SOC 2
P - Privacy

SOC 2 SOC2-P5.1: P5.1 Data subject access

Identified and authenticated data subjects can see their stored personal information and, on request, receive physical or electronic copies; if access is denied they are told why, as objectives require. Points of focus: identity is authenticated before access is given; people can find out whether information about them is held and obtain it; it is provided in an understandable form, in reasonable time and at reasonable cost; and denials are explained promptly unless law prohibits it. The 2022 revision adds, for data processors, a process to act on data subject requests passed on by data controllers under the service agreement, including authenticating them, giving access where appropriate, answering in reasonable time and notifying any denial.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 82 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 14 controls

  • 6.3.2 Mobile devices and teleworking
  • 6.4.2 During employment
  • 6.4.3 Termination and change of employment
  • 6.5.2 Information classification
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 6.6.3 User responsibilities
  • 6.6.4 System and application access control
  • 7.3.6 Access, correction and/or erasure
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests
  • 7.4 Privacy by design and privacy by default
  • 7.4.9 PII transmission controls

NIST SP 800-53 Rev 5 · 10 controls

PCI DSS 4.0 · 8 controls

  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components

ISO 27001:2022 · 5 controls

  • 5.15 Access control
  • 5.18 Access rights
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.11 Data masking
  • 8.3 Information access restriction

ISO 27002:2022 · 5 controls

  • 5.12 Classification of information
  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 8.3 Information access restriction

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • AC-21 Information Sharing
  • AC-3 Access Enforcement
  • MP-2 Media Access
  • SC-15 Collaborative Computing Devices and Applications

FedRAMP Moderate · 4 controls

  • AC-21 Information Sharing
  • AC-3 Access Enforcement
  • MP-2 Media Access
  • SC-15 Collaborative Computing Devices and Applications

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

CIS Controls v8 · 3 controls

  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-6.8 Define and Maintain Role-Based Access Control

GDPR · 3 controls

  • MYHR-REG-2 Healthcare recipient registration and identity verification
  • MYHR-SEC-7 Consumer access controls and consent

CCPA/CPRA · 2 controls

  • §1798.110 Right to Know Categories and Specific Pieces of Personal Information Collected
  • §1798.130(a)(2) 45-Day Response Window and Identity Verification
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • CCM-DSP-17 Sensitive Data Protection

APPI · 1 control

  • APPI-A33 Request for Disclosure of Retained Personal Data
  • AUCDR-PS-5 Privacy Safeguard 5 - Notifying of the collection of CDR data

C5 (Germany) · 1 control

EU AI Act · 1 control

  • EUAI-Art.86 Right to explanation of individual decision-making
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 82 it maps to, and the evidence behind each claim, over MCP and REST.