A system and method for assessing the risk associated with the protection
of data privacy by software application. A decision engine is provided to
assess monitor and manage key issues around the risk management of data
privacy. The system creates a core repository that manages, monitors and
measures the data privacy assessments of applications across an
institution (e.g., a corporation). The system and method employs
automated questionnaires that require responses from the user (preferably
the manager responsible for the application). The responses are tracked
in order to evaluate the progress of the assessment and the status of the
applications with respect to compliance with the enterprise's data
privacy policies and procedures as well as the regulations and laws of
the jurisdictions in which the application is operated. Once a
questionnaire has been completed, the application is given ratings both
with respect to the data privacy impact of the application and the
application's compliance with the data privacy requirements. If a risk
exists, a plan for reducing the risk or bringing the application into
compliance can be formulated, and progress towards compliance can be
tracked. Alternatively, an identified exposure to risk can be
acknowledged through the system, which requires sign off by various
higher level managers and administrators.