Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques

US11308435B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11308435-B2
Application numberUS-202016908081-A
CountryUS
Kind codeB2
Filing dateJun 22, 2020
Priority dateJun 10, 2016
Publication dateApr 19, 2022
Grant dateApr 19, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In various embodiments, a system may be configured to substantially automatically determine whether to take one or more actions in response to one or more identified risk triggers (e.g., data breaches, regulation change, etc.). The system may, for example: (1) compare the potential risk trigger to one or more previous risks triggers experienced by the particular entity at a previous time; (2) identify a similar previous risk trigger (e.g., one or more previous risk triggers related to a similar change in regulation, breach of data, type of issue identified, etc.); (3) determine the relevance of the current risk trigger based at least in part on a determined relevance of the previous risk trigger; and (4) determine whether to take one or more actions to the current risk trigger based at least in part on one or more determined actions to take in response to the previous, similar risk trigger.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented data processing method for identifying and automatically determining a response to one or more potential risk triggers based on a data model, the method comprising: identifying, by computing hardware, the one or more potential risk triggers for an entity; assessing and analyzing, by the computing hardware, the one or more potential risk triggers to determine a relevance of a risk posed to the entity by the one or more potential risk triggers, wherein determining the relevance of the risk comprises: identifying one or more similarly situated entities to the entity; receiving risk remediation data for the one or more similarly situated entities, the risk remediation data comprising one or more previous risk triggers experienced by the one or more similarly situated entities and a relevance of each of the one or more previous risk triggers determined by the one or more similarly situated entities; identifying one or more similar risk triggers from the one or more previous risk triggers experienced by the one or more similarly situated entities, the one or more similar risk triggers being similar to the one or more potential risk triggers; and determining the relevance of the risk posed by the one or more potential risk triggers based at least in part on the risk remediation data; identifying, by the computing hardware using one or more data modeling techniques, one or more data assets associated with the entity that may be affected by the one or more potential risk triggers, wherein identifying the one or more data assets that may be affected by the one or more potential risk triggers comprises: scanning a respective digital inventory for each of the one or more data assets, each respective digital inventory comprising one or more inventory attributes, and analyzing each respective digital inventory to determine the one or more inventory attributes that may be affected by the one or more potential risk triggers; determining, by the computing hardware, based at least in part on the one or more identified data assets and the relevance of the risk posed to the entity by the one or more potential risk triggers, whether to take one or more actions in response to the one or more potential risk triggers; and in response to determining to take the one or more actions, facilitating an adjustment, by the computing hardware, of one or more data attributes of the one or more identified data assets. 2. The computer-implemented data processing method of claim 1 , wherein determining whether to take the one or more actions in response to the one or more potential risk triggers comprises: determining a respective risk level for each of the one or more potential risk triggers; and determining that one or more risk levels for the one or more potential risk triggers exceeds a threshold risk level. 3. The computer-implemented data processing method of claim 2 , wherein determining the respective risk level for each of the one or more potential risk triggers is based at least in part on at least one of: (1) an amount of personal data stored on a data asset that may be affected by a potential risk trigger associated with the respective risk level; (2) a type of personal data stored on a data asset that may be affected by the potential risk trigger associated with the respective risk level; (3) a number of the one or more identified data assets affected by the potential risk trigger associated with the respective risk level; and (4) a type of issue associated with the potential risk trigger associated with the respective risk level. 4. The computer-implemented data processing method of claim 1 , wherein the one or more inventory attributes comprise at least one of: (1) a type of data being stored at a data asset; (2) an amount of data being stored at a data asset; (3) an encryption status of data being stored at a data asset; (4) a storage location of data being stored at a data asset; and (5) information technology data related to a data asset. 5. The computer-implemented data processing method of claim 1 , wherein the one or more potential risk triggers comprise a data breach associated with the one or more data assets. 6. The computer-implemented data processing method of claim 1 , wherein the one or more similarly situated entities comprise at least one of: (1) one or more other entities in a similar location as the entity; (2) one or more other entities in a similar industry to an industry of the entity; (3) one or more entities of a similar size to the entity; and (4) one or more entities that are governed by one or more regulations that are similar to regulations that govern the entity. 7. The computer-implemented data processing method of claim 1 , further comprising updating the risk remediation data to include the one or more actions in response to the one or more potential risk triggers. 8. A computer-implemented data processing method for identifying and automatically determining a response to one or more potential risk triggers based on a data model, the method comprising: identifying, by computing hardware, the one or more potential risk triggers for an entity; assessing and analyzing, by the computing hardware, the one or more potential risk triggers to determine a relevance of a risk posed to the entity by the one or more potential risk triggers, wherein determining the relevance of the risk comprises: identifying one or more similarly situated entities, the one or more similarly situated entities being situated similarly to the entity; comparing the one or more potential risk triggers to one or more previous risk triggers experienced by the one or more similarly situated entities; identifying one or more similar risk triggers from the one or more previous risk triggers, the one or more similar risk triggers being similar to the one or more potential risk triggers; determining one or more respective risk levels for each of the one or more similar risk triggers; and determining the relevance of the risk posed by the one or more potential risk triggers based at least in part on the one or more respective risk levels for each of the one or more similar risk triggers; identifying, by the computing hardware using one or more data modeling techniques, one or more processing activities performed by the entity that may be affected by the one or more potential risk triggers by analyzing one or more attributes of a data model to determine that the one or more processing activities are performed by the entity, wherein identifying the one or more processing activities that may be affected by the one or more potential risk triggers further comprises: scanning a respective digital inventory for each of the one or more processing activities, each respective digital inventory comprising one or more inventory attributes; and analyzing each respective digital inventory to determine the one or more inventory attributes that may be affected by the one or more potential risk triggers; determining, by the computing hardware, based at least in part on the one or more identified processing activities and the relevance of the risk posed to the entity by the one or more potential risk triggers, whether to take one or more actions in response to the one or more potential risk triggers; and in response to determining to take the one or more actions, facilitating modification, by the computing hardware, of at least one piece of data stored by one or more data assets associated with the one or more identified processing activities. 9. The computer-implemented data processing method of claim 8 , wherein determining whether to take the one or more actions in response to the one or more potenti

Assignees

Inventors

Classifications

  • Risk analysis of enterprise or organisation activities · CPC title

  • G06F21/552Primary

    involving long-term monitoring or reporting · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • Retrieval from the web · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11308435B2 cover?
In various embodiments, a system may be configured to substantially automatically determine whether to take one or more actions in response to one or more identified risk triggers (e.g., data breaches, regulation change, etc.). The system may, for example: (1) compare the potential risk trigger to one or more previous risks triggers experienced by the particular entity at a previous time; (2) i…
Who is the assignee on this patent?
Onetrust Llc
What technology area does this patent fall under?
Primary CPC classification G06Q10/0635. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 19 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).