<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - SOC 2 Compliance  - Privacy &amp;#40;Additional Criteria&amp;#41;  </title>
<link>http://www.compliancewiki.org/category/soc-2-compliance/privacy-additional-criteria/60/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-breach-and-incident-notification-p6-6-273.html</guid>
										<title>SOC 2 Breach and Incident Notification &#40;P6.6&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-breach-and-incident-notification-p6-6-273.html</link>
										<description><![CDATA[Overview:The entity provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity&rsquo;s objectives related to privacy. Action Items:1) Create an escalation procedure and publish on the company...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-collecting-personal-information-p3-1-261.html</guid>
										<title>SOC 2 Collecting Personal Information &#40;P3.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-collecting-personal-information-p3-1-261.html</link>
										<description><![CDATA[Overview:Personal information is collected consistent with the entity&rsquo;s objectives related to privacy. Action Items:1) Create a privacy notice (externally facing) and privacy policy (internally facing) and publish on the company intranet for...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-communicating-to-inquiries-complaints-and-disputes-p8-1-276.html</guid>
										<title>SOC 2 Communicating to Inquiries, Complaints, and Disputes &#40;P8.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-communicating-to-inquiries-complaints-and-disputes-p8-1-276.html</link>
										<description><![CDATA[Overview:The entity implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity&rsquo;s...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-communicating-use-of-personal-information-p2-1-260.html</guid>
										<title>SOC 2 Communicating Use of Personal Information &#40;P2.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-communicating-use-of-personal-information-p2-1-260.html</link>
										<description><![CDATA[Overview:The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-disposing-personal-information-p4-3-265.html</guid>
										<title>SOC 2 Disposing Personal Information &#40;P4.3&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-disposing-personal-information-p4-3-265.html</link>
										<description><![CDATA[Overview:The entity securely disposes of personal information to meet the entity&rsquo;s objectives related to privacy. Action Items:1) Create a data retention and disposal policy and related procedures and publish on the company intranet for...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-accuracy-of-personal-information-p7-1-275.html</guid>
										<title>SOC 2 Accuracy of Personal Information &#40;P7.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-accuracy-of-personal-information-p7-1-275.html</link>
										<description><![CDATA[Overview:The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity&rsquo;s objectives related to privacy. Action Items:1) Create an access control policy and related procedures and publish...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-consent-for-disclosing-personal-information-p6-1-268.html</guid>
										<title>SOC 2 Consent for Disclosing Personal Information &#40;P6.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-consent-for-disclosing-personal-information-p6-1-268.html</link>
										<description><![CDATA[Overview:The entity discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity&rsquo;s objectives related to privacy. Action Items:1) Create a...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-notice-of-privacy-practices-p1-1-259.html</guid>
										<title>SOC 2 Notice of Privacy Practices &#40;P1.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-notice-of-privacy-practices-p1-1-259.html</link>
										<description><![CDATA[Overview:The entity provides notice to data subjects about its privacy practices to meet the entity&rsquo;s objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity&rsquo;s...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-correcting-personal-information-p5-2-267.html</guid>
										<title>SOC 2 Correcting Personal Information &#40;P5.2&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-correcting-personal-information-p5-2-267.html</link>
										<description><![CDATA[Overview:The entity corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity&rsquo;s objectives related to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-recording-the-disclosure-of-personal-information-p6-2-269.html</guid>
										<title>SOC 2 Recording the Disclosure of Personal Information &#40;P6.2&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-recording-the-disclosure-of-personal-information-p6-2-269.html</link>
										<description><![CDATA[Overview:The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity&rsquo;s objectives related to privacy. Action Items:1) Create a privacy notice (externally facing)...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-limiting-use-of-personal-information-p4-1-263.html</guid>
										<title>SOC 2 Limiting Use of Personal Information &#40;P4.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-limiting-use-of-personal-information-p4-1-263.html</link>
										<description><![CDATA[Overview:The entity limits the use of personal information to the purposes identified in the entity&rsquo;s objectives related to privacy. Action Items:1) Create a privacy notice (externally facing) and privacy policy (internally facing) and publish...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-consent-for-requesting-personal-information-p3-2-262.html</guid>
										<title>SOC 2 Consent for Requesting Personal Information &#40;P3.2&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-consent-for-requesting-personal-information-p3-2-262.html</link>
										<description><![CDATA[Overview:For information requiring explicit consent, the entity communicates the need for such consent, as well as the consequences of a failure to provide consent for the request for personal information, and obtains the consent prior to the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-granting-access-to-personal-information-p5-1-266.html</guid>
										<title>SOC 2 Granting Access to Personal Information &#40;P5.1&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-granting-access-to-personal-information-p5-1-266.html</link>
										<description><![CDATA[Overview:The entity grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-retaining-personal-information-p4-2-264.html</guid>
										<title>SOC 2 Retaining Personal Information &#40;P4.2&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-retaining-personal-information-p4-2-264.html</link>
										<description><![CDATA[Overview:The entity retains personal information consistent with the entity&rsquo;s objectives related to privacy. Action Items:1) Create a data retention and disposal policy and related procedures and publish on the company intranet for employees to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-recording-unauthorized-disclosures-p6-3-270.html</guid>
										<title>SOC 2 Recording Unauthorized Disclosures &#40;P6.3&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-recording-unauthorized-disclosures-p6-3-270.html</link>
										<description><![CDATA[Overview:The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity&rsquo;s objectives related to privacy. Action Items:1)...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-responding-to-personal-information-requests-p6-7-274.html</guid>
										<title>SOC 2 Responding to Personal Information Requests &#40;P6.7&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-responding-to-personal-information-requests-p6-7-274.html</link>
										<description><![CDATA[Overview:The entity provides data subjects with an accounting of the personal information held and disclosure of the data subjects&rsquo; personal information, upon the data subjects&rsquo; request, to meet the entity&rsquo;s objectives related to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-vendor-privacy-commitments-p6-4-271.html</guid>
										<title>SOC 2 Vendor Privacy Commitments &#40;P6.4&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-vendor-privacy-commitments-p6-4-271.html</link>
										<description><![CDATA[Overview:The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity&rsquo;s objectives related to privacy. The entity assesses those parties&rsquo; compliance on a periodic...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/soc-2-vendor-notification-for-unauthorized-disclosures-p6-5-272.html</guid>
										<title>SOC 2 Vendor Notification for Unauthorized Disclosures &#40;P6.5&#41;</title>
										<link>http://www.compliancewiki.org/article/soc-2-vendor-notification-for-unauthorized-disclosures-p6-5-272.html</link>
										<description><![CDATA[Overview:The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are...]]></description>

									</item>

</channel>

</rss>