What Privacy actually requires
The AICPA Trust Services Criteria for Privacy define the controls that demonstrate personal information is collected, used, retained, disclosed, and disposed of in conformity with the entity's privacy commitments and the Generally Accepted Privacy Principles (GAPP). The criterion is published as part of the AICPA TSP Section 100 framework available at aicpa.org and covers ten domain areas: notice and choice (transparent disclosure to data subjects about data collection), consent (explicit consent for collection and use), collection limitation (collecting only necessary data), use limitation (using data only for disclosed purposes), retention limitation (deleting data when no longer needed), access (data subject rights to access, correct, and delete their data), disclosure to third parties (controlled sharing with vendors and partners), security for privacy (controls supporting privacy specifically), quality (data accuracy and currency), and monitoring and enforcement (ongoing oversight of privacy programme effectiveness).
Privacy is the heaviest single-criterion lift in the AICPA TSC catalog because the GAPP control set is broad, the controls are bespoke to the SaaS's privacy practices, and the audit testing requires the auditor to verify that the SaaS's stated privacy commitments are operationally implemented across all ten GAPP domains. The control set is layered on top of the Security Common Criteria; a Privacy scope means the auditor tests Common Criteria plus all ten Privacy domains during the same engagement.
What the marginal cost actually depends on
There is no published figure for what Privacy adds, because no CPA firm publishes a SOC 2 rate card of any kind and a criterion add-on is one component of a fee set per engagement. Anyone quoting a precise add-on split by firm tier is quoting a number nobody published. The mechanism is knowable, though, and for this criterion it explains why it is the most expensive of the four.
Two things stack. Privacy carries the largest set of additional criteria of any optional TSC, so the marginal auditor testing is the heaviest. And underneath the audit sits an actual privacy programme: notice, choice and consent, collection limits, retention schedules, disposal, vendor privacy assessments, breach notification and data-subject rights workflows. For most companies that programme is not a documentation exercise over something they already run. It is work that does not exist yet, has to be built, and has to be operating before the observation period opens. That build is usually larger than the audit fee it unlocks. The exception is a company already doing this work for GDPR or CCPA, where much of the programme exists and Privacy becomes an evidence exercise rather than a build. To get your real number, ask one firm to quote Security only and Security plus Privacy against the same written scope, then budget the programme work separately.
When to scope Privacy in
Privacy scope is editorially defensible when the SaaS handles personal information under privacy regulations (GDPR, CCPA/CPRA, PIPEDA, LGPD, or similar) and the customer base specifically asks for third-party-attested privacy verification. The clearest scope-in scenarios include: healthcare SaaS handling protected health information where privacy controls are part of the customer's HIPAA compliance posture; AdTech and MarTech platforms handling consumer behavioural data where privacy controls are part of GDPR and CCPA compliance; edutech handling student personal data where privacy controls intersect with FERPA, COPPA, and state student privacy laws; B2C SaaS with EU or California user bases where GDPR and CCPA compliance is a procurement question; HR SaaS handling employee personal data at scale where privacy controls are part of vendor risk management for the employer.
The other case for scoping Privacy in is when the SaaS is selling to procurement teams that explicitly require Privacy TSC in vendor risk reviews. This is increasingly common in EU-headquartered customer bases (where GDPR sensitivity is high) and in California-headquartered customer bases (where CCPA/CPRA is the analog). Procurement teams use the SOC 2 Privacy TSC as the third-party verification that the vendor has implemented controls supporting the customer's own GDPR or CCPA compliance posture.
When to skip Privacy and use ISO 27701 instead
For SaaS already pursuing or planning ISO 27001, adding ISO 27701 alongside is often more economic than adding Privacy TSC to SOC 2. ISO 27701 is the privacy-management extension to ISO 27001 and provides a parallel third-party-attested privacy verification. The ISO 27701 audit work piggybacks on the existing ISO 27001 audit infrastructure (same auditor, same evidence flow, same control documentation) which materially reduces marginal cost. The combined ISO 27001 plus ISO 27701 audit fee is typically lower than the equivalent SOC 2 plus Privacy TSC audit fee for the same scope.
For SaaS pursuing SOC 2 only without ISO 27001 in scope, Privacy TSC is the more natural choice because the audit firm and the GRC platform are already engaged for SOC 2. Adding Privacy TSC to the existing SOC 2 engagement is operationally simpler than adding a separate ISO 27701 programme.
When to skip Privacy entirely
SaaS without personal information processing or with very limited PII (only employee accounts, no customer personal data) can typically skip Privacy. The criterion does not provide additional procurement signal for SaaS where the customer is not relying on the SaaS to handle their own customers' personal data. B2B SaaS that processes only company-level data (financial information, operational metrics, vendor relationships) without consumer or employee personal data falls into this category.
Adding Privacy scope without customer-facing demand for it is the largest over-spend available in a SOC 2 scope, because you are paying to build and then operate a whole privacy programme in perpetuity, not just to be tested on one. The right scoping for typical commercial B2B SaaS without personal data processing is Security plus Availability plus Confidentiality, with Privacy as a later addition only if the customer base or regulatory environment shifts to require it.
Specific controls to implement or formalise
The control set that satisfies Privacy TSC requirements maps to the GAPP domains. Document the following: privacy notice posted on customer-facing properties with clear disclosure of data collection, use, sharing, and retention practices; consent management workflow with documented consent capture and withdrawal procedures (cookie banners are necessary but not sufficient; consent tracking infrastructure is required); data subject rights workflow supporting access, correction, deletion, and portability requests with documented timeline targets (GDPR requires 30 days; CCPA requires 45 days); data retention schedule with explicit retention rules per data type and documented deletion procedures with verification; vendor privacy assessment procedures including review of vendor privacy practices before sharing personal data, and ongoing monitoring; breach notification procedures aligned with GDPR (72-hour notification to supervisory authority), CCPA (notification to California Attorney General for breaches affecting 500+ California residents), and other applicable jurisdictions; privacy impact assessments for new product features that materially change data handling; privacy programme governance including a designated privacy officer or DPO where required and ongoing privacy training. The privacy programme work is the heaviest part of the readiness effort.
How Privacy fits with the other optional criteria
Privacy is rarely scoped in isolation. SaaS that adds Privacy typically already has Availability and Confidentiality in scope. Each criterion added to one engagement adds its own control points and testing hours on top of the Security baseline, and no firm publishes what any of that costs. Processing Integrity may also be in scope for processing-critical SaaS that handles personal data, particularly in healthcare and fintech verticals where the combined four-criteria scope is editorially defensible.
For SaaS in regulated verticals (healthcare with HIPAA, fintech with PCI DSS, AdTech with industry-specific frameworks), Privacy TSC is typically scoped alongside the regulatory framework rather than as a substitute. The healthcare SaaS and fintech SaaS cost pages cover these vertical-specific scoping decisions in more depth.