A growing company selling on both sides of the Atlantic ends up chasing two very different stamps: SOC 2 to clear American security reviews, and GDPR to operate legally in Europe. Run as separate projects, they duplicate effort, contradict each other’s documentation, and exhaust the same small team twice. Run as one strategy, the shared majority is built once and the divergent remainder handled deliberately. The trap is assuming a clean SOC 2 report means European regulators are satisfied — because the two frameworks answer fundamentally different questions.
Two Frameworks, Two Audiences, Two Questions
SOC 2 is an American attestation, produced by an auditor against the Trust Services Criteria — Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are optional add-ons. Its purpose is to reassure a buyer’s security team that a vendor’s controls work. GDPR is European law — enforceable by regulators, owed to individuals, and concerned with whether processing is lawful and rights are honoured. One is a report you show a customer; the other is a duty you answer to a regulator for. They are not different grades of the same thing.
Where They Overlap (Build Once)
The good news is that the security backbone is genuinely shared. Access control, change management, encryption, monitoring and logging, vendor management, incident response — these satisfy SOC 2’s common security criteria and GDPR’s Article 32 at the same time. For most companies this is the large majority of the work, and it’s wasteful to build it twice. Map this layer once, collect the evidence once, and let it serve both outputs.
| Area | SOC 2 | GDPR |
|---|---|---|
| Security controls | Core — the common criteria | Required under Article 32 |
| Lawful basis | Not assessed | Mandatory for all processing |
| Individual rights | Lightly, only under the Privacy criterion | Access, erasure, portability — enforceable |
| International transfers | Not assessed | Strict rules for leaving the EU |
| Breach notification | Incident handling | 72-hour regulator notice, individual notice |
Where SOC 2 Goes Quiet
The divergence is where companies get caught. Even with the optional Privacy criterion, SOC 2 does not establish a lawful basis for processing, does not grant enforceable individual rights, does not govern international transfers, does not require a 72-hour regulator notification, and does not mandate a data processing agreement in GDPR’s terms. The Privacy criterion reflects a largely American notion of privacy — notice and choice — not the European framework of enforceable rights. A report can be spotless and leave every GDPR-specific obligation untouched.
The clearest way to see the gap is in the fines that hit companies with formidable security. When Ireland’s regulator fined Meta €1.2 billion in 2023, it was not for weak controls — Meta’s security would clear most frameworks comfortably. The violation was an international-transfer failure: moving European data to the US without adequate protection, a question SOC 2 simply does not ask. The same pattern recurs at smaller scale — Spain’s €6 million CaixaBank fine was about lawful basis and transparency, not security; Germany’s €14.5 million Deutsche Wohnen fine was about retention. None of those failures would surface in a SOC 2 audit, because SOC 2 tests whether systems are secure, not whether the processing is lawful. A clean report and a regulatory fine can, and regularly do, coexist — which is exactly why one is not a substitute for the other.
The Combined Strategy: One Control Library, Two Reports
The efficient design is a single control library, mapped on one side to the SOC 2 criteria and on the other to the relevant GDPR articles, with evidence collected once and feeding both outputs — the SOC 2 report and the GDPR accountability record. The shared security controls do most of the work. Then the GDPR-only obligations — lawful basis, individual rights, transfers, processing agreements, regulator notification — run as a dedicated workstream layered on top. The aim is to never build, evidence, or audit the same control twice while still covering what each framework uniquely demands.
Looks Like Dual Compliance vs. Is
Pattern-matching from real dual-track programmes — the gap between running two projects and running one strategy tends to follow the same shape:
| Looks like dual compliance | Is actually dual compliance |
|---|---|
| ✗ Two separate projects, two teams | ✓ One control library mapped to both |
| ✗ “SOC 2 report, so GDPR’s fine” | ✓ Shared controls plus GDPR-only obligations |
| ✗ Privacy criterion treated as GDPR rights | ✓ Enforceable rights handled separately |
| ✗ Transfers ignored because SOC 2 is silent | ✓ A transfer mechanism in place for EU data |
| ✗ Evidence collected twice, inconsistently | ✓ Evidence collected once, two outputs |
| ✗ Incident plan with no regulatory clock | ✓ 72-hour regulator notification built in |
| ✗ Two drifting sets of documentation | ✓ One source of truth, two attestations |
Sequence by What Sells and What’s Legal
In practice SOC 2 often comes first, because an American deal won’t move without it — and that’s fine, provided the shared security core is built in a way that already serves GDPR. The mistake is stopping there. SOC 2 unlocks revenue; GDPR is the condition of operating in Europe at all, and its specific obligations have to be closed before EU exposure, not discovered after a regulator asks. Build the shared core to serve both, then sequence the GDPR-only gap deliberately rather than assuming the report covered it.
Final Thought
SOC 2 and GDPR look like overlapping compliance burdens and are better understood as a shared foundation with two different roofs. The security controls underneath serve both; the obligations on top — assurance for American buyers, lawfulness for European regulators — are genuinely different, and the most expensive mistake is treating the report as proof of the law. Build once where they agree, deliberately where they don’t, and neither audience is left unsatisfied.
The test: take any GDPR-specific obligation a SOC 2 report doesn’t touch — lawful basis, a real access-and-deletion workflow, a transfer mechanism, regulator notification — and ask whether it exists, or whether the SOC 2 report is quietly standing in for it. If the report is doing work it was never designed to do, the European side is exposed.
Frequently Asked Questions
No. SOC 2 is an American attestation that tests whether your systems are secure; GDPR is European law about whether your processing is lawful and rights are honoured. A clean report can leave every GDPR-specific obligation untouched.
On the security backbone — access control, change management, encryption, monitoring and logging, vendor management, incident response. These satisfy SOC 2’s common criteria and GDPR’s Article 32 at once, and for most companies that is the large majority of the work.
Even with the optional Privacy criterion, SOC 2 does not establish a lawful basis, grant enforceable rights, govern international transfers, require a 72-hour regulator notification, or mandate a GDPR-style data processing agreement.
Usually SOC 2, because an American deal will not move without it, provided the shared security core is built to serve GDPR too. The mistake is stopping there: GDPR’s specific obligations have to be closed before EU exposure, not discovered after a regulator asks.