SOC 2
P - Privacy

SOC 2 SOC2-P6.7: P6.7 Accounting of personal information held and disclosed

On request, data subjects receive a report of what personal information is held about them and its disclosures. Points of focus: the types of personal and sensitive personal information, and the processes, systems and third parties that handle them, are identified; and requests for an accounting are captured and answered. The 2022 revision adds, for data processors, answering data controllers when they ask what personal information the processor holds, in line with service agreements.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 28 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 11 controls

  • 7.3 Obligations to PII principals
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.10 Automated decision making
  • 7.3.2 Determining information for PII principals
  • 7.3.3 Providing information to PII principals
  • 7.3.6 Access, correction and/or erasure
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests
  • 7.5.4 Records of PII disclosure to third parties
  • 8.3 Obligations to PII principals
  • 8.3.1 Obligations to PII principals

APPI · 2 controls

  • APPI-A29 Records When Providing Personal Data to a Third Party
  • APPI-A33 Request for Disclosure of Retained Personal Data

CCPA/CPRA · 2 controls

  • §1798.110 Right to Know Categories and Specific Pieces of Personal Information Collected
  • §1798.115 Right to Know Personal Information Sold or Shared and Recipients

GDPR · 2 controls

  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction

PCI DSS 4.0 · 2 controls

  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • AUCDR-PS-10 Privacy Safeguard 10 - Notifying of the disclosure of CDR data

ISO 27001:2022 · 1 control

  • 5.34 Privacy and protection of personal identifiable information (PII)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P6.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.