Workflow of a processing activity
Summarize
Summary of Workflow of a processing activity
The processing activity workflow in ServiceNow enables privacy analysts and managers to manage the entire life cycle of a processing activity related to privacy compliance. It ensures proper tracking, assessment, control application, monitoring, and retirement of processing activities to maintain compliance with privacy requirements.
Show less
Only privacy analysts or managers who own a processing activity can edit it; others have view-only access.
Workflow Stages and Their Functions
- New: This initial state is for manually created processing activities to confirm if they involve business applications, processes, vendors, or services relevant to privacy compliance. Editable fields include Name, Justification, Privacy analyst, and Entity. After saving with Entity filled, the activity can move to the Discover state.
- Discover: In this state, owners gather detailed information on how personal data is processed by sending privacy assessments. They update the activity details, assign it to key stakeholders (with the snprivacy.businessuser role) to update tagged information objects and stakeholders, and review or adjust controls based on assessment responses. The activity then proceeds to Review.
- Review: Owners send control attestations and review compliance posture based on attestation responses and any non-compliance issues. They update details and information objects, review controls, and manage issues and policy exceptions.
- Monitor: This state supports continuous monitoring using indicator functionality to automatically track controls associated with the activity. Owners can manage and track issues, and based on updates, move the activity back to Discover or Review for reassessment. Sending a new privacy assessment during Monitor automatically returns the activity to Discover.
- Retire: When a business application or process is no longer in use, the processing activity is retired. All associated controls are retired, and no further edits are allowed. Inactivation of an entity automatically retires related processing activities.
Practical Benefits for ServiceNow Customers
- Provides a structured approach to managing processing activities to ensure privacy compliance throughout their life cycle.
- Enables collaboration between privacy analysts, managers, and key stakeholders for comprehensive data collection and control application.
- Supports continuous monitoring and issue management to maintain ongoing compliance and quickly address any gaps.
- Automates state transitions based on assessments and entity status to maintain data integrity and compliance rigor.
A processing activity workflow helps the privacy analysts to manage the life cycle of a processing activity.
New
- Name
- Justification
- Privacy analyst
- Entity: Only when this field is filled, and the processing activity form is saved. After saving the form, the privacy manager or a privacy analyst can move the processing activity the Discover state.
Discover
- Send privacy assessments.
- Update the processing activity Details section based on the assessment responses.
- Assign the processing activity to one of the key stakeholders for the key stakeholders to
update the details, the PI-tagged information objects, and the key
stakeholders.Note:You can assign the processing activity to those users who have the sn_privacy.business_user role.
- Review the controls applied based on the privacy assessment responses.
- Add or remove additional controls as necessary.
Review
- Update the processing activity Details section based on the assessment responses.
- Associate information objects and capture additional details related to the information objects based on the assessment responses.
- Review the controls applied automatically based on the privacy assessment responses, and add or remove additional controls as necessary.
- Send control attestations and track issues and policy exceptions.
Monitor
- Auto execution of indicator functionality to continuously monitor controls associated with processing activity.
- Create, manage issues, and track issues.
Retire
This is a state to retire the processing activity when the respective business application or business process is no longer used in the organization. When moved to this state, all the controls associated with the processing activity are retired. The privacy team cannot make any updates to a processing activity in the retired state. When an entity gets inactivated, the related processing activity is also automatically moved to the Retired state.