SOC 2 Type II: assurance for customers
SOC 2 is an examination framework for service organizations. The report addresses controls relevant to security, availability, processing integrity, confidentiality or privacy. Type II looks at control operation over a defined review period, while a point-in-time description cannot show months of operation. The exact system, services, criteria, dates, auditor opinion, exceptions and customer responsibilities matter.
What it changes for the business: customers may request the report during vendor review or contract renewal. Without suitable assurance, a supplier may face longer questionnaires, extra contract conditions, delayed deals or lost opportunities. SOC 2 itself does not impose a government fine. The commercial consequence comes from customer requirements and from any underlying security or contractual failure.
Evidence to request: the complete current report under appropriate confidentiality, bridge letter when the period is old, management response to exceptions, subservice organizations, and complementary user-entity controls your company must perform.
AICPA: System and Organization Controls resources · AICPA: Trust Services Criteria
GDPR: rules for covered European personal data
GDPR is not a security certificate. It requires a lawful basis for processing, clear notices, data minimization, support for individual rights, appropriate security, vendor governance, transfer safeguards and breach handling. Whether it applies depends on the organization’s activities and people whose data is processed.
Business impact example: Ireland’s Data Protection Commission found Meta Ireland had infringed GDPR transfer requirements, imposed a €1.2 billion administrative fine, ordered suspension of future covered transfers, and required processing to be brought into compliance. The operational orders mattered alongside the fine.
European Commission: data protection in the EU · Irish Data Protection Commission: Meta transfer decision
California privacy: consumer rights and operating duties
California privacy law can require covered businesses to explain data practices, respond to consumer requests, honor qualifying opt-out signals, control service-provider and contractor relationships, limit certain uses, and protect personal information. Marketing technology, connected products, HR data and website tracking can all create cross-functional work.
Business impact examples: California’s Attorney General announced a $1.2 million Sephora settlement involving alleged failures to disclose data sales and honor opt-out requests. In 2025, the California Privacy Protection Agency required Honda to change business practices and pay $632,500 over alleged consumer-request and contracting violations.
California Attorney General: privacy enforcement actions · California Privacy Protection Agency: Honda enforcement
What the CFO should askWhich legal entity and data are in scope? Who owns the data inventory and request deadlines? Which vendors receive personal information? What evidence shows the process works? Who tells finance when a contract, control gap or enforcement issue could affect revenue, cost or disclosure?