Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
SOC 2 (System and Organization Controls 2) is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates an organization's controls relevant to the Trust Services Criteria (TSC). The Privacy category is one of five TSC categories (Security, Availability, Processing Integrity, Confidentiality, and Privacy) and specifically addresses how the organization collects, uses, retains, discloses, and disposes of personal information in conformity with commitments in its privacy notice and with criteria set forth by the AICPA.
A SOC 2 Type II report covers a specified examination period (typically 6-12 months) during which the auditor (a licensed CPA firm) tests whether controls were not only designed appropriately (Type I) but also operated effectively throughout the period. For the Privacy TSC, this means demonstrating sustained compliance with criteria P1.0 through P8.1 as defined in TSP Section 100 (2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy).
Sentinel Compliance Group undergoes annual SOC 2 Type II examinations including the Privacy TSC to provide contractual assurance to enterprise clients in financial services, healthcare technology, and SaaS sectors.
Privacy Trust Services Criteria (P1.0 — P8.1)
P1.0 — Notice
Criterion: The entity provides notice to data subjects about its privacy practices.
P1.1: The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity's privacy practices, including changes in the use of personal information.
Required Controls:
Control ID
Control Description
Evidence Required
P1.1-01
Privacy notice is published on all data collection points (website, mobile app, paper forms)
Screenshots of privacy notices on all collection points, version history log
P1.1-02
Privacy notice describes: types of personal information collected, purposes of collection and use, categories of third parties to whom data is disclosed, data subject rights, retention periods
Privacy notice text, legal review records
P1.1-03
Privacy notice is reviewed and updated at minimum annually and when processing changes occur
Annual review meeting minutes, change log, approval records
P1.1-04
Material changes to privacy notice are communicated to affected data subjects via email or in-app notification prior to the change taking effect
Notification records, email delivery logs, communication templates
P1.1-05
Privacy notice is available in languages corresponding to the user base
Translated notice versions, translation vendor records
P1.2 — Choice and Consent
Criterion: The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information.
Required Controls:
Control ID
Control Description
Evidence Required
P1.2-01
Consent is obtained prior to or at the time of collection of personal information
Personal information is reviewed for accuracy on a periodic basis
Data quality review schedule, review results
P8.1 — Monitoring and Enforcement
Criterion: The entity monitors compliance with its privacy policies and procedures and has procedures to address privacy-related inquiries, complaints, and disputes.
Required Controls:
Control ID
Control Description
Evidence Required
P8.1-01
Privacy compliance monitoring is conducted at minimum quarterly
Compliance monitoring reports, finding logs
P8.1-02
A privacy complaint intake mechanism is available and publicized
Walkthrough of DSAR intake and fulfillment process
Demonstration of consent management platform
Demonstration of data deletion/anonymization processes
Walkthrough of privacy complaint handling
Demonstration of access control review process
Inspection
The auditor examines evidence artifacts:
Privacy notice versions and change logs
DSAR tracking spreadsheets or ticketing system records
Consent database records with timestamps
Data deletion job execution logs
Third-party DPA repository
Privacy training completion records
Privacy committee meeting minutes
Privacy risk assessment documentation
Reperformance
The auditor independently reperforms a control to verify its effectiveness:
Submit a test DSAR and verify the response process
Verify that retention period expiry triggers automated deletion
Verify that access controls prevent unauthorized access to personal information
Verify that privacy notice accurately reflects current processing activities
Report Review
Management Assertion
The service organization's management provides a written assertion that:
The system description is fairly presented
Controls were suitably designed (Type I and II)
Controls operated effectively throughout the examination period (Type II)
Auditor's Opinion
The auditor's report contains:
Unqualified (clean) opinion: Controls were suitably designed and operated effectively
Qualified opinion: One or more exceptions noted but controls are generally effective
Adverse opinion: Significant deficiencies exist in control design or operation
Disclaimer of opinion: Sufficient evidence could not be obtained
Exception Handling
When the auditor identifies exceptions during testing:
Deviation: A single instance where a control did not operate as designed (e.g., one DSAR exceeded the 30-day response window). The auditor documents the deviation and evaluates whether it represents a systematic failure.
Exception: A pattern of deviations or a significant individual deviation. Exceptions are described in the report with management's response.
Modified Opinion Threshold: Typically 3+ exceptions in a single control or exceptions across multiple controls in the same criterion may result in a qualified opinion for that criterion.
User Entity Considerations (Complementary User Entity Controls — CUECs)
The SOC 2 report identifies controls that user entities (customers) must implement for the system of controls to be effective. Privacy-related CUECs commonly include:
User entities are responsible for providing accurate personal information to the service organization
User entities are responsible for reviewing and approving data processing purposes
User entities are responsible for obtaining consent from their own data subjects before providing personal information to the service organization
User entities are responsible for notifying the service organization of DSARs that require the service organization's assistance
SOC 2 Privacy vs. GDPR Comparison
Aspect
SOC 2 Privacy TSC
GDPR
Regulatory nature
Voluntary attestation
Mandatory legislation
Scope
Service organization's system
All personal data processing
Enforcer
CPA auditor (AICPA standards)
Supervisory authorities
Consequence of failure
Qualified/adverse report
Fines up to EUR 20M or 4% global turnover
Coverage
Eight criteria (P1-P8)
99 articles, 173 recitals
Lawful basis
Not addressed (consent-focused)
Six lawful bases under Art. 6
Cross-border transfers
Not specifically addressed
Chapters V (Art. 44-49)
Data subject rights
Access and correction (P4)
Eight rights (Art. 15-22)
Breach notification
Covered under Security TSC
72-hour DPA notification, data subject notification
Sentinel Compliance Group SOC 2 Privacy Implementation
Sentinel Compliance Group maintains an annual SOC 2 Type II examination (12-month period, January 1 — December 31) including the Privacy TSC alongside Security and Confidentiality:
Examination Period: January 1, 2025 — December 31, 2025