09 Privacy
The Privacy Trust Services category focuses on how an organization collects, uses, retains, discloses, and disposes of personal information.
Unlike Confidentiality, which protects information designated as confidential, Privacy specifically concerns information related to individuals.
Examples include:
Employee Information
Customer Information
Contact Details
Identifiers
Account Information
Usage Data
Location Information
Support RecordsThe central question is:
Can the organization demonstrate that personal information is handled according to its privacy commitments and applicable processing requirements throughout the complete data lifecycle?
A practical privacy lifecycle looks like:
Privacy Governance ↓Notice ↓Collection ↓Consent / Authorization ↓Purpose ↓Use ↓Sharing ↓Individual Rights ↓Retention ↓Deletion ↓Incident Management ↓EvidenceFor GRC professionals, Privacy combines governance, data inventories, legal obligations, system controls, third-party management, security, retention, and evidence into one assurance model.
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the SOC 2 Privacy category.
-
Distinguish Privacy from Confidentiality.
-
Establish privacy governance.
-
Identify personal information.
-
Build a PII inventory.
-
Understand privacy notices.
-
Govern collection of personal information.
-
Understand choice and consent.
-
Define processing purposes.
-
Apply purpose limitation.
-
Apply data minimization.
-
Govern use of personal information.
-
Support individual rights.
-
Govern third-party disclosure.
-
Assess processors and subprocessors.
-
Define privacy retention.
-
Establish deletion controls.
-
Manage privacy incidents.
-
Define privacy evidence.
-
Test privacy controls.
-
Build practical SOC 2 Privacy artifacts.
1. What Is Privacy?
Section titled “1. What Is Privacy?”Privacy concerns how personal information is managed throughout its lifecycle.
The objective is not only:
Protect Databut also:
Collect Appropriately
Use Appropriately
Share Appropriately
Retain Appropriately
Delete Appropriately2. What Is Personal Information?
Section titled “2. What Is Personal Information?”Personal information is information associated with or reasonably related to an individual.
Examples may include:
Name
Email Address
Phone Number
Employee ID
Customer ID
IP Address
Device Identifier
Account InformationContext and applicable requirements matter when determining whether information is personal.
3. Sensitive Personal Information
Section titled “3. Sensitive Personal Information”Some personal information requires stronger protection.
Examples may include:
Financial Information
Government Identifiers
Authentication Information
Biometric Information
Health Information
Precise LocationThe organization should identify categories relevant to its operations.
4. Privacy vs Confidentiality
Section titled “4. Privacy vs Confidentiality”A simple distinction:
Confidentiality→ Protect information designated confidential.
Privacy→ Govern personal information throughout its lifecycle.Example:
Source Code→ Confidential→ Not necessarily Privacy Datawhile:
Employee Records→ Personal Information→ Usually Confidential5. Privacy Governance
Section titled “5. Privacy Governance”A privacy program should define:
Roles
Policies
Responsibilities
Processing Rules
Escalation
Oversight6. Privacy Ownership
Section titled “6. Privacy Ownership”Typical roles may include:
Privacy Officer ↓Privacy Governance
Legal ↓Legal Interpretation
Security ↓Data Protection
Business Owners ↓Processing Purpose
GRC ↓Control Assurance7. Privacy Policy
Section titled “7. Privacy Policy”A privacy policy may define organizational requirements for:
-
personal information collection.
-
use.
-
sharing.
-
retention.
-
deletion.
-
individual requests.
-
vendor processing.
-
privacy incidents.
8. Privacy Control Example
Section titled “8. Privacy Control Example”The organization maintains documented privacy requirements governing the collection, use, disclosure, retention, and disposal of personal information.
9. Privacy Policy Evidence
Section titled “9. Privacy Policy Evidence”Examples:
Approved Privacy Policy
Approval Record
Review History
Version10. Privacy Program Scope
Section titled “10. Privacy Program Scope”Determine:
Which Business Units?
Which Products?
Which Employees?
Which Customers?
Which Regions?
Which Systems?Privacy cannot be governed effectively without defined scope.
11. PII Inventory
Section titled “11. PII Inventory”Organizations should know:
What personal information exists?
Where is it stored?
Why is it processed?
Who owns it?
Who receives it?12. Build PII Inventory
Section titled “12. Build PII Inventory”Create:
01 PII InventoryUse:
| Data | Subject | System | Purpose | Owner | Classification |
|---|
13. Example PII Inventory
Section titled “13. Example PII Inventory”| Data | Subject | System | Purpose |
|---|---|---|---|
| Employee Email | Employee | HR Platform | Employment Administration |
| Customer Email | Customer | CRM | Customer Communication |
| IP Address | User | Application Logs | Security Monitoring |
14. Data Discovery
Section titled “14. Data Discovery”Possible sources include:
Data Catalog
Databases
SaaS Inventory
Cloud Storage
Logs
Application DocumentationAutomated discovery may supplement manual inventories.
15. Data Mapping
Section titled “15. Data Mapping”A privacy data-flow map shows how personal information moves.
Example:
Customer ↓Web Application ↓CRM ↓Analytics ↓Support Platform ↓Cloud Provider16. Why Data Mapping Matters
Section titled “16. Why Data Mapping Matters”It helps identify:
Storage Locations
Third Parties
Cross-Border Transfers
Subprocessors
Deletion Dependencies17. Build Privacy Data Flow
Section titled “17. Build Privacy Data Flow”Create:
02 Privacy Data Flow MapDocument:
Source
System
Transfer
Recipient
Purpose
Region18. Privacy Notice
Section titled “18. Privacy Notice”A privacy notice communicates relevant information about personal-data processing.
It may describe:
What Data Is Collected
Why
How Used
Who Receives It
Retention
Rights
Contact Information19. Notice Control
Section titled “19. Notice Control”Example:
Individuals are provided with privacy information describing relevant collection and processing practices in accordance with organizational commitments.
20. Notice Evidence
Section titled “20. Notice Evidence”Examples:
Published Notice
Version History
Approval
Website Record21. Notice Accuracy
Section titled “21. Notice Accuracy”Privacy notices should reflect actual processing.
Weak model:
Privacy Notice ↓Says One Thing
Systems ↓Do Something ElseThis creates assurance risk.
22. Notice Change Management
Section titled “22. Notice Change Management”When processing changes:
New Data Collection
New Analytics
New AI Feature
New Third Partythe privacy notice may require review.
23. Collection
Section titled “23. Collection”Organizations should collect personal information consistent with defined purposes.
Example:
Purpose:Create Customer AccountRequired:
Name
EmailPotentially unnecessary:
Passport Number24. Collection Control
Section titled “24. Collection Control”Personal information collected through organizational systems is limited to data required for defined and approved purposes.
25. Data Minimization
Section titled “25. Data Minimization”The principle is:
Collect Only What Is Neededand:
Retain Only As Long As Needed26. Minimization Example
Section titled “26. Minimization Example”Support ticket requires:
Customer ID
Issue
Contact InformationIt may not require:
Full Banking History27. Data Minimization Control
Section titled “27. Data Minimization Control”Personal information collection and processing are limited to data necessary for approved business purposes.
28. Choice and Consent
Section titled “28. Choice and Consent”Some processing activities may require:
Choice
Consent
Authorization
Preferencedepending on commitments and applicable requirements.
29. Consent Example
Section titled “29. Consent Example”A marketing service may ask:
Receive Marketing Emails?Response:
Yes / NoThe system should respect that decision.
30. Consent Record
Section titled “30. Consent Record”Evidence may include:
Individual
Purpose
Choice
Timestamp
Source
Current Status31. Build Consent Register
Section titled “31. Build Consent Register”Create:
03 Consent & Preference RegisterUse:
| Subject | Purpose | Choice | Date | Status |
|---|
32. Consent Withdrawal
Section titled “32. Consent Withdrawal”If individuals can withdraw consent:
Withdraw ↓Update Preference ↓Stop Applicable ProcessingControls should ensure downstream systems are updated.
33. Purpose Limitation
Section titled “33. Purpose Limitation”Personal information should be used for defined purposes.
Example:
Data Collected:Customer SupportUsing it later for:
Unrelated Marketing Campaignmay require additional assessment.
34. Processing Purpose Register
Section titled “34. Processing Purpose Register”Create:
04 Processing Purpose RegisterUse:
| Processing Activity | Personal Data | Purpose | Owner | Systems |
|---|
35. Purpose Control
Section titled “35. Purpose Control”Personal information is processed only for documented and approved business purposes consistent with organizational privacy commitments.
36. Purpose Change
Section titled “36. Purpose Change”Before changing how personal data is used:
New Purpose ↓Privacy Review ↓Legal / Policy Assessment ↓Approval37. New Technology Example
Section titled “37. New Technology Example”Existing purpose:
Customer SupportNew initiative:
Train AI Model Using Support ConversationsThis should trigger privacy review before processing changes.
38. Privacy by Design
Section titled “38. Privacy by Design”Privacy should be considered during:
Product Design
Architecture
Vendor Selection
Feature Changes
Data Collection Changesrather than only after deployment.
39. Privacy Review Trigger
Section titled “39. Privacy Review Trigger”Examples:
New Product
New Personal Data
New Region
New Vendor
New AI Use
New Tracking Technology40. Privacy Impact Assessment
Section titled “40. Privacy Impact Assessment”Organizations may use a structured assessment to evaluate new or changed processing.
Possible fields:
Processing Activity
Data
Purpose
Risk
Controls
Third Parties
Retention
Approval41. Use of Personal Information
Section titled “41. Use of Personal Information”Controls should ensure personal information is accessed and used only for approved purposes.
This may involve:
Role-Based Access
Need to Know
Logging
Training42. Access to PII
Section titled “42. Access to PII”Example:
HR Employee Data ↓HR Teamnot:
Entire Company43. PII Access Control
Section titled “43. PII Access Control”Access to personal information is limited to authorized users based on approved business need and job responsibility.
44. PII Access Evidence
Section titled “44. PII Access Evidence”Examples:
Permission Report
Access Approval
Access Review
Role Mapping45. Privileged PII Access
Section titled “45. Privileged PII Access”Administrators may have indirect access to personal information.
Consider:
Database Administrators
Cloud Administrators
Support AdministratorsThese users should be included in the privacy control environment.
46. PII Access Logging
Section titled “46. PII Access Logging”Sensitive personal-information access may require:
Access Logs
Administrative Logs
Download Logs
Export Logs47. Individual Rights
Section titled “47. Individual Rights”Depending on applicable commitments, individuals may have processes to request:
Access
Correction
Deletion
Restriction
Other Privacy Actions48. Data Subject Request
Section titled “48. Data Subject Request”A typical lifecycle:
Request Received ↓Identity Verification ↓Scope Request ↓Locate Data ↓Review ↓Respond ↓Evidence49. Build Data Subject Request Register
Section titled “49. Build Data Subject Request Register”Create:
05 Data Subject Request RegisterUse:
| Request ID | Type | Received | Due | Status | Owner |
|---|
50. Identity Verification
Section titled “50. Identity Verification”Before releasing personal information:
Requester ↓Identity Verified?Without verification, a privacy request itself can become a data breach.
51. Request Timeliness
Section titled “51. Request Timeliness”Define internal timelines aligned to commitments and requirements.
Monitor:
Received
Due
Completed52. Request Evidence
Section titled “52. Request Evidence”Examples:
Request
Identity Verification
Search Results
Response
Closure Date53. Data Accuracy
Section titled “53. Data Accuracy”Organizations may need processes to maintain accurate personal information where relevant.
Example:
Employee Changes Address ↓HR Record Updated54. Correction Requests
Section titled “54. Correction Requests”A request may trigger:
Verify Request ↓Update Source System ↓Propagate Change55. Disclosure
Section titled “55. Disclosure”Personal information may be shared with:
Vendors
Business Partners
Cloud Providers
Subprocessors
Government AuthoritiesDisclosure should be governed.
56. Third-Party Disclosure Control
Section titled “56. Third-Party Disclosure Control”Personal information is disclosed to third parties only for approved purposes and subject to applicable privacy, security, and contractual requirements.
57. Third-Party PII Sharing Register
Section titled “57. Third-Party PII Sharing Register”Create:
06 Third-Party PII Sharing RegisterUse:
| Data | Provider | Purpose | Location | Contract | Owner |
|---|
58. Vendor Due Diligence
Section titled “58. Vendor Due Diligence”For processors handling PII review:
Security Controls
Privacy Controls
SOC 2
ISO 27001
ISO 27018
Subprocessors
Incident Responseas appropriate.
59. Contractual Controls
Section titled “59. Contractual Controls”Contracts may address:
Processing Instructions
Confidentiality
Security
Subprocessors
Incident Notification
Deletion
Return of Data60. Processor Responsibilities
Section titled “60. Processor Responsibilities”The organization should understand:
What Provider Does
What Customer Does
What Is Shared61. Subprocessors
Section titled “61. Subprocessors”Vendors may use additional service providers.
Example:
Company ↓HR SaaS ↓Cloud Provider ↓Support ProviderThese relationships can affect privacy risk.
62. Subprocessor Inventory
Section titled “62. Subprocessor Inventory”Track:
Provider
Subprocessor
Service
Data
Region63. Cross-Border Processing
Section titled “63. Cross-Border Processing”Personal information may cross geographic boundaries.
Example:
Customer Data ↓EU ↓US AnalyticsSuch transfers may require additional governance depending on applicable requirements.
64. Data Location
Section titled “64. Data Location”Record:
Primary Location
Backup Location
Processing Location
Support Access65. Privacy and Cloud
Section titled “65. Privacy and Cloud”Cloud environments complicate privacy because data may exist across:
Primary Storage
Replication
Backup
Logs
Analytics
Support Systems66. Privacy and SaaS
Section titled “66. Privacy and SaaS”For SaaS platforms, review:
Data Collected
Purpose
Admins
Sharing
Retention
Deletion
Subprocessors67. Data Retention
Section titled “67. Data Retention”Personal information should not be retained indefinitely without justification.
Determine:
What Data?
Why Retained?
How Long?
Who Owns It?
How Deleted?68. Privacy Retention Register
Section titled “68. Privacy Retention Register”Create:
07 Privacy Retention RegisterUse:
| Data | Purpose | Retention | Trigger | Owner |
|---|
69. Retention Sources
Section titled “69. Retention Sources”Retention may be driven by:
Business Need
Contract
Law
Policy
Investigation
Legal Hold70. Retention Control
Section titled “70. Retention Control”Personal information is retained for defined periods based on approved business, legal, regulatory, and contractual requirements.
71. Retention Configuration
Section titled “71. Retention Configuration”Where possible:
Retention Policy ↓System Configuration ↓Automated Deletionreduces manual dependency.
72. Retention Gap
Section titled “72. Retention Gap”Example:
Policy:Delete after 3 yearsActual:
Database:Retains indefinitelyThis is an implementation gap.
73. Deletion
Section titled “73. Deletion”When data is no longer required:
Retention Ends ↓Deleteunless a valid hold applies.
74. Deletion Is More Complex Than One Record
Section titled “74. Deletion Is More Complex Than One Record”Personal information may exist in:
Primary Database
Backups
Logs
Exports
SaaS
Analytics
Data WarehouseDeletion design should account for the architecture.
75. Deletion Control
Section titled “75. Deletion Control”Personal information is securely deleted or anonymized when approved retention periods expire and no valid legal or business hold applies.
76. Deletion Evidence
Section titled “76. Deletion Evidence”Examples:
Deletion Ticket
System Log
Automated Job
Provider Confirmation
Closure Record77. SaaS Deletion
Section titled “77. SaaS Deletion”When a SaaS service is terminated:
Export Required Data ↓Remove Access ↓Request Deletion ↓Confirm Completion78. Backup Deletion
Section titled “78. Backup Deletion”Some backup technologies delete data through:
Retention Expiryrather than immediate record-level deletion.
This should be documented and understood.
79. Anonymization
Section titled “79. Anonymization”Some processing may use:
Anonymized Datato reduce privacy risk.
The method should prevent reasonable re-identification according to the intended use.
80. Pseudonymization
Section titled “80. Pseudonymization”Pseudonymization reduces direct identification but may still involve personal information.
Example:
Customer Name ↓Token IDIf the mapping exists, the data may still be linked back to a person.
81. Privacy Incident
Section titled “81. Privacy Incident”Examples include:
Wrong Recipient
Unauthorized Account Access
Lost Device
Public Database
Improper Sharing
Unauthorized Use82. Privacy Incident Lifecycle
Section titled “82. Privacy Incident Lifecycle”Detect ↓Contain ↓Identify Personal Data ↓Identify Individuals ↓Assess Impact ↓Escalate ↓Notify if Required ↓Remediate83. Privacy Incident Assessment
Section titled “83. Privacy Incident Assessment”Ask:
What happened?
What PII?
How many individuals?
Was data encrypted?
Who accessed it?
Which regions?
Which customers?84. Privacy Incident Control
Section titled “84. Privacy Incident Control”Incidents involving personal information are identified, investigated, escalated, documented, and handled according to the approved privacy and security incident process.
85. Notification
Section titled “85. Notification”Depending on commitments and applicable requirements:
Incident ↓Assessment ↓Notification Decisionmay involve:
Customers
Individuals
Regulators
Management86. Incident Evidence
Section titled “86. Incident Evidence”Examples:
Incident Record
Impact Assessment
Decision Record
Communication
Root Cause
Corrective Action87. Privacy Monitoring
Section titled “87. Privacy Monitoring”Organizations may monitor:
Bulk PII Downloads
PII Exports
Public Sharing
Unusual Access
Retention Failures
Unauthorized Processing88. Privacy Control Monitoring
Section titled “88. Privacy Control Monitoring”A mature model may combine:
IAM
DLP
Data Discovery
SIEM
Privacy Workflows89. Privacy Evidence Matrix
Section titled “89. Privacy Evidence Matrix”Create:
08 Privacy Evidence MatrixUse:
| Control | Evidence | Source | Frequency | Owner |
|---|
90. Evidence — PII Inventory
Section titled “90. Evidence — PII Inventory”Examples:
PII Register
Data Flow Map
Data Catalog91. Evidence — Notice
Section titled “91. Evidence — Notice”Examples:
Privacy Notice
Version History
Approval92. Evidence — Consent
Section titled “92. Evidence — Consent”Examples:
Consent Record
Preference Log
Withdrawal Record93. Evidence — Purpose
Section titled “93. Evidence — Purpose”Examples:
Processing Register
Privacy Review
Product Documentation94. Evidence — Individual Rights
Section titled “94. Evidence — Individual Rights”Examples:
Request Register
Verification
Response
Closure95. Evidence — Third Parties
Section titled “95. Evidence — Third Parties”Examples:
Vendor Assessment
DPA
Subprocessor Register
Security Assurance96. Evidence — Retention
Section titled “96. Evidence — Retention”Examples:
Retention Schedule
System Configuration
Deletion Report97. Evidence — Incident Response
Section titled “97. Evidence — Incident Response”Examples:
Privacy Incident Register
Impact Assessment
Notification Decision
Corrective Action98. Build Privacy Control Matrix
Section titled “98. Build Privacy Control Matrix”Create:
09 Privacy Control MatrixUse:
| Control ID | Risk | Control | Owner | Evidence |
|---|
99. Example Privacy Controls
Section titled “99. Example Privacy Controls”PRIV-001Privacy Governance
PRIV-002PII Inventory
PRIV-003Privacy Notice
PRIV-004Data Minimization
PRIV-005Processing Purpose
PRIV-006Consent & Preferences
PRIV-007PII Access
PRIV-008Individual Rights
PRIV-009Third-Party PII Processing
PRIV-010Subprocessor Governance
PRIV-011Retention
PRIV-012PII Deletion
PRIV-013Privacy Incident Management
PRIV-014Privacy Monitoring100. PRIV-001 — Privacy Governance
Section titled “100. PRIV-001 — Privacy Governance”Privacy responsibilities, policies, processing requirements, and oversight mechanisms are formally defined and periodically reviewed.
101. PRIV-002 — PII Inventory
Section titled “101. PRIV-002 — PII Inventory”Personal-information categories, processing systems, purposes, owners, and relevant data flows are maintained in an approved inventory.
102. PRIV-003 — Privacy Notice
Section titled “102. PRIV-003 — Privacy Notice”Privacy notices accurately describe applicable personal-information collection, use, disclosure, retention, and individual-right practices.
103. PRIV-004 — Data Minimization
Section titled “103. PRIV-004 — Data Minimization”Personal information collected and processed is limited to data required for approved purposes.
104. PRIV-005 — Processing Purpose
Section titled “104. PRIV-005 — Processing Purpose”Personal information is processed only for documented and approved purposes.
105. PRIV-006 — Consent & Preferences
Section titled “105. PRIV-006 — Consent & Preferences”Where required by organizational commitments, applicable choices and preferences are captured, maintained, and enforced.
106. PRIV-007 — PII Access
Section titled “106. PRIV-007 — PII Access”Access to personal information is restricted based on authorized business need and job responsibility.
107. PRIV-008 — Individual Rights
Section titled “107. PRIV-008 — Individual Rights”Requests relating to personal information are authenticated, tracked, processed, and completed according to defined requirements.
108. PRIV-009 — Third-Party Processing
Section titled “108. PRIV-009 — Third-Party Processing”Third parties processing personal information undergo appropriate privacy and security review and are subject to defined contractual requirements.
109. PRIV-010 — Subprocessor Governance
Section titled “109. PRIV-010 — Subprocessor Governance”Material subprocessors are identified, assessed, and monitored according to applicable privacy requirements.
110. PRIV-011 — Retention
Section titled “110. PRIV-011 — Retention”Personal information is retained according to approved retention requirements.
111. PRIV-012 — Deletion
Section titled “111. PRIV-012 — Deletion”Personal information is deleted or appropriately de-identified when retention requirements expire and no authorized hold applies.
112. PRIV-013 — Privacy Incident Management
Section titled “112. PRIV-013 — Privacy Incident Management”Privacy incidents are identified, investigated, escalated, and managed according to documented procedures.
113. PRIV-014 — Privacy Monitoring
Section titled “113. PRIV-014 — Privacy Monitoring”Material events involving personal-information access, sharing, retention, or processing are monitored according to risk.
114. Privacy Control Testing
Section titled “114. Privacy Control Testing”For each privacy control define:
Requirement
Population
Sample
Evidence
Test Procedure
Exceptions
Conclusion115. Test PII Inventory
Section titled “115. Test PII Inventory”Select systems known to process PII.
Verify:
System Listed?
Data Listed?
Purpose Listed?
Owner Listed?
Data Flow Known?116. Test Privacy Notice
Section titled “116. Test Privacy Notice”Compare published privacy notice against actual processing.
Example:
Notice:No Analytics SharingActual:
Customer Data Sent to Analytics ProviderPotential gap.
117. Test Data Minimization
Section titled “117. Test Data Minimization”Select forms or applications collecting PII.
Ask:
Is every field necessary?Identify unnecessary data collection.
118. Test Processing Purpose
Section titled “118. Test Processing Purpose”Sample processing activities.
Verify:
Purpose Documented?
Approved?
Actual Use Matches?119. Test Consent
Section titled “119. Test Consent”Where applicable:
Consent Required?
Captured?
Timestamped?
Current?
Withdrawal Enforced?120. Test PII Access
Section titled “120. Test PII Access”For selected systems:
Users
Roles
Approvals
Need to Know
Access Review121. Test Individual Requests
Section titled “121. Test Individual Requests”Sample requests.
Verify:
Identity Verified
Request Completed
Timely
Evidence Retained122. Test Third-Party Processing
Section titled “122. Test Third-Party Processing”Select providers receiving PII.
Verify:
Purpose
Risk Assessment
Contract
Security Review
Subprocessors123. Test Retention
Section titled “123. Test Retention”Select datasets.
Compare:
Required Retention vsActual System Configuration124. Test Deletion
Section titled “124. Test Deletion”Sample completed deletion cases.
Verify:
Request / Trigger
Systems Identified
Deletion Performed
Evidence
Provider Action125. Test Privacy Incidents
Section titled “125. Test Privacy Incidents”Select privacy-related incidents.
Trace:
Detection
Assessment
Escalation
Decision
Notification
Closure126. Design Effectiveness
Section titled “126. Design Effectiveness”Ask:
If this privacy control operates exactly as designed, will it reasonably achieve the intended privacy objective?
Example:
Risk:
Excessive PII CollectionControl:
Developers decide individuallywhat fields to collect.This may be poorly designed.
Better:
Defined Data Collection Standard+Privacy Review+Approved Purpose127. Operating Effectiveness
Section titled “127. Operating Effectiveness”Example control:
Annual Privacy Review for Critical VendorsPopulation:
25 Critical PII VendorsCompleted:
22Conclusion:
Partially Effective128. Complete Population Testing
Section titled “128. Complete Population Testing”Automation may help identify:
All SaaS Applications With PII
All PII Repositories
All Expired Retention Records
All External Sharing Events129. Sampling Manual Controls
Section titled “129. Sampling Manual Controls”Manual privacy controls may include:
Privacy Reviews
DSR Processing
Vendor Assessments
Deletion Approvals
Consent Reviews130. Privacy Finding — Inventory
Section titled “130. Privacy Finding — Inventory”Three production applications processing customer personal information were not recorded in the approved PII inventory.
Risk:
Unknown Processing
Unmanaged Retention
Unassessed Third Parties131. Privacy Finding — Data Minimization
Section titled “131. Privacy Finding — Data Minimization”The customer registration form collects date-of-birth information despite no documented business requirement for processing that field.
132. Privacy Finding — Purpose
Section titled “132. Privacy Finding — Purpose”Customer support conversations collected for service delivery were subsequently used for analytics without documented privacy review or approved purpose change.
133. Privacy Finding — Individual Rights
Section titled “133. Privacy Finding — Individual Rights”Four individual-access requests were completed beyond the organization’s defined response timeline.
134. Privacy Finding — Third Party
Section titled “134. Privacy Finding — Third Party”A marketing provider receives customer contact information without a current privacy/security assessment.
135. Privacy Finding — Retention
Section titled “135. Privacy Finding — Retention”Personal information associated with inactive customer accounts remains in the CRM beyond the approved retention period.
136. Privacy Finding — Deletion
Section titled “136. Privacy Finding — Deletion”Customer deletion requests remove information from the primary application but do not trigger deletion from the analytics warehouse.
137. Root Cause Analysis — Retention
Section titled “137. Root Cause Analysis — Retention”Example:
Expired PII Remains ↓Retention Policy Exists ↓CRM Has No Automated Deletion ↓Manual Process Never AssignedRoot cause:
The CRM retention requirement has not been translated into an operational deletion process with assigned ownership.
138. Correction
Section titled “138. Correction”Delete Expired Records139. Corrective Action
Section titled “139. Corrective Action”Implement Automated Retention+Assign Owner+Create Monitoring140. Privacy Exceptions
Section titled “140. Privacy Exceptions”A privacy exception should include:
Requirement
Business Need
Risk
Compensating Controls
Approval
Expiry
RemediationAvoid indefinite exceptions where possible.
141. Privacy Dashboard
Section titled “141. Privacy Dashboard”Useful metrics include:
PII Inventory Coverage
Privacy Reviews Completed
DSR Completion
Overdue DSRs
Critical PII Vendors Reviewed
Expired PII Records
Privacy Incidents
Open Privacy Findings142. Example Privacy Dashboard
Section titled “142. Example Privacy Dashboard”| Metric | Target | Current |
|---|---|---|
| PII Inventory Coverage | 100% | 96% |
| DSR Completion Within Target | 100% | 97% |
| Critical PII Vendor Reviews | 100% | 92% |
| Expired PII Records | 0 | 240 |
| Open High Privacy Findings | 0 | 2 |
143. Privacy KPI
Section titled “143. Privacy KPI”Example:
KPI:Percentage of personal-data processingactivities recorded in the PII inventory144. Privacy KRI
Section titled “144. Privacy KRI”Example:
KRI:Number of overdue personal-data deletion actions145. Individual Rights KRI
Section titled “145. Individual Rights KRI”Example:
Overdue individual privacy requestsTolerance may be:
0146. Third-Party Privacy KRI
Section titled “146. Third-Party Privacy KRI”Example:
Critical PII processorswithout current assessment147. Audit Walkthrough — Privacy Notice
Section titled “147. Audit Walkthrough — Privacy Notice”Auditor selects:
Customer Registration ProcessTrace:
Data Collected ↓Purpose ↓Privacy Notice ↓System ProcessingVerify alignment.
148. Audit Walkthrough — PII Inventory
Section titled “148. Audit Walkthrough — PII Inventory”Auditor selects:
CRMReview:
Data Categories
Purpose
Owner
Location
Third Parties
Retention149. Audit Walkthrough — Individual Request
Section titled “149. Audit Walkthrough — Individual Request”Auditor selects:
Access Request DSR-102Trace:
Request
Identity Verification
Search
Response
Closure150. Audit Walkthrough — Vendor Processing
Section titled “150. Audit Walkthrough — Vendor Processing”Auditor selects:
HR SaaSReview:
PII
Purpose
Contract
Security Review
Subprocessors
Retention
Deletion151. Audit Walkthrough — Retention
Section titled “151. Audit Walkthrough — Retention”Auditor selects:
Former Customer RecordsVerify:
Retention Requirement
System Configuration
Deletion Evidence152. Common Privacy Mistakes
Section titled “152. Common Privacy Mistakes”Mistake 1 — Privacy Equals Security
Section titled “Mistake 1 — Privacy Equals Security”Security alone does not govern purpose, notice, rights, or retention.
Mistake 2 — Privacy Equals Confidentiality
Section titled “Mistake 2 — Privacy Equals Confidentiality”Not all privacy requirements are confidentiality requirements.
Mistake 3 — No PII Inventory
Section titled “Mistake 3 — No PII Inventory”Unknown processing remains unmanaged.
Mistake 4 — Privacy Notice Not Matched to Reality
Section titled “Mistake 4 — Privacy Notice Not Matched to Reality”Actual processing exceeds disclosed practices.
Mistake 5 — Collect Everything
Section titled “Mistake 5 — Collect Everything”Data minimization is ignored.
Mistake 6 — Purpose Changes Without Review
Section titled “Mistake 6 — Purpose Changes Without Review”Data is reused without governance.
Mistake 7 — DSR Process Depends on Manual Email
Section titled “Mistake 7 — DSR Process Depends on Manual Email”Requests can be missed or delayed.
Mistake 8 — Vendors Reviewed Only for Security
Section titled “Mistake 8 — Vendors Reviewed Only for Security”Privacy processing risks are ignored.
Mistake 9 — Retention Policy Exists but Is Not Enforced
Section titled “Mistake 9 — Retention Policy Exists but Is Not Enforced”PII remains indefinitely.
Mistake 10 — Deletion Covers Only Primary Application
Section titled “Mistake 10 — Deletion Covers Only Primary Application”Analytics, SaaS, exports, and backups are ignored.
153. Weak Privacy Model
Section titled “153. Weak Privacy Model”Privacy Policy +Security Controls =Assume Privacy154. Strong Privacy Model
Section titled “154. Strong Privacy Model”Governance ↓PII Inventory ↓Notice ↓Purpose ↓Collection ↓Minimization ↓Use ↓Access ↓Sharing ↓Individual Rights ↓Retention ↓Deletion ↓Incident Management ↓Evidence155. Practical Activity — Build Privacy Control Matrix
Section titled “155. Practical Activity — Build Privacy Control Matrix”Create:
01 Privacy Control MatrixInclude at least 15 controls across:
Governance
Inventory
Notice
Collection
Purpose
Consent
Access
Individual Rights
Third Parties
Retention
Deletion
Incident Management156. Practical Activity — Build PII Inventory
Section titled “156. Practical Activity — Build PII Inventory”Create:
02 PII InventoryAdd at least 20 fictional personal-information categories across:
HR
CRM
Support
Marketing
Application
Security Logs
SaaS157. Practical Activity — Build Processing Purpose Register
Section titled “157. Practical Activity — Build Processing Purpose Register”Create:
03 Processing Purpose RegisterUse:
| Processing Activity | Data | Purpose | Owner | Status |
|---|
158. Practical Activity — Build Consent Register
Section titled “158. Practical Activity — Build Consent Register”Create:
04 Consent & Preference RegisterTrack fictional:
Marketing Consent
Cookie Preference
Communication Preference159. Practical Activity — Build Data Subject Request Register
Section titled “159. Practical Activity — Build Data Subject Request Register”Create:
05 Data Subject Request RegisterAdd examples for:
Access
Correction
Deletion160. Practical Activity — Build Third-Party PII Sharing Register
Section titled “160. Practical Activity — Build Third-Party PII Sharing Register”Create:
06 Third-Party PII Sharing RegisterInclude:
HR Provider
CRM Provider
Analytics Provider
Support Platform
Cloud Provider161. Practical Activity — Build Privacy Retention Register
Section titled “161. Practical Activity — Build Privacy Retention Register”Create:
07 Privacy Retention RegisterInclude at least ten PII categories.
162. Practical Activity — Build Privacy Evidence Matrix
Section titled “162. Practical Activity — Build Privacy Evidence Matrix”Create:
08 Privacy Evidence MatrixMap evidence for:
Inventory
Notice
Consent
Purpose
Access
DSRs
Third Parties
Retention
Deletion
Incidents163. Practical Activity — Build Privacy Control Testing Checklist
Section titled “163. Practical Activity — Build Privacy Control Testing Checklist”Create:
09 Privacy Control Testing ChecklistTest:
PII Inventory
Privacy Notice
Data Minimization
Purpose Limitation
Consent
PII Access
Individual Requests
Third-Party Processing
Retention
Deletion
Privacy Incident Response164. Privacy Readiness Checklist
Section titled “164. Privacy Readiness Checklist”Governance
Section titled “Governance”-
Privacy policy established.
-
Privacy roles defined.
-
Ownership established.
-
Privacy review triggers defined.
Inventory
Section titled “Inventory”-
PII categories identified.
-
Systems identified.
-
Purposes documented.
-
Owners identified.
-
Data flows mapped.
-
Third parties identified.
Notice
Section titled “Notice”-
Privacy notices documented.
-
Notices match actual processing.
-
Changes are reviewed.
Collection
Section titled “Collection”-
Collection purpose defined.
-
Data minimization applied.
-
Unnecessary fields avoided.
Consent / Preferences
Section titled “Consent / Preferences”-
Required preferences captured.
-
Evidence retained.
-
Withdrawals enforced.
-
Processing purpose documented.
-
New uses reviewed.
-
Access restricted.
Individual Rights
Section titled “Individual Rights”-
Request process established.
-
Identity verification implemented.
-
Requests tracked.
-
Deadlines monitored.
-
Evidence retained.
Third Parties
Section titled “Third Parties”-
PII processors identified.
-
Privacy/security assessments performed.
-
Contracts established.
-
Subprocessors identified.
-
Data locations reviewed.
Retention
Section titled “Retention”-
Retention requirements defined.
-
System configuration aligned.
-
Holds supported.
-
Expired PII identified.
Deletion
Section titled “Deletion”-
Deletion workflow established.
-
SaaS included.
-
Analytics included.
-
Backups considered.
-
Evidence retained.
Incidents
Section titled “Incidents”-
Privacy incidents identified.
-
Escalation defined.
-
Impact assessment established.
-
Notification decision documented.
-
Corrective actions tracked.
165. GRC Analyst Responsibilities
Section titled “165. GRC Analyst Responsibilities”A GRC professional supporting SOC 2 Privacy may:
-
Maintain privacy-control mappings.
-
Maintain PII inventories.
-
Coordinate data-flow mapping.
-
Review processing purposes.
-
Review privacy notices.
-
Support consent governance.
-
Review data minimization.
-
Monitor individual-right requests.
-
Assess third-party privacy controls.
-
Maintain subprocessor inventories.
-
Review retention requirements.
-
Review deletion evidence.
-
Test privacy controls.
-
Document findings.
-
Facilitate remediation.
-
Maintain privacy dashboards.
-
Support external SOC auditors.
GRC connects:
Privacy
Legal
Security
IAM
Engineering
Product
HR
Marketing
Procurement
Vendors
Auditors166. Privacy Maturity Model
Section titled “166. Privacy Maturity Model”Level 1 — Reactive
Section titled “Level 1 — Reactive”Privacy Issues ↓Handled Case by CaseLevel 2 — Defined
Section titled “Level 2 — Defined”Privacy Policy
PII Inventory
Request ProcessLevel 3 — Governed
Section titled “Level 3 — Governed”Purpose Register
Vendor Governance
Retention
DeletionLevel 4 — Integrated
Section titled “Level 4 — Integrated”Automated Discovery
Privacy Workflows
Metrics
MonitoringLevel 5 — Continuous Privacy Assurance
Section titled “Level 5 — Continuous Privacy Assurance”Continuous Data Discovery
Automated Retention
Privacy-by-Design Workflows
Continuous Evidence
Dynamic Risk Signals167. Privacy Mindset
Section titled “167. Privacy Mindset”For every personal-information processing activity ask:
What personal information are we processing?
Whose information is it?
Why do we need it?
Did we disclose the processing appropriately?
Do we need consent or preference management?
Are we collecting more than necessary?
Who can access it?
Are administrators included?
Which systems receive it?
Which third parties receive it?
Where is it processed?
How long should it be retained?
How will individuals exercise relevant rights?
How will the data be deleted?
What happens if processing changes?
What happens if there is an incident?
What evidence proves the controls operate?When these questions can be answered, Privacy becomes an operational governance program rather than merely a published privacy notice.
Key Takeaways
Section titled “Key Takeaways”-
Privacy governs personal information throughout its lifecycle.
-
Privacy and Confidentiality overlap but are not the same.
-
A PII inventory is foundational to privacy governance.
-
Data-flow mapping helps identify systems, locations, providers, and subprocessors.
-
Privacy notices should accurately reflect actual processing.
-
Collection should be connected to defined purposes.
-
Data minimization reduces unnecessary privacy risk.
-
Processing-purpose changes should trigger review.
-
Consent and preferences should be captured and enforced where applicable.
-
Access to PII should follow business need and least privilege.
-
Individual-right requests require identity verification, tracking, response, and evidence.
-
Third-party processors and subprocessors should be governed through privacy, security, and contractual controls.
-
Retention should define how long personal information is needed.
-
Deletion should address all relevant systems and providers.
-
Privacy incidents require structured impact assessment and escalation.
-
SOC 2 Privacy assurance requires controls, evidence, testing, monitoring, and remediation across the full personal-information lifecycle.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What does SOC 2 Privacy address?
-
How is Privacy different from Confidentiality?
-
What is a PII inventory?
-
Why is data-flow mapping important?
-
What should a privacy notice describe?
-
What is data minimization?
-
What is purpose limitation?
-
Why should new processing purposes be reviewed?
-
What role can consent or preferences play?
-
Why should privileged access to PII be considered?
-
What is a data subject request?
-
Why is identity verification important?
-
How should third-party PII processing be governed?
-
What is a subprocessor?
-
Why does data location matter?
-
Why should retention be operationalized?
-
Why can deletion be complex?
-
What should a privacy incident assessment consider?
-
What evidence supports Privacy controls?
-
What role does GRC play in SOC 2 Privacy?
What’s Next?
Section titled “What’s Next?”➡️ Next: 10 — SOC Type I vs Type II
In the next lesson, you will bring the SOC reporting concepts together and examine the practical differences between Type I and Type II reports, including:
Point-in-Time Assurance ↓Period-of-Time Assurance ↓Control Design ↓Control Implementation ↓Operating Effectiveness ↓Control Population ↓Sampling ↓Exceptions ↓Report Period ↓Audit RelianceYou will also build practical artifacts including a Type I vs Type II Comparison Matrix, SOC Report Period Register, Control Operating Period Matrix, Evidence Coverage Register, Exception Impact Matrix, and SOC Report Selection Checklist.