---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Initiating privacy assessments

# Initiating privacy assessments for an entity or a processing activity {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To discover whether a business process or an application is processing personal data, you can use privacy screening assessments. To regularly assess how processing activities are processing personal data, you can use privacy
assessments such as privacy impact assessment (PIA).

## Privacy screening assessment {#trigger-privacy-assessmt-on-entities__section_b4v_2nj_5qb}

Conducting a privacy screening assessment helps you discover whether the entity is processing personal information or not.  
You can send the privacy screening assessments in the following ways:

* From the entity record only when a processing activity is not available.
* From the entities related list in entity types.
{#trigger-privacy-assessmt-on-entities__ul_zpn_hnj_5qb}  
When you initiate privacy screening assessments for entities, processing activities are created based on the responses submitted by the entity owners.  
Note:  
The processing activity creation rules can be configured based on the screening assessment responses.
After a processing activity is created, based on the assessment configurations, the following events occur:

1. The necessary information objects are mapped to the processing activity record. To understand more about information objects and their uses, see [Information objects](https://servicenow-prod.fluidtopics.net/RROHCccR6HomBQXNxejkdQ "Information objects are a part of the information portfolio management capability in the Application Portfolio Management application.").
2. The necessary controls are mapped to the processing activity record.
3. Critical assessment responses such as the purpose of the processing activity, data subject type and so on are copied over to the processing activity record.
{#trigger-privacy-assessmt-on-entities__ol_lsp_3nj_5qb}  
Note:  
If you accidentally send an assessment and the assessment is not completed, you can cancel the assessment.

## Privacy assessments {#trigger-privacy-assessmt-on-entities__section_o5t_knj_5qb}

When processing activity records are identified, to understand how a processing activity is processing personal information, various types of privacy assessments such as privacy impact assessments (PIA) and transfer impact
assessment (TIA) are sent. You can trigger PIAs from a single processing activity record. For more information, see [Send a privacy assessment from a processing activity](https://servicenow-prod.fluidtopics.net/Ifx9W0wEDmZDMhP1R5cwUg "Send a privacy assessment to a processing activity owner from a processing activity record to collect more information on why and how the processing activity is using personal information."). Alternatively, you can send privacy impact assessments to multiple processing activities, using the Entity type capability or from the processing activity list view. For more information
on how to send an assessment to multiple entities, see [Send a privacy assessment to multiple entities](https://servicenow-prod.fluidtopics.net/2~pQOCDHiDJ74zWTplBB2w "Send the privacy screening assessment or the Privacy impact assessment (PIA) assessments to multiple entities to understand why and how personal data is being processed.").
* **[Send a privacy assessment from an entity](https://servicenow-prod.fluidtopics.net/TdRdkP74ZtKRrzuw1kr26A)**   
  Send a privacy assessment to an entity owner to determine if there's personal data involved in the processing activities.
* **[Send a privacy assessment to multiple entities](https://servicenow-prod.fluidtopics.net/2~pQOCDHiDJ74zWTplBB2w)**   
  Send the privacy screening assessment or the Privacy impact assessment (PIA) assessments to multiple entities to understand why and how personal data is being processed.

**Related tasks**   

* [Send a privacy assessment to multiple entities](https://servicenow-prod.fluidtopics.net/2~pQOCDHiDJ74zWTplBB2w "Send the privacy screening assessment or the Privacy impact assessment (PIA) assessments to multiple entities to understand why and how personal data is being processed.")

