SOC 2
P - Privacy

SOC 2 SOC2-P4.3: P4.3 Securely disposing of personal information

Personal information is disposed of securely in line with privacy objectives. Points of focus: deletion requests are captured and the related information flagged for destruction; information no longer retained is anonymised, disposed of or destroyed in a way that prevents loss, theft, misuse or unauthorised access; and policies and procedures destroy information identified for destruction.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 245 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 10 controls

  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 3.3.1.2 3.3.1.2 Card verification code not retained after authorization
  • 3.3.1.3 3.3.1.3 PIN and PIN block not retained after authorization
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.7.5 3.7.5 Retirement, replacement or destruction of keys
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 9.4.6 9.4.6 Destruction of hard-copy materials
  • 9.4.7 9.4.7 Destruction of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

NIST SP 800-53 Rev 5 · 9 controls

ISO 27701:2019 · 8 controls

  • 6.11.3 Test data
  • 6.5.3 Media handling
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.6 Temporary files
  • 7.4.7 Retention
  • 7.4.8 Disposal
  • 8.4.1 Temporary files
  • 8.4.2 Return, transfer or disposal of PII

GDPR · 7 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.17 Right to erasure (right to be forgotten)
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.32 Security of processing
  • GDPR-Art.9 Processing of special categories of personal data

CIS Controls v8 · 6 controls

  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.5 Securely Dispose of Data
  • CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices

ISO 27001:2022 · 6 controls

  • 5.33 Protection of records
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion
  • 8.11 Data masking

ISO 27002:2022 · 6 controls

  • 5.33 Protection of records
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion
  • 8.24 Use of cryptography
  • 8.33 Test information

FedRAMP High · 5 controls

  • MP-6 Media Sanitization
  • PE-16 Delivery and Removal
  • PS-4 Personnel Termination
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

FedRAMP Moderate · 5 controls

  • MP-6 Media Sanitization
  • PE-16 Delivery and Removal
  • PS-4 Personnel Termination
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-3 Data Subject Rights
  • TANZANIA-4 Security and Cross-Border
  • TANZANIA-5 DPO, Governance, Breach
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

HIPAA Security Rule · 3 controls

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

Saudi Arabia PDPL · 3 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-22 Privacy by design and default

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)

CMMC 2.0 · 2 controls

EU AI Act · 2 controls

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • EUAI-Art.60 Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration

SASB Standards · 2 controls

  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Uruguay DPL · 2 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • SEC07-BP04 Define scalable data lifecycle management
  • AL-DPA-12 International Data Transfers
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • DS-2 Ensure software supply chain security

C5 (Germany) · 1 control

CCPA/CPRA · 1 control

  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

ISO/IEC 42001:2023 · 1 control

  • 7.5.3 Control of documented information
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SOC-CY-DC2 Nature of Sensitive Information
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • UKAI-2 Sector-Specific Regulator Engagement
  • OB-CX.2 Granular Consent Management

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • SO3.2 Regulatory frameworks for digital health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 245 it maps to, and the evidence behind each claim, over MCP and REST.