Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx
XLSX spreadsheet 23 KB Posted
- Attached to
- Enterprise Asset Management - Software & Implementation State and local contract opportunity
- Solicitation number
- RFP 26-0007
- Issued by
- Maricopa County, Phoenix City, Arizona
About this file
The document is a Data Privacy Questionnaire for the City of Phoenix's Enterprise Asset Management (EAM) Software and Implementation procurement, designed to assess vendor privacy risk levels. The five-year contract is scheduled to commence on or about May 1, 2026, seeking a comprehensive cloud-based SaaS solution for multiple municipal departments including Aviation, Public Works, Street Transportation, and Water Services. The solicitation was released on October 1, 2025, with a pre-offer conference on October 10, 2025, and proposal responses due by November 14, 2025. The evaluation process will distribute 675 total points across System Capabilities (300 points), Experience and Qualifications (185 points), and Method of Approach (190 points).
The questionnaire includes a weighted scoring mechanism to determine privacy risk levels, categorizing vendors as low, medium, or high risk based on their responses to three key questions about privacy program implementation, incident/breach response plans, and previous reportable security breaches. The procurement requires a vendor with at least five years of experience implementing EAM products for public entities, capable of integrating with existing systems like SAP, eChris (PeopleSoft), HARS, SCADA, GIS, AutoCAD, Dynamics365, and various Building Automation Systems. The city's current infrastructure supports 443 properties across 11 client departments, totaling 10,496,280 square feet and 14,709 land acres, with Water Services managing 2,128,271 total assets and potential future expansion to 340,000 assets.
View the file
Other files for this state and local contract opportunity
Show all 50
Enterprise Asset Management - Software & Implementation has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For RFP Panel
| Instructions: Each question is weighted and the overall summation score will give the RFP panel a low, medium or high privacy risk rating. This is to allow the RFP panel to make an informed decision. The DPO does not need to review. Note: This should go to all vendors, not just those in the competitive range. | RFP Privacy Questions | |||
| Question | Risk | Response | Score | |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | If “No”, high risk (5) |
If no response, high risk (5) If “Yes”, low risk (1) 5
Does your organization have an incident/breach escalation and response plan? (Yes/No) If “No”, high risk (5) If no response, high risk (5) If “Yes”, low risk (1) 5
Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) If “Yes”, high risk (5) If no response, high risk (5) If “No”, low risk (1) 5
Total 15 Privacy Risk by Total Score:
Low = 1-4 Med = 5-7 High = 8 and above
For Vendor
| RFP Data Privacy Questions | |
| Question | Response |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | |
| Does your organization have an incident/breach escalation and response plan? (Yes/No) | |
| Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) |
File details come from the government source that posted it. Updated .