SOC 2
P - Privacy

SOC 2 SOC2-P2.1: P2.1 Choice and consent

Data subjects are told what choices they have over how personal information is collected, used, kept, shared and disposed of and the consequences of each; explicit consent is obtained where required and only for the intended purpose; and the basis for relying on implicit consent is documented. Points of focus: data subjects learn their choices and that consent is needed unless law provides otherwise; they learn the consequences of refusing or withdrawing consent; consent, implied or express, is obtained at or before collection or soon after and their preferences are honoured; new purposes are documented, notified and consented before use; explicit consent is obtained directly for sensitive information unless law says otherwise; and consent is obtained before information moves onto or off a person's device.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 41 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 11 controls

  • 7.2 Conditions for collection and processing
  • 7.2.2 Identify lawful basis
  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.10 Automated decision making
  • 7.3.3 Providing information to PII principals
  • 7.3.4 Providing mechanism to modify or withdraw consent
  • 7.3.5 Providing mechanism to object to PII processing
  • 8.1 General
  • 8.2 Conditions for collection and processing

NIST SP 800-53 Rev 5 · 8 controls

APPI · 3 controls

  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision

GDPR · 3 controls

  • AUCDR-PS-3 Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
  • AUCDR-PS-6 Privacy Safeguard 6 - Use or disclosure of CDR data
  • MYHR-REG-9 Non-discrimination in providing healthcare
  • MYHR-SEC-7 Consumer access controls and consent

CCPA/CPRA · 2 controls

  • §1798.120 Right to Opt Out of Sale or Sharing of Personal Information
  • §1798.135(a) Do Not Sell or Share My Personal Information Link
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • CCM-DSP-12 Limitation of Purpose in Personal Data Processing

EU AI Act · 1 control

  • EUAI-Art.61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes

ISO 27001:2022 · 1 control

  • 5.34 Privacy and protection of personal identifiable information (PII)

ISO 27002:2022 · 1 control

  • 5.34 Privacy and protection of PII

ISO/IEC 42001:2023 · 1 control

  • A.7.3 Acquisition of data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P2.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.