Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx
XLSX spreadsheet 23 KB Posted
- Attached to
- Enterprise Asset Management - Software & Implementation State and local contract opportunity
- Solicitation number
- RFP 26-0007
- Issued by
- Maricopa County, Phoenix City, Arizona
About this file
The document is a Data Privacy Questionnaire for the City of Phoenix's Enterprise Asset Management software and implementation procurement, designed to assess vendors' privacy risk levels. The solicitation is for a five-year enterprise asset management software and implementation contract, scheduled to commence on or about May 1, 2026, with the contract term beginning upon City Council award and recording by the City Clerk's department. The procurement will be conducted through the City's OpenGov e-Procurement Portal, with technical support available via support bubble or email.
The questionnaire includes a weighted scoring mechanism to evaluate vendors' privacy practices, with three key assessment areas: privacy program implementation, incident/breach response planning, and reportable privacy or security breach history. Vendors will be categorized into low (1-4 points), medium (5-7 points), or high (8+ points) privacy risk ratings, enabling the RFP panel to make an informed decision. The document specifies that the questionnaire should be distributed to all vendors, not just those in the competitive range, and does not require review by the Data Protection Officer (DPO).
View the file
Other files for this state and local contract opportunity
Show all 50
Enterprise Asset Management - Software & Implementation has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For RFP Panel
| Instructions: Each question is weighted and the overall summation score will give the RFP panel a low, medium or high privacy risk rating. This is to allow the RFP panel to make an informed decision. The DPO does not need to review. Note: This should go to all vendors, not just those in the competitive range. | RFP Privacy Questions | |||
| Question | Risk | Response | Score | |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | If “No”, high risk (5) |
If no response, high risk (5) If “Yes”, low risk (1) 5
Does your organization have an incident/breach escalation and response plan? (Yes/No) If “No”, high risk (5) If no response, high risk (5) If “Yes”, low risk (1) 5
Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) If “Yes”, high risk (5) If no response, high risk (5) If “No”, low risk (1) 5
Total 15 Privacy Risk by Total Score:
Low = 1-4 Med = 5-7 High = 8 and above
For Vendor
| RFP Data Privacy Questions | |
| Question | Response |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | |
| Does your organization have an incident/breach escalation and response plan? (Yes/No) | |
| Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) |
File details come from the government source that posted it. Updated .