addresses information designated as confidential more broadly rather than personal information specifically.
Relationship to the overall engagement
Privacy is evaluated within a SOC 2 examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report. When included, it may be assessed for suitability of design (Type I) or for both design and operating effectiveness over a review period (Type II), depending on scoping decisions.
Distinction from ISO frameworks
Privacy under SOC 2's Trust Services Criteria is separate from ISO privacy-related standards such as ISO 27018, which addresses protection of personally identifiable information in public cloud contexts. The Trust Services Criteria should not be conflated with ISO 27001 Annex A controls.

Common questions

Answers to the questions practitioners most commonly ask about Privacy.

Is Privacy a required category in every SOC 2 examination?
No. Security (the Common Criteria) is the only required Trust Services Criteria category. Privacy is one of the optional categories, alongside Availability, Processing Integrity, and Confidentiality, that an organization selects based on the scope of its engagement. Whether Privacy is included depends on scoping decisions rather than a universal rule.
Does including the Privacy category in a SOC 2 report make it equivalent to ISO 27001 certification or guarantee compliance with privacy regulations?
No. A SOC 2 report is an attestation examination performed by a licensed CPA firm and is distinct from an ISO 27001 certification issued by an accredited certification body. The Privacy category addresses controls relevant to how personal information is handled against the applicable criteria, but it attests only to the controls and period covered. It does not automatically satisfy any specific privacy law, and it does not guarantee freedom from breaches.
How do I decide whether to include the Privacy category in my SOC 2 scope?
In most engagements, the decision depends on whether your system collects, uses, retains, discloses, or disposes of personal information in ways that are relevant to your customers or stakeholders. Organizations that process personal information on behalf of clients typically consider Privacy where it addresses commitments they have made. The choice is a scoping decision made in consultation with the service auditor, and it should reflect the criteria applicable to your service.
How does the Privacy category differ from the Confidentiality category?
Depending on scope, Confidentiality typically addresses information designated as confidential by agreement or policy, regardless of whether it is personal, while Privacy addresses personal information specifically and the commitments made about its collection, use, retention, disclosure, and disposal. An engagement may include one, both, or neither, based on the applicable criteria and scoping decisions.
Should Privacy be assessed under a SOC 2 Type I or Type II?
Either is possible, depending on your objective. A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions. In most engagements, customers seeking assurance about how privacy controls actually operate over time request a Type II.
If I already hold an ISO 27001 certificate, do I still need the SOC 2 Privacy category to demonstrate privacy controls?
Possibly, depending on what your stakeholders require. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other. An ISO 27001 certificate covers only the defined scope of the ISMS, and the SOC 2 Privacy category is not the same as ISO 27001's Annex A reference controls. Which one you pursue typically depends on the criteria your customers, auditors, or certification bodies expect.

Common misconceptions

Privacy is a mandatory part of every SOC 2 report.
Only the Security category (Common Criteria) is required in a SOC 2 examination. Privacy is one of the optional categories and is included only when selected based on scope, typically when personal information is relevant to the services covered.
The SOC 2 Privacy category is the same as the Confidentiality category.
The two are distinct. Privacy addresses the handling of personal information, while Confidentiality addresses information designated as confidential more broadly. An engagement may include one, both, or neither depending on scope.
Including Privacy in a SOC 2 report guarantees an organization will not experience a privacy breach.
A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. Its scope is limited to the criteria selected and the review period defined during scoping.

Best practices

Confirm during scoping whether Privacy is relevant to the services being examined, and include it as an optional Trust Services Criteria category only when personal information handling is in scope.
Clearly document the boundary between the Privacy and Confidentiality categories so that personal information and other confidential information are addressed by the appropriate controls.
Determine early whether the engagement is a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a review period) examination, since this affects how Privacy controls are evidenced.
Avoid conflating SOC 2 Privacy criteria with ISO 27001 Annex A controls or ISO privacy standards such as ISO 27018; treat any mapping between frameworks as partial rather than equivalent.
Communicate to report users that Privacy coverage is limited to the controls and period covered and does not certify the organization or guarantee against breaches.
Engage the licensed CPA firm performing the SSAE 18 examination to confirm how Privacy scoping decisions will be reflected in the resulting report.