Frameworks / SSAE 18 - Attestation Standards (SOC Reporting) / SSAE18-P1.2 SSAE 18 - Attestation Standards (SOC Reporting)
SOC 2 - Additional Trust Services Categories
SSAE 18 - Attestation Standards (SOC Reporting) SSAE18-P1.2: P1.2 - Choice and Consent The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects.
What else in your programme already covers this This control maps to 168 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer SOC2-P3.1 Personal information is collected consistent with privacy commitments SOC2-P4.3 Personal information is securely disposed of SOC2-P6.1 Personal information is disclosed to third parties only as committed SWE-1 Scope and Purpose SWE-11 Integritetsskyddsmyndigheten (IMY) SWE-2 Relationship to GDPR FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) UGA-13 Unlawful Obtaining or Disclosure UGA-15 Unauthorized Sale of Data DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities RIDTPPA-11 Data Minimisation and Purpose Limitation TISAXASS-3 Prototype Protection and Confidentiality UKAI-2 Sector-Specific Regulator Engagement OB-CX.2 Granular Consent Management SO3.2 Regulatory frameworks for digital health Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SOC 2 - Additional Trust Services Categories Query this from an agent The graph holds this control, the 168 it maps to, and the evidence behind each claim, over MCP and REST.