Processing activity hierarchy
Summarize
Summary of Processing activity hierarchy
Processing activities involve multiple personal information objects that exchange data with various entities. Establishing a data lineage or hierarchy is essential to track where personal data is shared, helping mitigate privacy-related risks by providing clear visibility into data flows.
Show less
Methods to Create Data Lineage
- From the Hierarchy tab of a processing activity
- Using the Data lineage button on a processing activity
These methods allow you to map the flow and transformation of personal data within your organization.
Importance of Data Lineage
Data lineage is critical for understanding data management and privacy risks. For example, in a Human Resources context:
- Employee and candidate records include sensitive personal details
- Data flows between internal departments (e.g., Talent Acquisition, Recruiters) and external applications (e.g., calendar tools, benefits tracking)
- Tracking data from candidate registration through hiring and employee profile creation helps identify where personal data originates, how it is processed, and where it is shared
This clarity enables identification of potential privacy risks such as unauthorized access or breaches during data exchange, supporting the implementation of effective safeguards.
Information Displayed on the Data Lineage Page
Once data lineage is established, the data lineage page provides key information including:
- Description of the processing activity, its owner, and type
- Criticality score (if High)
- Risk rating (if High and Critical)
- Compliance score
- Number of open and critical open issues
- Ongoing assessments
- Linked processing activities to selected CMDB records, if any
A toggle switch labeled View roll-up enables viewing of aggregated personal information objects associated with selected assets and their destinations, providing a comprehensive perspective on data flow.
Practical Benefits for ServiceNow Customers
By leveraging processing activity hierarchy and data lineage features, you can:
- Gain a clear understanding of personal data flows across your enterprise systems
- Identify and manage privacy risks effectively
- Monitor processing activities with visibility into criticality, risk, compliance, and open issues
- Support regulatory compliance through detailed data flow tracking
This capability empowers you to maintain robust data privacy governance within ServiceNow.
Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a data lineage or hierarchy that tracks where personal data is shared. This understanding helps mitigate privacy-related risks.
Methods to create data lineage
- From the Hierarchy tab of a processing activity.
- From the Data lineage button on a processing activity. For more information see, Create a data lineage for a processing activity.
Importance of data lineage
- Employee records: These include personal details like names, addresses, phone numbers, and email addresses.
- Prospective interview candidate records: Contains candidate names, interview dates, and times.
- Internal departments such as Talent acquisition, Recruiters, People Management teams.
- External tools and applications to track time off, benefits, and so on.
- Candidate registration:
- A person registers on the careers portal and submits their resume.
- The candidate's details such as name, email, phone number are entered into the applicant tracking system (ATS).
- Scheduling an interview:
- The Talent Acquisition team selects the candidate for an interview and enters the interview date and time into the calendar application.
- The calendar application sends an email to the candidate with the interview details.
- Conducting the interview:
- The recruiters access the candidate’s profile on the ATS, review the resume, and conduct the interview.
- Post-interview, they add their feedback to the candidate's ATS profile.
- Hiring process:
- The candidate is selected for the position.
- The candidate details are transferred from the ATS to the HR database, and additional information is collected and updated.
- The HR database uses other external applications to create the candidate’s employee profile, including time-off records and benefits information.
By establishing a data lineage, the HR organization can track where each piece of personal data originates, how it’s processed, and where it’s shared. Understanding the data flow helps identify potential privacy risks, such as unauthorized access or data breaches at any point where data is shared. By establishing the data lineage in this way, the HR organization can ensure that they’re aware of all points where personal data is exchanged. This understanding helps them implement appropriate safeguards to mitigate privacy-related risks.
Information displayed on the data lineage page
- Description of the processing activity along with its owner and the type.
- Criticality score of the processing activity if the score is High.
- Risk rating of the processing activity if the score is High and Critical.
- Compliance score of the processing activity.
- Number of open issues.
- Number of critical open issues.
- On going assessments.
If a selected CMDB record already has a processing activity linked to it, then that information is also displayed during the hierarchy creation. A toggle switch View roll-up is provided to view the rollup of personal information objects. If this switch is turned on, then the personal information objects associated with the selected asset and its associated destinations are displayed.
Data lineage example
The following image shows a sample data lineage hierarchy.