Skip to content

Commit e8d566d

Browse files
authored
Merge pull request #49007 from MicrosoftDocs/NEW-priva-privacy-assessment
New priva privacy assessment
2 parents fad7e0b + b98bf46 commit e8d566d

20 files changed

+656
-0
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-privacy-assessments.configure-metamodel-register-assets
3+
title: Configure the metamodel and register assets
4+
metadata:
5+
title: Configure the metamodel and register assets
6+
description: "Configure the metamodel and register assets."
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/configure-metamodel-register-assets.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-privacy-assessments.create-manage-privacy-assessments
3+
title: Create and manage privacy assessments
4+
metadata:
5+
title: Create and manage privacy assessments
6+
description: "Create and manage privacy assessments."
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 10
14+
content: |
15+
[!include[](includes/create-manage-privacy-assessments.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-privacy-assessments.create-privacy-rules
3+
title: Create and manage privacy assessments
4+
metadata:
5+
title: Create and manage privacy assessments
6+
description: "Create and manage privacy assessments."
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 10
14+
content: |
15+
[!include[](includes/create-privacy-rules.md)]
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
Before assigning privacy assessments (preview), organizations need a way to define and structure the data assets they evaluate. Privacy assessments are typically assigned to business assets, such as projects or business processes, rather than individual datasets like a database or table. These business assets provide context about how data is used across an organization.
2+
3+
Microsoft Purview's metamodel helps organizations represent business assets in a structured way. By defining business assets and their relationships to physical data in the Microsoft Purview Unified Catalog, organizations ensure privacy assessments evaluate data usage within the correct context.
4+
5+
## Why configure the metamodel?
6+
7+
Privacy assessments evaluate whether personal data is being used appropriately in business operations. Instead of assessing individual datasets, organizations assess how data is used within broader processes like projects, applications, or business workflows.
8+
9+
Configuring the metamodel allows organizations to:
10+
11+
- **Define business assets** that represent data use cases, such as projects or business processes.
12+
- **Establish relationships** between business assets and physical data assets, ensuring assessments reflect real-world data usage.
13+
- **Ensure privacy assessments align** with business functions rather than focusing solely on technical data storage.
14+
15+
Teams responsible for curating data usage, such as business owners, compliance officers, or technical stakeholders—are typically involved in configuring the metamodel.
16+
17+
## What is the metamodel?
18+
19+
The metamodel is a feature in Microsoft Purview that enables organizations to represent logical business concepts, such as projects or business processes, and relate them to actual data assets. These relationships help organizations evaluate how personal data is used in different business contexts.
20+
21+
Organizations can use predefined asset types or create custom ones based on their needs. Examples of asset relationships in the metamodel include:
22+
23+
- **An organization asset** _has_ a department asset.
24+
- **A department asset** _owns_ a business process.
25+
- **A project or system asset** _uses_ a database or has a dataset, creating a relationship between business and physical data assets.
26+
27+
By defining these relationships, privacy assessments can evaluate data usage within a specific business process rather than looking at datasets in isolation.
28+
29+
## Prerequisites
30+
31+
Before configuring the metamodel and registering assets, ensure that your organization has access to the Microsoft Purview Data Map. Privacy Assessments rely on the Data Map to track relationships between business and physical data assets.
32+
33+
## Register an asset
34+
35+
To assign an asset to a privacy assessment, it must first be registered in Privacy Assessments. Follow these steps:
36+
37+
1. In **Privacy Assessments**, navigate to the **Assessment management** page.
38+
1. On the **Assets** tab, select **Register asset**.
39+
1. At **Asset type**, the default is **Project**. You can keep this selection or choose a different asset type from the dropdown.
40+
1. Enter a **Name** and an optional **Description**.
41+
1. In the **Contacts** section, assign the appropriate owner to ensure they receive notifications about assessment activity, such as assignment, approval, or decline.
42+
1. Select **Create**.
43+
44+
Once an asset is created, its details page displays privacy-related information. Any privacy assessments assigned to the asset will be listed under the **Privacy** section.
45+
46+
Organizations can also create logical business assets directly in Microsoft Purview Data Map and Unified Catalog, which allows for more advanced customization.
47+
48+
With assets registered, organizations can now assign privacy assessments to track data usage in business operations.
49+
50+
## Legal disclaimer
51+
52+
[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true)
Lines changed: 166 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,166 @@
1+
Privacy assessments (preview) help organizations document and evaluate how personal data is used across business processes. A structured approach ensures consistency in data collection, supports privacy risk evaluation, and helps organizations track compliance.
2+
3+
Organizations can create assessments from templates or customize them to capture specific details about data use. Once published, assessments can be assigned to business assets, reviewed by designated stakeholders, and updated as needed to reflect evolving data practices. Risk settings can also be configured to assess privacy risks based on responses, providing a standardized way to measure potential concerns.
4+
5+
## Assessment management overview
6+
7+
Privacy Assessments are managed from the **Assessment management** page, where organizations can create, assign, and review assessments. This page includes three main sections:
8+
9+
:::image type="content" source="../media/assessment-management-page.png" alt-text="Screenshot showing the Assessment management page in Privacy Assessments." lightbox="../media/assessment-management-page.png":::
10+
11+
- **Assets tab**: Lists business assets (such as projects or business processes) that have been registered in Purview. From here, assessments can be assigned to specific assets.
12+
- **Assessments tab**: Displays registered business assets (such as projects or business processes). Use this tab to assign assessments to specific assets and manage related privacy documentation.
13+
- **Assessment responses tab**: Shows submitted responses with details such as assigned assets, completion status, and risk scores. Reviewers can evaluate responses and take action here.
14+
15+
## Creating assessments
16+
17+
When you create an assessment, you build a questionnaire that respondents complete and submit for review. Assessments can be customized to fit specific business needs, ensuring that privacy teams capture relevant details about data use.
18+
19+
### Before you create an assessment
20+
21+
Consider:
22+
23+
- **Assessment name and purpose**: What data use case does this assessment cover?
24+
- **Reviewers and approvers**: Who will review submitted responses?
25+
- **Risk settings**: Will the assessment measure privacy risks? If so, configure risk factors in the risk register.
26+
27+
### Steps to create an assessment
28+
29+
1. In **Privacy Assessments**, navigate to **Assessment management**.
30+
1. On the **Assessments** tab, select **New assessment**, then choose:
31+
- **From template**: Use a predefined privacy assessment or data use inventory template.
32+
- **Custom**: Build a custom questionnaire.
33+
1. Enter a **Name** and **Description**, then select **Next**.
34+
1. At **Assign reviewers**, select users with the **Privacy Curator** role to review and approve responses.
35+
1. Select **Create**.
36+
37+
Once created, the assessment opens in Edit Assessment, where you can add and configure questions.
38+
39+
## Building the assessment questionnaire
40+
41+
The questionnaire is the core of the assessment. You can add different question types, group them into sections, and configure logic to show or hide questions based on responses.
42+
43+
### Question types
44+
45+
- **Text**: Open-ended response.
46+
- **Choice**: Single-select response with radio buttons.
47+
- **Checkbox**: Multi-select response with checkboxes.
48+
- **Date**: Date selection from a calendar.
49+
- **Informational**: Provides guidance or links; doesn't require a response.
50+
51+
**Checkbox** questions default to multi-select but can be switched to single-select **(Choice)**.
52+
53+
## Configuring questions
54+
55+
Each question includes:
56+
57+
- **Prompt**: The question text respondents see.
58+
- **Required answer**: Ensures a response is provided.
59+
- **Attachments**: Allows respondents to upload supporting files, up to six files, 5 MB each.
60+
- **Risk settings**: Assigns risk levels to responses (if applicable).
61+
62+
The assessment editor provides options to add and configure questions. The example shows a text-based question with toggles for required responses, attachments, and risk settings.
63+
64+
:::image type="content" source="../media/assessment-editor.png" alt-text="Screenshot showing the assessment editor where users can configure question text, required answers, attachments, and risk settings." lightbox="../media/assessment-editor.png":::
65+
66+
## Applying logic to questions
67+
68+
Logic controls whether a question appears based on a previous response. To configure logic:
69+
70+
1. Select **Add logic** on a question.
71+
1. Set conditions that determine when a question appears. For example, "If Question 3 is answered 'Yes,' show Question 4."
72+
1. Choose whether to **Show** or **Hide** the question based on the conditions.
73+
74+
The screenshot shows an example of logic applied to an assessment question, where the "Assessment Concluded" question is only shown if the response to "Personal Data Use" is No.
75+
76+
:::image type="content" source="../media/logic-conditions-example.png" alt-text="Screenshot of an assessment question with logic conditions applied, showing how a question is displayed based on a previous response." lightbox="../media/logic-conditions-example.png":::
77+
78+
Use **Preview** at any time to test how the questionnaire behaves, including logic-based visibility settings.
79+
80+
## Assigning assessments to assets
81+
82+
Assigning assessments to assets links privacy evaluations to specific business operations. To assign an assessment:
83+
84+
1. In **Assessment management**, open the **Assessments** tab.
85+
1. Select the assessment to open its details page.
86+
1. Select **Assign**, then:
87+
- Select one or more assets.
88+
- Select one or more reviewers to approve submitted responses.
89+
1. Select **Assign** to complete the process.
90+
91+
## Submitting and reviewing assessments
92+
93+
Asset owners receive an email with a link to complete the assigned assessment. The **Privacy** section of the asset lists all assigned assessments and their status.
94+
95+
### Submitting an assessment
96+
97+
1. Open the assigned assessment.
98+
1. Complete all required questions.
99+
1. Save progress if needed.
100+
1. Select **Submit** when ready.
101+
102+
### Reviewing and approving assessments
103+
104+
Reviewers receive email notifications when an assessment is submitted. To review an assessment:
105+
106+
1. Open the assessment from the **Assessment responses** tab.
107+
1. Review answers and check the **Risk score** panel.
108+
1. Choose **Approve** or **Decline**.
109+
110+
If declined, the respondent can update responses and resubmit.
111+
112+
## Configuring risk settings
113+
114+
Risk settings define the risk factors organizations want to assess. These settings influence the Risk score, which helps privacy teams evaluate potential data risks.
115+
116+
### Defining risk factors
117+
118+
1. In **Privacy Assessments**, navigate to the **Risk register**.
119+
1. Select **Risk settings**, then **Add risk factor**.
120+
1. Enter a **Category name**, **Description**, and assign a **Risk rating** (Low, Medium, or High).
121+
122+
### Assigning risk levels to questions
123+
124+
For **Choice** and **Checkbox** questions, assign a risk level (No risk, Low, Medium, or High) to each response. For **Text** questions, risk is determined during assessment review.
125+
126+
## Understanding risk scores
127+
128+
Risk scores quantify potential privacy risks based on assessment responses.
129+
130+
- Assign a maximum possible risk score to each question with a risk factor.
131+
- Calculate the total risk score based on respondents' selections.
132+
- Determine the final score as a percentage of the maximum possible risk.
133+
134+
Risk levels are categorized as:
135+
136+
| Score Range | Risk Level |
137+
|-----|-----|
138+
| 1 - 3 | Low |
139+
| 4 - 7 | Medium |
140+
| 8 - 10 | High|
141+
142+
Risk scores help organizations quantify potential privacy risks, making it easier to prioritize mitigation efforts.
143+
144+
## Exporting an assessment response
145+
146+
Export assessment results as a **Word** or **PDF** file for auditing and compliance reporting.
147+
148+
1. In **Assessment management**, open the **Assessment responses** tab.
149+
1. Select the response you want to export.
150+
1. Select **Export** response and choose the file format.
151+
152+
The file downloads immediately for external sharing.
153+
154+
## Next steps
155+
156+
Once assessments are in place, organizations can:
157+
158+
- **Monitor assessment responses** to ensure privacy compliance.
159+
- **Adjust risk settings** based on changing business needs.
160+
- **Automate privacy rules** to streamline assessment assignments.
161+
162+
Regularly reviewing assessments ensures organizations stay aligned with evolving privacy requirements.
163+
164+
## Legal disclaimer
165+
166+
[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true)

0 commit comments

Comments
 (0)