GetSOC2

SOC 2 Privacy criteria, and PIPEDA

The Privacy category tests whether you handle personal information the way you said you would. It is not a privacy law compliance opinion, and Canadian companies confuse the two constantly.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The Privacy category covers eight series, P1 to P8, from notice and consent through to monitoring and enforcement. Including it in a SOC 2 means an auditor tested whether you collect, use, retain, disclose and dispose of personal information in line with your own published commitments. It does not mean you comply with PIPEDA, Quebec's Law 25 or Ontario's PHIPA, and no Canadian regulator treats a SOC 2 as evidence of statutory compliance. Adding the category adds 20 to 30 percent to a Canadian audit fee.

The eight series

Privacy criteria series and what each covers
SeriesSubjectTypical evidence
P1Notice and communication of objectivesA published privacy notice, versioned, with evidence of how changes are communicated
P2Choice and consentConsent capture records, preference settings, evidence that withdrawal works
P3CollectionData inventory showing what is collected and why, limited to the stated purposes
P4Use, retention and disposalRetention schedule, evidence deletion runs, restrictions on secondary use
P5AccessA process for individuals to see and correct their information, with fulfilled requests as evidence
P6Disclosure and notificationThird party disclosure records, data processing agreements, breach notification procedures and any notifications made
P7QualityControls that keep personal information accurate and current
P8Monitoring and enforcementComplaint handling records, periodic privacy compliance review, remediation of issues found

What the category is not

The Privacy criteria are built on privacy principles developed by the accounting profession, not on any statute. The opinion is measured against your commitments. If your privacy notice promises little, and you keep those small promises, you can pass Privacy while falling well short of what PIPEDA requires.

What Canadian statutes require that a Privacy opinion does not deliver
ObligationSourceCovered by SOC 2 Privacy
Accountability, including a designated privacy officerPIPEDA, Schedule 1 principle 4.1Partly, through P8
Safeguards proportionate to sensitivityPIPEDA, Schedule 1 principle 4.7Largely, through the Security criteria
Breach reporting to the Privacy Commissioner and to individualsPIPEDA, real risk of significant harm testOnly that a procedure exists, not that your assessment was right
Privacy impact assessment before communicating personal information outside QuebecQuebec Law 25No
Privacy by default for public-facing technologyQuebec Law 25No
Data portability on requestQuebec Law 25No
Health information custodian and agent dutiesOntario PHIPANo

The PIPEDA page works through the federal picture, and the Law 25 page covers Quebec, where the gap between an audit and the statute is widest.

When to include Privacy anyway

The case for it is narrower than vendors suggest. Include Privacy when a buyer named it in writing, when you are a processor for customers in regulated sectors who need to show their own regulator that they diligenced you, or when personal information is the product rather than a byproduct of it.

  1. Get the request in writing and check whether the buyer means the SOC 2 Privacy category or a data protection agreement. Half the time it is the latter, and a signed agreement costs nothing.
  2. Read your own privacy notice. Everything in it becomes a commitment the auditor tests.
  3. Confirm you can evidence access and deletion requests. P5 and P4 are where companies discover their process is a shared inbox.
  4. Decide whether ISO 27701 or a privacy assessment against the actual statute would serve the buyer better. Sometimes it would.

The common Canadian mistake

Companies add the Privacy category expecting it to answer PIPEDA questions in security reviews, then find that reviewers still send the privacy questionnaire. Security plus a signed data processing agreement plus a defensible privacy program answers more questions for less money than the Privacy category does on its own.

Get advice before you scope Privacy in

It is the category most often added for the wrong reason. Ask firms what it will cost and what it will answer.

Get matched

Common questions

Does a SOC 2 with Privacy make us PIPEDA compliant?

No. The Privacy criteria test your handling of personal information against your own published commitments, not against Canadian law. PIPEDA obligations including accountability, consent, access and breach reporting apply whether or not you have any SOC 2 report, and no Canadian regulator accepts an attestation as evidence of compliance.

How many Privacy criteria are in SOC 2?

The Privacy category is organized into eight series, P1 through P8, covering notice, choice and consent, collection, use and retention and disposal, access, disclosure and notification, quality, and monitoring and enforcement. Each series contains several numbered criteria.

Should a Canadian SaaS company include Privacy?

Usually not in a first report. Security only answers most enterprise security reviews, and privacy questions are better answered with a data processing agreement and a real privacy program. Include Privacy when a buyer has asked for it in writing or when personal information is the core of what you do.

Is ISO 27701 a better fit than SOC 2 Privacy?

For companies whose buyers are in Europe or the United Kingdom, often yes, because it extends an ISO 27001 management system and maps to data protection duties directly. For North American buyers asking for SOC 2, it is an extra certification they did not request. Follow the buyer rather than the framework.