A
system and method for assessing the risk associated with the protection of data privacy by
software application. A decision engine is provided to assess monitor and manage
key issues around the risk management of data privacy. The
system creates a core repository that manages, monitors and measures the data privacy assessments of applications across an institution (e.g., a corporation). The
system and method employs automated questionnaires that require responses from the user (preferably the manager responsible for the application). The responses are tracked in order to evaluate the progress of the assessment and the status of the applications with respect to compliance with the enterprise's data privacy policies and procedures as well as the regulations and laws of the jurisdictions in which the application is operated. Once a questionnaire has been completed, the application is given ratings both with respect to the data privacy
impact of the application and the application's compliance with the data privacy requirements. If a risk exists, a plan for reducing the risk or bringing the application into compliance can be formulated, and progress towards compliance can be tracked. Alternatively, an identified
exposure to risk can be acknowledged through the system, which requires sign off by various higher level managers and administrators.