Skip to main content

๐Ÿ’ผ P2.1 The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice.

  • Contextual name: ๐Ÿ’ผ P2.1 The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice.

  • ID: /frameworks/soc-2/p2/01

  • Located in: ๐Ÿ’ผ P2.0 Privacy Criteria Related to Choice and Consent

Descriptionโ€‹

Explicit consent for the collection, use, retention, disclosure, and disposal of personal information is obtained from data subjects or other authorized persons, if required. Such consent is obtained only for the intended purpose of the information to meet the entity's objectives related to privacy. The entity's basis for determining implicit consent for the collection, use, retention, disclosure, and disposal of personal information is documented.

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ P2.1-1 Communicates to Data Subjects
๐Ÿ’ผ P2.1-2 Communicates Consequences of Denying or Withdrawing Consent
๐Ÿ’ผ P2.1-3 Obtains Implicit or Explicit Consent
๐Ÿ’ผ P2.1-4 Documents and Obtains Consent for New Purposes and Uses
๐Ÿ’ผ P2.1-5 Obtains Explicit Consent for Sensitive Information
๐Ÿ’ผ P2.1-6 Obtains Consent for Data Transfers