Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx

XLSX spreadsheet 23 KB Posted

Attached to
Enterprise Asset Management - Software & Implementation State and local contract opportunity
Solicitation number
RFP 26-0007
Issued by
Maricopa County, Phoenix City, Arizona

About this file

The document is a Data Privacy Questionnaire for the City of Phoenix's Enterprise Asset Management software and implementation procurement, designed to assess vendors' privacy risk levels. The solicitation is for a five-year enterprise asset management software and implementation contract, scheduled to commence on or about May 1, 2026, with the contract term beginning upon City Council award and recording by the City Clerk's department. The procurement will be conducted through the City's OpenGov e-Procurement Portal, with technical support available via support bubble or email.

The questionnaire includes a weighted scoring mechanism to evaluate vendors' privacy practices, with three key assessment areas: privacy program implementation, incident/breach response planning, and reportable privacy or security breach history. Vendors will be categorized into low (1-4 points), medium (5-7 points), or high (8+ points) privacy risk ratings, enabling the RFP panel to make an informed decision. The document specifies that the questionnaire should be distributed to all vendors, not just those in the competitive range, and does not require review by the Data Protection Officer (DPO).

View the file

Other files for this state and local contract opportunity

Other files attached to Enterprise Asset Management - Software & Implementation, newest first.
File Type Posted
RFP_26-0007_Exhibit_6_-_Sensitive_System_Information_Acknowledgement_Form.docx DOCX document
Enterprise_Asset_Management_-_Software_&_Implementation_(Addendum_#1_Revision).pdf PDF
Enterprise_Asset_Management_-_Software_&_Implementation_(Addendum_#1_Revision).pdf PDF
RFP_26-0007_-_Evaluation_Criteria_Questionaire_Rev._A1.pdf PDF
RFP_26-0007_-_Evaluation_Criteria_Questionaire_Rev._A1.pdf PDF
RFP_26-0007_-_Evaluation_Criteria_Questionaire_Rev._A1.pdf PDF
Enterprise_Asset_Management_-_Software_&_Implementation.pdf PDF
Enterprise_Asset_Management_-_Software_&_Implementation.pdf PDF
Attachment_3_-_RFP_26-0007_-_Evaluation_Criteria_Questionnaire.pdf PDF
Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx XLSX spreadsheet
Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx XLSX spreadsheet
Exhibit_5_-_Physical_Assets_and_Equipment_Inventory.xlsx XLSX spreadsheet
Exhibit_5_-_Physical_Assets_and_Equipment_Inventory.xlsx XLSX spreadsheet
Exhibit_5_-_Physical_Assets_and_Equipment_Inventory.xlsx XLSX spreadsheet
Exhibit_1_-_Detailed_System_Application_Requirements.xlsm XLSM spreadsheet
Exhibit_1_-_Detailed_System_Application_Requirements.xlsm XLSM spreadsheet
Exhibit_1_-_Detailed_System_Application_Requirements.xlsm XLSM spreadsheet
RFP_26-0007_ATTACHMENT_4.docx DOCX document
RFP_26-0007_ATTACHMENT_4.docx DOCX document
RFP_26-0007_ATTACHMENT_4.docx DOCX document
Attachment_1_-_Pricing_Proposal.xlsx XLSX spreadsheet
Attachment_1_-_Pricing_Proposal.xlsx XLSX spreadsheet
Attachment_1_-_Pricing_Proposal.xlsx XLSX spreadsheet
Exhibit_3_-_Complexity_Guidelines.xlsx XLSX spreadsheet
Exhibit_4_-_Quantitative_Assumptions.pdf PDF
Exhibit_3_-_Complexity_Guidelines.xlsx XLSX spreadsheet
Exhibit_4_-_Quantitative_Assumptions.pdf PDF
Exhibit_3_-_Complexity_Guidelines.xlsx XLSX spreadsheet
Exhibit_4_-_Quantitative_Assumptions.pdf PDF
Exhibit_2_-_Integration_Inventory.xlsx XLSX spreadsheet
Exhibit_2_-_Integration_Inventory.xlsx XLSX spreadsheet
Exhibit_2_-_Integration_Inventory.xlsx XLSX spreadsheet
Exhibit_2_-_Integration_Inventory.xlsx XLSX spreadsheet
Supplemental_Terms_And_Conditions_To_All_Airport_Agreements_(Rev._5-22-24-Formatting_Rev._7-11-24).pdf PDF
Supplemental_Terms_And_Conditions_To_All_Airport_Agreements_(Rev._5-22-24-Formatting_Rev._7-11-24).pdf PDF
Supplemental_Terms_And_Conditions_To_All_Airport_Agreements_(Rev._5-22-24-Formatting_Rev._7-11-24).pdf PDF
Supplemental_Terms_And_Conditions_To_All_Airport_Agreements_(Rev._5-22-24-Formatting_Rev._7-11-24).pdf PDF
Acceptance_of_Offer_Form_2025.pdf PDF
Acceptance_of_Offer_Form_2025.pdf PDF
Attachment_B_-_FTA_-_Federal_Certifications_(March_2025).pdf PDF
Acceptance_of_Offer_Form_2025.pdf PDF
Attachment_B_-_FTA_-_Federal_Certifications_(March_2025).pdf PDF
Attachment_B_-_FTA_-_Federal_Certifications_(March_2025).pdf PDF
Attachment_B_-_FTA_-_Federal_Certifications_(March_2025).pdf PDF
Acceptance_of_Offer_Form_2025.pdf PDF
Addendum_Form.docx DOCX document
Addendum_Form.docx DOCX document
Addendum_Form.docx DOCX document
Addendum_Form.docx DOCX document
Addendum_Form.docx DOCX document
Show all 50

Enterprise Asset Management - Software & Implementation has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For RFP Panel

Instructions: Each question is weighted and the overall summation score will give the RFP panel a low, medium or high privacy risk rating. This is to allow the RFP panel to make an informed decision. The DPO does not need to review. Note: This should go to all vendors, not just those in the competitive range.RFP Privacy Questions
QuestionRiskResponseScore
Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No)If “No”, high risk (5)

If no response, high risk (5) If “Yes”, low risk (1) 5

Does your organization have an incident/breach escalation and response plan? (Yes/No) If “No”, high risk (5) If no response, high risk (5) If “Yes”, low risk (1) 5

Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) If “Yes”, high risk (5) If no response, high risk (5) If “No”, low risk (1) 5

Total 15 Privacy Risk by Total Score:

Low = 1-4 Med = 5-7 High = 8 and above

For Vendor

RFP Data Privacy Questions
QuestionResponse
Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No)
Does your organization have an incident/breach escalation and response plan? (Yes/No)
Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No)

File details come from the government source that posted it. Updated .