The SOC 2 is a separate report that focuses on controls at a service provider relevant to security, availability, processing integrity, confidentiality, and privacy of a system. GDPR is the unique possible response, even though It's only applied in EU. The other responses are not related to client data.