Data processing systems and methods for populating and maintaining a centralized database of personal data

US11409908B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11409908-B2
Application numberUS-202117234205-A
CountryUS
Kind codeB2
Filing dateApr 19, 2021
Priority dateJun 10, 2016
Publication dateAug 9, 2022
Grant dateAug 9, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A centralized data repository system, in various embodiments, is configured to provide a central data-storage repository (e.g., one or more servers, databases, etc.) for the centralized storage of personally identifiable information (PII) and/or personal data for one or more particular data subjects. In particular embodiments, the centralized data repository may enable the system to populate one or more data models (e.g., using one or more suitable techniques described above) substantially on-the-fly (e.g., as the system collects, processes, stores, etc. personal data regarding a particular data subject). In this way, in particular embodiments, the system is configured to maintain a substantially up-to-date data model for a plurality of data subjects (e.g., each particular data subject for whom the system collects, processes, stores, etc. personal data).

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, by computing hardware, an indication that a first party data system has at least one of collected, transferred, stored, or processed a new piece of personal data for a data subject obtained through a transaction with the data subject; identifying, by the computing hardware, the data subject associated with the new piece of personal data; identifying, by the computing hardware, a processing activity utilizing a data asset involved in the at least one of collecting, transferring, storing, or processing of the new piece of personal data obtained through the transaction by the first party data system, wherein the data asset comprises at least one of a software application, computing system, or data storage; generating, by the computing hardware, based on the processing activity, a unique transaction identifier representing the transaction through which the new piece of personal data is obtained; receiving, by the computing hardware and from a consent receipt management system, an indication that the data subject has not provided valid consent for the processing activity being involved in the least one of collecting, transferring, storing, or processing of the new piece of personal data; obtaining, by the computing hardware and based on the indication that the data subject has not provided the valid consent, a unique consent receipt key from the consent receipt management system, wherein the unique consent receipt key represents a request to be made to the data subject for the valid consent; associating, by the computing hardware in computer memory, the unique consent receipt key with the data subject and with the unique transaction identifier; requesting, by the computing hardware and from the data subject, the valid consent for the processing activity being involved in the at least one of collecting, transferring, storing, or processing of the new piece of personal data; receiving, by the computing hardware and from the data subject, the valid consent for the processing activity being involved in the at least one of collecting, transferring, storing, or processing of the new piece of personal data; and transmitting, by the computing hardware and based on receiving the valid consent for the processing activity being involved in the at least one of collecting, transferring, storing, or processing of the new piece of personal data, the unique consent receipt key and the unique transaction identifier to the consent receipt management system and to a centralized repository of personal data. 2. The method of claim 1 , further comprising: generating, by the computing hardware, a unique identifier associated with the data subject; and transmitting, by the computing hardware, to the centralized repository of personal data, the unique identifier along with the unique consent receipt key and the unique transaction identifier. 3. The method of claim 2 , wherein generating the unique identifier comprises generating, by the computing hardware, the unique identifier using the unique consent receipt key. 4. The method of claim 2 , wherein generating the unique identifier comprises generating, by the computing hardware, the unique identifier using one or more pieces of personal data associated with the data subject. 5. The method of claim 2 , further comprising: generating, by the computing hardware, a consent receipt based on one or more of: (a) the unique identifier, (b) the unique consent receipt key, and (c) the unique transaction identifier; and transmitting, by the computing hardware, the consent receipt to the data subject. 6. The method of claim 1 , wherein requesting the valid consent for the processing activity being involved in processing the new piece of personal data comprises providing, by the computing hardware and to the data subject, a graphical user interface having the new piece of personal data. 7. The method of claim 1 , further comprising transmitting, by the computing hardware and to the centralized repository of personal data, along with the unique consent receipt key and the unique transaction identifier, one or more of: (a) the new piece of personal data, and (b) an indication of a storage location of the new piece of personal data. 8. A system comprising: processing hardware; computer memory communicatively coupled to the processing hardware; and a non-transitory computer-readable medium communicatively coupled to the processing hardware, and storing computer-executable instructions, wherein the processing hardware is configured for executing the computer-executable instructions and thereby performing operations comprising: receiving a first indication that a data system has at least one of collected, transferred, stored, or processed a new piece of personal data for a data subject obtained through a transaction with the data subject; identifying the data subject and a processing activity utilizing a data asset involved in the at least one of collecting, transferring, storing, or processing the new piece of personal data obtained through the transaction, wherein the data asset comprises at least one of a software application, computing system, or data storage; generating, based on the processing activity, a unique transaction identifier representing the transaction with the data subject; receiving a second indication from a consent receipt management system that the data subject has provided valid consent for the processing activity being involved in the least one of collecting, transferring, storing, or processing the new piece of personal data; generating a unique consent receipt key based on a consent receipt associated with the valid consent, wherein the unique consent receipt key represents the valid consent received from the data subject; determining a unique subject identifier to represent the data subject; associating the unique consent receipt key with the unique subject identifier, the unique transaction identifier, and the new piece of personal data in the computer memory; and transmitting the unique consent receipt key, the unique transaction identifier, and the unique subject identifier to a centralized repository of personal data. 9. The system of claim 8 , wherein determining the unique subject identifier comprises : determining that the centralized repository of personal data does not currently store personal data associated with the data subject; and determining the unique subject identifier based on the consent receipt. 10. The system of claim 8 , wherein determining the unique subject identifier comprises identifying the unique subject identifier from among one or more unique subject identifiers stored at the centralized repository of personal data. 11. The system of claim 8 , wherein the operations further comprise: receiving, from the data subject, a request for the new piece of personal data; determining, based on the request for the new piece of personal data, the unique subject identifier associated with the data subject; retrieving, based on the unique subject identifier associated with the data subject, the new piece of personal data; and transmitting the new piece of personal data to the data subject. 12. The system of claim 8 , wherein receiving the first indication comprises receiving a request from the data subject to initiate the transaction through which the new piece of personal data is obtained. 13. The system of claim 12 , wherein the operations further comprise: determining a transaction identifier for the transaction in response to receiving the request; and transmitting the transaction identifier to the cent

Assignees

Inventors

Classifications

  • Ensuring data consistency and integrity · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • Indexing; Data structures therefor; Storage structures · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11409908B2 cover?
A centralized data repository system, in various embodiments, is configured to provide a central data-storage repository (e.g., one or more servers, databases, etc.) for the centralized storage of personally identifiable information (PII) and/or personal data for one or more particular data subjects. In particular embodiments, the centralized data repository may enable the system to populate on…
Who is the assignee on this patent?
Onetrust Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 09 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).