Workflow of a processing activity
Summarize
Summary of Workflow of a processing activity
A processing activity workflow enables privacy analysts and managers to manage the entire life cycle of a processing activity within ServiceNow. This workflow ensures privacy compliance by guiding the processing activity through various stages, from creation to retirement. Only privacy analysts or managers who own the processing activity can edit it; others have view-only access.
Show less
Workflow Stages
- New: Initial manual creation and confirmation of the processing activity. Editable fields include Name, Justification, Privacy Analyst, and Entity. The activity moves to the Discover state after saving with an entity specified.
- Discover: Privacy managers or analysts gather detailed information by sending privacy assessments and update the processing activity accordingly. They assign the activity to key stakeholders (with the snprivacy.businessuser role) to update relevant details and information objects. Controls are reviewed and adjusted based on assessment responses before moving to Review.
- Review: Controls and compliance posture are validated by sending control attestations. Privacy managers or analysts update details, associate information objects, and manage controls. Non-compliance issues and policy exceptions are tracked during this phase.
- Monitor: Continuous monitoring of the processing activity occurs using indicator functionality. Privacy managers or analysts can revert the activity to Discover or Review states if further assessment is needed. Issues are managed actively. If a new privacy assessment is initiated during Monitor, the activity automatically returns to Discover.
- Retire: The processing activity is retired when the related business application or process is no longer in use. All associated controls are retired, and no further updates are allowed. Processing activities linked to inactivated entities automatically move to this state.
Key Outcomes
- Structured management of processing activities ensures privacy compliance throughout their life cycle.
- Clear roles and permissions restrict editing to authorized privacy analysts and managers.
- Privacy assessments and control attestations facilitate informed control application and compliance tracking.
- Continuous monitoring maintains ongoing compliance vigilance and enables timely remediation.
- Automatic retirement of processing activities linked to inactive entities keeps compliance data current and relevant.
A processing activity workflow helps the privacy analysts to manage the life cycle of a processing activity.
New
- Name
- Justification
- Privacy analyst
- Entity: Only when this field is filled, and the processing activity form is saved. After saving the form, the privacy manager or a privacy analyst can move the processing activity the Discover state.
Discover
- Send privacy assessments.
- Update the processing activity Details section based on the assessment responses.
- Assign the processing activity to one of the key stakeholders for the key stakeholders to
update the details, the PI-tagged information objects, and the key
stakeholders.Note:You can assign the processing activity to those users who have the sn_privacy.business_user role.
- Review the controls applied based on the privacy assessment responses.
- Add or remove additional controls as necessary.
Review
- Update the processing activity Details section based on the assessment responses.
- Associate information objects and capture additional details related to the information objects based on the assessment responses.
- Review the controls applied automatically based on the privacy assessment responses, and add or remove additional controls as necessary.
- Send control attestations and track issues and policy exceptions.
Monitor
- Auto execution of indicator functionality to continuously monitor controls associated with processing activity.
- Create, manage issues, and track issues.
Retire
This is a state to retire the processing activity when the respective business application or business process is no longer used in the organization. When moved to this state, all the controls associated with the processing activity are retired. The privacy team cannot make any updates to a processing activity in the retired state. When an entity gets inactivated, the related processing activity is also automatically moved to the Retired state.