Tapad earns SOC 2 Type 2 certification for third year in a row

by Experian Marketing Services 4 min read January 24, 2023

Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.

Two information security certifications you can trust

Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?

  1. The International Organization for Standardization (ISO) 27001
  2. The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)

International Organization for Standardization (ISO)

27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information

System and Organization Controls (SOC)

The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.

SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.

Why ISO 27001 and SOC 2 are important

The value of these third-party attestations is two-fold:

  1. Organizations can show they have passed an independent external audit
  2. Third-party attestations save organizations the time of having to do their own audits

In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.

Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.

So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.

We’re powered by decades of setting standards in marketing services

At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.

The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.

Contact us today

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


About our expert

Ben Rothke headshot

Ben Rothke, Senior Information Security Manager

Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.


Latest posts

Cannes Lions 2026: What it takes for brands to become part of the culture

Every brand wants to be part of the culture. Few know how to show up without crashing the party.  The brands that get it right stay true to who they are, and the moments they create tend to stick long after the attention moves on. At Cannes Lions 2026, leaders from Alaska Airlines, Fetch, FreeWheel, Goodway Group, Grupo Bimbo, OAAA, PMG, Quan Media Group, Significant, The Weather Company, and Wpromote talked through what real cultural relevance looks like, from finding the right moments to keeping them alive long after the attention fades. Watch the conversation below to hear what it takes for brands to earn their place in culture. Watch the conversation How brands earn their way into cultural moments Build the strategy behind the creative A clear rationale helps bold ideas earn internal support and achieve the intended outcome. Make cultural relevance feel genuine A cultural connection lands when it reflects something people already care about, not when a brand forces it. Move quickly and stay true to the brand Teams create strong brand moments when they act on an opportunity without compromising the brand’s identity. Plan the second act Once attention drops, give people new ways to relive the experience and remain part of it. Read the early audience response Comments, shares, and other reactions can show whether an idea connects before campaign data offers a more complete view. Add value to the experience Brands earn attention when they give people something worthwhile, not when they simply place a logo in the moment. Featured partners Alaska Airlines – Eric Edge, Chief Marketing Officer Fetch – Emily Starer-Wallace, General Manager of Data Partnerships FreeWheel – Larry Allen, Vice President of Global Strategy, Data, Measurement and Addressable Goodway Group – Mike Wolk, Senior Vice President of Partnerships Grupo Bimbo – Catherine Berger, Vice President of Marketing Transformation and Services OAAA – Anna Bager, President and Chief Executive Officer PMG – Chad Stoller, Global Head of Media Quan Media Group – Brian Rappaport, Chief Executive Officer Significant – Jesse Unger, Co-Founder The Weather Company – AnneMette Bontaites, Vice President of Sales Wpromote – Deanna Cullen, Vice President of Media Investment Want more conversations like this one? Connect with us to learn more about how streaming media helps brands reach real people across every screen. This is one of several conversations from Cannes Lions 2026 on how brands can show up in culture with relevance that feels real. Subscribe to our newsletter to receive our next Cannes conversation, fresh takes on cultural relevance, and honest advice from industry leaders on how brands earn a real place in culture. Subscribe to our newsletter For more from Cannes Lions 2026, continue with another conversation in the series What it takes to move patients from awareness to care What commerce media can see beyond a single retailer What streaming media reveals about cross-screen viewing What creators earn that reach can’t buy Contact us Latest posts

September 1, 2026 by Experian Marketing Services
Cannes Lions 2026: What streaming media reveals about cross-screen viewing

Watch leaders from Adobe DSP, FreeWheel, Madhive, Minerva, OpenX, and Pinterest at Cannes Lions 2026 discuss how streaming media connects viewers across screens.

August 20, 2026 by Experian Marketing Services
Healthcare marketing enters a mixed-identity world

Pharma marketing now runs across mixed-identity conditions. Learn how to keep DTC and HCP data separate while connecting signals across activation and measurement.