SOC2-P4.3 P4.3 Securely disposing of personal information
SOC2-P4.3 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
P4.3 Securely disposing of personal information. Personal information is disposed of securely in line with privacy objectives. Points of focus: deletion requests are captured and the related information flagged for destruction; information no longer retained is anonymised, disposed of or destroyed in a way that prevents loss, theft, misuse or unauthorised access; and policies and procedures destroy information identified for destruction.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(3)(ii)(C) Termination Procedures (Addressable) (closest match)
- 164.310(d)(2)(i) Disposal (Required) (closest match)
- 164.310(d)(2)(ii) Media Re-use (Required) (closest match)
NIST SP 800-53 Rev 5
- NIST800-MP-4 MP-4 Media Storage (closest match)
- NIST800-MP-6 MP-6 Media Sanitization (closest match)
- NIST800-MP-8 MP-8 Media Downgrading (closest match)
- NIST800-PL-8 PL-8 Security and Privacy Architectures (closest match)
- NIST800-SC-28 SC-28 Protection of Information at Rest (closest match)
- NIST800-SI-12 SI-12 Information Management and Retention (closest match)
- NIST800-SI-21 SI-21 Information Refresh (closest match)
- NIST800-SR-12 SR-12 Component Disposal (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.
- the privacy notice and its change log
- the consent and preference records
- the data-subject request log with resolution
- the retention and disposal records