On this page
- What is the difference between SOC 2 and GDPR?
- Where do SOC 2 controls overlap with GDPR?
- What does GDPR require that SOC 2 does not cover?
- Is a SOC 2 report a GDPR certification or a transfer tool?
- How should SaaS, FinTech, and HealthTech teams sequence both?
- How do SOC 2 and GDPR timelines differ?
- How do you run one program for both?
- Frequently Asked Questions
SOC 2 is a voluntary CPA attestation of a service organization’s controls. GDPR is mandatory EU law protecting personal data of people in the EU and EEA. A SOC 2 report does not make you GDPR-compliant. Security evidence overlaps; lawful basis, data-subject rights, and international transfers do not.
| SOC 2 | GDPR | |
|---|---|---|
| What it is | AICPA attestation (Type 1 design, Type 2 operating effectiveness) | EU regulation (2016/679), enforceable since 25 May 2018 |
| Who it protects | Customer trust in your systems (B2B assurance) | Individuals’ rights over personal data |
| When it applies | When buyers or contracts ask for a report | When you process personal data of people in the EU/EEA, including many US SaaS firms under Article 3(2) |
| Output | Confidential CPA report | No SOC-style report; documented, ongoing compliance. Article 42 seals (for example Europrivacy) are optional and separate |
| Enforcement | Lost deals, stalled security reviews | Supervisory authorities; fines up to €20 million or 4% of worldwide annual turnover (Article 83) |
| Scope flexibility | You pick Trust Services Criteria; Security is required | Articles apply where the regulation applies; you do not “descope” data-subject rights |
| Breach clock | Incident response is tested; no 72-hour regulator deadline | Notify the supervisory authority without undue delay and, where feasible, within 72 hours (Article 33) |
| Individual rights | Optional Privacy criterion covers notice, choice, access, use, retention | Binding rights: access, rectification, erasure, restriction, portability, objection (Articles 15–22); typically one month to respond (Article 12(3)) |
| EU-US transfers | Not a transfer mechanism | Chapter V: adequacy (including the EU-US Data Privacy Framework), standard contractual clauses, or another Article 46 tool |
Where to look next. This page is the long-form SOC 2 vs GDPR comparison. For the GDPR reference card (scope and a sourced program cost range), see the GDPR explainer. For the short answer to “does SOC 2 cover GDPR?”, see the buyer guide. If the question is ISO 27001 instead, use SOC 2 vs ISO 27001.
What is the difference between SOC 2 and GDPR?
SOC 2 is an AICPA attestation: a licensed CPA firm examines controls against the Trust Services Criteria and issues a report. GDPR is EU law. One is market-driven assurance. The other is a legal duty to people in the EU and EEA, wherever the company sits.
A SOC 2 report tests one or more of five Trust Services Criteria: Security (always in), Availability, Processing Integrity, Confidentiality, and Privacy. Type 1 is design at a point in time. Type 2 is operating effectiveness over a period, usually three to twelve months. There is no pass/fail certificate and no EU regulator behind it.
GDPR (Regulation (EU) 2016/679) became enforceable on 25 May 2018. It applies to organizations that process personal data of people in the EU and EEA, including many US SaaS companies that offer services to those people or monitor their behavior (Article 3). The UK runs a separate UK GDPR; this comparison uses the EU text.
DLA Piper’s January 2026 GDPR Fines and Data Breach Survey, published 13 February 2026, reported about €1.2 billion in fines for the year beginning 28 January 2025 and a cumulative total since May 2018 of about €7.1 billion. The same survey put personal-data-breach notifications at 443 per day in 2025, up 22% year over year (DLA Piper). SOC 2’s “penalty” is commercial: the deal that will not close without a Type 2.
The AICPA publishes a mapping of the 2017 Trust Services Criteria (with March 2020 updates) to GDPR. Use it as a crosswalk, not as a certificate of GDPR compliance.
Where do SOC 2 controls overlap with GDPR?
The overlap is Article 32: “appropriate technical and organizational measures.” Access control, encryption, monitoring, change management, and incident detection tested in a SOC 2 Security audit are the same class of evidence a supervisory authority expects for security of processing.
Teams reuse these mappings:
- CC6 (logical and physical access). Least-privilege access and access reviews are evidence that personal data is not an open share. They do not prove you had a lawful basis to collect it.
- CC7 (system operations). Logging and alerting support both SOC 2 monitoring and GDPR breach detection. They do not satisfy the Article 33 72-hour notification clock by themselves; the runbook has to name the supervisory authority and the 72-hour trigger.
- CC8 (change management). Authorized, tested changes protect integrity — a security principle GDPR also assumes. They do not replace purpose limitation.
- CC3 (risk assessment). A serious risk process is an input to a DPIA. A DPIA is still a GDPR legal document with a different audience and threshold (Article 35).
Add the optional Privacy criterion if EU personal data is in scope and buyers will read that section. It tracks notice, choice, collection, use, retention, and disposal, which sit closer to Articles 13–14 and data-minimization than Security alone does. It still does not test Article 6 lawful basis, Chapter V transfers, or a DPO appointment.
For how much of the technical GDPR workload a mature SOC 2 typically covers, and the list of legal work it never covers, use the does SOC 2 cover GDPR guide rather than a vendor “60–80% reuse” slide.
What does GDPR require that SOC 2 does not cover?
SOC 2 does not establish a lawful basis, run data-subject rights, produce a record of processing, appoint a DPO, or authorize an international transfer. Those are legal and governance obligations. A Type 2 report can sit next to them. It cannot replace them.
| Workstream | SOC 2 hook | GDPR article | After a clean SOC 2, you still need |
|---|---|---|---|
| Encryption, access, logging, change control | Security TSC (CC6, CC7, CC8) | Article 32 security of processing | The legal program around those controls |
| Risk assessment | CC3 | Article 35 DPIA where required | A DPIA is a legal assessment, not a TSC test |
| Vendors / sub-processors | Vendor-risk criteria (often CC9) | Article 28 | DPAs, sub-processor list, transfer clauses |
| Notices and consent records | Privacy TSC notice and choice criteria, if scoped | Articles 13–14, Article 6 | Lawful basis documented for each purpose |
| Access / deletion / portability | Privacy TSC helps; Common Criteria do not | Articles 15–22 | A one-month DSAR workflow |
| Records of processing | Not a TSC | Article 30 | A living ROPA |
| DPO | Not a TSC | Article 37 | Appoint where required |
| International transfers | Not a TSC | Chapter V | DPF self-certification, SCCs, or another valid tool — not the SOC 2 PDF |
| GDPR “certification” | SOC 2 is not one | Article 42 | An approved scheme if a customer asked for a seal, not a CPA report |
Italian 2026 enforcement is a useful check on “we have SOC 2, so privacy is handled.” On 12 March 2026 the Garante fined Intesa Sanpaolo €17.6 million for unlawfully processing data of about 2.4 million customers during a business-unit transfer, including profiling that lacked a valid basis and was not disclosed in the privacy notice (ICLG). On 17 April 2026 it fined Poste Italiane and Postepay a combined €12.5 million after finding mobile-banking apps collected device-level data beyond what fraud prevention required (DataGuidance). Those findings are lawful-basis and minimization problems. A Security TSC audit would not have been the test.
Is a SOC 2 report a GDPR certification or a transfer tool?
No on both counts. SOC 2 is an AICPA attestation. GDPR certification, when it exists, is an Article 42 scheme. EU-to-US data flows need a Chapter V tool such as an adequacy decision or standard contractual clauses. The SOC 2 PDF is not that tool.
Certification. Article 42 allows approved certification schemes. Europrivacy is a European Data Protection Seal. In April 2026 the EDPB adopted Opinion 14/2026 and Opinion 15/2026. IAPP’s 28 May 2026 summary of those opinions — written by Europrivacy’s board chair — describes two changes: the seal can be requested by certain controllers and processors established outside the EEA, and a Europrivacy variant can be used as an Article 46 transfer mechanism when paired with a binding commitment. Certification remains voluntary and does not move legal responsibility off the controller or processor. If a European buyer asks for a “GDPR certification,” they are not asking for SOC 2.
Transfers. US SaaS serving EU customers usually needs an adequacy route — the EU-US Data Privacy Framework, still documented as an adequacy decision as of the ICO’s 30 July 2026 UK-extension note — or another Chapter V tool such as the standard contractual clauses. Putting “SOC 2 Type 2” in a security questionnaire does not substitute for that paperwork.
Program cost for the GDPR side lives on the GDPR explainer (€30K–€500K+ initial build is the sourced range there). That figure is a GDPR program range, not a SOC 2 audit fee.
How should SaaS, FinTech, and HealthTech teams sequence both?
If US buyers are blocking revenue, run SOC 2 Type 2 on Security, adding Privacy when EU personal data is in scope. Build GDPR lawful basis, ROPA, DSAR, DPAs, and a transfer tool in parallel — those clocks do not wait for the Type 2 letter.
SaaS. A US company with EU users is usually in both scopes: SOC 2 because procurement asks, GDPR because Article 3 does. Shared controls (encryption, IAM, logging, vendor inventory) should be designed once. The DSAR inbox and the SCC pack are extra.
FinTech. Partners want Security and often Processing Integrity. GDPR treats financial data as personal data and, in some cases, as data needing extra care. The 2026 Italian fines above turned on legal basis and data minimization, not on whether logs existed.
HealthTech. PHI under HIPAA is also a special category under GDPR when EU residents are involved. Encryption and access evidence can serve HIPAA, SOC 2 Confidentiality, and Article 32. Breach clocks do not match: GDPR’s 72-hour supervisory notice is much shorter than HIPAA’s 60-day individual-notice window. Design the incident plan to the tighter clock. For HIPAA-specific SOC 2 work, use the HIPAA overlay page rather than stretching this comparison.
How do SOC 2 and GDPR timelines differ?
SOC 2 is a project with an observation window and an annual repeat. GDPR is continuous. The same incident-response and access-control processes have to produce auditor evidence and hit legal deadlines when a breach or a DSAR arrives.
SOC 2 Type 1 is often a few weeks of fieldwork once controls exist. Type 2 needs a 3–12 month observation period, then fieldwork and a report. Cadence is yearly. Detail: how long a SOC 2 audit takes.
GDPR does not wait for that calendar:
- 72 hours to notify the supervisory authority of a personal-data breach where Article 33 applies.
- One month (extendable in limited cases) for data-subject requests under Article 12(3).
- Article 30 records that stay current as processing changes.
- A DPO as an ongoing role where Article 37 applies.
Configure logging (CC7) so a SOC 2 sample and a GDPR investigation can use the same stream. That is the operational overlap. The deadlines are GDPR’s.
How do you run one program for both?
Do one gap analysis against the Trust Services Criteria and the GDPR articles you actually owe. Implement each control so the evidence file can be handed to a CPA and to a DPO. Treat the Type 2 as Article 32 evidence, not as the whole GDPR file.
- One matrix. Each control row lists the TSC point and the GDPR article. Empty GDPR cells are the legal backlog (basis, rights, transfers, ROPA), not more CC6 work.
- Dual-purpose evidence. Access reviews, encryption configs, and incident tickets should be labeled for both the auditor and Article 32/33. Do not keep a second screenshot folder “for GDPR” that nobody updates.
- Sequence. Close the commercial SOC 2 if that is what is blocking US deals, but stand up DSAR and breach notification before you have EU personal data in production — those clocks do not care that fieldwork is next quarter.
Frequently Asked Questions
SOC 2 and GDPR are not substitutes. These are the questions that show up next to the comparison: whether SOC 2 equals GDPR or CCPA, whether SOC 2 is required by law, and whether a SOC 2 report is a GDPR certification.
Is SOC 2 compliant with GDPR and CCPA?
No. SOC 2 is a CPA attestation of controls, not a privacy-law certification. Passing SOC 2 does not make you GDPR- or CCPA-compliant. Security evidence can support GDPR Article 32. Lawful basis, data-subject rights, and transfer tools still have to be built separately.
Is SOC 2 legally required?
No. SOC 2 is voluntary. Customers and contracts often require a report before they will buy. GDPR is legally required when you process personal data of people in the EU or EEA, including many US SaaS companies under Article 3(2).
Does SOC 2 cover GDPR?
No. SOC 2 overlaps GDPR on technical and organizational security measures. It does not cover lawful basis, data-subject rights, DPIAs, records of processing, DPO appointment where required, or Chapter V transfers. The remaining list sits on does SOC 2 cover GDPR.
Does the USA have an equivalent to GDPR?
No single federal statute matches GDPR. The US uses sector rules (HIPAA, GLBA, COPPA) and state laws such as California’s CPRA. SOC 2 is not that equivalent: it is an attestation report, not a privacy regulation.
What is better than SOC 2 compliance?
Neither framework replaces the other. SOC 2 answers enterprise buyers who want a CPA report on your systems. GDPR answers the legal duty to protect EU personal data. A company selling in the US and the EU usually needs both.
Is a SOC 2 report a GDPR certification?
No. GDPR Article 42 certifications are approved schemes such as the Europrivacy European Data Protection Seal. A SOC 2 Type 1 or Type 2 report is an AICPA attestation. It is not an Article 42 seal and not an Article 46 transfer tool.
Related: GDPR explainer • Does SOC 2 cover GDPR? • Trust Services Criteria • SOC 2 vs ISO 27001 • Compare SOC 2 auditors