Privacy Criteria (P1-P8)
The Privacy Criteria are one of the optional categories organizations can include in a SOC 2 examination, focused on how personal information is handled throughout its lifecycle. They are organized into eight series labeled P1 through P8, covering topics such as giving notice to individuals, obtaining consent, and managing the collection, use, retention, disposal, access, and disclosure of personal data. Because Privacy is optional rather than required, it is included only when it falls within the defined scope of the engagement.
Within the AICPA Trust Services Criteria, Privacy is an optional category (distinct from the required Security/Common Criteria) that an organization may elect based on scope. The Privacy Criteria are structured across series P1 through P8, addressing, depending on the specific criteria selected, notice and communication of privacy objectives, choice and consent, collection, use, retention and disposal, access, disclosure to third parties, and related areas of personal information management. These criteria typically center on commitments made to data subjects and are most applicable where the organization acts in a controller-type role; processors often address privacy-related concerns primarily through the Confidentiality category. Selecting Privacy adds it to the controls assessed in the SOC 2 report, which attests only to the controls and period covered and does not, by itself, satisfy separate legal regimes or other frameworks. The Privacy Criteria should not be conflated with ISO/IEC 27001 Annex A controls or with the NIST Privacy Framework, which uses its own distinct 'P' designations.
Why it matters
Personal information handling has become one of the most scrutinized aspects of vendor and service provider relationships, and the Privacy Criteria give organizations a structured way to demonstrate how they manage personal data across its lifecycle within a SOC 2 examination. Because Privacy is an optional category rather than the required Security (Common Criteria), including it signals a deliberate commitment to addressing notice, consent, collection, use, retention, disposal, access, and disclosure of personal information, concerns that increasingly drive customer due diligence, contract negotiations, and risk assessments.
For organizations that act in a controller-type role and make direct commitments to data subjects, the Privacy Criteria provide a way to evidence that those commitments are backed by controls that a CPA firm has examined. This can matter significantly when customers or partners want assurance about privacy practices but are evaluating a service provider through a single attestation report rather than requesting separate privacy audits. However, it is important to understand the boundary of what a SOC 2 report provides: it attests only to the controls and the period covered by the examination and does not, by itself, satisfy separate legal privacy regimes or other frameworks. Selecting the Privacy Criteria demonstrates alignment with defined privacy commitments; it is not a substitute for compliance with applicable law.
Misunderstanding what the Privacy Criteria cover can also create risk. They should not be conflated with ISO/IEC 27001 Annex A controls or with the NIST Privacy Framework, which uses its own distinct 'P' designations for entirely different purposes. Treating these as interchangeable can lead to gaps in scoping decisions and to misplaced confidence that one framework's outcome automatically covers another's requirements.
Who it's relevant to
Inside P1-P8
Common questions
Answers to the questions practitioners most commonly ask about P1-P8.