SOC 2 Privacy Gaps

Your SOC 2 auditor flagged privacy gaps

Some of those gaps close quickly. Others are structural and will not close before the audit window without real work. The distinction matters.

Documentation gaps and capability gaps are not the same problem

Where privacy is in scope, SOC 2 criteria track the lifecycle: notice and consent, collection limitation, use and retention, access, disclosure to third parties, and quality and monitoring.

The distinction is whether the gap is documentation or capability. Documentation can be produced. Capability has to be built, and auditors increasingly want evidence that a control operated, not confirmation that a policy exists.

What the criteria are actually testing

The privacy criteria follow the processing lifecycle. Notice and consent means your privacy notice reflects what the business actually does. Collection limitation means you can show what you collect and why. Use and retention means documented retention periods that are enforced, not just written down. Access means a functioning process for responding to data subject requests, with evidence of responses. Disclosure to third parties means vendor diligence you can show to an auditor. Quality and monitoring means the program runs continuously, not just at audit time.

Auditors are increasingly testing whether controls operated. A policy that exists but is not followed does not close the gap.

Gaps that close quickly

  • A compliant privacy notice
  • Documented retention periods
  • Updated processor terms
  • Evidence of training

Gaps that require real work

  • A complete data inventory — surveys capture what people believe happens rather than what the systems actually do, and miss processing that sits outside IT's visibility, including tools procured on a corporate card, spreadsheets held locally, and data held by third parties on the company's behalf
  • A functioning DSAR process with evidence of responses, not just a documented procedure
  • Vendor diligence — records of what processors do with data, not just signed DPAs
  • Enforced retention and deletion — evidence the schedule runs, not just that it exists

Common questions

Why is our data map not passing scrutiny even though we built one?

The most common reason is that the exercise was run as a survey circulated to system owners, so it captures what people believe happens rather than what the systems actually do. It also tends to miss processing that sits outside IT's visibility — tools procured on a corporate card, spreadsheets held locally, data held by third parties on the company's behalf. Records built at the system level rather than the processing activity level cannot be used to assess legal basis or retention, which is what an auditor needs.

We have a data map — why does it keep going stale?

Once built without a maintenance process, a record diverges from the business within a quarter and cannot be relied on when a regulator, an auditor, or a data subject request tests it. A record is only useful if it reflects what the business currently does.

Can the structural gaps be closed before our audit window?

Some can, depending on how much time remains and where your current state sits. The ones that cannot close quickly are structural: a complete data inventory, a functioning DSAR process with evidence of responses, vendor diligence, and enforced retention and deletion. These require building capability, and auditors increasingly want evidence that a control operated, not confirmation that a policy exists. The starting point is a gap assessment that distinguishes which gaps are documentation and which are capability, so the remaining time is spent on the right work.

How Applied Privacy Consulting Remediates SOC 2 Privacy Findings

  • Finding Triage And Remediation Planning

    Review of the exceptions in your report to separate one-off documentation gaps from underlying process failures, followed by a written plan per finding covering the corrective action, the control owner, the closure evidence, and the sequencing needed to have controls operating before your next observation window opens.

  • Notice And Consent Alignment

    Review and redrafting of privacy notices, in-product disclosures, and internal commitments so that what you tell individuals matches what your systems do, together with assessment of how consent and opt-outs are captured, evidenced, and honored downstream.

  • Data Inventory, Retention, And Disposal

    Data mapping to establish what is collected, from where, and for what purpose, plus a retention schedule tied to legal and business justifications with defined disposal triggers and evidence that disposal occurs as scheduled.

  • Data Subject Rights And Correction

    Design or rebuild of the DSAR process where the report cites missed timelines, incomplete searches, or absent handling records, including procedures for accuracy, correction, and the propagation of corrections to downstream systems and recipients.

  • Third-Party And Vendor Oversight

    Review of processor arrangements, contractual privacy terms, and the diligence and monitoring applied to parties receiving personal data.

  • Privacy Governance, Monitoring, And Training

    Establishment of the governance layer auditors look for, including privacy policies, complaint handling, periodic control testing, and escalation paths, with onsite or remote training for control owners so the process holds through the next observation period.

  • Evidence Package And Readiness Review

    Assembly of the artifacts your auditor will request, followed by a walkthrough of remediated controls before fieldwork so gaps surface on your timeline instead of theirs.

Explore

Start with a defined assessment

Start the assessment

The typical path is an audit or gap assessment as a fixed-scope project first, then a retainer to run what the assessment recommends. Hourly work is available at $275/hr for straightforward advisory.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.