IP Library Granted Patent US 11,651,106
Granted Patent B2
US 11,651,106 · App. 17/530,201 · Granted May 16, 2023

Data processing systems for fulfilling data subject access requests and related methods

Inventors: Kabir A. Barday (Atlanta, GA); Jason L. Sabourin (Brookhaven, GA); Jonathan Blake Brannon (Smyrna, GA); Mihir S. Karanjkar (Marietta, GA); Kevin Jones (Atlanta, GA)
Assignee: OneTrust, LLC
G06F21/6245G06F15/76G06F21/31G06F21/552H04L41/5029H04L41/5064H04L63/102H04L63/107H04L63/108H04L63/12H04L63/20G06F2221/2103G06F2221/2111G06F2221/2137H04L67/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,651,106
App. No.
17/530,201
Filed
Nov 18, 2021
Granted
May 16, 2023
Kind
B2
Art Unit
2191
USPC
726/26
Abstract

Responding to a data subject access request includes receiving the request and identifying the requestor and source. In response to identifying the requestor and source, a computer processor determines whether the data subject access request is subject to fulfillment constraints, including whether the requestor or source is malicious. If so, then the computer processor denies the request or requests a processing fee prior to fulfillment. If not, then the computer processor fulfills the request.

Claims (54)

1. A method comprising:

providing, by computing hardware, a query interface that is accessible via a public data network and that is configured for querying a plurality of data storage systems included in a private data network;

determining, by the computing hardware, that a plurality of queries comprising data subject access requests have been received via the query interface from an Internet Protocol (IP) address;

responsive to determining that the plurality of queries have originated from the IP address, adding a processing constraint for the IP address to fulfillment constraint data in a data repository;

receiving, via the query interface and the public data network, a query comprising a data subject access request from a computing device;

determining, by the computing hardware, that the computing device is associated with the IP address;

querying, by the computing hardware and using the IP address, the fulfillment constraint data from the data repository to identify the processing constraint;

determining, by the computing hardware, that the data subject access request is subject to the processing constraint; and

preventing, based on the determining that the data subject access request is subject to the processing constraint, the plurality of data storage systems from executing processing operations or performing network communication for retrieving data responsive to the data subject access request from a plurality of data sources included in the private data network.

2. The method of claim 1 further comprising:

providing, by the computing hardware, an authorization interface that is accessible via the public data network and that is configured for requesting authorization data from the computing device;

receiving, by the computing hardware and via the authorization interface, the authorization data from the computing device; and

overriding, by the computing hardware, the processing constraint based on receiving the authorization data, wherein overriding the processing constraint permits retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

3. The method of claim 2 , wherein the authorization data comprises at least one of a username, a password, an authorization code, or data confirming payment of a processing fee associated with fulfilling the data subject access request.

4. The method of claim 1 , wherein adding the processing constraint for the IP address to the fulfillment constraint data in the data repository is based on a number of the plurality of queries originating from the IP address satisfying a threshold quantity within a threshold period of time.

5. The method of claim 1 , wherein adding the processing constraint for the IP address to the fulfillment constraint data is based on the IP address being associated with at least one of a competitor of an entity associated with the plurality of data storage systems, a geographic region, a particular political group, or a particular protesting group.

6. The method of claim 1 further comprising storing, by the computing hardware, documentation supporting preventing retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

7. The method of claim 1 further comprising providing, by the computing hardware, for display on the query interface, a reason for preventing retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

8. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium,

wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

determining that a plurality of queries comprising data subject access requests have been received via a query interface from a domain, wherein the query interface is accessible via a public data network and is configured for querying a plurality of data storage systems included in a private data network;

responsive to determining that the plurality of queries have originated from the domain, adding a processing constraint for the domain to fulfillment constraint data in a data repository;

receiving, via the query interface and the public data network, a query comprising a data subject access request from a computing device;

determining that the computing device is associated with the domain;

querying, using the domain, the fulfillment constraint data from the data repository to identify the processing constraint;

determining that the data subject access request is subject to the processing constraint; and

preventing, based on the determining that the data subject access request is subject to the processing constraint, the plurality of data storage systems from executing processing operations or performing network communication for retrieving data responsive to the data subject access request from a plurality of data sources included in the private data network.

9. The system of claim 8 , wherein the operations further comprise:

providing an authorization interface that is accessible via the public data network and that is configured for requesting authorization data from the computing device;

receiving, via the authorization interface, the authorization data from the computing device; and

overriding the processing constraint based on receiving the authorization data, wherein overriding the processing constraint permits retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

10. The system of claim 9 , wherein the authorization data comprises at least one of a username, a password, an authorization code, or data confirming payment of a processing fee associated with fulfilling the data subject access request.

11. The system of claim 8 , wherein adding the processing constraint for the domain to the fulfillment constraint data in the data repository is based on a number of the plurality of queries originating from the domain satisfying a threshold quantity within a threshold period of time.

12. The system of claim 8 , wherein adding the processing constraint for the domain to the fulfillment constraint data is based on the domain being associated with at least one of a competitor of an entity associated with the plurality of data storage systems, a geographic region, a particular political group, or a particular protesting group.

13. The system of claim 8 , wherein the operations further comprise storing documentation supporting preventing retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

14. The system of claim 8 , wherein the operations further comprise providing, for display on the query interface, a reason for preventing retrieval of the data responsive to the data subject access request from the plurality of data sources included in the private data network.

15. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

determining that a first query comprising a first data subject request has been received via a query interface from at least one of an Internet Protocol (IP) address, a domain, or a geographic location wherein the query interface is accessible via a public data network and is configured for querying a data storage system included in a private data network;

responsive to determining the first query has originated from the at least one of the IP address, the domain, or the geographic location, adding a processing constraint for at least one of the IP address, the domain, or the geographic location to fulfillment constraint data in a data repository;

receiving, via the query interface and the public data network, a second query comprising a second data subject access request from a computing device;

determining that the computing device is associated with the at least one of the IP address, the domain, or the geographic location;

querying, using at least one of the IP address, the domain, or the geographic location, the fulfillment constraint data from the data repository to identify the processing constraint;

determining that the second query is subject to the processing constraint; and

preventing, based on the determining that the second query is subject to the processing constraint, the data storage system from executing processing operations or performing network communication for retrieving data responsive to the second query from a data source included in the private data network.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

providing an authorization interface that is accessible via the public data network and that is configured for requesting authorization data from the computing device;

receiving, via the authorization interface, the authorization data from the computing device; and

overriding the processing constraint based on receiving the authorization data, wherein overriding the processing constraint permits retrieval of the data responsive to the second query from the data source included in the private data network.

17. The non-transitory computer-readable medium of claim 16 , wherein the authorization data comprises at least one of a username, a password, an authorization code, or data confirming payment of a processing fee associated with fulfilling the data subject access request.

18. The non-transitory computer-readable medium of claim 15 , wherein adding the processing constraint for at least one of the IP address, the domain, or the geographic location to the fulfillment constraint data is based on at least one of the IP address or the domain being associated with at least one of a competitor of an entity associated with the data storage system, a geographic region, a particular political group, or a particular protesting group.

19. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise storing documentation supporting preventing retrieval of the data responsive to the second query from the data source included in the private data network.

20. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise providing a reason for display on the query interface for preventing retrieval of the data responsive to the second query from the data source included in the private data network.