Workflow of a processing activity
Summarize
Summary of Workflow of a Processing Activity
The processing activity workflow in Privacy Management assists privacy analysts in managing the life cycle of processing activities related to privacy compliance. This workflow comprises several stages, each with specific responsibilities and actions for privacy managers and analysts. Note that only privacy analysts who own the processing activity can edit it; others can only view it.
Show less
Key Features
- New: This initial state allows manual creation of a processing activity. Privacy managers or analysts can modify fields such as Name, Justification, and Privacy Analyst before saving and moving to the Discover state.
- Discover: In this stage, the owner gathers details on how personal information is processed through privacy assessments. Activities include sending assessments, updating details, assigning tasks to stakeholders, and reviewing applied controls.
- Review: Here, control attestations are sent, and compliance posture is assessed. The owner can update details, associate information objects, and monitor non-compliance issues.
- Monitor: This state focuses on continuous monitoring of processing activities. The privacy analyst can move activities back to Discover or Review based on new updates and track issues.
- Retire: The final state for processing activities that are no longer in use. All associated controls are retired, and no updates can be made to the processing activity.
Key Outcomes
By effectively managing the processing activity workflow, privacy analysts can ensure compliance with privacy regulations, continuously monitor controls, and retire activities that are no longer relevant. This structured approach streamlines the management of privacy-related tasks and enhances the organization's compliance posture.
A processing activity workflow helps the privacy analysts to manage the life cycle of a processing activity.
New
- Name
- Justification
- Privacy analyst
- Entity: Only when this field is filled, and the processing activity form is saved. After saving the form, the privacy manager or a privacy analyst can move the processing activity the Discover state.
Discover
- Send privacy assessments.
- Update the processing activity Details section based on the assessment responses.
- Assign the processing activity to one of the key stakeholders for the key stakeholders to
update the details, the PI-tagged information objects, and the key
stakeholders.Note:You can assign the processing activity to those users who have the sn_privacy.business_user role.
- Review the controls applied based on the privacy assessment responses.
- Add or remove additional controls as necessary.
Review
- Update the processing activity Details section based on the assessment responses.
- Associate information objects and capture additional details related to the information objects based on the assessment responses.
- Review the controls applied automatically based on the privacy assessment responses, and add or remove additional controls as necessary.
- Send control attestations and track issues and policy exceptions.
Monitor
- Auto execution of indicator functionality to continuously monitor controls associated with processing activity.
- Create, manage issues, and track issues.
Retire
This is a state to retire the processing activity when the respective business application or business process is no longer used in the organization. When moved to this state, all the controls associated with the processing activity are retired. The privacy team cannot make any updates to a processing activity in the retired state. When an entity gets inactivated, the related processing activity is also automatically moved to the Retired state.