SOC 2 P4.2: Personal information is retained for only as long as needed
Retains personal information consistent with the entity's objectives related to privacy
What else in your programme already covers this
This control maps to 70 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-22 Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate
NIST800-PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or
NIST800-PT-3 Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable
NIST800-SI-18 Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-defined] ; and Correct or delete inaccurate or outdated personally identifiable information
NIST800-SI-19 De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification
NIST800-SI-21 Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed
3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following: • Coverage for all locations of stored account data.
You are reading one control. How much of SOC 2 have you already done?
SOC 2 P4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.