PDOC-01

If you have completed a SOC 2 audit, does it include the Privacy Trust Service Principle?

Explanation

This question is asking whether your organization's SOC 2 audit specifically included the Privacy Trust Service Principle. SOC 2 (Service Organization Control 2) is a framework for auditing a company's controls related to data security and privacy. SOC 2 audits can be conducted against five different Trust Service Principles: Security (also called Common Criteria), Availability, Processing Integrity, Confidentiality, and Privacy. Companies can choose which principles to include in their audit based on their business needs and customer requirements. The Privacy Trust Service Principle specifically focuses on how an organization collects, uses, retains, discloses, and disposes of personal information. It evaluates whether the organization's privacy practices align with its privacy notice and with the AICPA's Generally Accepted Privacy Principles (GAPP). This question is being asked in a security assessment because the assessor wants to understand the scope of your SOC 2 audit and whether it specifically evaluated your privacy controls. Many organizations only include the Security principle (which is mandatory) and perhaps one or two others, but not necessarily Privacy. Including the Privacy principle demonstrates a higher level of commitment to protecting personal information and indicates that your privacy controls have been independently verified. To best answer this question, you should: 1. Confirm whether your organization has completed a SOC 2 audit 2. If yes, check which Trust Service Principles were included in the scope 3. Specifically indicate whether the Privacy principle was included 4. If you're unsure, consult your SOC 2 report or speak with your compliance team

Guidance

SOC 2 Type II audits can be conducted for any or all of five trust principles (confidentiality, integrity, availability, security, and privacy). Answer "yes" if your audit included the privacy principle.

Example Responses

Example Response 1

Yes, our organization has completed a SOC 2 Type II audit that includes the Privacy Trust Service Principle Our most recent audit was completed in March 2023 and covers all five Trust Service Principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy The Privacy principle assessment verified our controls for the collection, use, retention, disclosure, and disposal of personal information in accordance with our privacy notice and the AICPA's Generally Accepted Privacy Principles.

Example Response 2

Yes, we have a SOC 2 Type II audit that includes the Privacy Trust Service Principle While our initial SOC 2 audit in 2021 only covered the Security and Availability principles, we expanded our scope in 2022 to include Privacy due to the increasing amount of personal data we process Our auditors specifically evaluated our privacy notice, consent mechanisms, data minimization practices, and our procedures for responding to data subject requests.

Example Response 3

No, our SOC 2 Type II audit does not currently include the Privacy Trust Service Principle Our audit covers the Security (Common Criteria), Availability, and Confidentiality principles, which were determined to be most relevant to our business operations and customer requirements While we maintain robust privacy controls aligned with GDPR and CCPA requirements, these controls have not been formally assessed under the SOC 2 Privacy principle We are considering expanding our SOC 2 scope to include the Privacy principle in our next audit cycle based on evolving customer needs and regulatory requirements.

Context

Tab
Privacy
Category
General Privacy

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron