Some of those gaps close quickly. Others are structural and will not close before the audit window without real work. The distinction matters.
Where privacy is in scope, SOC 2 criteria track the lifecycle: notice and consent, collection limitation, use and retention, access, disclosure to third parties, and quality and monitoring.
The distinction is whether the gap is documentation or capability. Documentation can be produced. Capability has to be built, and auditors increasingly want evidence that a control operated, not confirmation that a policy exists.
The privacy criteria follow the processing lifecycle. Notice and consent means your privacy notice reflects what the business actually does. Collection limitation means you can show what you collect and why. Use and retention means documented retention periods that are enforced, not just written down. Access means a functioning process for responding to data subject requests, with evidence of responses. Disclosure to third parties means vendor diligence you can show to an auditor. Quality and monitoring means the program runs continuously, not just at audit time.
Auditors are increasingly testing whether controls operated. A policy that exists but is not followed does not close the gap.
The most common reason is that the exercise was run as a survey circulated to system owners, so it captures what people believe happens rather than what the systems actually do. It also tends to miss processing that sits outside IT's visibility — tools procured on a corporate card, spreadsheets held locally, data held by third parties on the company's behalf. Records built at the system level rather than the processing activity level cannot be used to assess legal basis or retention, which is what an auditor needs.
Once built without a maintenance process, a record diverges from the business within a quarter and cannot be relied on when a regulator, an auditor, or a data subject request tests it. A record is only useful if it reflects what the business currently does.
Some can, depending on how much time remains and where your current state sits. The ones that cannot close quickly are structural: a complete data inventory, a functioning DSAR process with evidence of responses, vendor diligence, and enforced retention and deletion. These require building capability, and auditors increasingly want evidence that a control operated, not confirmation that a policy exists. The starting point is a gap assessment that distinguishes which gaps are documentation and which are capability, so the remaining time is spent on the right work.
Review of the exceptions in your report to separate one-off documentation gaps from underlying process failures, followed by a written plan per finding covering the corrective action, the control owner, the closure evidence, and the sequencing needed to have controls operating before your next observation window opens.
Review and redrafting of privacy notices, in-product disclosures, and internal commitments so that what you tell individuals matches what your systems do, together with assessment of how consent and opt-outs are captured, evidenced, and honored downstream.
Data mapping to establish what is collected, from where, and for what purpose, plus a retention schedule tied to legal and business justifications with defined disposal triggers and evidence that disposal occurs as scheduled.
Design or rebuild of the DSAR process where the report cites missed timelines, incomplete searches, or absent handling records, including procedures for accuracy, correction, and the propagation of corrections to downstream systems and recipients.
Review of processor arrangements, contractual privacy terms, and the diligence and monitoring applied to parties receiving personal data.
Establishment of the governance layer auditors look for, including privacy policies, complaint handling, periodic control testing, and escalation paths, with onsite or remote training for control owners so the process holds through the next observation period.
Assembly of the artifacts your auditor will request, followed by a walkthrough of remediated controls before fieldwork so gaps surface on your timeline instead of theirs.
The typical path is an audit or gap assessment as a fixed-scope project first, then a retainer to run what the assessment recommends. Hourly work is available at $275/hr for straightforward advisory.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.