Skip to content

09 Privacy

The Privacy Trust Services category focuses on how an organization collects, uses, retains, discloses, and disposes of personal information.

Unlike Confidentiality, which protects information designated as confidential, Privacy specifically concerns information related to individuals.

Examples include:

Employee Information
Customer Information
Contact Details
Identifiers
Account Information
Usage Data
Location Information
Support Records

The central question is:

Can the organization demonstrate that personal information is handled according to its privacy commitments and applicable processing requirements throughout the complete data lifecycle?

A practical privacy lifecycle looks like:

Privacy Governance
Notice
Collection
Consent / Authorization
Purpose
Use
Sharing
Individual Rights
Retention
Deletion
Incident Management
Evidence

For GRC professionals, Privacy combines governance, data inventories, legal obligations, system controls, third-party management, security, retention, and evidence into one assurance model.

By the end of this lesson, you will be able to:

  • Explain the SOC 2 Privacy category.

  • Distinguish Privacy from Confidentiality.

  • Establish privacy governance.

  • Identify personal information.

  • Build a PII inventory.

  • Understand privacy notices.

  • Govern collection of personal information.

  • Understand choice and consent.

  • Define processing purposes.

  • Apply purpose limitation.

  • Apply data minimization.

  • Govern use of personal information.

  • Support individual rights.

  • Govern third-party disclosure.

  • Assess processors and subprocessors.

  • Define privacy retention.

  • Establish deletion controls.

  • Manage privacy incidents.

  • Define privacy evidence.

  • Test privacy controls.

  • Build practical SOC 2 Privacy artifacts.

Privacy concerns how personal information is managed throughout its lifecycle.

The objective is not only:

Protect Data

but also:

Collect Appropriately
Use Appropriately
Share Appropriately
Retain Appropriately
Delete Appropriately

Personal information is information associated with or reasonably related to an individual.

Examples may include:

Name
Email Address
Phone Number
Employee ID
Customer ID
IP Address
Device Identifier
Account Information

Context and applicable requirements matter when determining whether information is personal.

Some personal information requires stronger protection.

Examples may include:

Financial Information
Government Identifiers
Authentication Information
Biometric Information
Health Information
Precise Location

The organization should identify categories relevant to its operations.

A simple distinction:

Confidentiality
→ Protect information designated confidential.
Privacy
→ Govern personal information throughout its lifecycle.

Example:

Source Code
→ Confidential
→ Not necessarily Privacy Data

while:

Employee Records
→ Personal Information
→ Usually Confidential

A privacy program should define:

Roles
Policies
Responsibilities
Processing Rules
Escalation
Oversight

Typical roles may include:

Privacy Officer
Privacy Governance
Legal
Legal Interpretation
Security
Data Protection
Business Owners
Processing Purpose
GRC
Control Assurance

A privacy policy may define organizational requirements for:

  • personal information collection.

  • use.

  • sharing.

  • retention.

  • deletion.

  • individual requests.

  • vendor processing.

  • privacy incidents.

The organization maintains documented privacy requirements governing the collection, use, disclosure, retention, and disposal of personal information.

Examples:

Approved Privacy Policy
Approval Record
Review History
Version

Determine:

Which Business Units?
Which Products?
Which Employees?
Which Customers?
Which Regions?
Which Systems?

Privacy cannot be governed effectively without defined scope.

Organizations should know:

What personal information exists?
Where is it stored?
Why is it processed?
Who owns it?
Who receives it?

Create:

01 PII Inventory

Use:

Data Subject System Purpose Owner Classification
Data Subject System Purpose
Employee Email Employee HR Platform Employment Administration
Customer Email Customer CRM Customer Communication
IP Address User Application Logs Security Monitoring

Possible sources include:

Data Catalog
Databases
SaaS Inventory
Cloud Storage
Logs
Application Documentation

Automated discovery may supplement manual inventories.

A privacy data-flow map shows how personal information moves.

Example:

Customer
Web Application
CRM
Analytics
Support Platform
Cloud Provider

It helps identify:

Storage Locations
Third Parties
Cross-Border Transfers
Subprocessors
Deletion Dependencies

Create:

02 Privacy Data Flow Map

Document:

Source
System
Transfer
Recipient
Purpose
Region

A privacy notice communicates relevant information about personal-data processing.

It may describe:

What Data Is Collected
Why
How Used
Who Receives It
Retention
Rights
Contact Information

Example:

Individuals are provided with privacy information describing relevant collection and processing practices in accordance with organizational commitments.

Examples:

Published Notice
Version History
Approval
Website Record

Privacy notices should reflect actual processing.

Weak model:

Privacy Notice
Says One Thing
Systems
Do Something Else

This creates assurance risk.

When processing changes:

New Data Collection
New Analytics
New AI Feature
New Third Party

the privacy notice may require review.

Organizations should collect personal information consistent with defined purposes.

Example:

Purpose:
Create Customer Account

Required:

Name
Email

Potentially unnecessary:

Passport Number

Personal information collected through organizational systems is limited to data required for defined and approved purposes.

The principle is:

Collect Only What Is Needed

and:

Retain Only As Long As Needed

Support ticket requires:

Customer ID
Issue
Contact Information

It may not require:

Full Banking History

Personal information collection and processing are limited to data necessary for approved business purposes.

Some processing activities may require:

Choice
Consent
Authorization
Preference

depending on commitments and applicable requirements.

A marketing service may ask:

Receive Marketing Emails?

Response:

Yes / No

The system should respect that decision.

Evidence may include:

Individual
Purpose
Choice
Timestamp
Source
Current Status

Create:

03 Consent & Preference Register

Use:

Subject Purpose Choice Date Status

If individuals can withdraw consent:

Withdraw
Update Preference
Stop Applicable Processing

Controls should ensure downstream systems are updated.

Personal information should be used for defined purposes.

Example:

Data Collected:
Customer Support

Using it later for:

Unrelated Marketing Campaign

may require additional assessment.

Create:

04 Processing Purpose Register

Use:

Processing Activity Personal Data Purpose Owner Systems

Personal information is processed only for documented and approved business purposes consistent with organizational privacy commitments.

Before changing how personal data is used:

New Purpose
Privacy Review
Legal / Policy Assessment
Approval

Existing purpose:

Customer Support

New initiative:

Train AI Model Using Support Conversations

This should trigger privacy review before processing changes.

Privacy should be considered during:

Product Design
Architecture
Vendor Selection
Feature Changes
Data Collection Changes

rather than only after deployment.

Examples:

New Product
New Personal Data
New Region
New Vendor
New AI Use
New Tracking Technology

Organizations may use a structured assessment to evaluate new or changed processing.

Possible fields:

Processing Activity
Data
Purpose
Risk
Controls
Third Parties
Retention
Approval

Controls should ensure personal information is accessed and used only for approved purposes.

This may involve:

Role-Based Access
Need to Know
Logging
Training

Example:

HR Employee Data
HR Team

not:

Entire Company

Access to personal information is limited to authorized users based on approved business need and job responsibility.

Examples:

Permission Report
Access Approval
Access Review
Role Mapping

Administrators may have indirect access to personal information.

Consider:

Database Administrators
Cloud Administrators
Support Administrators

These users should be included in the privacy control environment.

Sensitive personal-information access may require:

Access Logs
Administrative Logs
Download Logs
Export Logs

Depending on applicable commitments, individuals may have processes to request:

Access
Correction
Deletion
Restriction
Other Privacy Actions

A typical lifecycle:

Request Received
Identity Verification
Scope Request
Locate Data
Review
Respond
Evidence

Create:

05 Data Subject Request Register

Use:

Request ID Type Received Due Status Owner

Before releasing personal information:

Requester
Identity Verified?

Without verification, a privacy request itself can become a data breach.

Define internal timelines aligned to commitments and requirements.

Monitor:

Received
Due
Completed

Examples:

Request
Identity Verification
Search Results
Response
Closure Date

Organizations may need processes to maintain accurate personal information where relevant.

Example:

Employee Changes Address
HR Record Updated

A request may trigger:

Verify Request
Update Source System
Propagate Change

Personal information may be shared with:

Vendors
Business Partners
Cloud Providers
Subprocessors
Government Authorities

Disclosure should be governed.

Personal information is disclosed to third parties only for approved purposes and subject to applicable privacy, security, and contractual requirements.

Create:

06 Third-Party PII Sharing Register

Use:

Data Provider Purpose Location Contract Owner

For processors handling PII review:

Security Controls
Privacy Controls
SOC 2
ISO 27001
ISO 27018
Subprocessors
Incident Response

as appropriate.

Contracts may address:

Processing Instructions
Confidentiality
Security
Subprocessors
Incident Notification
Deletion
Return of Data

The organization should understand:

What Provider Does
What Customer Does
What Is Shared

Vendors may use additional service providers.

Example:

Company
HR SaaS
Cloud Provider
Support Provider

These relationships can affect privacy risk.

Track:

Provider
Subprocessor
Service
Data
Region

Personal information may cross geographic boundaries.

Example:

Customer Data
EU
US Analytics

Such transfers may require additional governance depending on applicable requirements.

Record:

Primary Location
Backup Location
Processing Location
Support Access

Cloud environments complicate privacy because data may exist across:

Primary Storage
Replication
Backup
Logs
Analytics
Support Systems

For SaaS platforms, review:

Data Collected
Purpose
Admins
Sharing
Retention
Deletion
Subprocessors

Personal information should not be retained indefinitely without justification.

Determine:

What Data?
Why Retained?
How Long?
Who Owns It?
How Deleted?

Create:

07 Privacy Retention Register

Use:

Data Purpose Retention Trigger Owner

Retention may be driven by:

Business Need
Contract
Law
Policy
Investigation
Legal Hold

Personal information is retained for defined periods based on approved business, legal, regulatory, and contractual requirements.

Where possible:

Retention Policy
System Configuration
Automated Deletion

reduces manual dependency.

Example:

Policy:
Delete after 3 years

Actual:

Database:
Retains indefinitely

This is an implementation gap.

When data is no longer required:

Retention Ends
Delete

unless a valid hold applies.

74. Deletion Is More Complex Than One Record

Section titled “74. Deletion Is More Complex Than One Record”

Personal information may exist in:

Primary Database
Backups
Logs
Exports
SaaS
Analytics
Data Warehouse

Deletion design should account for the architecture.

Personal information is securely deleted or anonymized when approved retention periods expire and no valid legal or business hold applies.

Examples:

Deletion Ticket
System Log
Automated Job
Provider Confirmation
Closure Record

When a SaaS service is terminated:

Export Required Data
Remove Access
Request Deletion
Confirm Completion

Some backup technologies delete data through:

Retention Expiry

rather than immediate record-level deletion.

This should be documented and understood.

Some processing may use:

Anonymized Data

to reduce privacy risk.

The method should prevent reasonable re-identification according to the intended use.

Pseudonymization reduces direct identification but may still involve personal information.

Example:

Customer Name
Token ID

If the mapping exists, the data may still be linked back to a person.

Examples include:

Wrong Recipient
Unauthorized Account Access
Lost Device
Public Database
Improper Sharing
Unauthorized Use
Detect
Contain
Identify Personal Data
Identify Individuals
Assess Impact
Escalate
Notify if Required
Remediate

Ask:

What happened?
What PII?
How many individuals?
Was data encrypted?
Who accessed it?
Which regions?
Which customers?

Incidents involving personal information are identified, investigated, escalated, documented, and handled according to the approved privacy and security incident process.

Depending on commitments and applicable requirements:

Incident
Assessment
Notification Decision

may involve:

Customers
Individuals
Regulators
Management

Examples:

Incident Record
Impact Assessment
Decision Record
Communication
Root Cause
Corrective Action

Organizations may monitor:

Bulk PII Downloads
PII Exports
Public Sharing
Unusual Access
Retention Failures
Unauthorized Processing

A mature model may combine:

IAM
DLP
Data Discovery
SIEM
Privacy Workflows

Create:

08 Privacy Evidence Matrix

Use:

Control Evidence Source Frequency Owner

Examples:

PII Register
Data Flow Map
Data Catalog

Examples:

Privacy Notice
Version History
Approval

Examples:

Consent Record
Preference Log
Withdrawal Record

Examples:

Processing Register
Privacy Review
Product Documentation

Examples:

Request Register
Verification
Response
Closure

Examples:

Vendor Assessment
DPA
Subprocessor Register
Security Assurance

Examples:

Retention Schedule
System Configuration
Deletion Report

Examples:

Privacy Incident Register
Impact Assessment
Notification Decision
Corrective Action

Create:

09 Privacy Control Matrix

Use:

Control ID Risk Control Owner Evidence
PRIV-001
Privacy Governance
PRIV-002
PII Inventory
PRIV-003
Privacy Notice
PRIV-004
Data Minimization
PRIV-005
Processing Purpose
PRIV-006
Consent & Preferences
PRIV-007
PII Access
PRIV-008
Individual Rights
PRIV-009
Third-Party PII Processing
PRIV-010
Subprocessor Governance
PRIV-011
Retention
PRIV-012
PII Deletion
PRIV-013
Privacy Incident Management
PRIV-014
Privacy Monitoring

Privacy responsibilities, policies, processing requirements, and oversight mechanisms are formally defined and periodically reviewed.

Personal-information categories, processing systems, purposes, owners, and relevant data flows are maintained in an approved inventory.

Privacy notices accurately describe applicable personal-information collection, use, disclosure, retention, and individual-right practices.

Personal information collected and processed is limited to data required for approved purposes.

Personal information is processed only for documented and approved purposes.

Where required by organizational commitments, applicable choices and preferences are captured, maintained, and enforced.

Access to personal information is restricted based on authorized business need and job responsibility.

Requests relating to personal information are authenticated, tracked, processed, and completed according to defined requirements.

Third parties processing personal information undergo appropriate privacy and security review and are subject to defined contractual requirements.

Material subprocessors are identified, assessed, and monitored according to applicable privacy requirements.

Personal information is retained according to approved retention requirements.

Personal information is deleted or appropriately de-identified when retention requirements expire and no authorized hold applies.

112. PRIV-013 — Privacy Incident Management

Section titled “112. PRIV-013 — Privacy Incident Management”

Privacy incidents are identified, investigated, escalated, and managed according to documented procedures.

Material events involving personal-information access, sharing, retention, or processing are monitored according to risk.

For each privacy control define:

Requirement
Population
Sample
Evidence
Test Procedure
Exceptions
Conclusion

Select systems known to process PII.

Verify:

System Listed?
Data Listed?
Purpose Listed?
Owner Listed?
Data Flow Known?

Compare published privacy notice against actual processing.

Example:

Notice:
No Analytics Sharing

Actual:

Customer Data Sent to Analytics Provider

Potential gap.

Select forms or applications collecting PII.

Ask:

Is every field necessary?

Identify unnecessary data collection.

Sample processing activities.

Verify:

Purpose Documented?
Approved?
Actual Use Matches?

Where applicable:

Consent Required?
Captured?
Timestamped?
Current?
Withdrawal Enforced?

For selected systems:

Users
Roles
Approvals
Need to Know
Access Review

Sample requests.

Verify:

Identity Verified
Request Completed
Timely
Evidence Retained

Select providers receiving PII.

Verify:

Purpose
Risk Assessment
Contract
Security Review
Subprocessors

Select datasets.

Compare:

Required Retention
vs
Actual System Configuration

Sample completed deletion cases.

Verify:

Request / Trigger
Systems Identified
Deletion Performed
Evidence
Provider Action

Select privacy-related incidents.

Trace:

Detection
Assessment
Escalation
Decision
Notification
Closure

Ask:

If this privacy control operates exactly as designed, will it reasonably achieve the intended privacy objective?

Example:

Risk:

Excessive PII Collection

Control:

Developers decide individually
what fields to collect.

This may be poorly designed.

Better:

Defined Data Collection Standard
+
Privacy Review
+
Approved Purpose

Example control:

Annual Privacy Review for Critical Vendors

Population:

25 Critical PII Vendors

Completed:

22

Conclusion:

Partially Effective

Automation may help identify:

All SaaS Applications With PII
All PII Repositories
All Expired Retention Records
All External Sharing Events

Manual privacy controls may include:

Privacy Reviews
DSR Processing
Vendor Assessments
Deletion Approvals
Consent Reviews

Three production applications processing customer personal information were not recorded in the approved PII inventory.

Risk:

Unknown Processing
Unmanaged Retention
Unassessed Third Parties

131. Privacy Finding — Data Minimization

Section titled “131. Privacy Finding — Data Minimization”

The customer registration form collects date-of-birth information despite no documented business requirement for processing that field.

Customer support conversations collected for service delivery were subsequently used for analytics without documented privacy review or approved purpose change.

133. Privacy Finding — Individual Rights

Section titled “133. Privacy Finding — Individual Rights”

Four individual-access requests were completed beyond the organization’s defined response timeline.

A marketing provider receives customer contact information without a current privacy/security assessment.

Personal information associated with inactive customer accounts remains in the CRM beyond the approved retention period.

Customer deletion requests remove information from the primary application but do not trigger deletion from the analytics warehouse.

Example:

Expired PII Remains
Retention Policy Exists
CRM Has No Automated Deletion
Manual Process Never Assigned

Root cause:

The CRM retention requirement has not been translated into an operational deletion process with assigned ownership.

Delete Expired Records
Implement Automated Retention
+
Assign Owner
+
Create Monitoring

A privacy exception should include:

Requirement
Business Need
Risk
Compensating Controls
Approval
Expiry
Remediation

Avoid indefinite exceptions where possible.

Useful metrics include:

PII Inventory Coverage
Privacy Reviews Completed
DSR Completion
Overdue DSRs
Critical PII Vendors Reviewed
Expired PII Records
Privacy Incidents
Open Privacy Findings
Metric Target Current
PII Inventory Coverage 100% 96%
DSR Completion Within Target 100% 97%
Critical PII Vendor Reviews 100% 92%
Expired PII Records 0 240
Open High Privacy Findings 0 2

Example:

KPI:
Percentage of personal-data processing
activities recorded in the PII inventory

Example:

KRI:
Number of overdue personal-data deletion actions

Example:

Overdue individual privacy requests

Tolerance may be:

0

Example:

Critical PII processors
without current assessment

Auditor selects:

Customer Registration Process

Trace:

Data Collected
Purpose
Privacy Notice
System Processing

Verify alignment.

Auditor selects:

CRM

Review:

Data Categories
Purpose
Owner
Location
Third Parties
Retention

149. Audit Walkthrough — Individual Request

Section titled “149. Audit Walkthrough — Individual Request”

Auditor selects:

Access Request DSR-102

Trace:

Request
Identity Verification
Search
Response
Closure

150. Audit Walkthrough — Vendor Processing

Section titled “150. Audit Walkthrough — Vendor Processing”

Auditor selects:

HR SaaS

Review:

PII
Purpose
Contract
Security Review
Subprocessors
Retention
Deletion

Auditor selects:

Former Customer Records

Verify:

Retention Requirement
System Configuration
Deletion Evidence

Security alone does not govern purpose, notice, rights, or retention.

Mistake 2 — Privacy Equals Confidentiality

Section titled “Mistake 2 — Privacy Equals Confidentiality”

Not all privacy requirements are confidentiality requirements.

Unknown processing remains unmanaged.

Mistake 4 — Privacy Notice Not Matched to Reality

Section titled “Mistake 4 — Privacy Notice Not Matched to Reality”

Actual processing exceeds disclosed practices.

Data minimization is ignored.

Mistake 6 — Purpose Changes Without Review

Section titled “Mistake 6 — Purpose Changes Without Review”

Data is reused without governance.

Mistake 7 — DSR Process Depends on Manual Email

Section titled “Mistake 7 — DSR Process Depends on Manual Email”

Requests can be missed or delayed.

Mistake 8 — Vendors Reviewed Only for Security

Section titled “Mistake 8 — Vendors Reviewed Only for Security”

Privacy processing risks are ignored.

Mistake 9 — Retention Policy Exists but Is Not Enforced

Section titled “Mistake 9 — Retention Policy Exists but Is Not Enforced”

PII remains indefinitely.

Mistake 10 — Deletion Covers Only Primary Application

Section titled “Mistake 10 — Deletion Covers Only Primary Application”

Analytics, SaaS, exports, and backups are ignored.

Privacy Policy
+
Security Controls
=
Assume Privacy
Governance
PII Inventory
Notice
Purpose
Collection
Minimization
Use
Access
Sharing
Individual Rights
Retention
Deletion
Incident Management
Evidence

155. Practical Activity — Build Privacy Control Matrix

Section titled “155. Practical Activity — Build Privacy Control Matrix”

Create:

01 Privacy Control Matrix

Include at least 15 controls across:

Governance
Inventory
Notice
Collection
Purpose
Consent
Access
Individual Rights
Third Parties
Retention
Deletion
Incident Management

156. Practical Activity — Build PII Inventory

Section titled “156. Practical Activity — Build PII Inventory”

Create:

02 PII Inventory

Add at least 20 fictional personal-information categories across:

HR
CRM
Support
Marketing
Application
Security Logs
SaaS

157. Practical Activity — Build Processing Purpose Register

Section titled “157. Practical Activity — Build Processing Purpose Register”

Create:

03 Processing Purpose Register

Use:

Processing Activity Data Purpose Owner Status

158. Practical Activity — Build Consent Register

Section titled “158. Practical Activity — Build Consent Register”

Create:

04 Consent & Preference Register

Track fictional:

Marketing Consent
Cookie Preference
Communication Preference

159. Practical Activity — Build Data Subject Request Register

Section titled “159. Practical Activity — Build Data Subject Request Register”

Create:

05 Data Subject Request Register

Add examples for:

Access
Correction
Deletion

160. Practical Activity — Build Third-Party PII Sharing Register

Section titled “160. Practical Activity — Build Third-Party PII Sharing Register”

Create:

06 Third-Party PII Sharing Register

Include:

HR Provider
CRM Provider
Analytics Provider
Support Platform
Cloud Provider

161. Practical Activity — Build Privacy Retention Register

Section titled “161. Practical Activity — Build Privacy Retention Register”

Create:

07 Privacy Retention Register

Include at least ten PII categories.

162. Practical Activity — Build Privacy Evidence Matrix

Section titled “162. Practical Activity — Build Privacy Evidence Matrix”

Create:

08 Privacy Evidence Matrix

Map evidence for:

Inventory
Notice
Consent
Purpose
Access
DSRs
Third Parties
Retention
Deletion
Incidents

163. Practical Activity — Build Privacy Control Testing Checklist

Section titled “163. Practical Activity — Build Privacy Control Testing Checklist”

Create:

09 Privacy Control Testing Checklist

Test:

PII Inventory
Privacy Notice
Data Minimization
Purpose Limitation
Consent
PII Access
Individual Requests
Third-Party Processing
Retention
Deletion
Privacy Incident Response
  • Privacy policy established.

  • Privacy roles defined.

  • Ownership established.

  • Privacy review triggers defined.

  • PII categories identified.

  • Systems identified.

  • Purposes documented.

  • Owners identified.

  • Data flows mapped.

  • Third parties identified.

  • Privacy notices documented.

  • Notices match actual processing.

  • Changes are reviewed.

  • Collection purpose defined.

  • Data minimization applied.

  • Unnecessary fields avoided.

  • Required preferences captured.

  • Evidence retained.

  • Withdrawals enforced.

  • Processing purpose documented.

  • New uses reviewed.

  • Access restricted.

  • Request process established.

  • Identity verification implemented.

  • Requests tracked.

  • Deadlines monitored.

  • Evidence retained.

  • PII processors identified.

  • Privacy/security assessments performed.

  • Contracts established.

  • Subprocessors identified.

  • Data locations reviewed.

  • Retention requirements defined.

  • System configuration aligned.

  • Holds supported.

  • Expired PII identified.

  • Deletion workflow established.

  • SaaS included.

  • Analytics included.

  • Backups considered.

  • Evidence retained.

  • Privacy incidents identified.

  • Escalation defined.

  • Impact assessment established.

  • Notification decision documented.

  • Corrective actions tracked.

A GRC professional supporting SOC 2 Privacy may:

  • Maintain privacy-control mappings.

  • Maintain PII inventories.

  • Coordinate data-flow mapping.

  • Review processing purposes.

  • Review privacy notices.

  • Support consent governance.

  • Review data minimization.

  • Monitor individual-right requests.

  • Assess third-party privacy controls.

  • Maintain subprocessor inventories.

  • Review retention requirements.

  • Review deletion evidence.

  • Test privacy controls.

  • Document findings.

  • Facilitate remediation.

  • Maintain privacy dashboards.

  • Support external SOC auditors.

GRC connects:

Privacy
Legal
Security
IAM
Engineering
Product
HR
Marketing
Procurement
Vendors
Auditors
Privacy Issues
Handled Case by Case
Privacy Policy
PII Inventory
Request Process
Purpose Register
Vendor Governance
Retention
Deletion
Automated Discovery
Privacy Workflows
Metrics
Monitoring
Continuous Data Discovery
Automated Retention
Privacy-by-Design Workflows
Continuous Evidence
Dynamic Risk Signals

For every personal-information processing activity ask:

What personal information are we processing?
Whose information is it?
Why do we need it?
Did we disclose the processing appropriately?
Do we need consent or preference management?
Are we collecting more than necessary?
Who can access it?
Are administrators included?
Which systems receive it?
Which third parties receive it?
Where is it processed?
How long should it be retained?
How will individuals exercise relevant rights?
How will the data be deleted?
What happens if processing changes?
What happens if there is an incident?
What evidence proves the controls operate?

When these questions can be answered, Privacy becomes an operational governance program rather than merely a published privacy notice.

  • Privacy governs personal information throughout its lifecycle.

  • Privacy and Confidentiality overlap but are not the same.

  • A PII inventory is foundational to privacy governance.

  • Data-flow mapping helps identify systems, locations, providers, and subprocessors.

  • Privacy notices should accurately reflect actual processing.

  • Collection should be connected to defined purposes.

  • Data minimization reduces unnecessary privacy risk.

  • Processing-purpose changes should trigger review.

  • Consent and preferences should be captured and enforced where applicable.

  • Access to PII should follow business need and least privilege.

  • Individual-right requests require identity verification, tracking, response, and evidence.

  • Third-party processors and subprocessors should be governed through privacy, security, and contractual controls.

  • Retention should define how long personal information is needed.

  • Deletion should address all relevant systems and providers.

  • Privacy incidents require structured impact assessment and escalation.

  • SOC 2 Privacy assurance requires controls, evidence, testing, monitoring, and remediation across the full personal-information lifecycle.

Before continuing, make sure you can answer:

  1. What does SOC 2 Privacy address?

  2. How is Privacy different from Confidentiality?

  3. What is a PII inventory?

  4. Why is data-flow mapping important?

  5. What should a privacy notice describe?

  6. What is data minimization?

  7. What is purpose limitation?

  8. Why should new processing purposes be reviewed?

  9. What role can consent or preferences play?

  10. Why should privileged access to PII be considered?

  11. What is a data subject request?

  12. Why is identity verification important?

  13. How should third-party PII processing be governed?

  14. What is a subprocessor?

  15. Why does data location matter?

  16. Why should retention be operationalized?

  17. Why can deletion be complex?

  18. What should a privacy incident assessment consider?

  19. What evidence supports Privacy controls?

  20. What role does GRC play in SOC 2 Privacy?

➡️ Next: 10 — SOC Type I vs Type II

In the next lesson, you will bring the SOC reporting concepts together and examine the practical differences between Type I and Type II reports, including:

Point-in-Time Assurance
Period-of-Time Assurance
Control Design
Control Implementation
Operating Effectiveness
Control Population
Sampling
Exceptions
Report Period
Audit Reliance

You will also build practical artifacts including a Type I vs Type II Comparison Matrix, SOC Report Period Register, Control Operating Period Matrix, Evidence Coverage Register, Exception Impact Matrix, and SOC Report Selection Checklist.