Data Protection & Privacy
DETAIL

Generally Accepted Privacy Principles (GAPP)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

Generally Accepted Privacy Principles (GAPP) is a comprehensive privacy framework that assists organizations in establishing, managing, and assessing data protection and privacy controls. The framework provides a structured approach for addressing privacy risks and maintaining compliance with relevant data protection laws and regulations.

Developed by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA), GAPP is used by organizations, auditors, and compliance professionals across industries. It covers key areas including privacy governance, risk management, data lifecycle controls, and incident response. GAPP is often referenced in alignment with other regulatory and cybersecurity frameworks, such as SOC 2 and international privacy standards.

Organizations typically adopt GAPP by integrating its privacy criteria into internal controls, policy development, and audit processes. By doing so, they strengthen privacy accountability, support regulatory compliance efforts, and facilitate third-party assurance programs, particularly within the context of SOC reporting and broader information security management systems.

Why it Matters

Generally Accepted Privacy Principles (GAPP) help organizations structure effective privacy programs, enabling accountability, transparency, and alignment with global privacy expectations.

Key benefits include:

  • Strengthen privacy governance

Establish clear accountability and oversight for personal data handling across organizational functions and third-party relationships.

  • Enhance regulatory alignment

Support compliance with diverse privacy regulations by providing a principles-based framework that maps to multiple legal requirements.

  • Build stakeholder trust

Demonstrate commitment to responsible data handling through transparent privacy practices that foster customer and partner confidence.

  • Improve risk management

Identify and mitigate privacy risks systematically through structured assessments and controls aligned with GAPP principles.

  • Support audit readiness

Provide documented privacy practices and controls that facilitate privacy audits and assessments by internal and external parties.

How it Works

GAPP is structured around ten privacy principles that define the core components of an effective privacy program: Management, Notice, Choice and Consent, Collection, Use Retention and Disposal, Access, Disclosure to Third Parties, Security for Privacy, Quality, and Monitoring and Enforcement. Each principle includes specific criteria and illustrative controls that organizations use to assess and improve their privacy practices.

Organizations implement GAPP by conducting privacy assessments against each of the ten principles, identifying gaps in current practices, and implementing improvements to meet the criteria. Implementation activities include updating privacy policies, establishing consent mechanisms, conducting privacy impact assessments, implementing data security controls, and creating monitoring and enforcement mechanisms. GAPP is often used as a foundation for SOC 2 privacy criteria assessments and broader privacy program development.

SmartSuite enables operationalization of GAPP by providing control libraries mapped to the ten principles, risk registers for privacy-related risks, and policy governance modules. Evidence collection, compliance tracking, and reporting dashboards support ongoing privacy program management and audit readiness.

Key Elements

  • Management Principle

Establishes accountability for privacy policies, procedures, and oversight within the organization.

  • Notice Principle

Specifies requirements for communicating privacy practices to individuals before or at the time of data collection.

  • Choice and Consent

Defines mechanisms for obtaining individual consent for data collection and use.

  • Collection Principle

Outlines limitations on data collection to information necessary for stated purposes.

  • Use, Retention and Disposal

Establishes requirements for appropriate use, retention periods, and secure disposal of personal information.

  • Security for Privacy

Specifies safeguards to protect personal information against unauthorized access, disclosure, and loss.

Framework Scope

GAPP is adopted by organizations across industries seeking to establish comprehensive privacy programs aligned with professional standards. It governs the collection, use, retention, and disclosure of personal information, and is typically implemented when developing privacy programs, preparing for privacy audits, or demonstrating privacy maturity to customers and regulators.

Framework in Context

GAPP was developed by the AICPA and CICA and provides a comprehensive framework for privacy program management. It aligns with major privacy regulations including GDPR and CCPA and is commonly used as the basis for SOC 2 Type II privacy assessments. Organizations implement GAPP for privacy program governance, regulatory alignment, and third-party assurance.

Common Framework Mappings

Mapped frameworks include: AICPA Trust Services Criteria, CCPA/CPRA, EU GDPR, ISO/IEC 27701, NIST Privacy Framework, SOC 2

At a Glance
AICPA/CICA Generally Accepted Privacy Principles (GAPP)
  • checklist
    Classification
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    SOC Frameworks
  • info
    Regulatory Context
    Type
    info
    Control Framework
    Legal Instrument
    info
    Framework
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    United States
    Publisher
    info
    American Institute of Certified Public Accountants (AICPA)
  • published_with_changes
    Versioning
    Version
    info
    2011
    Effective Date
    info
    2006
    Issue Date
    info
    2006
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    Moderate
  • captive_portal
    Official Reference
License Information

License included / downloadable: No

GAPP is published by the AICPA and CICA and requires purchase or licensed access. License not included with platform

Official Resources
Generally Accepted Privacy Principles (GAPP) Framework
Defines the privacy framework established by AICPA and CICA for managing data protection.
chevron_forward
AICPA Privacy Management Resources
Provides resources and guidance for implementing GAPP within organizations.
chevron_forward
CICA Privacy Framework Overview
Outlines the principles and application of the GAPP framework in privacy governance.
chevron_forward
AICPA Trust Services Criteria
Describes the framework for evaluating and reporting on system controls.
chevron_forward
SMARTSUITE

How SmartSuite Supports Generally Accepted Privacy Principles (GAPP)

Implement structured privacy governance and accountability practices to align organizational privacy programs with the Generally Accepted Privacy Principles framework.

Privacy Control Library

Structure GAPP principles and criteria into a centralized privacy control library with clear ownership and accountability.

Data Inventory and Processing Records

Track personal data categories, processing purposes, retention rules, and ownership across systems and business processes.

Privacy Risk and Assessment Workflows

Manage privacy impact assessments, risk evaluations, and mitigation actions tied to GAPP privacy principles.

Vendor and Data Sharing Governance

Monitor third-party data processing, contractual obligations, and privacy assurance evidence for vendors and partners.

Privacy Incident Response Workflows

Coordinate investigation, escalation, and response workflows for privacy incidents and potential data breaches.

Privacy Control and Program Maturity Reporting

Provide dashboards showing privacy control status, open risks, incidents, and program maturity across the organization.

Related frameworks

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Generally Accepted Privacy Principles (GAPP)

What is GAPP used for?

GAPP is used by organizations to establish, manage, and evaluate comprehensive privacy and data protection programs. It serves as a structured framework for addressing privacy risks, aligning with regulatory expectations, and supporting privacy compliance initiatives.

Is GAPP a certifiable or mandatory framework?

GAPP itself is not a certifiable or legally mandatory framework; it provides best practices and principles for privacy management. However, organizations may be assessed against GAPP criteria during audits, particularly in the context of SOC (System and Organization Controls) reporting.

What is the scope or applicability of GAPP?

GAPP applies to any organization that collects, processes, stores, or transmits personal data, regardless of industry or geography. It is designed to be adaptable to various regulatory environments and is commonly used in conjunction with international privacy laws and standards.

What are the key principles or controls required by GAPP?

GAPP is organized around ten core privacy principles, covering areas such as notice, choice, collection, use, access, disclosure, security, data quality, monitoring, and enforcement. These principles are implemented through specific organizational controls, policies, and procedures.

How do organizations implement GAPP?

Organizations implement GAPP by mapping privacy principles to internal controls and procedures, conducting data inventories, performing privacy impact and risk assessments, and establishing policy frameworks. The process also involves ongoing training, vendor due diligence, and development of incident response mechanisms.

How does GAPP relate to other privacy and cybersecurity frameworks?

GAPP can be aligned with other privacy and information security standards, such as SOC 2, ISO 27001, and GDPR. Its principles complement these frameworks by focusing specifically on privacy controls and facilitating integrated governance and audit processes.

What are the ongoing compliance requirements for GAPP?

Maintaining GAPP compliance requires continual monitoring of privacy controls, regular risk assessments, periodic reviews of policies and procedures, and documenting evidence of effective implementation. Organizations must also ensure their practices remain aligned with evolving privacy regulations and industry standards.

How would SmartSuite support GAPP?

SmartSuite enables organizations to operationalize GAPP by linking privacy controls to risk registers, policy management, and compliance dashboards. It supports evidence collection, compliance tracking, audit readiness processes, and centralized reporting, streamlining ongoing monitoring and documentation for both internal and external stakeholders.

Operationalize GAPP with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward