Workflow of a processing activity
Summarize
Summary of Workflow of a processing activity
The processing activity workflow in ServiceNow enables privacy analysts and managers to manage the complete life cycle of a processing activity related to privacy compliance. It helps track the status, apply controls, and ensure continuous monitoring of processing activities involving personal information.
Show less
Workflow Stages and Their Functions
- New: This initial state allows privacy managers or analysts to create and define a processing activity manually. Key fields such as Name, Justification, Privacy Analyst, and Entity are editable. Once saved with an entity, the activity can move to the Discover state.
- Discover: In this state, the owner collects detailed information about the processing activity by sending privacy assessments. Based on responses, they update details, assign key stakeholders (with the snprivacy.businessuser role), and apply or adjust controls to ensure proper compliance measures. The activity then progresses to Review.
- Review: The privacy manager or analyst reviews compliance posture by sending control attestations and examining any issues from non-compliant controls. They update details, associate information objects, and adjust controls as needed. This step ensures the processing activity meets compliance requirements.
- Monitor: This stage supports continuous monitoring of the processing activity using indicator functionality. It allows automatic control checks, issue creation, and tracking. If new privacy assessments are sent during this state, the activity automatically moves back to Discover for re-evaluation. The activity can also be moved back to Discover or Review manually based on updates.
- Retire: When a business application or process is no longer in use, the processing activity moves to Retire. All associated controls are retired, and no further updates can be made. If the related entity is inactivated, the processing activity automatically retires.
Key Considerations for ServiceNow Customers
- Only privacy managers or analysts who own the processing activity can edit it; others have view-only access.
- Assigning key stakeholders requires users to have the snprivacy.businessuser role.
- The workflow ensures structured privacy compliance management, from creation through continuous monitoring to retirement.
- Automated transitions based on assessment submissions streamline compliance updates and monitoring.
A processing activity workflow helps the privacy analysts to manage the life cycle of a processing activity.
New
- Name
- Justification
- Privacy analyst
- Entity: Only when this field is filled, and the processing activity form is saved. After saving the form, the privacy manager or a privacy analyst can move the processing activity the Discover state.
Discover
- Send privacy assessments.
- Update the processing activity Details section based on the assessment responses.
- Assign the processing activity to one of the key stakeholders for the key stakeholders to
update the details, the PI-tagged information objects, and the key
stakeholders.Note:You can assign the processing activity to those users who have the sn_privacy.business_user role.
- Review the controls applied based on the privacy assessment responses.
- Add or remove additional controls as necessary.
Review
- Update the processing activity Details section based on the assessment responses.
- Associate information objects and capture additional details related to the information objects based on the assessment responses.
- Review the controls applied automatically based on the privacy assessment responses, and add or remove additional controls as necessary.
- Send control attestations and track issues and policy exceptions.
Monitor
- Auto execution of indicator functionality to continuously monitor controls associated with processing activity.
- Create, manage issues, and track issues.
Retire
This is a state to retire the processing activity when the respective business application or business process is no longer used in the organization. When moved to this state, all the controls associated with the processing activity are retired. The privacy team cannot make any updates to a processing activity in the retired state. When an entity gets inactivated, the related processing activity is also automatically moved to the Retired state.