← SOC 2 · CC2 — Communication and Information
CC2.3 — External communication
low
vendor-managementprivacy-notice
Requirement
The entity communicates with external parties regarding matters affecting the functioning of internal control, including commitments made to customers.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
customerexternalthird partycontractcommitmentcontractual
Supporting terms — specificity signals
slatrust centretrust centerstatus pagenotifyterms of service
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(a) | Lawfulness, fairness and transparency | privacy-notice |
| GDPR | Art.12 | Transparent communication and handling of rights requests | privacy-notice |
| GDPR | Art.13 | Information when data is collected from the data subject | privacy-notice |
| GDPR | Art.14 | Information when data is not obtained from the data subject | privacy-notice |
| GDPR | Art.26 | Joint controllers | vendor-management |
| GDPR | Art.28 | Processors and processing agreements | vendor-management |
| GDPR | Art.44-49 | Transfers of personal data to third countries | vendor-management |
| CCPA/CPRA | 1798.100(a)-(b) | Notice at collection | privacy-notice |