- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
an hour ago
Privacy Management is the ServiceNow product you use to run the operational side of your privacy program on the ServiceNow AI Platform: your record of processing activities (RoPA), privacy assessments, personal data rights requests, privacy cases, and the obligations, policies, and controls behind them. You get the Privacy workspace, prebuilt assessment and regulatory content, and configurable workflows.
Keep reading to find out more about what Privacy Management does and how to install it. We also recommend that you visit Explore Privacy Management in the product documentation.
Use it to:
- Maintain a record of processing activities (RoPA)
- Document how personal data moves across systems, vendors, and business processes
- Run privacy impact assessments (PIAs) and data protection impact assessments (DPIAs)
- Intake and fulfill data subject access requests (DSARs) and other rights requests
- Manage privacy obligations, policies, controls, and exceptions
- Investigate privacy complaints and reported breaches
- Track privacy risks and their remediation tasks
Deployment dependency. Privacy Management is a standalone product. You do not need any other Risk product to run it. If you also run Integrated Risk Management (IRM), Third-party Risk Management (TPRM), Business Continuity Management (BCM), or AI Control Tower (AICT), your privacy records relate to the same risks, controls, policies, issues, vendors, compliance requirements, and AI governance records you already manage there, thanks to the ServiceNow AI platform.
What you can do with Privacy Management
The capabilities below are the workflows you get. You activate and configure each one independently, so you can start with one or two and add the rest later.
- Privacy compliance and governance
Use this to hold your privacy obligations, policies, standards, controls, and exceptions, and the mappings between regulations and the controls that satisfy them. Your changes are versioned, so you can show what a mapping looked like at a point in time.
The Privacy Content Accelerator imports prebuilt regulatory content, assessment templates, control objectives, and risk statements, so you do not author this content yourself. You get content for:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Lei Geral de Proteção de Dados (LGPD)
- Digital Personal Data Protection Act (DPDPA)
- National Institute of Standards and Technology (NIST) Privacy Framework
Use it for: maintaining privacy policies and standards, mapping controls to regulations, tracking obligations, and processing regulatory change.
- Privacy data inventory and mapping
Use this to build and maintain your record of processing activities (RoPA). You relate each processing activity record to:
- Systems and applications
- Data categories
- Business owners
- Data subjects
- Third parties and vendors
- Data flows and transfers
Questions the inventory answers: what personal data you are processing, where it resides, who owns the process, which systems and vendors are involved, and how the data moves across your organization. You reuse the same records for assessments, investigations, audits, and regulatory reporting.
Use it for: building a RoPA, GDPR Article 30 documentation, privacy audits, data inventory work, and data governance programs.
- Privacy assessments
You get five assessment types out of the box: privacy screening assessments, PIAs, DPIAs, privacy risk assessments, and privacy breach assessments.
By default, you start with a screening assessment. When the responses meet the criteria you configure, the workflow routes the request into a full assessment. Your responses, findings, issues, and remediation tasks stay attached to the assessment record, so you keep the evidence trail for your next review or audit.
Your assessments run on the Smart Assessment Engine (SAE), which provides templates, workflows, question guidance, and the review experience. Enable it with the sn_privacy.enable_smart_assessment system property.
Start new implementations on the Privacy Screening Assessment [V4] and Privacy Impact Assessment [V4] templates; the [V3] templates are still available. Only published templates are available to send. A screening template has three sections: General (assessment category and targets), Questions (including data elements and the criticality factors that feed the criticality score), and Automations.
In Workflow Studio, you can build automation rules that create processing activities and apply risk statements and control objectives based on assessment responses. For example, a response indicating a data transfer outside the European Union (EU) can trigger the Data Transfer risk and assign Explicit Consent as the mitigating control. Copied automation rules remain in Draft until activated, while the impact assessment template requires you to create rules from scratch.
When reviewing an assessment, you can approve it or request revisions. You can also review its information objects, trace where the data comes from and where it goes under the Hierarchy tab, and view associated risk statements and control objectives under the Outcomes tab.
Trigger points: a new application, vendor, project, product launch, or business process that involves personal data; high-risk processing; regulatory assessment requirements.
- Personal data rights (PDR)
Use this to process DSARs and other rights requests: access, deletion, correction, portability, and jurisdiction-specific rights.
The workflow provides intake from internal and external request forms, requester validation, assignment of fulfillment tasks, due-date tracking, documentation of the actions you take, and an audit history of the request lifecycle. The external form accepts submissions from authorized agents and, beginning with the Australia release, can be configured to meet your needs.
Use it for: meeting regulatory response deadlines, tracking fulfillment across teams, and keeping audit records of each request.
- Privacy case management
Privacy Case Management handles your complaints, reported breaches, and other privacy issues. You get structured intake, and you can configure it to accept anonymous submissions.
Your case record holds investigation details, assigned tasks, evidence and documentation, remediation activities, and closure records. Because cases are platform task records, your privacy, legal, security, human resources (HR), and compliance teams work on the same case with their own assignments.
Use it for: privacy complaints, breach investigations, privacy incidents, corrective actions, and the documentation regulators ask for.
- Employee Center integration
Your employees are usually the first to know about a new processing activity or a privacy concern. Integrating Privacy Management with Employee Center publishes intake items so they can submit new processing activities, request a privacy review, complete assessments, and report privacy concerns. Their submissions land as records in the matching Privacy Management workflow instead of in your shared mailbox.
- AI capabilities
ServiceNow Otto for Privacy Management adds AI to the privacy workflows you already run:
- Assessment summarization
- Privacy issue summarization
- Control rationalization recommendations
- Risk and control recommendations
You can also build your own AI agents and flows against your privacy records. Which AI features you get depends on the Privacy Management edition you license.
Roles in Privacy Management
These are the users the out-of-the-box workflows and workspace are built around. Confirm the role assignments you need for your instance in the configuration checklist.
|
User |
What they do in the product |
|
Privacy Manager |
Owns privacy policies, obligations, controls, assessments, risks, and program reporting |
|
Privacy Analyst |
Runs assessments, maintains processing activities, works on issues, and monitors compliance activity |
|
Privacy Case Analyst |
Investigates complaints, breaches, and reported privacy incidents |
|
Personal Data Rights Agent |
Processes DSARs and coordinates fulfillment tasks to the due date |
|
Business owners |
Maintain their processing activity records, answer assessments, and respond to privacy reviews |
|
Risk and compliance teams |
Reconcile privacy risks, controls, issues, and regulatory requirements with the wider governance, risk, and compliance (GRC) program |
|
AI governance teams |
Review privacy considerations for AI systems and use cases |
Because your teams work on one platform, they share tasks, records, approvals, and reporting instead of passing spreadsheets back and forth.
Where Most Privacy Teams Start
You don’t need to activate everything at once. Pick the workflow that matches the problem you are trying to solve first.
|
If you need to… |
Start with… |
|
Replace spreadsheet-based processing activity inventories |
Privacy data inventory and mapping |
|
Build a record of processing activities (RoPA) |
Privacy data inventory and mapping |
|
Standardize privacy impact assessments |
Privacy assessments |
|
Manage data subject access requests (DSARs) |
Personal data rights |
|
Investigate privacy incidents and complaints |
Privacy case management |
Go deeper: product and implementation guidance. Start with the Privacy Management product documentation for capability and configuration detail. For implementation sequencing, see the Privacy Management best practices success pack, which provides the methodology and prescriptive steps for standing up the product.
How you can use Privacy Mgmt. with other ServiceNow Risk products
Privacy Management runs on the same platform and data model as the other Risk products, so you relate your privacy records directly to the risks, controls, policies, vendors, and business services you already hold in those products. Each pairing below is optional.
|
Product |
What it is |
How Privacy Management works with it |
|
Enterprise GRC: risks, controls, policies, obligations, issues, and audit across the business |
Manage privacy risks, controls, obligations, and issues in your wider GRC. Relate privacy assessments, risks, issues, controls, and obligations to records you already manage in IRM. Map privacy obligations and controls into your compliance framework to reduce duplicate control testing and accelerate regulatory change. You can also embed privacy reviews and approvals into business workflows, creating privacy checkpoints before new systems, vendors, and processes go live. |
|
|
Vendor and third-party risk: vendor records, tiering, assessments, and ongoing monitoring |
Extend your third-party reviews to include privacy requirements. Assess each vendor’s privacy risk and document the processing activities and personal data categories you share with them. Your RoPA identifies the personal data each vendor handles, while your TPRM records show you where personal data sits outside your organization. |
|
|
Continuity and recovery: critical services, service dependencies, and continuity plans |
Identify privacy impacts during disruption and recovery. Your RoPA supplies the business processes, applications, third parties, and data flows that underpin your critical services, enriching your dependency mapping. You then record privacy recovery requirements in your continuity plans, so privacy obligations are covered during outages and recovery. |
|
|
AI governance: inventory of AI systems and use cases, plus AI-specific risks and controls |
Assess AI use cases that process personal data. AICT inventories your AI systems and manages AI-specific risks and controls. Privacy Management runs the PIAs, DPIAs, and privacy risk assessments for those systems. IRM holds the resulting AI and privacy risks in your enterprise risk program. |
Release Updates
You will find the full details in the Privacy Management release notes—select your release from the version picker at the top of the page.
Brazil (Q3 2026)
- Record data transfers on processing activities – document cross-border and internal data flows.
- AI Reviewer Assist – AI-assisted review of privacy records and assessments.
- Modernized issue management, consistent with the rest of the Risk portfolio – updated issue workflows and user experience.
- AI Data Explorer – query enterprise data in natural language and receive an analysis without building a report.
- PDR intake form update - multilingual support for internal and external PDR intake forms.
Australia (Q2 2026)
- Configurable external-facing personal data rights form – customizable intake experience for rights requests.
- Stakeholder editing of processing activities – business users can maintain RoPA records directly.
- New privacy content for the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (CDPA), and the India Digital Personal Data Protection Act (DPDPA) - pre-built regulatory mappings, controls, and assessment content.
- Template versioning for Privacy Management and Privacy Case Management – track and manage changes to templates over time
Resources to Get Started
- Privacy Management product documentation—capabilities, workflows, and feature reference
- Explore Privacy Management—how privacy managers, users, and administrators work in the product
- Configuration checklist—activation, roles, and setup order
- Privacy Management release notes – Australia—what's new and changed in the Australia (Q1 2026) release
- Privacy Management success pack—prescriptive implementation guidance
- Privacy Management product page—capability overview and use cases
Get started with courses in ServiceNow University
- What is ServiceNow Privacy Management?—foundational course on the product, its key features, and how you manage privacy risk across the enterprise
- GRC: Privacy Management (PRM) Essentials—hands-on course for implementers and process users: navigating the core capabilities, applying privacy by design and data minimization, running smart assessments, and configuring the workflows and dashboards behind privacy compliance and personal data rights
Frequently Asked Questions
Q: How do you get content updates when regulations change or a new one takes effect?
A: ServiceNow updates the Privacy Content Accelerator as regulations change and new ones are introduced. You import the updated packages—regulatory mappings, assessment templates, control objectives, and risk statements—rather than authoring them yourself. Recent additions include CPA (Colorado), CDPA (Virginia), and DPDPA (India), shipped in the Australia release.
Q: What does the AI in Privacy Management actually do?
A: It summarizes your privacy assessments and issues, recommends control objectives for consolidation, identifies control rationalization of candidates, and suggests risk statements and control objectives based on your existing risk and control data. You can also build custom agents against your privacy records. What you get varies by edition—check the Privacy Management packages page for your edition.
Ready to configure? Start with the Privacy Management configuration checklist.
