---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create or update a processing activity

# Create or update a processing activity {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Manually create a processing activity or update a processing activity that is
automatically created out of a privacy screening assessment. You can also update a
processing activity that is created from an entity record. When you update a processing
activity, you can fill in the relevant details about the personal data that is being
processed.

## Before you begin

Role required: sn_privacy.analyst (who owns the processing activity) or sn_privacy.manager

## About this task

You can create a processing activity in two ways:

* Manually create a processing activity for a business application or process that handles personal data.
* Update a processing activity that was automatically created when a privacy screening assessment determined that personal data is being processed. Screening assessments include automation rules that create processing activities based on specific responses. To configure automation in your assessment template, refer to [Post-assessment automations](https://servicenow-prod.fluidtopics.net/C9EsQ0ZXG5cMPTavcGunXg "Post-assessment automations, also known as post-assessment actions, in Smart Assessment Engine are actions that happen automatically after an assessment is complete. These actions use the responses from an assessment to automate tasks. Using action sets, automated actions, trigger conditions, and evaluation criteria, post-assessment actions can help your assessments be efficient, consistent, accurate, and scalable.").

## Procedure

1. Navigate to one of the following.

   | Action | Procedure |
   | To create a new processing activity | 1. Navigate to AllPrivacy ManagementProcessing activitiesAll processing activities. 2. Click New. {#create-processing-activity__ol_vyw_3fc_sqb} |
   | To update a processing activity | 1. Navigate to AllPrivacy ManagementPrivacy WorkspaceListMy itemsProcessing activities. 2. Open the processing activity that you want to update. {#create-processing-activity__ol_ywl_sfc_sqb} |
   |-|-|

   {#create-processing-activity__choicetable_kjs_yc1_sqb}
2. On the form, fill in the fields.  
   {#create-processing-activity__table_FloorForm__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the processing activity. |
   | Processing activity purpose | Business justification or reason for using an application or a process that stores personal data. |
   | Number | Number of the processing activity. This field is automatically set. |
   | Privacy analyst | Analyst responsible for the processing activity. |
   | Business unit | Business unit of the processing activity. |
   | Department | Department of the processing activity. |
   | Processing activity type | Context of the processing activity such as a business application or a business process. |
   | Entity | Entity of the processing activity. |
   | Applies to record | Reference record used to create the processing activity record. |
   | Owned by | Owner of the processing activity. |
   | Data processing role | Defines if a processing activity is a data controller or a data processor. |
   | Processing activity status | Status of the processing activity. The choices are as follows: * Implementing * In Production * Pilot * Retired * Under Evaluation {#create-processing-activity__ul_f3r_kc4_3qb} |
   | Processing activity category | Category to which the processing activity belongs for example, customer care, finance, and so on. |
   | Compliance score | Privacy compliance score calculated based on all the controls mapped to this processing activity. |
   | Process owner | Any user, with the sn_privacy.business_user role, from the list of key stakeholders who has the editing privileges for the processing activity. Note: The user selected in this field can update the this field and select a new process owner. Updating this field is only possible when the processing activity is in the Discover or Review state. |
   | Data subject ||
   | Data storage type | Format in which the personal information is stored. The choices are as follows: * Digital * Paper * Both {#create-processing-activity__ul_bbw_5c4_3qb} |
   | Data storage locations | Physical location of where the personal information is stored. |
   | Data retention period (in days) | Number of days for which personal information must be retained. |
   | Data subject type | User type related to the personal information that is being used and processed. The choices are as follows: * Customers * Employees * Others {#create-processing-activity__ul_xkk_zc4_3qb} |
   | Data subject range | Range of users for whom the personal information is being processed. |
   | Contains special category data? | This field is automatically set to either Yes or No. If any information object associated with the processing activity is classified as special category data, then this field is automatically set to Yes. |
   | Obtain special category data? | Does this processing activity process any special category data such as racial, ethnic, political information? The choices are as follows: * Yes * No {#create-processing-activity__ul_hxd_ch1_sqb} |
   | Activity ||
   | Additional comments | Additional information about the processing activity. |
   | Work notes | Internal notes not visible to the external people. |
   [Table 1. New processing activity form]

   {#create-processing-activity__table_FloorForm}
3. Click Save.
{#create-processing-activity__steps_xss_gjv_gqb}

## What to do next

Send a privacy assessment to a processing activity owner to collect more information on why and how the processing activity is using personal information. For more information, see [Send a privacy assessment from a processing activity](https://servicenow-prod.fluidtopics.net/DbAr6q75HU~WWkGOR83WCw "Send a privacy assessment to a processing activity owner from a processing activity record to collect more information on why and how the processing activity is using personal information.").

*[\>]: and then


