---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Access control by legal entity

# Accessing
control through organizational structure {#ariaid-title1}

* Release version: Zurich
* 
* Updated November 27, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Access
to
processing activity records can be restricted by using Entity-Based Access (EBA).
User access to processing activity records and related data can be restricted based on an organizational structure. This structure may reflect a legal entity, jurisdiction, business unit, or any segmentation aligned with how your
privacy teams operate. This approach enables granular security and supports regulatory compliance for organizations functioning across multiple regions or subsidiaries.

Entity-Based Access (EBA) implements this control by enforcing data segregation according to the defined organizational structure. With EBA, users can only view and manage records for the entities or jurisdictions to which they have
been explicitly granted access. Records outside this defined scope remain hidden.

## Key characteristics {#access-control-by-legal-entity__section_j3f_3hf_lhc}

* Dynamic segmentation: Access can be assigned based on the organizational structure, such as legal entity, jurisdiction, business unit, or any defined grouping. So processing activity records are only visible to the appropriate teams.
* Regulatory alignment: Access controls can be mapped to organizational structures, helping organizations meet local regulatory requirements and maintain clear audit trails.

{#access-control-by-legal-entity__ul_nzg_khf_lhc}

For information about configuring access control, see [Configuring access control](https://www.servicenow.com/docs/dhUVn3O06oh_UVQeuFGtcg "Configurie Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.").

## UI impact {#access-control-by-legal-entity__section_jjg_mtm_lhc}

* Processing activity details: Hidden for records outside the user's scope.
* Data lineage: Information for inaccessible entities is hidden, and navigation buttons on the side panel are disabled.
* Reports and dashboards: Visibility in reports such as processing activity, risk scan, and compliance is filtered based on entity configuration.
{#access-control-by-legal-entity__ul_hnj_dfn_lhc}

## Role capabilities {#access-control-by-legal-entity__section_a3z_g5m_lhc}

{#access-control-by-legal-entity__table_gyj_m5m_lhc__entry__2}

| Role | Capabilities |
|-|-|
| Privacy admin | * Create entity configurations * Perform bulk access updates {#access-control-by-legal-entity__ul_upz_p5m_lhc} |
| Privacy manager | View entity configurations |
| Privacy analyst | Access records for configured entities and their associated downstream entities |
| Privacy business user | Access records for configured entities and their associated downstream entities |
[Table 1. Role capabilities]

{#access-control-by-legal-entity__table_gyj_m5m_lhc}  
Note:  
Assigned roles such as assignee, reviewer, and analyst retain access to their assigned records even if those records fall outside the configured entity.
* **[Configuring access control](https://www.servicenow.com/docs/dhUVn3O06oh_UVQeuFGtcg)**   
  Configurie Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.

