---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Processing activities

# Processing activities {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

A processing activity is a record that processes personal data. Examples of such records
can be a business process or a business application of an organization that has personal
information. Processing activities enable the privacy management teams to understand how personal
information is being processed or used.

To manage the privacy programs, use any business process or business application that is
available as inventory or records in the Configuration Management Database (CMDB) to create a
processing activity record. Each business process or an application is a separate processing
activity. After the privacy teams understand how personal data is being used, they can work with
the business owners who own the processing activity and help them to be compliant with the
necessary privacy regulations.  
A processing activity stores the following type of information:

* Name and contact information of the data controller and the data processor.
* Regulatory details such as data sensitivity, scale of data processing and so on.
* The purpose for which a processing activity is processing personal data. For example, lawful basis, legal obligations, and so on.
* Categories of data subjects and categories of personal data being processed. Examples of data subjects are customers or employees.
* Recipients with whom personal data is shared. For example, vendors or third parties and internal systems.
* Third parties in other countries and international organizations that receive the personal data.
* Privacy regulations, policies, risks, controls, and issues related to each processing activity.
* Key stakeholders of the processing activity such as the entity owners and others who are involved in the processing activity.
{#ropa-record__ul_z2q_t5s_mqb}  
The following image shows the overview of a processing activity:  
Note:  
The policies and controls that appear on the Overview page of the processing activity are specific to Privacy Management.
* **[Processing activity hierarchy](https://servicenow-prod.fluidtopics.net/L80~9jFBmyGwESKz_82epg)**   
  Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a data lineage or hierarchy that tracks where personal data is shared. This understanding helps mitigate privacy-related risks.
* **[Hierarchy tab](https://servicenow-prod.fluidtopics.net/GCLqNevS_7ZL7dVWgm3_Ew)**   
  Use the Hierarchy tab to connect your processing activity to applications, vendors, companies, entities, business processes, and other activities. The Hierarchy tab builds a clear picture of how data moves through your organization.

