Privacy and Data Protection Policy template (SOC 2)

Sets out how personal data handled through the product and the business is collected, used, shared, protected, retained and made available to the people it concerns.

Policy P22 of 22 · Owner: Security Owner · 4 criteria in the crosswalk · Apache-2.0

What this policy is for

The Privacy and Data Protection Policy is one of the 22 governance policies in the Policyseed set. It is owned by the Security Owner, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.

SOC 2 criteria this policy addresses

The Policyseed crosswalk maps 4 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.

CriterionWhat it coversWhere in this policy
CC2.3External communicationSection 4 (Policy Statements)
CC9.2Vendor and business partner riskSection 4 (Policy Statements)
C1.1Identifying and protecting confidential informationSection 4 (Policy Statements)
C1.2Disposing of confidential informationSection 5 (Procedures)

Evidence auditors typically ask for

A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.

  • Public security page or trust page URL and a dated screenshot
  • Published privacy notice with the date it was last updated
  • Customer incident notification template from the Incident Response Policy procedures
  • Contract or DPA clause stating customer breach notification timelines
  • Vendor inventory with data access level, criticality tier and review date for each vendor
  • SOC 2 report review notes or completed security questionnaire for each critical vendor
  • Signed vendor DPA or contract with security and confidentiality clauses
  • Annual vendor review record signed by the Security Owner

Full text: the Privacy and Data Protection Policy rendered for Northwind Cloud Inc

Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.

Sample document

Northwind Cloud Inc Privacy and Data Protection Policy

1. Purpose

Northwind Cloud Inc handles personal data belonging to customers, the users of Northwind, prospects, personnel and business contacts. This policy defines how that data is collected, used, shared, protected, retained and deleted, and how Northwind Cloud Inc responds to the people it concerns, so that Northwind Cloud Inc meets its legal and contractual privacy obligations and takes privacy decisions deliberately rather than by default.

2. Scope

This policy applies to all personal data processed by Northwind Cloud Inc, whether as a controller (personnel and marketing data) or as a processor for its customers (data submitted to Northwind). It applies to all personnel and to all systems, including Northwind, corporate applications and third-party services, currently including Supabase, Stripe, Datadog and Slack. Northwind Cloud Inc currently processes the following regulated categories of data through Northwind: PII. This policy is not legal advice; stricter local requirements prevail.

3. Roles and Responsibilities

  • Executive Management approves this policy and the privacy notice and is accountable for Northwind Cloud Inc's privacy obligations to customers and regulators; Priya Natarajan, CEO is the approver of record.
  • Security Owner (Dana Whitfield, CTO) owns this policy and acts as privacy lead: maintains the data inventory, approves new processing and vendors, coordinates data subject requests, leads breach assessment and reports privacy risk to Executive Management, which appoints a data protection officer or representative where law requires one.
  • Engineering builds privacy protections into Northwind (access controls, encryption, retention enforcement, export and deletion), implements approved data flows only and supports requests and investigations with technical evidence.
  • People Operations handles personnel data under this policy, ensures privacy training is completed and manages the privacy aspects of recruitment and employment records.
  • All Personnel use personal data only for the purpose it was collected for, follow the Data Classification and Handling Policy, and report suspected privacy incidents and any individual's request about their data to security@northwindcloud.example without delay.

4. Policy Statements

  • 4.1 Northwind Cloud Inc maintains a data inventory (record of processing activities) listing each category of personal data, its purpose, source, systems, recipients, retention period and whether Northwind Cloud Inc acts as controller or processor. The inventory underpins the privacy notice, vendor agreements and data subject responses.
  • 4.2 Personal data is processed only for specified, explicit and legitimate purposes. Each processing activity records its lawful basis (such as contract, legitimate interests, legal obligation or consent), and consent, where relied upon, is freely given, specific, recorded and as easy to withdraw as to give.
  • 4.3 Personal data is limited to what is necessary for the purpose. Northwind features collect the minimum data needed, default to the most privacy-protective setting and give customers the means to export and delete the data they submit. New features and processing activities are assessed for privacy risk before launch, with a documented privacy impact assessment where the risk to individuals is likely to be high.
  • 4.4 Individuals may exercise their rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent. Northwind Cloud Inc verifies the requester's identity, responds within 30 days of receipt (or any shorter statutory period) and logs every request and its outcome. Requests from a customer's end users are referred to that customer, with Northwind Cloud Inc's assistance.
  • 4.5 Every vendor that processes personal data for Northwind Cloud Inc is bound by a written data processing agreement covering the scope and purpose of processing, security measures, onward sub-processing, and assistance with data subject requests and breach notification. This applies to Supabase, Stripe, Datadog and Slack and to any future vendor. No vendor receives personal data before the agreement is in place and the vendor has been assessed under the Vendor and Third-Party Risk Management Policy.
  • 4.6 Where Northwind Cloud Inc acts as a processor for customers, it processes personal data only on the customer's documented instructions, maintains a published list of sub-processors, gives customers advance notice of changes to that list, and flows down equivalent obligations to each sub-processor.
  • 4.7 Personal data crosses national borders only where a lawful transfer mechanism applies, such as an adequacy decision or standard contractual clauses. The hosting regions used for Northwind on AWS and Vercel are documented in the data inventory and disclosed to customers.
  • 4.8 Northwind Cloud Inc does not knowingly process health information or other special categories of personal data through Northwind. Any proposal to process such data requires a privacy impact assessment and, where required, additional contractual instruments before processing begins.
  • 4.9 Northwind Cloud Inc does not handle payment card data directly; payments go through a third-party processor, and Northwind Cloud Inc systems never store full card numbers or security codes.
  • 4.10 Personal data is retained only as long as the data inventory, law or contract requires and is then deleted or irreversibly anonymised under the Data Retention and Disposal Policy. Customer data is deleted or returned within 30 days of contract termination or of the customer's request, and deletion from backups follows the backup rotation schedule.
  • 4.11 A breach affecting personal data is handled under the Incident Response Policy. The Security Owner assesses the risk to individuals, notifies supervisory authorities where the law requires (within 72 hours where the GDPR or a similar law applies), notifies affected customers within their contractual period and no later than 72 hours after confirmation, and notifies affected individuals where the risk to them is high.
  • 4.12 Northwind Cloud Inc publishes a privacy notice that describes in plain language what personal data it collects, why, on what basis, with whom it is shared, how long it is kept, where it is stored, and how individuals can exercise their rights and contact Northwind Cloud Inc. Marketing messages always include a working unsubscribe mechanism.

5. Procedures

  • 5.1 Data inventory maintenance. Engineering notifies the Security Owner of any new data field, flow, system or vendor involving personal data before deployment, and the Security Owner updates the inventory within ten business days. The full inventory is reviewed annually with Engineering and People Operations. Owner: Security Owner. Cadence: on change; full review Annual.
  • 5.2 Data subject request handling. Requests arriving through any channel are forwarded to security@northwindcloud.example on the day received. The Security Owner logs the request, verifies the requester's identity, and either fulfils the request with Engineering's assistance or refers it to the responsible customer. Owner: Security Owner. Timing: acknowledged within three business days; completed within 30 days of receipt.
  • 5.3 Privacy impact assessment. Before launching a feature or processing activity involving new personal data, new purposes, profiling, special categories or cross-border transfers, the product owner completes the privacy impact template describing the processing, its necessity, risks and mitigations. The Security Owner approves it, requires changes or escalates residual risk to Executive Management. Owner: product owner, with the Security Owner. Timing: before launch.
  • 5.4 Vendor data protection onboarding. Before any vendor receives personal data, the Security Owner confirms that a data processing agreement or equivalent terms are executed, that the vendor risk assessment is complete, that any transfer mechanism is recorded, and that the vendor is added to the data inventory and, where applicable, the sub-processor list with customer notice given. Owner: Security Owner. Timing: before data is shared; sub-processor list reviewed quarterly.
  • 5.5 Breach assessment and notification. When an incident may involve personal data, the incident lead notifies the Security Owner immediately. Within 24 hours the Security Owner records what data, individuals and customers are affected, assesses the likely risk and determines notification obligations. Notifications are drafted with Executive Management and sent within the required deadlines; the assessment is retained with the incident record. Owner: Security Owner. Timing: assessment within 24 hours; notifications within 72 hours where required.
  • 5.6 Retention enforcement. Engineering automates deletion or anonymisation of Northwind data to the retention periods in the data inventory, and the Security Owner verifies each quarter that the jobs ran, that deletion requests were completed within 30 days and that offboarded customers' data is gone. Backups taken by AWS Backup on the Daily schedule age out under the Backup and Recovery Policy. Owner: Engineering, verified by the Security Owner. Cadence: continuous; verification quarterly.
  • 5.7 Privacy notice and consent records. The Security Owner reviews the privacy notice annually and whenever the data inventory changes materially, and Executive Management approves each revision before publication. Consent records capture the timestamp, wording and method of consent, and unsubscribe requests are actioned within ten business days. Owner: Security Owner. Cadence: Annual and on material change.
  • 5.8 Privacy training. All personnel complete privacy training as part of the security awareness programme within 30 days of starting and annually thereafter. Roles that regularly handle personal data (support, sales, engineers with production access) receive role-specific guidance on recognising requests, minimisation and secure handling. Owner: Security Owner, with People Operations. Cadence: at hire and annually.

6. Exceptions

Exceptions must be requested in writing to the Security Owner with the business reason and the compensating controls, and approved by Priya Natarajan, CEO. Approved exceptions are recorded in the exception register with an expiry date no more than 12 months away and are reviewed at each policy review. No exception may waive the requirement for a written agreement before personal data is shared with a vendor.

7. Enforcement

Failure to comply with this policy is subject to disciplinary action under the Human Resources Security Policy, up to and including termination of employment or contract. Contractual remedies apply to contractors and vendors.

8. Review Cadence

The Security Owner reviews this policy on a annual basis and whenever Northwind Cloud Inc begins processing a new category of personal data, enters a new jurisdiction or changes its hosting regions or sub-processors. Reviews are recorded in Section 9 and changes communicated to all personnel within 30 days.

9. Revision History

VersionDateDescriptionApproved by
1.02026-09-02Initial releasePriya Natarajan, CEO

Frequently asked questions

Who should own the Privacy and Data Protection Policy?
In the Policyseed template the Security Owner owns the Privacy and Data Protection Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
Which SOC 2 criteria does the Privacy and Data Protection Policy address?
4 criteria in the Policyseed crosswalk: CC2.3 (External communication), CC9.2 (Vendor and business partner risk), C1.1 (Identifying and protecting confidential information) and C1.2 (Disposing of confidential information). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
Is the Privacy and Data Protection Policy template free to use?
Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.