IBM OpenPages Data Privacy Management (DPM) workflows
The sample workflows are enabled in fresh installations.
- Privacy Impact Assessment
-
When a new data asset (resource) is imported into IBM® Knowledge Catalog, the Privacy Impact Assessment workflow starts automatically. The first stage is Data Asset Review, where a privacy officer (business owner) must determine whether a privacy assessment is needed or not. If the privacy officer needs more information, the officer can request more information from the data steward (primary owner) by selecting . The data asset owner would then need to provide the requested information and select .
If the privacy officer determines that a privacy assessment is not needed, the officer selects . This action sets the PIA Status field on the resource to Not Needed, and then the workflow ends.
If the privacy officer determines that a privacy assessment is needed, the officer selects . This action sets the PIA Status field on the resource to Needed and creates a Questionnaire Assessment, which is assigned to the data steward (primary owner) of the resource.
The privacy officer then selects a questionnaire template for the assessment, and the data steward completes the questionnaire. When the questionnaire is complete, the data steward selects .
The privacy officer now reviews the privacy assessment and can either Approve PIA or Reject PIA. If rejected, the assessment is returned to the data steward for remediation. If the assessment is approved, the workflow ends.
Figure 1. Privacy Impact Assessment workflow 
- Data Protection Impact Assessment
-
After a privacy impact assessment (PIA) on a data asset is completed or if a PIA is not needed, the Data Protection Impact Assessment workflow starts automatically. When it starts, the workflow sets the DPIA Status field on the resource to Needed and creates a Questionnaire Assessment that is assigned to the privacy officer (business owner) of the resource.
At the first stage of the workflow, DPIA Started, a data steward (primary owner) has the option to override and cancel the DPIA, if it is determined that the DPIA is not needed. In this case, the data steward selects .
If the data steward does not override the DPIA, then the data steward completes the questionnaire assessment and selects .
At the next stage of the workflow, DPIA Awaiting Approval, the privacy officer (business owner) reviews the DPIA questionnaire assessment, and has the option to reject it by selecting , which sends it back to the data steward for remediation, or approve it by selecting , which ends the workflow.
Figure 2. Data Protection Impact Assessment workflow 