Generally Accepted Privacy Principles (GAPP)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
Generally Accepted Privacy Principles (GAPP) is a comprehensive privacy framework that assists organizations in establishing, managing, and assessing data protection and privacy controls. The framework provides a structured approach for addressing privacy risks and maintaining compliance with relevant data protection laws and regulations.
Developed by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA), GAPP is used by organizations, auditors, and compliance professionals across industries. It covers key areas including privacy governance, risk management, data lifecycle controls, and incident response. GAPP is often referenced in alignment with other regulatory and cybersecurity frameworks, such as SOC 2 and international privacy standards.
Organizations typically adopt GAPP by integrating its privacy criteria into internal controls, policy development, and audit processes. By doing so, they strengthen privacy accountability, support regulatory compliance efforts, and facilitate third-party assurance programs, particularly within the context of SOC reporting and broader information security management systems.
Why it Matters
Generally Accepted Privacy Principles (GAPP) help organizations structure effective privacy programs, enabling accountability, transparency, and alignment with global privacy expectations.
Key benefits include:
- Strengthen privacy governance
Establish clear accountability and oversight for personal data handling across organizational functions and third-party relationships.
- Enhance regulatory alignment
Support compliance with diverse privacy regulations by providing a principles-based framework that maps to multiple legal requirements.
- Build stakeholder trust
Demonstrate commitment to responsible data handling through transparent privacy practices that foster customer and partner confidence.
- Improve risk management
Identify and mitigate privacy risks systematically through structured assessments and controls aligned with GAPP principles.
- Support audit readiness
Provide documented privacy practices and controls that facilitate privacy audits and assessments by internal and external parties.
How it Works
GAPP is structured around ten privacy principles that define the core components of an effective privacy program: Management, Notice, Choice and Consent, Collection, Use Retention and Disposal, Access, Disclosure to Third Parties, Security for Privacy, Quality, and Monitoring and Enforcement. Each principle includes specific criteria and illustrative controls that organizations use to assess and improve their privacy practices.
Organizations implement GAPP by conducting privacy assessments against each of the ten principles, identifying gaps in current practices, and implementing improvements to meet the criteria. Implementation activities include updating privacy policies, establishing consent mechanisms, conducting privacy impact assessments, implementing data security controls, and creating monitoring and enforcement mechanisms. GAPP is often used as a foundation for SOC 2 privacy criteria assessments and broader privacy program development.
SmartSuite enables operationalization of GAPP by providing control libraries mapped to the ten principles, risk registers for privacy-related risks, and policy governance modules. Evidence collection, compliance tracking, and reporting dashboards support ongoing privacy program management and audit readiness.
Key Elements
- Management Principle
Establishes accountability for privacy policies, procedures, and oversight within the organization.
- Notice Principle
Specifies requirements for communicating privacy practices to individuals before or at the time of data collection.
- Choice and Consent
Defines mechanisms for obtaining individual consent for data collection and use.
- Collection Principle
Outlines limitations on data collection to information necessary for stated purposes.
- Use, Retention and Disposal
Establishes requirements for appropriate use, retention periods, and secure disposal of personal information.
- Security for Privacy
Specifies safeguards to protect personal information against unauthorized access, disclosure, and loss.
Framework Scope
GAPP is adopted by organizations across industries seeking to establish comprehensive privacy programs aligned with professional standards. It governs the collection, use, retention, and disclosure of personal information, and is typically implemented when developing privacy programs, preparing for privacy audits, or demonstrating privacy maturity to customers and regulators.
Framework in Context
GAPP was developed by the AICPA and CICA and provides a comprehensive framework for privacy program management. It aligns with major privacy regulations including GDPR and CCPA and is commonly used as the basis for SOC 2 Type II privacy assessments. Organizations implement GAPP for privacy program governance, regulatory alignment, and third-party assurance.
Common Framework Mappings
Mapped frameworks include: AICPA Trust Services Criteria, CCPA/CPRA, EU GDPR, ISO/IEC 27701, NIST Privacy Framework, SOC 2
- ClassificationCategoryData Protection & PrivacyDomainPrivacyFramework FamilySOC Frameworks
- Regulatory ContextTypeControl FrameworkLegal InstrumentFrameworkSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailUnited StatesPublisherAmerican Institute of Certified Public Accountants (AICPA)
- VersioningVersion2011Effective Date2006Issue Date2006
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityModerate
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
GAPP is published by the AICPA and CICA and requires purchase or licensed access. License not included with platform
How SmartSuite Supports Generally Accepted Privacy Principles (GAPP)
Implement structured privacy governance and accountability practices to align organizational privacy programs with the Generally Accepted Privacy Principles framework.
Privacy Control Library
Structure GAPP principles and criteria into a centralized privacy control library with clear ownership and accountability.
Data Inventory and Processing Records
Track personal data categories, processing purposes, retention rules, and ownership across systems and business processes.
Privacy Risk and Assessment Workflows
Manage privacy impact assessments, risk evaluations, and mitigation actions tied to GAPP privacy principles.
Vendor and Data Sharing Governance
Monitor third-party data processing, contractual obligations, and privacy assurance evidence for vendors and partners.
Privacy Incident Response Workflows
Coordinate investigation, escalation, and response workflows for privacy incidents and potential data breaches.
Privacy Control and Program Maturity Reporting
Provide dashboards showing privacy control status, open risks, incidents, and program maturity across the organization.
Related frameworks

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.
Frequently Asked Questions For Generally Accepted Privacy Principles (GAPP)
GAPP is used by organizations to establish, manage, and evaluate comprehensive privacy and data protection programs. It serves as a structured framework for addressing privacy risks, aligning with regulatory expectations, and supporting privacy compliance initiatives.
GAPP itself is not a certifiable or legally mandatory framework; it provides best practices and principles for privacy management. However, organizations may be assessed against GAPP criteria during audits, particularly in the context of SOC (System and Organization Controls) reporting.
GAPP applies to any organization that collects, processes, stores, or transmits personal data, regardless of industry or geography. It is designed to be adaptable to various regulatory environments and is commonly used in conjunction with international privacy laws and standards.
GAPP is organized around ten core privacy principles, covering areas such as notice, choice, collection, use, access, disclosure, security, data quality, monitoring, and enforcement. These principles are implemented through specific organizational controls, policies, and procedures.
Organizations implement GAPP by mapping privacy principles to internal controls and procedures, conducting data inventories, performing privacy impact and risk assessments, and establishing policy frameworks. The process also involves ongoing training, vendor due diligence, and development of incident response mechanisms.
GAPP can be aligned with other privacy and information security standards, such as SOC 2, ISO 27001, and GDPR. Its principles complement these frameworks by focusing specifically on privacy controls and facilitating integrated governance and audit processes.
Maintaining GAPP compliance requires continual monitoring of privacy controls, regular risk assessments, periodic reviews of policies and procedures, and documenting evidence of effective implementation. Organizations must also ensure their practices remain aligned with evolving privacy regulations and industry standards.
SmartSuite enables organizations to operationalize GAPP by linking privacy controls to risk registers, policy management, and compliance dashboards. It supports evidence collection, compliance tracking, audit readiness processes, and centralized reporting, streamlining ongoing monitoring and documentation for both internal and external stakeholders.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.