Privacy
In the SOC 2 context, Privacy is one of the optional categories an organization can choose to include in the scope of its examination. It concerns how personal information is collected, used, retained, disclosed, and disposed of. Because it is optional, Privacy is only assessed when the organization and its auditor decide to include it in the engagement scope.
Privacy is one of the five Trust Services Criteria categories under the AICPA framework used in SOC 2 examinations. Unlike the Security category (the Common Criteria), which is required in every SOC 2 engagement, Privacy is optional and is selected based on scoping decisions. When in scope, it addresses the organization's controls over personal information across its lifecycle, collection, use, retention, disclosure, and disposal, typically aligned with the entity's privacy commitments and system requirements. Privacy in the SOC 2 sense should not be conflated with the broader concept of information confidentiality (the Confidentiality category), nor with ISO/IEC 27001 Annex A controls or standards such as ISO/IEC 27018. A SOC 2 report that includes Privacy attests only to the controls and review period covered and does not guarantee freedom from breaches or comprehensive regulatory compliance.
Why it matters
Privacy matters in the SOC 2 context because personal information carries distinct obligations that go beyond general security safeguards. When an organization collects, uses, retains, discloses, or disposes of personal information, the parties who entrust that information, customers, partners, and the individuals themselves, increasingly expect assurance that it is handled according to the organization's stated commitments. Including the Privacy category in a SOC 2 examination allows an independent CPA firm to attest to the design, and (in a Type II examination) the operating effectiveness, of the controls governing that personal information over the review period.
Because Privacy is optional rather than required, its presence or absence in a report is itself meaningful. A SOC 2 report scoped to Security alone (the Common Criteria) does not address how personal information is managed across its lifecycle, so readers should not assume privacy controls were evaluated unless the Privacy category is explicitly in scope. Compliance managers and auditors therefore need to confirm which Trust Services Criteria categories a given report actually covers before relying on it for privacy-related assurance.
It is also important to understand the limits of what a Privacy-inclusive SOC 2 report conveys. The report attests only to the controls and the specific review period covered; it does not guarantee freedom from breaches, nor does it constitute comprehensive compliance with any particular privacy law or regulation. Privacy in the SOC 2 sense should not be conflated with information confidentiality, with ISO/IEC 27001 Annex A controls, or with standards such as ISO/IEC 27018, each of which addresses personal information from a different angle.
Who it's relevant to
Inside Privacy
Common questions
Answers to the questions practitioners most commonly ask about Privacy.