{"description":"Design-readiness review of the full SOC 2 privacy series: notice and choice, collection through disposal, data subject access and disclosure, and data quality with dispute monitoring (P1.1–P8.1), concluded with dual sign-off on the criteria-bearing final assessment. Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-DATA-01","UC-DATA-02","UC-DATA-03","UC-DATA-05","UC-DATA-06","UC-DATA-07","UC-DATA-09","UC-DATA-14","UC-DATA-15","UC-DATA-16","UC-DATA-17"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-privacy-criteria-assessment","contentDigest":"sha256:e6d523b7976d80d05bd077cdc53c1be7c8205d77d0da9569a624c7dca13e8a2f","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:e6d523b7976d80d05bd077cdc53c1be7c8205d77d0da9569a624c7dca13e8a2f","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-privacy-criteria-assessment"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion.","slug":"audit-soc2-privacy-criteria-assessment","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Privacy Criteria Assessment","nodes":[{"data":{"controls":["UC-DATA-07","UC-DATA-17","UC-DATA-02","UC-DATA-05","UC-DATA-01","UC-DATA-03","UC-DATA-09","UC-DATA-06","UC-DATA-14","UC-DATA-15","UC-DATA-16"],"description":"Evaluate P1.1–P8.1 notice, consent, collection, use, retention, access, disclosure, quality and dispute handling and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.","instructions":"**Objective**\nEvaluate P1.1–P8.1 notice, consent, collection, use, retention, access, disclosure, quality and dispute handling and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\n- The linked consolidated controls for privacy notice and consent\n- The current privacy notice with its revision history\n- Consent capture design: what is asked, when, and where the record lands\n- The documented basis for any implicit-consent processing\n\nThe linked consolidated controls for lawful basis, consent, use limitation, and retention\n- Data inventory listing personal-information elements, purposes, and lawful bases\n- Retention schedule entries for personal data with disposal methods\n- Disposal evidence for the window, including customer-environment teardown records\n\nThe linked consolidated controls for access, correction, disclosure records, vendor commitments, and breach notification\n- Data subject request procedure with identity verification and response clocks\n- Disclosure log and any unauthorized-disclosure records for the window\n- Vendor privacy terms for the cloud provider, the workforce identity and collaboration platform, and the source-control platform\n\nPrivacy Policy and Legal & Regulatory Compliance Policy (current approved versions with effective dates)\n- The linked consolidated controls for data quality and dispute resolution\n- Complaint and inquiry records for the window with resolution times\n- Design conclusions and open issues recorded in the preceding procedure items\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Assess Privacy Notice & Consent Choices”, “Evaluate Collection, Use, Retention & Disposal”, “Evaluate Data Subject Access & Disclosure Controls”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Assess Privacy Notice & Consent Choices: Assess P1.1 and P2.1: notice about privacy practices is provided to data subjects and updated in a timely manner for changes, and choices about collection, use, retention, disclosure, and disposal are communicated, with explicit consent obtained where required and the basis for implicit consent documented. Identify the published privacy notices and consent mechanisms applicable to the scoped service, including account creation and product communications where relevant.\n\n2. Verify the privacy notice describes actual practice - categories collected, purposes, retention, disclosure, and contact paths - and reads accurately against the product's behavior.\n3. Confirm notice updates follow a defined path: review, approval, publication, and timely communication to data subjects.\n4. Inspect consent capture for the explicit-consent cases and verify records tie each consent to its purpose and moment.\n5. Check the implicit-consent basis is documented and defensible for processing not covered by explicit consent.\n6. Record a design conclusion per criterion and log gaps as candidate findings.\n\n7. Assessment scope for Evaluate Collection, Use, Retention & Disposal: Evaluate the collection-through-disposal chain: personal information is collected consistent with privacy objectives (P3.1), explicit consent is obtained before collection where required (P3.2), use is limited to the identified purposes (P4.1), retention matches the objectives (P4.2), and disposal is secure (P4.3). The platform's minimalist collection posture - workspace account data and customer workflow content only - is the design baseline.\n\n8. Verify each collected element maps to a documented purpose and lawful basis, and nothing is collected without one.\n9. Confirm explicit consent is captured before collection for the cases that require it, and that refusal paths behave as the notice describes.\n10. Check use limitation in practice: personal data does not drift into analytics, testing, or AI features beyond the stated purposes without a documented decision.\n11. Verify retention limits and secure-disposal methods executed during the window, including deletion within decommissioned customer environments.\n12. Record a design conclusion per criterion and log gaps as candidate findings.\n\n13. Assessment scope for Evaluate Data Subject Access & Disclosure Controls: Evaluate the access and disclosure criteria: data subjects can access their stored information with denials explained (P5.1) and obtain correction with third-party propagation (P5.2); disclosures require prior consent (P6.1) and are recorded (P6.2), unauthorized disclosures including breaches are recorded (P6.3), vendors with access to personal information carry privacy commitments (P6.4) and breach-notification duties (P6.5), affected data subjects and regulators are notified of breaches (P6.6), and an accounting of the personal information held and its disclosures is available on request (P6.7).\n\n14. Walk the request path for access and correction: identity verification, retrieval across tenant and corporate stores, response within the committed window, and denial reasoning where applicable.\n15. Verify disclosures to third parties trace to prior consent and land in the disclosure log completely and timely.\n16. Confirm unauthorized-disclosure records feed the incident process and the notification duties toward data subjects and regulators are scripted.\n17. Inspect vendor terms for privacy commitments and breach-notification clauses, with periodic compliance review of both.\n18. Check an accounting of the personal information held and its disclosures can actually be produced for a data subject on request.\n19. Record a design conclusion per criterion and log gaps as candidate findings.\n\n20. Assessment scope for Conclude on Data Quality, Dispute Handling & Privacy Program: Assess the final privacy criteria and close the series: personal information is accurate, up-to-date, complete, and relevant (P7.1), and a process receives, addresses, and resolves inquiries, complaints, and disputes from data subjects with periodic compliance monitoring (P8.1). Then consolidate the conclusions of the preceding privacy procedure items into a series verdict against the governing privacy policies.\n\n21. Verify data-quality measures keep personal information accurate and current: correction propagation, staleness review, and source-of-truth discipline.\n22. Confirm the inquiry and complaint channel is reachable from the privacy notice, tracked to resolution, and periodically reviewed for compliance and trends.\n23. Reconcile the design conclusions for all eighteen privacy criteria recorded across this workflow against their evidence.\n24. Verify every open privacy gap exists as an issue on the readiness audit with a named owner and a target date.\n25. Present the consolidated privacy verdict for dual sign-off by the executive sponsor and the security and compliance lead; an unresolved objection returns the work to the relevant assessment activity instead of closing it here.\n\n**Record in AssureSwarm**\nAttach the notice revision history and consent-record samples to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the data inventory, retention extract, and disposal evidence to this step. Raise gaps as issues linked to the readiness audit and record the five conclusions in the step record.\n\nAttach request-procedure evidence, the disclosure log extract, and vendor terms to this step. Raise gaps as issues linked to the readiness audit and record the nine conclusions in the step record.\n\nAttach complaint-handling evidence and the privacy section of the readiness summary to this step and record the consolidated verdict. Confirm every gap carries its issue link before requesting approval.\n\n**Exit criteria**\nP1.1 and P2.1 each carry a documented design conclusion supported by attached evidence, and every notice or consent gap has a named owner and a target date. P3.1, P3.2, P4.1, P4.2, and P4.3 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. All nine access and disclosure criteria carry documented design conclusions supported by attached evidence, and every gap has a named owner and a target date. P7.1 and P8.1 carry supported design conclusions, all eighteen privacy criteria are classified in the readiness summary, both approvers have signed off on this step, and no privacy gap remains without an owner, a target date, and a linked issue.","kind":"task","label":"Conclude on Data Quality, Dispute Handling & Privacy Program","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-4"}],"sourceTemplateId":"workflow-library:audit-soc2-privacy-criteria-assessment"}
