SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
SOC2-P3.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
P3.1 Collecting personal information consistent with objectives. Personal information is collected in line with the organisation's privacy objectives. Points of focus: collection is limited to what the objectives need; collection methods are reviewed by management before use to confirm information is gathered fairly, without deception or intimidation, and lawfully; third-party sources are confirmed to be reliable and to collect fairly and lawfully; and data subjects are told when additional information about them is developed or acquired.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
NIST SP 800-53 Rev 5
- NIST800-AC-16 AC-16 Security and Privacy Attributes (closest match)
- NIST800-PM-25 PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research (closest match)
- NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information (closest match)
- NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes (closest match)
- NIST800-PT-4 PT-4 Consent (closest match)
- NIST800-PT-5 PT-5 Privacy Notice (closest match)
- NIST800-PT-7 PT-7 Specific Categories of Personally Identifiable Information (closest match)
- NIST800-RA-8 RA-8 Privacy Impact Assessments (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.
- the privacy notice and its change log
- the consent and preference records
- the data-subject request log with resolution
- the retention and disposal records