Data Protection & Privacy
DETAIL

Generally Accepted Privacy Principles (GAPP)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

GenerallyAccepted Privacy Principles (GAPP) is a comprehensive privacyframework that assists organizations in establishing, managing, andassessing data protection and privacy controls. The frameworkprovides a structured approach for addressing privacy risks andmaintaining compliance with relevant data protection laws andregulations.

Developed by theAmerican Institute of Certified Public Accountants (AICPA) and theCanadian Institute of Chartered Accountants (CICA), GAPP is used byorganizations, auditors, and compliance professionals acrossindustries. It covers key areas including privacy governance, riskmanagement, data lifecycle controls, and incident response. GAPP isoften referenced in alignment with other regulatory and cybersecurityframeworks, such as SOC 2 and international privacy standards.

Organizationstypically adopt GAPP by integrating its privacy criteria intointernal controls, policy development, and audit processes. By doingso, they strengthen privacy accountability, support regulatorycompliance efforts, and facilitate third-party assurance programs,particularly within the context of SOC reporting and broaderinformation security management systems.

Why it Matters

GenerallyAccepted Privacy Principles (GAPP) help organizations structureeffective privacy programs, enabling accountability and compliancewithin today’s complex data protection environment.

Key benefitsinclude:

•  Support regulatory compliance efforts

Demonstraterobust privacy controls that facilitate adherence to global andindustry-specific data protection requirements.

•  Strengthen privacy governance

Establish clearpolicies and management responsibilities to enhance oversight for theentire data lifecycle.

•  Increase audit and third-party assurance readiness

Enableorganizations to efficiently meet reporting requirements and buildtrust through independent privacy assessments.

•  Enhance stakeholder trust

Promotetransparency and responsible data management, supporting confidenceamong customers, partners, and regulators.

•  Reduce liability and reputational risk

Minimize thepotential for data breaches and compliance failures that could resultin financial penalties or operational disruptions.

How it Works

The GenerallyAccepted Privacy Principles (GAPP) framework establishes ten coreprivacy principles and organizes them into control families thatcover notice, choice, collection, use, access, disclosure, security,quality, monitoring, and enforcement. GAPP outlines lifecycleprocesses for personal data and integrates with risk management andregulatory requirements to provide a structured privacy controlcatalog and maturity-oriented governance model.

Organizationsapply GAPP by mapping its principles to security controls, policies,and operational processes: conducting data inventories and DPIAs,performing risk assessments, implementing technical andadministrative controls, vetting vendors, and running monitoring andcompliance assessments. Teams use GAPP to align governance, incidentresponse, and audit programs with privacy requirements and tooperationalize security practices across the enterprise.

WithinSmartSuite, GAPP can be operationalized by importing controllibraries and linking them to risk registers and policy governanceboards. SmartSuite supports evidence collection, compliance tracking,remediation workflows, audit readiness, and reporting dashboards,enabling ongoing monitoring of control effectiveness and centralizedreporting for regulators and internal stakeholders.

Key Elements

•  Privacy Governance Framework

Establishes thestructure for oversight, accountability, and leadership of theorganization’s privacy program.

•  Risk Assessment and Management

Describes theprocess for identifying and addressing data privacy risks withinbusiness operations.

•  Data Lifecycle Controls

Defines specificrequirements for collecting, using, storing, and disposing ofpersonal information.

•  Individual Rights Management

Specifiesmechanisms for respecting and facilitating individuals’ rightsregarding their personal data.

•  Security of Personal Information

Outlinesstandards to safeguard personal data against unauthorized access,disclosure, or destruction.

•  Incident Response Procedures

Organizesprotocols for detecting, reporting, and managing privacy incidents ordata breaches.

•  Monitoring and Compliance Review

Describesongoing evaluation and audit activities to ensure alignment withprivacy requirements and regulatory obligations.

Framework Scope

GenerallyAccepted Privacy Principles (GAPP) is applied by organizationsprocessing personal and sensitive data across diverse businessfunctions and IT environments. The framework governs privacy, dataprotection, and risk management requirements, and is commonly adoptedwhen complying with privacy regulations, enhancing internal controls,or supporting assurance programs focused on effective data governanceand operational accountability.

Framework Objectives

GenerallyAccepted Privacy Principles (GAPP) provides a comprehensive structurefor managing privacy, data protection, and compliance risks acrossorganizations.

•  Safeguard personal information through robust privacy andsecurity controls

•  Strengthen governance and oversight of data privacy and riskmanagement practices

•  Enable compliance with privacy regulations and data protectionlaws

•  Enhance operational resilience by addressing privacy-relatedcybersecurity threats

•  Support audit readiness with well-documented privacy controlsand monitoring

•  Promote accountability for data protection across theorganization Generally Accepted Privacy Principles (GAPP) align withinternational privacy guidance and are commonly mapped to GDPR,ISO/IEC 27701, and the AICPA Trust Services Privacy criteria (SOC 2).Organizations adopt GAPP when building privacy programs, seekingassurance reporting, meeting regulatory obligations, or demonstratingcontrols to customers and auditors.

Organizationsmap GAPP to complementary privacy and security frameworks toharmonize controls, demonstrate legal alignment, enablecross-jurisdictional compliance, and streamline audit and reportingacross programs.

Mappedframeworks include:

APEC PrivacyFramework

CaliforniaConsumer Privacy Act (CCPA)

EU General DataProtection Regulation (GDPR)

ISO/IEC 27701

ISO/IEC 29100

NIST PrivacyFramework

OECD PrivacyGuidelines

SOC 2 (AICPATrust Services Criteria — Privacy)

At a Glance
AICPA/CICA Generally Accepted Privacy Principles (GAPP)
  • checklist
    Classicifation
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    SOC Frameworks
  • info
    Regulatory Context
    Type
    info
    Control Framework
    Legal Instrument
    info
    Framework
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    United States
    Publisher
    info
    American Institute of Certified Public Accountants (AICPA)
  • published_with_changes
    Versioning
    Version
    info
    2011
    Effective Date
    info
    2006
    Issue Date
    info
    2006
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    Moderate
  • captive_portal
    Official Reference
License Information
License included / downloadable: No GAPP is published by the AICPA and CICA and requires purchase or licensed access. License not included with platform
Official Resources
Generally Accepted Privacy Principles (GAPP) Framework
Defines the privacy framework established by AICPA and CICA for managing data protection.
chevron_forward
AICPA Privacy Management Resources
Provides resources and guidance for implementing GAPP within organizations.
chevron_forward
CICA Privacy Framework Overview
Outlines the principles and application of the GAPP framework in privacy governance.
chevron_forward
AICPA Trust Services Criteria
Describes the framework for evaluating and reporting on system controls.
chevron_forward
SMARTSUITE

How SmartSuite Supports Generally Accepted Privacy Principles (GAPP)

Implement structured privacy governance and accountability practices to align organizational privacy programs with the Generally Accepted Privacy Principles framework.

Privacy Control Library

Structure GAPP principles and criteria into a centralized privacy control library with clear ownership and accountability.

Data Inventory and Processing Records

Track personal data categories, processing purposes, retention rules, and ownership across systems and business processes.

Privacy Risk and Assessment Workflows

Manage privacy impact assessments, risk evaluations, and mitigation actions tied to GAPP privacy principles.

Vendor and Data Sharing Governance

Monitor third-party data processing, contractual obligations, and privacy assurance evidence for vendors and partners.

Privacy Incident Response Workflows

Coordinate investigation, escalation, and response workflows for privacy incidents and potential data breaches.

Privacy Control and Program Maturity Reporting

Provide dashboards showing privacy control status, open risks, incidents, and program maturity across the organization.

Related frameworks

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Generally Accepted Privacy Principles (GAPP)

What is GAPP used for?

GAPP is used by organizations to establish, manage, and evaluate comprehensive privacy and data protection programs. It serves as a structured framework for addressing privacy risks, aligning with regulatory expectations, and supporting privacy compliance initiatives.

Is GAPP a certifiable or mandatory framework?

GAPP itself is not a certifiable or legally mandatory framework; it provides best practices and principles for privacy management. However, organizations may be assessed against GAPP criteria during audits, particularly in the context of SOC (System and Organization Controls) reporting.

What is the scope or applicability of GAPP?

GAPP applies to any organization that collects, processes, stores, or transmits personal data, regardless of industry or geography. It is designed to be adaptable to various regulatory environments and is commonly used in conjunction with international privacy laws and standards.

What are the key principles or controls required by GAPP?

GAPP is organized around ten core privacy principles, covering areas such as notice, choice, collection, use, access, disclosure, security, data quality, monitoring, and enforcement. These principles are implemented through specific organizational controls, policies, and procedures.

How do organizations implement GAPP?

Organizations implement GAPP by mapping privacy principles to internal controls and procedures, conducting data inventories, performing privacy impact and risk assessments, and establishing policy frameworks. The process also involves ongoing training, vendor due diligence, and development of incident response mechanisms.

How does GAPP relate to other privacy and cybersecurity frameworks?

GAPP can be aligned with other privacy and information security standards, such as SOC 2, ISO 27001, and GDPR. Its principles complement these frameworks by focusing specifically on privacy controls and facilitating integrated governance and audit processes.

What are the ongoing compliance requirements for GAPP?

Maintaining GAPP compliance requires continual monitoring of privacy controls, regular risk assessments, periodic reviews of policies and procedures, and documenting evidence of effective implementation. Organizations must also ensure their practices remain aligned with evolving privacy regulations and industry standards.

How would SmartSuite support GAPP?

SmartSuite enables organizations to operationalize GAPP by linking privacy controls to risk registers, policy management, and compliance dashboards. It supports evidence collection, compliance tracking, audit readiness processes, and centralized reporting, streamlining ongoing monitoring and documentation for both internal and external stakeholders.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward