SOC 2 Privacy criteria, and PIPEDA
The Privacy category tests whether you handle personal information the way you said you would. It is not a privacy law compliance opinion, and Canadian companies confuse the two constantly.
The Privacy category covers eight series, P1 to P8, from notice and consent through to monitoring and enforcement. Including it in a SOC 2 means an auditor tested whether you collect, use, retain, disclose and dispose of personal information in line with your own published commitments. It does not mean you comply with PIPEDA, Quebec's Law 25 or Ontario's PHIPA, and no Canadian regulator treats a SOC 2 as evidence of statutory compliance. Adding the category adds 20 to 30 percent to a Canadian audit fee.
The eight series
| Series | Subject | Typical evidence |
|---|---|---|
| P1 | Notice and communication of objectives | A published privacy notice, versioned, with evidence of how changes are communicated |
| P2 | Choice and consent | Consent capture records, preference settings, evidence that withdrawal works |
| P3 | Collection | Data inventory showing what is collected and why, limited to the stated purposes |
| P4 | Use, retention and disposal | Retention schedule, evidence deletion runs, restrictions on secondary use |
| P5 | Access | A process for individuals to see and correct their information, with fulfilled requests as evidence |
| P6 | Disclosure and notification | Third party disclosure records, data processing agreements, breach notification procedures and any notifications made |
| P7 | Quality | Controls that keep personal information accurate and current |
| P8 | Monitoring and enforcement | Complaint handling records, periodic privacy compliance review, remediation of issues found |
What the category is not
The Privacy criteria are built on privacy principles developed by the accounting profession, not on any statute. The opinion is measured against your commitments. If your privacy notice promises little, and you keep those small promises, you can pass Privacy while falling well short of what PIPEDA requires.
| Obligation | Source | Covered by SOC 2 Privacy |
|---|---|---|
| Accountability, including a designated privacy officer | PIPEDA, Schedule 1 principle 4.1 | Partly, through P8 |
| Safeguards proportionate to sensitivity | PIPEDA, Schedule 1 principle 4.7 | Largely, through the Security criteria |
| Breach reporting to the Privacy Commissioner and to individuals | PIPEDA, real risk of significant harm test | Only that a procedure exists, not that your assessment was right |
| Privacy impact assessment before communicating personal information outside Quebec | Quebec Law 25 | No |
| Privacy by default for public-facing technology | Quebec Law 25 | No |
| Data portability on request | Quebec Law 25 | No |
| Health information custodian and agent duties | Ontario PHIPA | No |
The PIPEDA page works through the federal picture, and the Law 25 page covers Quebec, where the gap between an audit and the statute is widest.
When to include Privacy anyway
The case for it is narrower than vendors suggest. Include Privacy when a buyer named it in writing, when you are a processor for customers in regulated sectors who need to show their own regulator that they diligenced you, or when personal information is the product rather than a byproduct of it.
- Get the request in writing and check whether the buyer means the SOC 2 Privacy category or a data protection agreement. Half the time it is the latter, and a signed agreement costs nothing.
- Read your own privacy notice. Everything in it becomes a commitment the auditor tests.
- Confirm you can evidence access and deletion requests. P5 and P4 are where companies discover their process is a shared inbox.
- Decide whether ISO 27701 or a privacy assessment against the actual statute would serve the buyer better. Sometimes it would.
The common Canadian mistake
Companies add the Privacy category expecting it to answer PIPEDA questions in security reviews, then find that reviewers still send the privacy questionnaire. Security plus a signed data processing agreement plus a defensible privacy program answers more questions for less money than the Privacy category does on its own.
Get advice before you scope Privacy in
It is the category most often added for the wrong reason. Ask firms what it will cost and what it will answer.
Get matchedCommon questions
Does a SOC 2 with Privacy make us PIPEDA compliant?
No. The Privacy criteria test your handling of personal information against your own published commitments, not against Canadian law. PIPEDA obligations including accountability, consent, access and breach reporting apply whether or not you have any SOC 2 report, and no Canadian regulator accepts an attestation as evidence of compliance.
How many Privacy criteria are in SOC 2?
The Privacy category is organized into eight series, P1 through P8, covering notice, choice and consent, collection, use and retention and disposal, access, disclosure and notification, quality, and monitoring and enforcement. Each series contains several numbered criteria.
Should a Canadian SaaS company include Privacy?
Usually not in a first report. Security only answers most enterprise security reviews, and privacy questions are better answered with a data processing agreement and a real privacy program. Include Privacy when a buyer has asked for it in writing or when personal information is the core of what you do.
Is ISO 27701 a better fit than SOC 2 Privacy?
For companies whose buyers are in Europe or the United Kingdom, often yes, because it extends an ISO 27001 management system and maps to data protection duties directly. For North American buyers asking for SOC 2, it is an extra certification they did not request. Follow the buyer rather than the framework.