---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Elements of a privacy breach assessment

# Elements of a privacy breach assessment {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Elements of a Privacy Breach Assessment

A privacy breach assessment is a critical process that helps organizations understand and manage the exposure of personally identifiable information (PI) during a breach.
For ServiceNow customers, conducting a thorough assessment ensures compliance with relevant jurisdictional laws and enables appropriate mitigation strategies.
Show full answer Show less  

## Key Features

* **Jurisdiction Identification:** The assessment must specify the jurisdiction where the breach occurred. This is essential because privacy and data protection laws vary by region, and compliance depends on applying the correct legal framework. For example, breaches in California require adherence to California-specific regulations.
* **PI Artifacts Specification:** PI artifacts refer to the forms in which personally identifiable information exists and may be compromised. These can be verbal (spoken/recorded), visual (printed/displayed), electronic (stored digitally), or paper-based (physical documents). Each artifact captures detailed information about the breach, including incident nature, description, recipient details, and risk mitigation plans.
* **Data Elements Identification:** Within each PI artifact, specific data elements impacted by the breach must be identified. Examples include contact information, medical records, financial data, and other personal details. Recognizing the affected data elements helps in assessing risk and guiding appropriate responses.
* **Region-Specific Data Collection:** Because jurisdictions may be divided into states or regions with unique laws, the assessment collects data relevant to each impacted area, including the number of affected individuals.

## Key Outcomes

By accurately defining the breach jurisdiction, specifying PI artifacts, and identifying compromised data elements, ServiceNow customers can:

* Ensure compliance with relevant privacy laws and data protection regulations specific to the breach location.
* Understand the scope and nature of the breach to inform effective risk mitigation and incident response.
* Document detailed breach information to support regulatory reporting and communication with affected parties.  
A privacy breach assessment must clearly indicate the jurisdiction in which the breach occurred. This is crucial because each jurisdiction operates under distinct laws and regulations pertaining to privacy and data protection.
It must also specify the personally identifiable information (PI) artifacts.

## PI Artifact {#elements-of-a-privacy-breach-assessment__section_m4t_ybn_m1c}

PI artifacts typically refer to the physical or digital forms of personally identifiable information that may be lost or stolen. These artifacts can include verbal (spoken or recorded), visual (printed or displayed), electronic (stored on devices or systems), or paper-based (documents or records) forms of data that contain personal information. A PI artifact contains details such as the nature of the incident, the description of the compromise, the recipient's details, the risk mitigation plan, and so on. Each PI artifact collects data for a particular region and category. The following image shows the information that is collected using the PI artifact form. Figure 1. PI artifact form  
A PI artifact consists of the following.

* Data elements: Data elements are specific pieces of information that are part of a larger dataset. In the context of a breach incident, data elements refer to the specific types or categories of data that are impacted or compromised. Examples of data elements can include contact information (such as names, addresses, phone numbers, or email addresses), medical information (such as medical history, diagnoses, or treatment records), financial information (such as credit card numbers, bank account details, or transaction records), and so on.

  When a breach incident occurs, it is important to identify and assess which data elements have been affected or exposed.
  This helps in understanding the potential risks and impacts of the breach, as well as determining the appropriate response and mitigation measures to protect the affected individuals and their data.
  Figure 2. Data elements form
* Jurisdiction: A picture of the items on the data elements form such as personal, medical, and financial information.To comply with the varying laws and regulations, it is necessary to identify the specific jurisdictions impacted during a breach assessment. Countries are typically divided into multiple states or regions, each governed by its own set of laws. For instance, within the United States of America, California is considered a jurisdiction with its own governing laws. Therefore, when a breach occurs in California, the applicable laws and regulations specific to California are applied. Jurisdictions also provide important details, such as the number of individuals impacted within that specific region.
{#elements-of-a-privacy-breach-assessment__ul_asr_35f_41c}

