---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# States of a privacy breach assessment

# States of a privacy breach assessment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After a privacy analyst initiates a privacy breach assessment, the assigned reviewer contributes their insights and includes the personally identifiable information (PI) artifacts and relevant jurisdictions before it is
completed and closed.  
The states of a breach assessment are listed as follows:

1. Draft: This is the default state when a breach assessment is initiated.
2. Assigned: This is the state when the privacy analyst assigns the assessment to a user.
3. Work in progress: This is the state when the reviewer accepts the assignment and adds PI artifacts and jurisdictions to the breach. The reviewer then sends the assessment for a review to the privacy analyst.
4. Review: In this state, the privacy analyst reviews the assessment.
5. Closed: After the reviewer completes the review, the reviewer completes and closes the assessment.
{#life-cycle-of-a-privacy-breach-assessment__ol_wvd_54c_n1c}

