Attachment_2_-RFP_Data_Privacy_Questionnaire.xlsx
XLSX spreadsheet 23 KB Posted
- Attached to
- Enterprise Asset Management - Software & Implementation State and local contract opportunity
- Solicitation number
- RFP 26-0007
- Issued by
- Maricopa County, Phoenix City, Arizona
About this file
RFP Data Privacy Questionnaire Summary
This is a Data Privacy Questionnaire assessment tool for the City of Phoenix's Enterprise Asset Management software and implementation RFP. The questionnaire is designed to evaluate vendor privacy risk across three weighted criteria: implementation of a comprehensive privacy program covering all operations and systems processing personal data, existence of an incident/breach escalation and response plan, and any reportable privacy or security breaches within the past two years. Each question carries a risk score with "No" responses or no response rated as high risk (5 points), and "Yes" responses rated as low risk (1 point). The total possible score of 15 points determines an overall privacy risk rating, with scores of 1-4 classified as low risk, 5-7 as medium risk, and 8 and above as high risk. The questionnaire is to be distributed to all vendors participating in the RFP, not limited to those in the competitive range, and does not require Data Protection Officer review.
The questionnaire serves as an evaluation mechanism to assist the RFP panel in making informed decisions regarding vendor privacy capabilities for a complex, multi-departmental contract involving extensive personal and operational data. Given the City of Phoenix's significant technological ecosystem managing 443 properties across 11 client departments with over 10 million square feet and 2.1 million tracked assets, vendor privacy risk assessment is critical for protecting sensitive information across integrations with existing systems including eChris, SAP, SCADA, and various Building Automation Systems. This privacy evaluation component complements the broader 675-point evaluation framework that assesses system capabilities, experience qualifications, and implementation methodology for the five-year Enterprise Asset Management contract commencing May or July 2026.
View the file
Other files for this state and local contract opportunity
Show all 50
Enterprise Asset Management - Software & Implementation has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For RFP Panel
| Instructions: Each question is weighted and the overall summation score will give the RFP panel a low, medium or high privacy risk rating. This is to allow the RFP panel to make an informed decision. The DPO does not need to review. Note: This should go to all vendors, not just those in the competitive range. | RFP Privacy Questions | |||
| Question | Risk | Response | Score | |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | If “No”, high risk (5) |
If no response, high risk (5) If “Yes”, low risk (1) 5
Does your organization have an incident/breach escalation and response plan? (Yes/No) If “No”, high risk (5) If no response, high risk (5) If “Yes”, low risk (1) 5
Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) If “Yes”, high risk (5) If no response, high risk (5) If “No”, low risk (1) 5
Total 15 Privacy Risk by Total Score:
Low = 1-4 Med = 5-7 High = 8 and above
For Vendor
| RFP Data Privacy Questions | |
| Question | Response |
| Has your organization implemented a privacy program that covers privacy risk across all operations, services, projects, programs and systems that process personal data? (Yes/No) | |
| Does your organization have an incident/breach escalation and response plan? (Yes/No) | |
| Has your organization experienced any reportable privacy or security breaches within the last 2 years? (Yes/No) |
File details come from the government source that posted it. Updated .