Data processing systems and methods for generating personal data inventories for organizations and other entities

US10026110B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10026110-B2
Application numberUS-201715619469-A
CountryUS
Kind codeB2
Filing dateJun 10, 2017
Priority dateApr 1, 2016
Publication dateJul 17, 2018
Grant dateJul 17, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Data processing systems and methods, according to various embodiments, are configured for generating personal data inventories for an organization by: (1) conducting, by one or more computer processors, privacy impact assessments for each of the organization's new business initiatives, the privacy impact assessments including both data-mapping and non-data-mapping questions; (2) flagging, by one or more computer processors, any data-mapping questions within the privacy impact assessments as data mapping questions; and (3) generating, one or more computer processors, personal data inventories on-demand based on the flagged data-mapping data.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented data processing method for automatically generating an inventory of personal data stored by a particular organization, the data processing method comprising, for each of a plurality of particular privacy campaigns: presenting, on one or more computer user interfaces, a plurality of prompts for the input of data mapping data related to the particular privacy campaign, wherein each of the plurality of particular privacy campaigns utilizes personal data collected from one or more persons or one or more entities; electronically receiving the data mapping data via input by one or more users, wherein the data mapping data comprises: a descriptor of the particular privacy campaign; an identification of one or more types of particular personal data to be acquired or used during the privacy campaign; data indicating one or more locations in computer memory where the particular personal data is to be stored; and data identifying one or more particular types of individuals who will have access to the particular personal data; processing the data mapping data by electronically associating the data mapping data with a record for the particular privacy campaign; digitally storing, in memory, the data mapping data associated with the record for the particular campaign; determining, based at least in part on the data mapping data, a risk value associated with the privacy campaign, wherein determining the risk value comprises: electronically retrieving, from memory, the data mapping data associated with the record for the privacy campaign; electronically determining a weighting factor for each of a plurality of risk factors, wherein the plurality of the risk factors comprises: the descriptor of the particular privacy campaign; the identification of one or more type of particular personal data to be acquired or used during the privacy campaign; the data indicating one or more locations in computer memory where the particular personal data is to be store; and the data identifying one or more particular types of individual who will have access to the particular personal data; electronically determining a relative risk rating for each of the plurality of risk factors; and electronically calculating a risk value for the privacy campaign based upon, for each respective one of the plurality of risk factors, the relative risk rating for the respective risk factor and the weighting factor for the respective risk factor; and storing the risk value in computer memory, wherein the computer-implemented data processing method further comprises: receiving, via a user interface, a request to generate an inventory of personal data for the particular organization; and in response to receiving the request, generating the requested inventory of personal data for the particular organization, wherein the requested inventory comprises the data mapping data for each of the plurality of particular privacy campaigns. 2. The computer-implemented data processing method of claim 1 , wherein the method further comprises electronically flagging one or more of the plurality of prompts as a prompt requesting data mapping data. 3. The computer-implemented data processing method of claim 2 , wherein the electronically flagged one or more of the plurality of prompts prompt a user to input data mapping data for the particular privacy campaign. 4. The computer-implemented method of claim 1 , wherein each of the plurality of prompts for input of data mapping data includes a respective unique identifier to associate its respective prompt with a respective category of data mapping data selected from a group consisting of: campaign description; type of personal data; time period for storage of the personal data; and storage location of personal data. 5. The computer-implemented method of claim 1 , further comprising automatically configuring the plurality of prompts for the input of data mapping data based on a selection of a particular template from one or more templates. 6. The computer-implemented method of claim 5 , wherein the particular template of the one or more templates is selected based on a type of the particular privacy campaign. 7. A computer-implemented data processing method for automatically generating an inventory of personal data stored by a particular organization, the data processing method comprising: for each of a plurality of particular privacy campaigns, wherein each of the plurality of particular privacy campaigns utilizes personal data collected from one or more persons or one or more entities: receiving, via a computer user interface, a command to create an electronic record for the particular privacy campaign; in response to receiving the command, creating an electronic record for the particular privacy campaign and digitally storing the record in memory; presenting, on one or more computer user interfaces, a plurality of prompts for the input of data mapping data related to the privacy campaign; electronically receiving data mapping data input by one or more users, wherein the data mapping data comprises: a description of the privacy campaign; an identification of one or more types of particular personal data related to the privacy campaign; data identifying a particular type of subject from which the personal data was collected; data indicating one or more locations in computer memory where the personal data is to be stored; and data identifying one or more particular types of individual who will have access to the particular personal data; processing the data mapping data by electronically associating the data mapping data with the record for the particular privacy campaign; and digitally storing, in memory, the data mapping data associated with the record for the particular campaign; determining, based at least in part on the data mapping data, a risk value associated with the privacy campaign, wherein determining the risk value comprises: electronically retrieving, from memory, the data mapping data associated with the record for the privacy campaign; electronically determining a weighting factor for each of a plurality of risk factors, wherein the plurality of risk factors comprises: the identification of one or more types of particular personal data related to the privacy campaign; the data identifying a particular type of subject from which the personal data was collected; and the data indicating one or more locations in computer memory where the particular personal data is to be stored, electronically determining a relative risk rating for each of the plurality of risk factors; electronically calculating a risk value for the privacy campaign based upon, for each respective one of the plurality of risk factors, the relative risk rating for the respective risk factor and the weighting factor for the respective risk factor; storing the risk value in computer memory; receiving a request, from a user, to display an inventory of personal data for the particular organization that includes the data mapping data for each of the plurality of particular campaigns; and in response to receiving the request to display the inventory of personal data for the particular organization that includes the data mapping data for each of the plurality of particular campaigns, displaying, on a display screen, the inventory of personal data for the particular organization. 8. The computer-implemented data processing method of claim 7 , further comprising: storing the plurality of prompts for the input of data mapping data among a plurality of user selection tabs for presentation of the plurality of prompts for the input of data mapping data along with one or more different prompts for no

Assignees

Inventors

Classifications

  • Personal security, identity or safety · CPC title

  • Qualifying participants for shopping transactions (payment transaction verification G06Q20/401) · CPC title

  • Status monitoring or status determination for a person or group · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10026110B2 cover?
Data processing systems and methods, according to various embodiments, are configured for generating personal data inventories for an organization by: (1) conducting, by one or more computer processors, privacy impact assessments for each of the organization's new business initiatives, the privacy impact assessments including both data-mapping and non-data-mapping questions; (2) flagging, by on…
Who is the assignee on this patent?
Onetrust Llc
What technology area does this patent fall under?
Primary CPC classification G06Q30/0609. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 17 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).