Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Mary Hain
Administrator

Privacy Management is the ServiceNow product you use to run the operational side of your privacy program on the ServiceNow AI Platform: your record of processing activities (RoPA), privacy assessments, personal data rights requests, privacy cases, and the obligations, policies, and controls behind them. You get the Privacy workspace, prebuilt assessment and regulatory content, and configurable workflows.  

Keep reading to find out more about what Privacy Management does and how to install it.  We also recommend that you visit Explore Privacy Management in the product documentation.

 

Use it to:

  • Maintain a record of processing activities (RoPA)
  • Document how personal data moves across systems, vendors, and business processes
  • Run privacy impact assessments (PIAs) and data protection impact assessments (DPIAs)
  • Intake and fulfill data subject access requests (DSARs) and other rights requests
  • Manage privacy obligations, policies, controls, and exceptions
  • Investigate privacy complaints and reported breaches
  • Track privacy risks and their remediation tasks

 

Deployment dependency. Privacy Management is a standalone product. You do not need any other Risk product to run it. If you also run Integrated Risk Management (IRM), Third-party Risk Management (TPRM), Business Continuity Management (BCM), or AI Control Tower (AICT), your privacy records relate to the same risks, controls, policies, issues, vendors, compliance requirements, and AI governance records you already manage there, thanks to the ServiceNow AI platform. 

 

What you can do with Privacy Management

The capabilities below are the workflows you get. You activate and configure each one independently, so you can start with one or two and add the rest later.

 

  1. Privacy compliance and governance

Use this to hold your privacy obligations, policies, standards, controls, and exceptions, and the mappings between regulations and the controls that satisfy them. Your changes are versioned, so you can show what a mapping looked like at a point in time.

 

The Privacy Content Accelerator imports prebuilt regulatory content, assessment templates, control objectives, and risk statements, so you do not author this content yourself. You get content for:

 

  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • Lei Geral de Proteção de Dados (LGPD)
  • Digital Personal Data Protection Act (DPDPA)
  • National Institute of Standards and Technology (NIST) Privacy Framework

Use it for: maintaining privacy policies and standards, mapping controls to regulations, tracking obligations, and processing regulatory change.

 

  1. Privacy data inventory and mapping

Use this to build and maintain your record of processing activities (RoPA). You relate each processing activity record to:

  • Systems and applications
  • Data categories
  • Business owners
  • Data subjects
  • Third parties and vendors
  • Data flows and transfers

 

Questions the inventory answers: what personal data you are processing, where it resides, who owns the process, which systems and vendors are involved, and how the data moves across your organization. You reuse the same records for assessments, investigations, audits, and regulatory reporting.

 

Use it for: building a RoPA, GDPR Article 30 documentation, privacy audits, data inventory work, and data governance programs.

 

  1. Privacy assessments

You get five assessment types out of the box: privacy screening assessments, PIAs, DPIAs, privacy risk assessments, and privacy breach assessments.

 

By default, you start with a screening assessment. When the responses meet the criteria you configure, the workflow routes the request into a full assessment. Your responses, findings, issues, and remediation tasks stay attached to the assessment record, so you keep the evidence trail for your next review or audit.

 

Your assessments run on the Smart Assessment Engine (SAE), which provides templates, workflows, question guidance, and the review experience. Enable it with the sn_privacy.enable_smart_assessment system property.

 

Start new implementations on the Privacy Screening Assessment [V4] and Privacy Impact Assessment [V4] templates; the [V3] templates are still available. Only published templates are available to send. A screening template has three sections: General (assessment category and targets), Questions (including data elements and the criticality factors that feed the criticality score), and Automations.

 

In Workflow Studio, you can build automation rules that create processing activities and apply risk statements and control objectives based on assessment responses. For example, a response indicating a data transfer outside the European Union (EU) can trigger the Data Transfer risk and assign Explicit Consent as the mitigating control. Copied automation rules remain in Draft until activated, while the impact assessment template requires you to create rules from scratch.

 

When reviewing an assessment, you can approve it or request revisions. You can also review its information objects, trace where the data comes from and where it goes under the Hierarchy tab, and view associated risk statements and control objectives under the Outcomes tab.

 

Trigger points: a new application, vendor, project, product launch, or business process that involves personal data; high-risk processing; regulatory assessment requirements.

 

  1. Personal data rights (PDR)

Use this to process DSARs and other rights requests: access, deletion, correction, portability, and jurisdiction-specific rights.

 

The workflow provides intake from internal and external request forms, requester validation, assignment of fulfillment tasks, due-date tracking, documentation of the actions you take, and an audit history of the request lifecycle. The external form accepts submissions from authorized agents and, beginning with the Australia release, can be configured to meet your needs.

 

Use it for: meeting regulatory response deadlines, tracking fulfillment across teams, and keeping audit records of each request.

 

  1. Privacy case management

Privacy Case Management handles your complaints, reported breaches, and other privacy issues. You get structured intake, and you can configure it to accept anonymous submissions.

 

Your case record holds investigation details, assigned tasks, evidence and documentation, remediation activities, and closure records. Because cases are platform task records, your privacy, legal, security, human resources (HR), and compliance teams work on the same case with their own assignments.

 

Use it for: privacy complaints, breach investigations, privacy incidents, corrective actions, and the documentation regulators ask for.

 

  1. Employee Center integration

Your employees are usually the first to know about a new processing activity or a privacy concern. Integrating Privacy Management with Employee Center publishes intake items so they can submit new processing activities, request a privacy review, complete assessments, and report privacy concerns. Their submissions land as records in the matching Privacy Management workflow instead of in your shared mailbox.

 

  1. AI capabilities

ServiceNow Otto for Privacy Management adds AI to the privacy workflows you already run:

  • Assessment summarization
  • Privacy issue summarization
  • Control rationalization recommendations
  • Risk and control recommendations

You can also build your own AI agents and flows against your privacy records. Which AI features you get depends on the Privacy Management edition you license.

 

Roles in Privacy Management

These are the users the out-of-the-box workflows and workspace are built around. Confirm the role assignments you need for your instance in the configuration checklist.

 

User

What they do in the product

Privacy Manager

Owns privacy policies, obligations, controls, assessments, risks, and program reporting

Privacy Analyst

Runs assessments, maintains processing activities, works on issues, and monitors compliance activity

Privacy Case Analyst

Investigates complaints, breaches, and reported privacy incidents

Personal Data Rights Agent

Processes DSARs and coordinates fulfillment tasks to the due date

Business owners

Maintain their processing activity records, answer assessments, and respond to privacy reviews

Risk and compliance teams

Reconcile privacy risks, controls, issues, and regulatory requirements with the wider governance, risk, and compliance (GRC) program

AI governance teams

Review privacy considerations for AI systems and use cases

 

Because your teams work on one platform, they share tasks, records, approvals, and reporting instead of passing spreadsheets back and forth.

 

Where Most Privacy Teams Start

You don’t need to activate everything at once. Pick the workflow that matches the problem you are trying to solve first.

 

If you need to…

Start with…

Replace spreadsheet-based processing activity inventories

Privacy data inventory and mapping

Build a record of processing activities (RoPA)

Privacy data inventory and mapping

Standardize privacy impact assessments

Privacy assessments

Manage data subject access requests (DSARs)

Personal data rights

Investigate privacy incidents and complaints

Privacy case management

 

Go deeper: product and implementation guidance. Start with the Privacy Management product documentation for capability and configuration detail. For implementation sequencing, see the Privacy Management best practices success pack, which provides the methodology and prescriptive steps for standing up the product.

 

How you can use Privacy Mgmt. with other ServiceNow Risk products

Privacy Management runs on the same platform and data model as the other Risk products, so you relate your privacy records directly to the risks, controls, policies, vendors, and business services you already hold in those products. Each pairing below is optional.

 

Product

What it is

How Privacy Management works with it

Integrated Risk Management (IRM)

Enterprise GRC: risks, controls, policies, obligations, issues, and audit across the business

Manage privacy risks, controls, obligations, and issues in your wider GRC. Relate privacy assessments, risks, issues, controls, and obligations to records you already manage in IRM. Map privacy obligations and controls into your compliance framework to reduce duplicate control testing and accelerate regulatory change. You can also embed privacy reviews and approvals into business workflows, creating privacy checkpoints before new systems, vendors, and processes go live.

Third-party Risk Management (TPRM)

Vendor and third-party risk: vendor records, tiering, assessments, and ongoing monitoring

Extend your third-party reviews to include privacy requirements. Assess each vendor’s privacy risk and document the processing activities and personal data categories you share with them. Your RoPA identifies the personal data each vendor handles, while your TPRM records show you where personal data sits outside your organization.

Business Continuity Management (BCM)

Continuity and recovery: critical services, service dependencies, and continuity plans

Identify privacy impacts during disruption and recovery. Your RoPA supplies the business processes, applications, third parties, and data flows that underpin your critical services, enriching your dependency mapping. You then record privacy recovery requirements in your continuity plans, so privacy obligations are covered during outages and recovery.

AI Control Tower (AICT)

AI governance: inventory of AI systems and use cases, plus AI-specific risks and controls

Assess AI use cases that process personal data. AICT inventories your AI systems and manages AI-specific risks and controls. Privacy Management runs the PIAs, DPIAs, and privacy risk assessments for those systems. IRM holds the resulting AI and privacy risks in your enterprise risk program.

 

Release Updates

You will find the full details in the Privacy Management release notes—select your release from the version picker at the top of the page.

 

Brazil (Q3 2026)

  • Record data transfers on processing activities – document cross-border and internal data flows.
  • AI Reviewer Assist – AI-assisted review of privacy records and assessments.
  • Modernized issue management, consistent with the rest of the Risk portfolio – updated issue workflows and user experience.
  • AI Data Explorer – query enterprise data in natural language and receive an analysis without building a report.
  • PDR intake form update  - multilingual support for internal and external PDR intake forms.

 

Australia (Q2 2026)

  • Configurable external-facing personal data rights form – customizable intake experience for rights requests.
  • Stakeholder editing of processing activities – business users can maintain RoPA records directly.
  • New privacy content for the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (CDPA), and the India Digital Personal Data Protection Act (DPDPA) - pre-built regulatory mappings, controls, and assessment content.
  • Template versioning for Privacy Management and Privacy Case Management – track and manage changes to templates over time

 

Resources to Get Started

 

Get started with courses in ServiceNow University

  • What is ServiceNow Privacy Management?—foundational course on the product, its key features, and how you manage privacy risk across the enterprise
  • GRC: Privacy Management (PRM) Essentials—hands-on course for implementers and process users: navigating the core capabilities, applying privacy by design and data minimization, running smart assessments, and configuring the workflows and dashboards behind privacy compliance and personal data rights

 

Frequently Asked Questions

Q: How do you get content updates when regulations change or a new one takes effect?

A: ServiceNow updates the Privacy Content Accelerator as regulations change and new ones are introduced. You import the updated packages—regulatory mappings, assessment templates, control objectives, and risk statements—rather than authoring them yourself. Recent additions include CPA (Colorado), CDPA (Virginia), and DPDPA (India), shipped in the Australia release.

 

Q: What does the AI in Privacy Management actually do?

A: It summarizes your privacy assessments and issues, recommends control objectives for consolidation, identifies control rationalization of candidates, and suggests risk statements and control objectives based on your existing risk and control data. You can also build custom agents against your privacy records. What you get varies by edition—check the Privacy Management packages page for your edition.

 

Ready to configure? Start with the Privacy Management configuration checklist.

Version history
Last update:
an hour ago
Updated by: