Skip to main content
Category: Trust Services Criteria

Privacy Criteria (P1-P8)

Also known as: P1-P8, Privacy Category, Privacy Trust Services Criteria, SOC 2 Privacy Criteria
Simply put

The Privacy Criteria are one of the optional categories organizations can include in a SOC 2 examination, focused on how personal information is handled throughout its lifecycle. They are organized into eight series labeled P1 through P8, covering topics such as giving notice to individuals, obtaining consent, and managing the collection, use, retention, disposal, access, and disclosure of personal data. Because Privacy is optional rather than required, it is included only when it falls within the defined scope of the engagement.

Formal definition

Within the AICPA Trust Services Criteria, Privacy is an optional category (distinct from the required Security/Common Criteria) that an organization may elect based on scope. The Privacy Criteria are structured across series P1 through P8, addressing, depending on the specific criteria selected, notice and communication of privacy objectives, choice and consent, collection, use, retention and disposal, access, disclosure to third parties, and related areas of personal information management. These criteria typically center on commitments made to data subjects and are most applicable where the organization acts in a controller-type role; processors often address privacy-related concerns primarily through the Confidentiality category. Selecting Privacy adds it to the controls assessed in the SOC 2 report, which attests only to the controls and period covered and does not, by itself, satisfy separate legal regimes or other frameworks. The Privacy Criteria should not be conflated with ISO/IEC 27001 Annex A controls or with the NIST Privacy Framework, which uses its own distinct 'P' designations.

Why it matters

Personal information handling has become one of the most scrutinized aspects of vendor and service provider relationships, and the Privacy Criteria give organizations a structured way to demonstrate how they manage personal data across its lifecycle within a SOC 2 examination. Because Privacy is an optional category rather than the required Security (Common Criteria), including it signals a deliberate commitment to addressing notice, consent, collection, use, retention, disposal, access, and disclosure of personal information, concerns that increasingly drive customer due diligence, contract negotiations, and risk assessments.

For organizations that act in a controller-type role and make direct commitments to data subjects, the Privacy Criteria provide a way to evidence that those commitments are backed by controls that a CPA firm has examined. This can matter significantly when customers or partners want assurance about privacy practices but are evaluating a service provider through a single attestation report rather than requesting separate privacy audits. However, it is important to understand the boundary of what a SOC 2 report provides: it attests only to the controls and the period covered by the examination and does not, by itself, satisfy separate legal privacy regimes or other frameworks. Selecting the Privacy Criteria demonstrates alignment with defined privacy commitments; it is not a substitute for compliance with applicable law.

Misunderstanding what the Privacy Criteria cover can also create risk. They should not be conflated with ISO/IEC 27001 Annex A controls or with the NIST Privacy Framework, which uses its own distinct 'P' designations for entirely different purposes. Treating these as interchangeable can lead to gaps in scoping decisions and to misplaced confidence that one framework's outcome automatically covers another's requirements.

Who it's relevant to

Compliance and GRC Managers
Those responsible for scoping SOC 2 engagements need to decide whether to include the optional Privacy category based on the organization's role and the commitments it makes to data subjects. Understanding the P1-P8 structure helps them determine whether Privacy, Confidentiality, or both best fit the engagement, and to communicate clearly that a SOC 2 report attests only to the controls and period covered rather than satisfying separate legal privacy regimes.
Auditors and CPA Firms
Practitioners conducting the SOC 2 examination assess the selected Privacy Criteria alongside the required Security category. They must apply the criteria across the personal information lifecycle areas, notice, choice and consent, collection, use, retention and disposal, access, and disclosure, and avoid conflating these criteria with ISO/IEC 27001 Annex A controls or the NIST Privacy Framework's distinct designations.
Data Controllers and Privacy Officers
Organizations that act in a controller-type role and make direct commitments to individuals about how their personal information is handled are the primary candidates for including the Privacy Criteria. Privacy officers can use the P1-P8 structure to align internal privacy commitments with controls that will be examined, while recognizing the report does not substitute for compliance with applicable privacy law.
Service Providers Acting as Processors
Organizations that primarily process personal data on behalf of others should understand that the Privacy Criteria center on controller-type commitments to data subjects. Processors often address privacy-related concerns through the Confidentiality category instead, making it important to scope the engagement to reflect their actual role rather than defaulting to Privacy.

Inside P1-P8

Privacy as an Optional Category
Privacy is one of the four optional Trust Services Criteria categories in a SOC 2 examination, selected based on scope. Unlike Security (the Common Criteria), which is required, Privacy is included only when an organization chooses to address the collection, use, retention, disclosure, and disposal of personal information.
Series of Privacy Criteria (P1 through P8)
The Privacy category is organized into a series of criteria typically referenced as P1 through P8, which address the privacy lifecycle. Depending on scope and the applicable version of the Trust Services Criteria, these cover areas such as notice and communication of privacy commitments, choice and consent, collection, use and retention, access, disclosure to third parties, quality, and monitoring and enforcement.
Relationship to Personal Information
The Privacy criteria specifically concern personal information rather than data generally. This distinguishes Privacy from Confidentiality, which addresses information designated as confidential regardless of whether it relates to individuals.
Attestation Context
As part of a SOC 2 examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, the Privacy criteria are evaluated as design suitability (Type I) or design and operating effectiveness over a defined review period (Type II), and the outcome is a report rather than a certification.

Common questions

Answers to the questions practitioners most commonly ask about P1-P8.

Are the Privacy Criteria a mandatory part of every SOC 2 examination?
No. Within the Trust Services Criteria, only the Security category (the Common Criteria) is required. Privacy, along with Availability, Processing Integrity, and Confidentiality, is optional and included only when the scope of the engagement calls for it. An organization selects Privacy typically when it wants assurance over how it collects, uses, retains, discloses, and disposes of personal information. Whether Privacy is in scope is a scoping decision made with the service organization and its CPA firm.
Do the Privacy Criteria in SOC 2 satisfy ISO 27001's privacy-related requirements?
Not automatically. The Privacy Criteria are part of the AICPA Trust Services Criteria evaluated in a SOC 2 attestation examination, whereas ISO 27001 is a separate certification against a management system standard. Privacy-related controls in the ISO family are addressed differently, and mapping between the two frameworks is possible but partial. Satisfying the SOC 2 Privacy Criteria does not by itself demonstrate conformance with ISO 27001 or with any privacy-specific ISO standard, and vice versa. Each should be evaluated on its own terms and scope.
How do we decide whether to include the Privacy Criteria in our SOC 2 scope?
The decision typically depends on whether your service involves collecting, using, retaining, disclosing, or disposing of personal information on behalf of your customers, and whether those customers or your contractual commitments call for assurance over privacy practices. In most engagements this is discussed with your CPA firm during scoping. If personal information is central to the service you provide, including Privacy may address stakeholder needs; if not, organizations often scope to Security alone or add Confidentiality instead.
What kinds of evidence support the Privacy Criteria during a SOC 2 examination?
Depending on scope, evidence commonly relates to how the organization communicates its privacy commitments, obtains consent or provides notice, limits collection and use of personal information, manages retention and disposal, handles data subject requests, and addresses disclosure to third parties. The specific controls and evidence vary by organization and are set through scoping decisions with the auditor. In a Type II examination, this evidence must also demonstrate operating effectiveness over the defined review period, not just design at a point in time.
How do the Privacy Criteria relate to the Confidentiality category?
They address different concerns and should not be conflated. The Confidentiality category typically covers information designated as confidential regardless of whether it is personal, while the Privacy Criteria specifically address personal information across its lifecycle, including notice, choice, and the rights of individuals. An organization may select one, both, or neither, depending on scope. Including Confidentiality does not cover the privacy-specific obligations, and including Privacy does not necessarily address all confidential information.
Does including the Privacy Criteria in our SOC 2 report guarantee we are free from privacy breaches?
No. A SOC 2 report attests only to the controls and the period covered by the examination and does not guarantee freedom from breaches or incidents. When Privacy is in scope, the report reflects the auditor's evaluation of the design, and in a Type II the operating effectiveness, of the privacy-related controls within the defined boundaries. It does not extend to matters outside that scope or period, and it is not a certification. Readers should interpret it within its stated limitations.

Common misconceptions

The Privacy criteria are a mandatory part of every SOC 2 report.
Privacy is an optional category. Only the Security category (the Common Criteria) is required. Privacy is included based on scoping decisions, so many SOC 2 reports do not cover it at all.
The Privacy criteria and the Confidentiality criteria address the same thing.
Privacy specifically concerns personal information and its lifecycle, while Confidentiality addresses information designated as confidential regardless of whether it relates to individuals. They are distinct optional categories selected independently based on scope.
Meeting the SOC 2 Privacy criteria is equivalent to satisfying ISO 27001 or its privacy-related extensions.
The Trust Services Criteria are not the same as ISO 27001 requirements or Annex A controls. Mapping between the frameworks is possible but partial, and addressing the SOC 2 Privacy criteria does not automatically satisfy ISO 27001 or related standards such as ISO 27018.

Best practices

Confirm during scoping whether Privacy should be included, and document the rationale, since it is optional and adds meaningful effort beyond the required Security category.
Clearly distinguish personal information from other confidential information so that Privacy and Confidentiality criteria are addressed with the appropriate scope and controls.
Align the privacy commitments described in your public notices with the controls actually implemented, since the criteria typically evaluate whether the organization meets its stated privacy commitments.
For a Type II examination, ensure evidence demonstrates operating effectiveness of privacy-related controls across the entire defined review period, not just at a point in time.
Communicate to report users that a SOC 2 report covering Privacy attests only to the controls and period covered and does not guarantee freedom from breaches or cover activities outside the defined scope.
If you also pursue ISO 27001 or privacy-focused extensions, treat any mapping to the SOC 2 Privacy criteria as partial and validate each framework's requirements independently.