---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Use

# Using Privacy Management {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As a privacy analyst or a privacy manager, you can identify which business applications
or processes store and use personal information.
* **[Entity scoping to plan a privacy program](https://servicenow-prod.fluidtopics.net/_I5S7R9DnTl5aXFgSnREFQ)**   
  When a privacy manager plans the privacy program for an organization, the first step is to scope those business applications or processes that contain personal data. In Governance, Risk, and Compliance, these business applications or business processes are called as entities. After you identify the entities processing personal data, the processing activities are automatically created.
* **[Types of privacy assessments](https://servicenow-prod.fluidtopics.net/4l20~4NdOSuJTpKdfFsvLw)**   
  Privacy assessments can be sent using various methods such as entities, entity types, and processing activities.
* **[Create a Risk Assessment Methodology](https://servicenow-prod.fluidtopics.net/Pq6obhAKXBq81uhwxxGEjA)**   
  Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.
* **[Respond to a privacy smart assessment](https://servicenow-prod.fluidtopics.net/O4JMLG_Z20Nbvdv~RMTqhw)**   
  Respond to either a screening assessment or an impact assessment from the Assessment Workspace. The assessment results help to understand the potential privacy risks and their mitigation measures.
* **[Respond to a privacy screening assessment](https://servicenow-prod.fluidtopics.net/5H74p27bxLrs20e4Lwndpw)**   
  As an entity owner or a processing activity key stakeholder, respond to the privacy assessment that is initiated by the privacy lead.
* **[Review a privacy assessment](https://servicenow-prod.fluidtopics.net/y5vR2tB81e7t9HXjMuxYxg)**   
  As a privacy analyst, review a privacy assessment after the responders submit the assessment. You can either close the assessment after a review or you can also request for revision if you determine that the assessment requires more information.
* **[Create or update a processing activity](https://servicenow-prod.fluidtopics.net/TlA0Lf5OgxstKflyu8K6sw)**   
  Manually create a processing activity or update a processing activity that is automatically created out of a privacy screening assessment. You can also update a processing activity that is created from an entity record. When you update a processing activity, you can fill in the relevant details about the personal data that is being processed.
* **[Create or manage an information object within a processing activity](https://servicenow-prod.fluidtopics.net/CsU5_N0k7Ck9vKgTzL1VCA)**   
  Add information objects to the processing activity after a processing activity is created. Adding information objects helps you understand the types of personal information that is being processed and the way it is processed. This task helps in applying the appropriate controls to the processing activity.
* **[Add data subject type to a processing activity](https://servicenow-prod.fluidtopics.net/TEVMj7j5hpbbeUzWKfgcGg)**   
  Add data subject types to a processing activity in the Privacy Workspace.
* **[Add data subject type to privacy impact assessment](https://servicenow-prod.fluidtopics.net/0J6uWoJHTAYJxmdZAlBT4A)**   
  Add data subject types to privacy impact assessment from the Employee Center.
* **[Classify data subject type as vulnerable](https://servicenow-prod.fluidtopics.net/I_GiBPs4ZvTzHNyb1k_EFA)**   
  Classify a data subject type as vulnerable. When you mark a data subject type as vulnerable, the criticality score is calculated as High.
* **[Add key stakeholders and send privacy assessments](https://servicenow-prod.fluidtopics.net/a24ujrWHgBW64LPIqS8JrQ)**   
  Add key stakeholders to a processing activity to identify the key members who are responsible for processing the personal data within the processing activity. You can then send the respective privacy assessments to the stakeholders based on their responsibilities. For example, an entity owner is a key stakeholder for a processing activity.
* **[Add a regulatory agency](https://servicenow-prod.fluidtopics.net/TVdE2zeGeOTzqP66XX0jrg)**   
  Add a regulatory agency in the Privacy Workspace to identify the relevant regulatory authorities that are responsible for overseeing the industries or sectors within each jurisdiction. The jurisdictions consolidate all the regulatory communications via emails and implement the notification rules for data privacy or security breaches for the reported privacy cases.
* **[Create a lineage for a processing activity](https://servicenow-prod.fluidtopics.net/zUdIwthHqVEdzicEhKB19Q)**   
  Establish a lineage to visualize data consumption, sharing, and the associated risks for a processing activity. Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a lineage or hierarchy that tracks where personal data is shared.
* **[Create or manage a control on a processing activity](https://servicenow-prod.fluidtopics.net/2AYwSAJcxHPHane93PhO7A)**   
  Add new controls or manage the controls that are automatically added to the processing activity from the assessment responses. Adding controls ensures that the appropriate regulations are applied to the processing activity.
* **[Delete a control from a processing activity](https://servicenow-prod.fluidtopics.net/YximiroW3quq5hUusKBhxQ)**   
  Delete the controls that are no longer required in the processing activity.
* **[Create or manage risks on a processing activity](https://servicenow-prod.fluidtopics.net/LaAMJop9Ats0SPRAUM5GQQ)**   
  Add new risks or manage the risks that are automatically added to the processing activity from the assessment responses. Adding risks helps you manage processing activities using the risk-based approach.
* **[Manage chat collaborations of a processing activity](https://servicenow-prod.fluidtopics.net/yvLBrLVg_pvFwr0AbSHaWQ)**   
  Initiate quick discussions with key stakeholders while working on a processing activity, privacy case, or a personal data rights request. The chat feature is integrated with Microsoft Teams and a group is automatically created on Microsoft Teams when a discussion is initiated.
* **[Create or add issues on a processing activity](https://servicenow-prod.fluidtopics.net/X3cPVFRrwlepAtp7zYFhwg)**   
  Create issues or add existing issues for a processing activity. Associating issues to a processing activity helps you to identify and prioritize remediation actions. Relating issues reduces the number of issues customers need to manage, thus improving the overall organizational efficiency in management of these issues.
* **[Assign a processing activity to a key stakeholder](https://servicenow-prod.fluidtopics.net/juEGC2oGCvO0hAP0HFsdww)**   
  Assign a processing activity to the defined key stakeholders for the stakeholders to start working on the processing activity.
* **[Access control through organizational structure](https://servicenow-prod.fluidtopics.net/5hzNyAzdgwsjIJ9vEKYg5g)**   
  Describes how access to processing activity records can be restricted by using Entity-Based Access (EBA).

