{
  "node_id": "aicpa-soc2-cc-privacy",
  "title": "AICPA SOC 2 Trust Services Criteria - Privacy Category (P1.0-P8.0 Privacy Notice and Choice)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-17",
  "bluf": "The AICPA SOC 2 Privacy Category requires service organizations to provide a clear privacy notice detailing their personal information practices (P1.0) and to offer choices to individuals regarding the collection, use, retention, and disclosure of their personal information (P2.0). This applies to any entity whose SOC 2 report scope includes the Privacy Trust Services Criterion.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "gdpr-adequacy-decisions-article-45",
    "california-ccpa-v2",
    "uk-retained-gdpr"
  ],
  "primary_citations_count": 7
}