|
| 1 | +Privacy assessments (preview) help organizations document and evaluate how personal data is used across business processes. A structured approach ensures consistency in data collection, supports privacy risk evaluation, and helps organizations track compliance. |
| 2 | + |
| 3 | +Organizations can create assessments from templates or customize them to capture specific details about data use. Once published, assessments can be assigned to business assets, reviewed by designated stakeholders, and updated as needed to reflect evolving data practices. Risk settings can also be configured to assess privacy risks based on responses, providing a standardized way to measure potential concerns. |
| 4 | + |
| 5 | +## Assessment management overview |
| 6 | + |
| 7 | +Privacy Assessments are managed from the **Assessment management** page, where organizations can create, assign, and review assessments. This page includes three main sections: |
| 8 | + |
| 9 | +:::image type="content" source="../media/assessment-management-page.png" alt-text="Screenshot showing the Assessment management page in Privacy Assessments." lightbox="../media/assessment-management-page.png"::: |
| 10 | + |
| 11 | +- **Assets tab**: Lists business assets (such as projects or business processes) that have been registered in Purview. From here, assessments can be assigned to specific assets. |
| 12 | +- **Assessments tab**: Displays registered business assets (such as projects or business processes). Use this tab to assign assessments to specific assets and manage related privacy documentation. |
| 13 | +- **Assessment responses tab**: Shows submitted responses with details such as assigned assets, completion status, and risk scores. Reviewers can evaluate responses and take action here. |
| 14 | + |
| 15 | +## Creating assessments |
| 16 | + |
| 17 | +When you create an assessment, you build a questionnaire that respondents complete and submit for review. Assessments can be customized to fit specific business needs, ensuring that privacy teams capture relevant details about data use. |
| 18 | + |
| 19 | +### Before you create an assessment |
| 20 | + |
| 21 | +Consider: |
| 22 | + |
| 23 | +- **Assessment name and purpose**: What data use case does this assessment cover? |
| 24 | +- **Reviewers and approvers**: Who will review submitted responses? |
| 25 | +- **Risk settings**: Will the assessment measure privacy risks? If so, configure risk factors in the risk register. |
| 26 | + |
| 27 | +### Steps to create an assessment |
| 28 | + |
| 29 | +1. In **Privacy Assessments**, navigate to **Assessment management**. |
| 30 | +1. On the **Assessments** tab, select **New assessment**, then choose: |
| 31 | + - **From template**: Use a predefined privacy assessment or data use inventory template. |
| 32 | + - **Custom**: Build a custom questionnaire. |
| 33 | +1. Enter a **Name** and **Description**, then select **Next**. |
| 34 | +1. At **Assign reviewers**, select users with the **Privacy Curator** role to review and approve responses. |
| 35 | +1. Select **Create**. |
| 36 | + |
| 37 | +Once created, the assessment opens in Edit Assessment, where you can add and configure questions. |
| 38 | + |
| 39 | +## Building the assessment questionnaire |
| 40 | + |
| 41 | +The questionnaire is the core of the assessment. You can add different question types, group them into sections, and configure logic to show or hide questions based on responses. |
| 42 | + |
| 43 | +### Question types |
| 44 | + |
| 45 | +- **Text**: Open-ended response. |
| 46 | +- **Choice**: Single-select response with radio buttons. |
| 47 | +- **Checkbox**: Multi-select response with checkboxes. |
| 48 | +- **Date**: Date selection from a calendar. |
| 49 | +- **Informational**: Provides guidance or links; doesn't require a response. |
| 50 | + |
| 51 | +**Checkbox** questions default to multi-select but can be switched to single-select **(Choice)**. |
| 52 | + |
| 53 | +## Configuring questions |
| 54 | + |
| 55 | +Each question includes: |
| 56 | + |
| 57 | +- **Prompt**: The question text respondents see. |
| 58 | +- **Required answer**: Ensures a response is provided. |
| 59 | +- **Attachments**: Allows respondents to upload supporting files, up to six files, 5 MB each. |
| 60 | +- **Risk settings**: Assigns risk levels to responses (if applicable). |
| 61 | + |
| 62 | +The assessment editor provides options to add and configure questions. The example shows a text-based question with toggles for required responses, attachments, and risk settings. |
| 63 | + |
| 64 | +:::image type="content" source="../media/assessment-editor.png" alt-text="Screenshot showing the assessment editor where users can configure question text, required answers, attachments, and risk settings." lightbox="../media/assessment-editor.png"::: |
| 65 | + |
| 66 | +## Applying logic to questions |
| 67 | + |
| 68 | +Logic controls whether a question appears based on a previous response. To configure logic: |
| 69 | + |
| 70 | +1. Select **Add logic** on a question. |
| 71 | +1. Set conditions that determine when a question appears. For example, "If Question 3 is answered 'Yes,' show Question 4." |
| 72 | +1. Choose whether to **Show** or **Hide** the question based on the conditions. |
| 73 | + |
| 74 | +The screenshot shows an example of logic applied to an assessment question, where the "Assessment Concluded" question is only shown if the response to "Personal Data Use" is No. |
| 75 | + |
| 76 | +:::image type="content" source="../media/logic-conditions-example.png" alt-text="Screenshot of an assessment question with logic conditions applied, showing how a question is displayed based on a previous response." lightbox="../media/logic-conditions-example.png"::: |
| 77 | + |
| 78 | +Use **Preview** at any time to test how the questionnaire behaves, including logic-based visibility settings. |
| 79 | + |
| 80 | +## Assigning assessments to assets |
| 81 | + |
| 82 | +Assigning assessments to assets links privacy evaluations to specific business operations. To assign an assessment: |
| 83 | + |
| 84 | +1. In **Assessment management**, open the **Assessments** tab. |
| 85 | +1. Select the assessment to open its details page. |
| 86 | +1. Select **Assign**, then: |
| 87 | + - Select one or more assets. |
| 88 | + - Select one or more reviewers to approve submitted responses. |
| 89 | +1. Select **Assign** to complete the process. |
| 90 | + |
| 91 | +## Submitting and reviewing assessments |
| 92 | + |
| 93 | +Asset owners receive an email with a link to complete the assigned assessment. The **Privacy** section of the asset lists all assigned assessments and their status. |
| 94 | + |
| 95 | +### Submitting an assessment |
| 96 | + |
| 97 | +1. Open the assigned assessment. |
| 98 | +1. Complete all required questions. |
| 99 | +1. Save progress if needed. |
| 100 | +1. Select **Submit** when ready. |
| 101 | + |
| 102 | +### Reviewing and approving assessments |
| 103 | + |
| 104 | +Reviewers receive email notifications when an assessment is submitted. To review an assessment: |
| 105 | + |
| 106 | +1. Open the assessment from the **Assessment responses** tab. |
| 107 | +1. Review answers and check the **Risk score** panel. |
| 108 | +1. Choose **Approve** or **Decline**. |
| 109 | + |
| 110 | +If declined, the respondent can update responses and resubmit. |
| 111 | + |
| 112 | +## Configuring risk settings |
| 113 | + |
| 114 | +Risk settings define the risk factors organizations want to assess. These settings influence the Risk score, which helps privacy teams evaluate potential data risks. |
| 115 | + |
| 116 | +### Defining risk factors |
| 117 | + |
| 118 | +1. In **Privacy Assessments**, navigate to the **Risk register**. |
| 119 | +1. Select **Risk settings**, then **Add risk factor**. |
| 120 | +1. Enter a **Category name**, **Description**, and assign a **Risk rating** (Low, Medium, or High). |
| 121 | + |
| 122 | +### Assigning risk levels to questions |
| 123 | + |
| 124 | +For **Choice** and **Checkbox** questions, assign a risk level (No risk, Low, Medium, or High) to each response. For **Text** questions, risk is determined during assessment review. |
| 125 | + |
| 126 | +## Understanding risk scores |
| 127 | + |
| 128 | +Risk scores quantify potential privacy risks based on assessment responses. |
| 129 | + |
| 130 | +- Assign a maximum possible risk score to each question with a risk factor. |
| 131 | +- Calculate the total risk score based on respondents' selections. |
| 132 | +- Determine the final score as a percentage of the maximum possible risk. |
| 133 | + |
| 134 | +Risk levels are categorized as: |
| 135 | + |
| 136 | +| Score Range | Risk Level | |
| 137 | +|-----|-----| |
| 138 | +| 1 - 3 | Low | |
| 139 | +| 4 - 7 | Medium | |
| 140 | +| 8 - 10 | High| |
| 141 | + |
| 142 | +Risk scores help organizations quantify potential privacy risks, making it easier to prioritize mitigation efforts. |
| 143 | + |
| 144 | +## Exporting an assessment response |
| 145 | + |
| 146 | +Export assessment results as a **Word** or **PDF** file for auditing and compliance reporting. |
| 147 | + |
| 148 | +1. In **Assessment management**, open the **Assessment responses** tab. |
| 149 | +1. Select the response you want to export. |
| 150 | +1. Select **Export** response and choose the file format. |
| 151 | + |
| 152 | +The file downloads immediately for external sharing. |
| 153 | + |
| 154 | +## Next steps |
| 155 | + |
| 156 | +Once assessments are in place, organizations can: |
| 157 | + |
| 158 | +- **Monitor assessment responses** to ensure privacy compliance. |
| 159 | +- **Adjust risk settings** based on changing business needs. |
| 160 | +- **Automate privacy rules** to streamline assessment assignments. |
| 161 | + |
| 162 | +Regularly reviewing assessments ensures organizations stay aligned with evolving privacy requirements. |
| 163 | + |
| 164 | +## Legal disclaimer |
| 165 | + |
| 166 | +[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true) |
0 commit comments