---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Information objects

# Information objects in Privacy Management {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The purpose of an information object is to logically describe the type of data that is exchanged between an application and a database.

To determine which information objects process personal data, you can classify the information objects as Personal information. For more details on how to classify an information object, see [Classify information objects as personal information](https://www.servicenow.com/docs/6vP1tWN1jWZbiRjFQYr4Vw "Categorize information objects as personal information. Only information objects classified as personal information can be associated with the processing activities.").  
After the information objects are created, they are mapped to business applications or business processes. This activity helps the privacy management teams to discover the information objects processing personal data. Some examples of \[PI\] Information objects in Privacy Management are:

* Email addresses
* Bank account numbers
* Educational details
* Personal email address
{#information-object-in-privacy__ul_l2d_hjx_jqb}

## Creation of information object categories {#information-object-in-privacy__section_htj_mtv_12c}

Information object categories provide a systematic way to classify information objects, making it easier to align with regulatory requirements. For instance, regulators often group attributes like iris scans and fingerprints
under the category of biometric data. Similarly, email addresses and phone numbers are commonly categorized as contact information. While regulators focus on these broad classifications, business users typically refer to the
individual data elements rather than the overarching category. In such scenarios, information object categories serve as a framework to organize and classify these data elements into their respective broader categories.

Also, if the regulators identify a new data element for a certain category, then the privacy administrator simply needs to add the data element to the data category and all the assessments are refreshed. This ability helps save
time and you do not have to manually add the new information objects to the assessments. For information on how to configure information object categories, see [Configure information object categories](https://www.servicenow.com/docs/QsNPX6qZswvBdF3HV_863w "Configure information object categories to classify information objects effectively. For example, attributes like iris scans and fingerprints are often referred to as biometric data, or email addresses and phone numbers can be grouped as contact information. Information object categories enable you to categorize these information objects under these broader classifications.").

You can create information objects manually. See [Create an information object](https://www.servicenow.com/docs/l_3_2bVmBPXEROAGWFh2eQ "Create information objects manually to associate the right data subject types with business processes or applications.").

