---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Use

# Using Privacy Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As a privacy analyst or a privacy manager, you can identify which business applications
or processes store and use personal information.
* **[Entity scoping to plan a privacy program](https://servicenow-prod.fluidtopics.net/L9qq~iYchg~9VDyOO2PXXw)**   
  When a privacy manager plans the privacy program for an organization, the first step is to scope those business applications or processes that contain personal data. In Governance, Risk, and Compliance, these business applications or business processes are called as entities. After you identify the entities processing personal data, the processing activities are automatically created.
* **[Types of privacy assessments](https://servicenow-prod.fluidtopics.net/1yZGohzGuDBy6Yyok~BrcA)**   
  Privacy assessments can be sent using various methods such as entities, entity types, and processing activities.
* **[Create a Risk Assessment Methodology](https://servicenow-prod.fluidtopics.net/1eHuVwOde5~BR~7H2Mox_A)**   
  Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.
* **[Respond to a privacy smart assessment](https://servicenow-prod.fluidtopics.net/FxENK8TfCH1gy5QhCvS~bw)**   
  Respond to either a screening assessment or an impact assessment from the Assessment Workspace. The assessment results help to understand the potential privacy risks and their mitigation measures.
* **[Respond to a privacy screening assessment](https://servicenow-prod.fluidtopics.net/txUnS~hmrARyHerONei7Mg)**   
  As an entity owner or a processing activity key stakeholder, respond to the privacy assessment that is initiated by the privacy lead.
* **[Review a privacy assessment](https://servicenow-prod.fluidtopics.net/NM0CwMbfFoS4b9ic1ge56Q)**   
  As a privacy analyst, review a privacy assessment after the responders submit the assessment. You can either close the assessment after a review or you can also request for revision if you determine that the assessment requires more information.
* **[Create or update a processing activity](https://servicenow-prod.fluidtopics.net/DjlDtlmQszgPD63_LZStaw)**   
  Manually create a processing activity or update a processing activity that is automatically created out of a privacy screening assessment. You can also update a processing activity that is created from an entity record. When you update a processing activity, you can fill in the relevant details about the personal data that is being processed.
* **[Create or manage an information object within a processing activity](https://servicenow-prod.fluidtopics.net/T8t9GOHhFO4n4ESYcYQW4Q)**   
  Add information objects to the processing activity after a processing activity is created. Adding information objects helps you understand the types of personal information that is being processed and the way it is processed. This task helps in applying the appropriate controls to the processing activity.
* **[Add data subject type to a processing activity](https://servicenow-prod.fluidtopics.net/nj5cuV2681dzGOCNB14OyA)**   
  Add data subject types to a processing activity in the Privacy Workspace.
* **[Add data subject type to privacy impact assessment](https://servicenow-prod.fluidtopics.net/M0FAHF05lXFa7qUREEJgXQ)**   
  Add data subject types to privacy impact assessment from the Employee Center.
* **[Classify data subject type as vulnerable](https://servicenow-prod.fluidtopics.net/PMQbSk70QZAWfPgxBgrGXA)**   
  Classify a data subject type as vulnerable. When you mark a data subject type as vulnerable, the criticality score is calculated as High.
* **[Add key stakeholders to a processing activity](https://servicenow-prod.fluidtopics.net/RxvxY2dI9xE9FaurI8wu0w)**   
  Add key stakeholders to a processing activity. Based on their role, users are assigned default processing activity privileges that control whether they can edit a processing activity, view it, or respond to its privacy assessments.
* **[Enable key stakeholders to update processing activities directly](https://servicenow-prod.fluidtopics.net/41aL9n2njHq2ATn80pxG2A)**   
  Enable stakeholders to update processing activities directly from the Employee Center by assigning the activity to them.
* **[Edit a processing activity from the Employee Center](https://servicenow-prod.fluidtopics.net/IbcwRxsTF5EBA6v3yoTNrQ)**   
  Access a processing activity directly from the Employee Center and request edit access to update the details your team is responsible for.
* **[Add a regulatory agency](https://servicenow-prod.fluidtopics.net/2Z2K~aM9L263tMcNQO68Bg)**   
  Add a regulatory agency in the Privacy Workspace to identify the relevant regulatory authorities that are responsible for overseeing the industries or sectors within each jurisdiction. The jurisdictions consolidate all the regulatory communications via emails and implement the notification rules for data privacy or security breaches for the reported privacy cases.
* **[Create a lineage for a processing activity](https://servicenow-prod.fluidtopics.net/cU8KAoNZ4OlmszYOF6Ao1Q)**   
  Establish a lineage to visualize data consumption, sharing, and the associated risks for a processing activity. Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a lineage or hierarchy that tracks where personal data is shared.
* **[Create or manage a control on a processing activity](https://servicenow-prod.fluidtopics.net/PZE3ysiT0CiQ_2HP6LWc6w)**   
  Add new controls or manage the controls that are automatically added to the processing activity from the assessment responses. Adding controls ensures that the appropriate regulations are applied to the processing activity.
* **[Delete a control from a processing activity](https://servicenow-prod.fluidtopics.net/~DmiJVUYfdgC6QKDKu2k2A)**   
  Delete the controls that are no longer required in the processing activity.
* **[Create or manage risks on a processing activity](https://servicenow-prod.fluidtopics.net/HhYVvR3GFtkL_tbHCnjWaw)**   
  Add new risks or manage the risks that are automatically added to the processing activity from the assessment responses. Adding risks helps you manage processing activities using the risk-based approach.
* **[Manage chat collaborations of a processing activity](https://servicenow-prod.fluidtopics.net/Qm2ccpTpMyrBaHmXVO5C2A)**   
  Initiate quick discussions with key stakeholders while working on a processing activity, privacy case, or a personal data rights request. The chat feature is integrated with Microsoft Teams and a group is automatically created on Microsoft Teams when a discussion is initiated.
* **[Create or add issues on a processing activity](https://servicenow-prod.fluidtopics.net/~XXIAy8LTWxthOvWrAq3Hg)**   
  Create issues or add existing issues for a processing activity. Associating issues to a processing activity helps you to identify and prioritize remediation actions. Relating issues reduces the number of issues customers need to manage, thus improving the overall organizational efficiency in management of these issues.
* **[Accessing control through organizational structure](https://servicenow-prod.fluidtopics.net/2bX32BFKcTcKLAkj5jAQfw)**   
  Access to processing activity records can be restricted by using Entity-Based Access (EBA).

