---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Configure privacy breach assessment

# Configuring privacy breach assessment {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Follow the order of the steps such as creating breach factor types, breach factors, PI data element types, and PI data elements to configure privacy breach assessment.
* **[Create a breach factor type](https://www.servicenow.com/docs/4MghKKrlHIqm~9oLRQlctQ)**   
  Create categories to help responders to identify breach factors within specific categories. For example, incident nature is a breach factor type which has factors under it as Intentional and Malicious, or Intentional and not malicious, and Unintentional or inadvertent.
* **[Create breach factors](https://www.servicenow.com/docs/PE_svrFYMh99XR9v6RP9Xg)**   
  Create breach factors to help privacy teams understand the characteristics of a breach and evaluate the related risks. Exercise your flexibility to either use the default breach factors or generate new ones. Additionally, link breach factors to specific regions or implement them universally across multiple regions or selected ones.
* **[Create a PI data element type](https://www.servicenow.com/docs/LlXilxGQNeNhEamo8QBPvA)**   
  Create categories to help responders to identify personal data elements within specific categories. For example, for a PI data element type such as Personal information, the PI data elements can be Name, Age, Employer ID, Marital Status, Email, and so on.
* **[Create PI data elements](https://www.servicenow.com/docs/_PB8SmsiaMVdW0a4OIQmPA)**   
  Create PI data elements based on residents' personal information collected during the business process, such as phone numbers and email IDs. Use pre-configured elements or create new ones. Customize for data elements for specific regions or map a single PI data element to multiple regions.
* **[Create a region](https://www.servicenow.com/docs/KAKBVbpfi~VP_a~hG1KqLQ)**   
  Create geographic regions based on the data of the residents that is collected as a part of your business operations. Examples of regions are America, Europe, Asia Pacific, and so on.

