Workflow Template
Privacy Impact Assessment Workflow
Enables a privacy team to intake initiatives involving personal information, screen them for privacy risk, conduct a full privacy impact assessment where required, obtain reviewer sign-off, record residual risk acceptance and treatment actions, close the assessment, and schedule a future reassessment.
Every time a new project touches personal information, someone has to figure out if it needs a privacy review — and too often that happens over email threads that go nowhere. This workflow gives your privacy team a structured intake for new initiatives, automatically screens them for risk, routes anything significant into a full privacy impact assessment, and captures reviewer sign-off and residual risk decisions along the way. The result is a clear, auditable trail from intake to closure, with reassessments scheduled automatically so nothing gets forgotten.
Business Outcomes
- Faster triage of new initiatives through automated privacy screening
- Consistent, documented PIAs for every high-risk project
- Clear audit trail of reviewer sign-off and residual risk acceptance
- Fewer missed reassessments through automatic scheduling
- Reduced back-and-forth with automatic owner notifications at each stage
Workflow Steps
Steps
- 1Create Privacy Assessment Recordcreate record
Registers the submitted initiative as a privacy assessment record.
- 2Set Status to Submittedupdate record
Marks the assessment as submitted and awaiting screening.
- 3Notify Owner of Receiptsend email
Confirms to the owner that their initiative has been received for privacy screening.
- 4Privacy Screeningcreate task
Privacy team screens the initiative to determine if a full assessment is required.
- 5Update Status to Screeningupdate record
Persists the screening outcome and notes onto the record.
- 6Route on Screening Outcome
Determines whether a full privacy impact assessment is required.
screening_outcome: "Full Assessment Required"→Set Status to Full Assessment Requiredscreening_outcome: "No Further Action"→Close - No Further ActionDefault→Close - No Further Action - 7Close - No Further Actionupdate record
Closes the assessment where screening determined no full assessment is needed.
- 8Notify Owner - Closedsend email
Informs the owner that no further privacy assessment is required.
- 9Set Status to Full Assessment Requiredupdate record
Marks the record as requiring a full assessment.
- 10Assign Assessorassign user
Assigns a privacy assessor to conduct the full assessment.
- 11Conduct Privacy Impact Assessmentcreate task
Assessor documents the risks, treatments, and residual risk rating for the initiative.
- 12Persist Assessment Findingsupdate record
Writes the documented risks, treatments, and residual risk rating to the record and updates status.
- 13Set Status to Under Reviewupdate record
Marks the assessment as pending reviewer sign-off.
- 14Reviewer Sign-offrequest approval
A reviewer signs off on the documented risks and treatments before closure.
- 15Route on Reviewer Sign-off Outcome
Branches based on whether the reviewer approved or rejected the assessment.
approval_status: "approved"→Record Residual Risk Acceptance and Actionsapproval_status: "rejected"→Return for RevisionDefault→End - 16Return for Revisionrestart from step
Sends the assessment back to the assessor to revise risks and treatments before resubmission.
- 17Record Residual Risk Acceptance and Actionscreate task
Privacy team records whether the residual risk is accepted and any follow-up actions.
- 18Persist Risk Acceptance and Actionsupdate record
Writes the residual risk acceptance decision and follow-up actions to the record.
- 19Route on Risk Acceptance
Determines the closure status based on whether the residual risk was accepted.
residual_risk_acceptance: "Accepted"→Close - Approved with Actionsresidual_risk_acceptance: "Not Accepted"→Close - RejectedDefault→Close - Approved with Actions - 20Close - Rejectedupdate record
Closes the assessment as rejected because the residual risk was not accepted.
- 21Notify Owner - Rejectedsend email
Informs the owner that the residual risk was not accepted and the initiative cannot proceed as assessed.
- 22Close - Approved with Actionsupdate record
Closes the assessment as approved, noting any follow-up actions.
- 23Set Review Date for Reassessmentset due date
Sets a future due date on the record to trigger periodic reassessment.
- 24Notify Owner - Closed Approvedsend email
Informs the owner the assessment is closed and shares any follow-up actions and reassessment timing.
Fields
- Initiative Owner Name*
- Owner Email*
- Initiative Name*
- Purpose of Initiative*
- Types of Personal Information Involved*
- Data Subjects*
- +12 more fields
Forms
Privacy Impact Assessment Intake
10 fields
Data Views
All Privacy Assessments
initiative_name, assessment_status, residual_risk_rating, residual_risk_acceptance +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
Do I need technical staff to set this up?
No. The Privacy Impact Assessment template is ready to publish as-is inside assess.one, and you can go live in minutes. If you want to tweak screening questions, roles, or notifications, that's done directly in the platform with no coding or developer involvement.
Can my team customise the screening questions and risk thresholds?
Yes. The screening step, assessment fields, and routing logic that decides whether an initiative needs a full PIA are all editable in assess.one. You can adjust the criteria to match your organisation's specific privacy risk appetite without rebuilding the workflow.
Is this suitable for a small privacy or compliance team?
Absolutely. Because it's a published template rather than a custom build, even a one- or two-person privacy function can run it without heavy admin overhead. The automated notifications and routing mean the workflow does the chasing for you.
How long does implementation take?
There's no lengthy setup project — you publish the template and it's live in seconds. Your team can start submitting initiatives for privacy screening immediately after that.
Who needs access to this workflow?
Typically initiative owners, a privacy screener, an assigned assessor, and a reviewer with sign-off authority. Access and permissions for each role are configured inside assess.one, so you control exactly who can submit, assess, or approve.
What happens if the reviewer doesn't sign off?
The Route on Reviewer Sign-off Outcome step sends the assessment back for revision rather than closing it. The assessor is notified to update the findings and resubmit, keeping the record open until sign-off is achieved or the assessment is formally rejected.
How is residual risk acceptance recorded?
After sign-off, the workflow captures residual risk acceptance and any required treatment actions in a dedicated step, which is then persisted to the record. This creates a clear, retrievable decision log for audits or regulatory enquiries.
Does this workflow support compliance and audit requirements?
Yes, every stage — screening outcome, assessment findings, reviewer sign-off, and risk acceptance — is logged with status changes and timestamps. This gives you a defensible audit trail showing how each privacy decision was reached.
What happens after an assessment is closed?
Closed assessments, whether closed with no further action or after full review, automatically trigger owner notification and a scheduled reassessment date. This ensures ongoing initiatives are periodically re-screened rather than assessed once and forgotten.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
