---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Discover processing activities involving personal data

# Scope entities to discover processing activities with personal information {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Determine which entities have and process personal information using the ServiceNow®
Configuration Management Database (CMDB) application.

## Before you begin

Ensure that you created the CMDB queries. For more
information on the CMDB queries, see [Querying the
CMDB](https://www.servicenow.com/docs/access?context=querying-cmdb&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US).

Role required: sn_privacy.manager

## About this task

In the Configuration Management Database (CMDB), you can search the database for entities that process personal data using one of the following methods:

* Using the predefined queries and selecting only those applications and processes that have associated information objects. For more information about information objects and their role in Privacy Management, see [Information objects in Privacy Management](https://servicenow-prod.fluidtopics.net/ntmK4EHhvet~BBW4DuiH7A "The purpose of an information object is to logically describe the type of data that is exchanged between an application and a database."). For information on how to scope entities with personal information, see [Scope entities to discover processing activities with personal information](https://servicenow-prod.fluidtopics.net/s8tddW_5YXmNdlCVc~RHow "Determine which entities have and process personal information using the ServiceNow Configuration Management Database (CMDB) application.")
* Building your own query. For more information on building the CMDB queries, see [Querying the
  CMDB](https://www.servicenow.com/docs/access?context=querying-cmdb&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US)

{#scope-entities-with-pi__ul_mpv_32y_jqb}To filter entities that contain personal data, you must filter the entities using the appropriate queries. ServiceNow® provides two default queries for you to use to filter entities with personal data. The default queries are provided for the following tables:

* Business process
* Business application
{#scope-entities-with-pi__ul_sjs_gbp_3qb}You can also create your own queries. This procedure demonstrates using the default queries.

## Procedure

1. Navigate to AllPrivacy WorkspaceScopingEntity types.
2. Open the entity you want to filter for personal information.
3. Click the Entity Filters related list.
4. Click New.  
   The Entity Filter form is displayed.
5. In the Filter conditions section, in the Entity filter type field, select Select from predefined queries.
6. In the Query field, select Business applications by IO.  
   The Table field is automatically set.
7. **Optional:** To add more information objects that contain personal information such as email address, click Information objects and type <kbd class="ph userinput">Email</kbd>.
8. Click Submit.

## Example

Figure 1. Usage of predefined queries

*[\>]: and then


