SOC 2 Privacy criteria (P1–P8)
By Sam Rivera, Founder, SentinelPanda · August 10, 2026 · 3 min read · SOC 2
Eight criteria series, the most points of focus of any category, and the one most often selected by companies that did not need it.
The eight series
- <strong>P1 Notice</strong> — you communicate your privacy objectives and practices to data subjects.
- <strong>P2 Choice and consent</strong> — you communicate choices available and obtain consent where required.
- <strong>P3 Collection</strong> — personal information is collected consistently with your stated objectives.
- <strong>P4 Use, retention, and disposal</strong> — limited to stated purposes, retained only as long as needed, disposed of properly.
- <strong>P5 Access</strong> — data subjects can access their personal information for review and correction.
- <strong>P6 Disclosure and notification</strong> — disclosure to third parties is consistent with objectives, including breach notification.
- <strong>P7 Quality</strong> — personal information is accurate, complete, and relevant for its purpose.
- <strong>P8 Monitoring and enforcement</strong> — you monitor compliance and have a process for handling complaints and disputes.
Controller obligations in a processor's report
Read P1, P2 and P5 again and notice who they assume you are. Communicating a privacy notice to data subjects, obtaining their consent, and fielding their access requests are controller activities.
A typical B2B SaaS is a processor: your customer collected the data, owes the individuals notice and choice, and passes you instructions under a DPA. Selecting Privacy commits you to controls for obligations you do not hold and, in many cases, cannot perform — you often have no relationship with the data subject and no lawful basis to respond to them directly.
This is the most common reason a Privacy category goes badly. It is not that the controls are hard; it is that they describe someone else's role.
It is not GDPR compliance
A SOC 2 report with the Privacy category is a CPA firm's opinion that you met the criteria you selected, over a period. It is not a determination that you comply with GDPR, CCPA, or any other privacy law. The obligations overlap in places and diverge in others, and no regulator treats a SOC 2 as evidence of statutory compliance.
If the underlying question from a buyer is "are you GDPR compliant", a SOC 2 Privacy section is an expensive and partial answer. A DPA, a records-of-processing summary, and clear sub-processor disclosure usually address it better.
When it genuinely fits
When you are a controller: you collect personal information directly from individuals for your own purposes, decide why and how it is processed, and have a direct relationship with those people. Consumer products, marketplaces, ad-tech, and some health and fintech models sit here.
If you are a processor and a buyer asks for Privacy, the productive move is usually to ask what they are trying to establish. Nine times out of ten it is "will you handle personal data responsibly and tell us about sub-processors", which Confidentiality plus a solid DPA answers at a fraction of the cost — and without committing you to controls for a role you do not occupy.