Using Privacy Management
As a privacy analyst or a privacy manager, you can identify which business applications or processes store and use personal information.
- Entity scoping to plan a privacy program
When a privacy manager plans the privacy program for an organization, the first step is to scope those business applications or processes that contain personal data. In Governance, Risk, and Compliance, these business applications or business processes are called as entities. After you identify the entities processing personal data, the processing activities are automatically created. - Types of privacy assessments
Privacy assessments can be sent using various methods such as entities, entity types, and processing activities. - Create a Risk Assessment Methodology
Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization. - Respond to a privacy smart assessment
Respond to either a screening assessment or an impact assessment from the Assessment Workspace. The assessment results help to understand the potential privacy risks and their mitigation measures. - Respond to a privacy screening assessment
As an entity owner or a processing activity key stakeholder, respond to the privacy assessment that is initiated by the privacy lead. - Review a privacy assessment
As a privacy analyst, review a privacy assessment after the responders submit the assessment. You can either close the assessment after a review or you can also request for revision if you determine that the assessment requires more information. - Create or update a processing activity
Manually create a processing activity or update a processing activity that is automatically created out of a privacy screening assessment. You can also update a processing activity that is created from an entity record. When you update a processing activity, you can fill in the relevant details about the personal data that is being processed. - Create or manage an information object within a processing activity
Add information objects to the processing activity after a processing activity is created. Adding information objects helps you understand the types of personal information that is being processed and the way it is processed. This task helps in applying the appropriate controls to the processing activity. - Add data subject type to a processing activity
Add data subject types to a processing activity in the Privacy Workspace. - Add data subject type to privacy impact assessment
Add data subject types to privacy impact assessment from the Employee Center. - Classify data subject type as vulnerable
Classify a data subject type as vulnerable. When you mark a data subject type as vulnerable, the criticality score is calculated as High. - Add key stakeholders to a processing activity
Add key stakeholders to a processing activity. Based on their role, users are assigned default processing activity privileges that control whether they can edit a processing activity, view it, or respond to its privacy assessments. - Enable key stakeholders to update processing activities directly
Enable stakeholders to update processing activities directly from the Employee Center by assigning the activity to them. - Edit a processing activity from the Employee Center
Access a processing activity directly from the Employee Center and request edit access to update the details your team is responsible for. - Add a regulatory agency
Add a regulatory agency in the Privacy Workspace to identify the relevant regulatory authorities that are responsible for overseeing the industries or sectors within each jurisdiction. The jurisdictions consolidate all the regulatory communications via emails and implement the notification rules for data privacy or security breaches for the reported privacy cases. - Create a lineage for a processing activity
Establish a lineage to visualize data consumption, sharing, and the associated risks for a processing activity. Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a lineage or hierarchy that tracks where personal data is shared. - Create or manage a control on a processing activity
Add new controls or manage the controls that are automatically added to the processing activity from the assessment responses. Adding controls ensures that the appropriate regulations are applied to the processing activity. - Delete a control from a processing activity
Delete the controls that are no longer required in the processing activity. - Create or manage risks on a processing activity
Add new risks or manage the risks that are automatically added to the processing activity from the assessment responses. Adding risks helps you manage processing activities using the risk-based approach. - Manage chat collaborations of a processing activity
Initiate quick discussions with key stakeholders while working on a processing activity, privacy case, or a personal data rights request. The chat feature is integrated with Microsoft Teams and a group is automatically created on Microsoft Teams when a discussion is initiated. - Create or add issues on a processing activity
Create issues or add existing issues for a processing activity. Associating issues to a processing activity helps you to identify and prioritize remediation actions. Relating issues reduces the number of issues customers need to manage, thus improving the overall organizational efficiency in management of these issues. - Accessing control through organizational structure
Access to processing activity records can be restricted by using Entity-Based Access (EBA).
Parent Topic:Privacy Management