Configuring the Privacy Worksheet

The TerraTrue Privacy Worksheet is a key workflow that helps your privacy managers evaluate how new product launches use data.

It automatically generates tailored questions based on a project’s Data Spec and historical data to identify risks, recommend security actions, and ensure compliance with global privacy laws including GDPR, CCPA/CPRA and the growing set of US state privacy laws.

Privacy Worksheet was a hard-coded module until early 2026. By moving to a workflow-based approach, Privacy Worksheets now support branching logic, custom questions, and specific triggers (custom actions) that can be further tailored to your organization's needs.

TerraTrue offers an out-of-the-box Privacy Worksheet as a workflow:

  • Controller Privacy Worksheet.

Important: Transitioning from Legacy to Workflow

Unlike the Data Spec, which is available as a workflow by default, the Privacy Worksheet workflow must be explicitly published to take effect.

  • Legacy Mode: Until you publish a workflow in the Workflow Library, TerraTrue will continue to use the existing "Legacy" Privacy Worksheet (which is not a configurable workflow).
     
  • The Switch: After you publish a Privacy Worksheet workflow, all future Privacy Worksheets will use the newly published workflow. This includes new launches and any existing launches where the Privacy Worksheet has not yet been started.
     
  • Existing Data: For any in-progress or completed Privacy Worksheets, TerraTrue will continue to use the "Legacy" version to ensure your existing work is not disrupted.
     
  • No Unpublishing: After you publish the Privacy Worksheet workflow, it cannot be unpublished and the legacy option will not be available for use in new launches. Like any other workflow, the Privacy Worksheet workflow can be edited, with every older version accessible and saved.

Accessing the Privacy Worksheet

TerraTrue admins determine if and when a specific Privacy Worksheet is available for end users. To manage Privacy Worksheets, navigate to Workflow Library > Privacy Worksheets. From here you have the ability to:

  1. Edit the Privacy Worksheet using the Workflow Builder.
  2. Publish a Privacy Worksheet.

What is the Privacy Worksheet Builder?

The Privacy Worksheet Builder uses the same interface as our other Workflow Builders. It allows you to move beyond a static questionnaire and customize the review experience.

By default, the Privacy Worksheet is a comprehensive assessment workflow related to all privacy considerations.

With the Builder, you can edit the language of existing questions, or add additional questions, pages, and custom actions. You can also edit the descriptions and context clues of pre-existing questions to better guide your team. You also have complete visibility into what custom actions are executed based on various criteria, e.g. the various criteria used to determine whether a DPIA (Data Processing Impact Assessment) is needed, such as US state modules being enabled, the launch Data Spec declaring use of a data type that requires a DPIA, or a high risk data type being used and so on.

Structure of the Privacy Worksheet Builder

To access the builder, visit Workflow Library > Privacy Worksheets.

Pages and Questions

The Pages and Questions section is the core of the builder. While the standard Privacy Worksheet contains foundational questions required for privacy reviews, you have the flexibility to:

  • Add new questions or pages to capture specific information, such as DPIA-specific details or cross-border transfer assessments.
  • Reorder content by dragging and dropping questions into the optimal flow for your users.
  • Edit descriptions to provide internal guidance or links to company policy.

Custom Actions

As with other custom workflows, you can assign custom actions to questions within the builder. This allows you to automate tasks, such as triggering a specific review or notifying a stakeholder, based on the answers provided in the worksheet.

Publishing your Privacy Worksheet

To move away from the Legacy worksheet and begin using the new configurable format:

  1. Navigate to the Workflow Library.
  2. Select Privacy Worksheets.
  3. Once your Controller Privacy Worksheet is configured to your satisfaction, click Publish.

Note:

  1. After publishing, all new launches will automatically use this workflow version. For older launches where a worksheet was already started, the Legacy version will remain active to preserve your data.
  2. After publishing the Privacy Worksheet, it will not be possible for you to unpublish it. We would like all our customers to begin adopting this Privacy Worksheet as a workflow. Like other workflows, the Privacy Worksheet can be edited and all previous revisions will be accessible.

Customizing the Privacy Worksheet

The Privacy Worksheet can be edited to:

  1. Update the language and context of existing questions.
  2. Make existing questions optional.
  3. Add new pages.
  4. Add new questions within any existing page.

The workflow has the following properties and constraints:

PageQuestionConstraints
Data Transfers(page itself)Mandatory
Where will you process data for this launch?

Mandatory


 

 What mechanisms or bases do you rely on to transfer data out of the EU?

Driven by Data Spec Selections

This question is shown for each data type selected in the Data Spec.

 

Mandatory

Basis for Processing(page itself)Mandatory
 Basis for processing questions:

Driven by Data Spec Selections

This question is shown for each data type of every data use selected in the Data Spec.

Mandatory

 What is your basis for processing to ${data use}– Child question of Basis for Processing
 When you rely on "legal obligation" to process ${data_types}, you need to identify the law that puts that obligation on you. Feel free to use links, citations, or just a description– Child question of Basis for Processing
 When you rely on "public task" to process ${data_types}, you need to identify the law that puts that obligation on you. Feel free to use links, citations, or just a description:– Child question of Basis for Processing
Choice(page itself)Mandatory
 Will individuals be able to revoke their consent for the following data uses?

Driven by Data Spec Selections

This question is shown for each data use in the Data Spec where at least one enabled privacy module indicates the data use should allow opt-out.


 

Mandatory

 Will individuals be able to opt out of:shown for each data use

Can set to be skipped
Access & Portability(page itself)Mandatory
 If an individual asks, will you be able to provide them with the following information?

Driven by Data Spec Selections

This question is shown for each data type selected in the Data Spec.

Mandatory

 Do individuals give you the following information?

Driven by Data Spec Selections

This question is shown for each data type selected in the Data Spec where the basis for processing is either “Consent” or “Contractual Necessity.”

Mandatory

 Will you be able to provide individuals with the following information in a portable format?

Driven by Data Spec Selections

This question is shown for each data type selected in the Data Spec.


 

Mandatory

Deletion & Correction(page itself)Mandatory
 If people ask, will you delete or correct their information?

Driven by Data Spec Selections

This question is shown for each data type selected in the Data Spec.

Mandatory

Special Considerations(page itself)Optional
 Will this launch involve any profiles or automated decisions that could significantly affect individuals?

Mandatory


 

 Which of the following data uses involve profiles or automated decisions that could significantly affect individuals?

Taxonomy question

Mandatory


 

 Would you like to run through the Special Considerations questions to see if a Data Protection Impact Assessment is needed?

Mandatory


 

 Will this launch involve regularly monitoring individuals?

Mandatory


 

 Which of the following data uses involve regularly monitoring individuals?

Taxonomy question

Mandatory


 

 Will this launch involve using data on a large scale?

Mandatory


 

 Which of the following data uses involve using data on a large scale?

Taxonomy question

Mandatory


 

 Will this launch involve combining data from different organizations or data that was originally collected for different purposes?Mandatory
 Which of the following data uses involve combining data from different organizations or data that was originally collected for different purposes?

Taxonomy question

Mandatory


 

 Will this launch involve using data about individuals who require special consideration or care?Mandatory
 Which of the following data uses involve using data about individuals who require special consideration or care?

Taxonomy question

Mandatory


 

 Will this launch involve an innovative new technology or use of data that poses novel risks or will be difficult for individuals to understand?Mandatory
 Which of the following data uses involve an innovative new technology or use of data that poses novel risks or will be difficult for individuals to understand?

Taxonomy question

Mandatory


 

 Do you sell personal information or create profiles about data subjects where there is a reasonably foreseeable risk of causing:Mandatory
Third Parties(page itself)Mandatory
 Third party questions

Driven by Data Spec Selections

This question is shown for each third party selected in the Data Spec.

Can set to be skipped

 Will $(third party) be able to use the data for their own purposes?– Child question: Third party questions
 Describe how $(third party) will use the data you share with them– Child question: Third party questions
 Do you have a contract clearly outlining $(third party)'s obligations?– Child question: Third party questions
 Is $(third party) a processor, controller, or joint controller?– Child question: Third party questions
 Are you selling any $(third party) data to , or sharing data in order to provide personalized advertising to the user?– Child question: Third party questions


The title and description for all the mandatory pages and the questions listed above can be edited.

 

Was this article helpful?
0 out of 0 found this helpful