Full Report
Huntress is SOC2, GDPR and CCPA Compliant. Read what this means for us—and for our partners.
Analysis Summary
# Regulation/Compliance: SOC2, GDPR, and CCPA
## Overview
This compliance suite covers three distinct areas of data protection: **SOC2** (an auditing procedure for service organizations to manage data), **GDPR** (legal protection for EU citizens' data), and **CCPA** (legal protection for California residents' privacy). Collectively, they ensure that Huntress manages data with high levels of security, availability, and confidentiality while granting users rights over their personal information.
## Key Details
- **Issuing Authority:**
- **SOC2:** American Institute of Certified Public Accountants (AICPA)
- **GDPR:** European Union (EU)
- **CCPA:** State of California, USA
- **Effective Date:** Huntress announced full compliance/audit completion as of April 6, 2023.
- **Jurisdiction:** Global (EU for GDPR, California for CCPA, and Service Organizations for SOC2).
- **Status:** In Effect (Huntress has successfully completed the SOC2 Type 1 audit).
## Requirements
### Mandatory Requirements
1. **SOC2 Security:** Protect systems and data from unauthorized access, theft, or destruction.
2. **SOC2 Availability:** Ensure systems are reliable and accessible for users at all times.
3. **SOC2 Confidentiality:** Protect sensitive information from unauthorized disclosure or use.
4. **GDPR/CCPA Data Control:** Provide users with the ability to control how their personal data is collected, processed, and shared.
5. **Transparency:** Maintain clear disclosures regarding data collection and sharing practices (CCPA).
### Recommended Practices
1. **Independent Auditing:** Utilize third-party auditors to ensure unbiased internal assessments (as done with Huntress’ SOC2 Type 1).
2. **Continuous Investment:** Regularly update systems and processes to stay ahead of evolving privacy standards.
## Affected Organizations
- **Industries:** Managed Service Providers (MSPs), IT administrators, and small-to-midmarket businesses (SMBs).
- **Organization Size:** All sizes that process data of EU or California residents or require service organization assurance.
- **Geographic Scope:** Primarily North America and the European Union, though applicable to any entity handling relevant data.
## Compliance Timeline
- **May 25, 2018:** GDPR implementation deadline (Historical).
- **January 1, 2020:** CCPA implementation deadline (Historical).
- **April 6, 2023:** Huntress announces successful completion of SOC2 Type 1 audit and full GDPR/CCPA compliance.
- **Ongoing:** Periodic audits (Type 2) and regular policy reviews.
## Implementation Guidance
### Assessment Phase
- **Audit Preparedness:** Review internal controls and policies against the AICPA Trust Service Criteria.
- **Data Mapping:** Identify where EU and California resident data resides to meet GDPR/CCPA mandates.
### Implementation Phase
- **Control Design:** Design and document internal controls effectively to meet stringent SOC2 standards.
- **Privacy Rights:** Implement mechanisms for users to exercise their rights (e.g., "Right to be Forgotten" or "Right to Opt-Out").
### Validation Phase
- **Third-Party Audit:** Engage a certified auditor to perform a SOC2 Type 1 assessment of systems and policies.
- **Report Verification:** Make audit reports available to partners/prospects to demonstrate compliance.
## Technical Requirements
- **Access Controls:** Measures to prevent unauthorized system access.
- **Redundancy/Uptime:** Infrastructure designed to ensure system availability.
- **Encryption:** Protective measures for sensitive data to maintain confidentiality.
- **Data Portability/Deletion:** Technical ability to export or delete user data upon request.
## Penalties & Enforcement
- **Fines:**
- **GDPR:** Up to €20 million or 4% of annual global turnover.
- **CCPA:** Up to $7,500 per intentional violation.
- **Other Consequences:** Loss of partner trust, damage to reputation, and potential litigation.
- **Enforcement:** Conducted by Data Protection Authorities (EU) and the California Privacy Protection Agency (CPPA).
## Related Standards
- **NIST/ISO:** While not explicitly cited in the text, SOC2 often aligns with NIST SP 800-53 or ISO 27001 regarding security control frameworks.
- **Trust Service Criteria:** The framework specifically used for the SOC2 audit (Security, Availability, Confidentiality).
## Resources
- **Official Documentation:** [Huntress Privacy Policy](https://www.huntress.com/privacy-policy) (Defanged)
- **Guidance Documents:** SOC2 Audit Report (Available upon request via Huntress sales representatives).
- **Tools:** [Huntress Portal](https://huntress.io/) for managing security and identity incidents.
## Practical Recommendations
- **Request the Report:** Partners should reach out to their sales representatives to review the SOC2 Type 1 audit report for due diligence.
- **Verify Data Handling:** Ensure your own organization’s data collection practices align with the transparency provided by Huntress’ GDPR/CCPA compliance.
- **Monitor for Type 2:** While Type 1 assesses the *design* of controls, organizations should watch for a future SOC2 Type 2 report, which assesses the *operational effectiveness* of those controls over time.