If you have completed a SOC 2 audit, does it include the Privacy Trust Service Principle?
Explanation
Guidance
SOC 2 Type II audits can be conducted for any or all of five trust principles (confidentiality, integrity, availability, security, and privacy). Answer "yes" if your audit included the privacy principle.
Example Responses
Example Response 1
Yes, our organization has completed a SOC 2 Type II audit that includes the Privacy Trust Service Principle Our most recent audit was completed in March 2023 and covers all five Trust Service Principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy The Privacy principle assessment verified our controls for the collection, use, retention, disclosure, and disposal of personal information in accordance with our privacy notice and the AICPA's Generally Accepted Privacy Principles.
Example Response 2
Yes, we have a SOC 2 Type II audit that includes the Privacy Trust Service Principle While our initial SOC 2 audit in 2021 only covered the Security and Availability principles, we expanded our scope in 2022 to include Privacy due to the increasing amount of personal data we process Our auditors specifically evaluated our privacy notice, consent mechanisms, data minimization practices, and our procedures for responding to data subject requests.
Example Response 3
No, our SOC 2 Type II audit does not currently include the Privacy Trust Service Principle Our audit covers the Security (Common Criteria), Availability, and Confidentiality principles, which were determined to be most relevant to our business operations and customer requirements While we maintain robust privacy controls aligned with GDPR and CCPA requirements, these controls have not been formally assessed under the SOC 2 Privacy principle We are considering expanding our SOC 2 scope to include the Privacy principle in our next audit cycle based on evolving customer needs and regulatory requirements.
Context
- Tab
- Privacy
- Category
- General Privacy

