SOC2-P1.1 P1.1 Privacy notice to data subjects
SOC2-P1.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
P1.1 Privacy notice to data subjects. Data subjects receive notice of the organisation's privacy practices, updated and communicated promptly when practices, including uses of personal information, change. Points of focus: notice covers purpose of collection, choice and consent, types of information collected, collection methods such as cookies and tracking, how information is used, kept and disposed of, how individuals can see it, sharing with third parties, security, quality and the data subject's part in it, and monitoring and enforcement, and names other sources where information is not collected from the individual; notice is given at or before collection or soon after, before a notice.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
NIST SP 800-53 Rev 5
- NIST800-AC-8 AC-8 System Use Notification (closest match)
- NIST800-PL-2 PL-2 System Security and Privacy Plans (closest match)
- NIST800-PM-18 PM-18 Privacy Program Plan (closest match)
- NIST800-PM-20 PM-20 Dissemination of Privacy Program Information (closest match)
- NIST800-PM-27 PM-27 Privacy Reporting (closest match)
- NIST800-PT-1 PT-1 Policy and Procedures (closest match)
- NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes (closest match)
- NIST800-PT-5 PT-5 Privacy Notice (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.
- the privacy notice and its change log
- the consent and preference records
- the data-subject request log with resolution
- the retention and disposal records