HomeBlog › SOC 2 and GDPR Together: How They Differ, Where They Overlap, How to Do Both

SOC 2 and GDPR Together: How They Differ, Where They Overlap, How to Do Both

Published 2026-07-15 · 6 min read · BALTUM

Companies serving both American and European clients eventually face two requests at once: “send us your SOC 2 report” and “confirm GDPR compliance”. The two are often treated as interchangeable — they are not. SOC 2 is a voluntary security attestation under AICPA standards; GDPR is binding EU data-protection law. Yet a large share of the work can be done once and reused for both. Here is how.

SOC 2 and GDPR in one paragraph each

SOC 2 is a report by an independent CPA firm stating that a service organisation’s controls meet the Trust Services Criteria (TSC): Security, Availability, Confidentiality, Processing Integrity and Privacy. It is voluntary and demanded by customers, not regulators. It is not a certificate — it is an attestation report.

GDPR (General Data Protection Regulation) is EU law that applies to anyone processing personal data of EU residents, regardless of where the company sits. A Ukrainian IT company building a product for a German client and touching user data is a processor under GDPR. Non-compliance leads to fines, not just lost deals.

Key differences

AspectSOC 2GDPR
NatureVoluntary attestationMandatory EU law
SubjectSecurity and operational controlsData-subject rights and lawful processing
Who checksIndependent CPA firmEU supervisory authorities, clients, DPO
OutputType 1 / Type 2 reportCompliance; no official certificate
GeographyPrimarily USEU / EEA, extraterritorial
Consequence of failureLost customersFines up to 4% of global turnover

Does SOC 2 replace GDPR compliance?

No. A SOC 2 report shows you protect data well, but says nothing about whether you have a lawful basis to process it, whether data subjects were informed, whether a data processing agreement (DPA) exists, or whether erasure requests are honoured. Conversely, GDPR compliance does not prove your technical controls operated for a year — that is exactly what SOC 2 Type 2 demonstrates.

In practice, an EU client may accept SOC 2 as evidence of “appropriate technical and organisational measures” under Article 32 GDPR, but will still require a DPA, a record of processing and other legal artefacts.

Where SOC 2 and GDPR overlap

The good news is that the overlap is substantial. Article 32 GDPR requires appropriate technical and organisational measures, and those are precisely what SOC 2 describes. Shared elements include:

  • Access control — least privilege, MFA, access reviews.
  • Encryption at rest and in transit.
  • Incident management — a control in SOC 2, a 72-hour notification duty in GDPR.
  • Vendor management — subprocessor review in both frameworks.
  • Risk assessment — general in SOC 2, a DPIA for high-risk processing in GDPR.
  • Staff training and acceptable-use policies.
  • Backups and continuity — the Availability criteria and the resilience requirement of Article 32.
  • Retention and deletion — Confidentiality/Privacy criteria and the storage-limitation principle.

What GDPR requires beyond SOC 2

Even with a clean SOC 2 report you will additionally need:

  1. A record of processing activities (Article 30).
  2. Lawful bases and privacy notices for data subjects.
  3. Data processing agreements with clients and subprocessors.
  4. A transfer mechanism — Standard Contractual Clauses (SCCs), since Ukraine has no adequacy decision.
  5. Procedures for data-subject rights: access, rectification, erasure, portability.
  6. A Data Protection Officer where required, and an EU representative under Article 27 for non-EU companies.
  7. Data Protection Impact Assessments for high-risk processing.

Should you add the Privacy category to SOC 2?

SOC 2 has a dedicated Privacy category that is close in spirit to GDPR: notice, choice and consent, collection, use, retention, disclosure, quality. Add it only if you process personal data as a controller or customers explicitly ask. For most B2B SaaS and outsourcing companies, Security plus Confidentiality is enough for the audit, with GDPR handled by a separate legal package. That is cheaper than expanding audit scope.

How to run a combined SOC 2 + GDPR project

Our approach is one management system with two sets of outputs:

  1. Joint gap analysis against the TSC and GDPR Articles 5, 25, 28, 30 and 32–36.
  2. A single policy set where GDPR requirements are embedded in the security, retention, incident and vendor policies.
  3. A shared risk assessment that feeds both SOC 2 controls and the DPIA.
  4. The GDPR legal block: record of processing, DPAs, SCCs, privacy notices, data-subject procedures.
  5. The SOC 2 audit by an independent CPA firm; GDPR compliance is supported by internal documentation and, if needed, an external review.

This is how our combined SOC 2 + ISO 27001 + GDPR + Cyber Essentials package is structured for companies serving the US, EU and UK. For the preparation plan itself, see our SOC 2 readiness checklist; for UK requirements, see Cyber Essentials explained.

Example: a Ukrainian outsourcing company with clients in the US and Germany

Consider a typical case: a team of 80 engineers builds and supports products for a US fintech client and a German retailer. The US client requires SOC 2 Type 2 covering Security and Availability. The German client requires a signed DPA, Standard Contractual Clauses, a record of processing and confirmation of technical measures under Article 32.

The rational answer is one project. Access-control, encryption, incident and vendor policies are written once and satisfy both sides. The risk assessment underpins both the SOC 2 controls and the DPIA. A separate GDPR legal block is prepared, and once the audit is complete the SOC 2 report is added to the German client’s document pack as evidence of appropriate measures. The company avoids maintaining two parallel documentation systems and never has to explain different versions of the same process to auditors and lawyers.

Common mistakes

  • Assuming the SOC 2 report “covers” GDPR and skipping the DPA.
  • Adding the Privacy category to SOC 2 scope “just in case”.
  • Maintaining separate, inconsistent policy sets for SOC 2 and GDPR.
  • Forgetting SCCs for data transfers from the EU to Ukraine.

If your clients require both SOC 2 and GDPR compliance, request a quote — we will design a single control system, prepare the GDPR legal package and support your SOC 2 audit with the BALTUM group's US CPA firm.