Data processing systems for webform crawling to map processing activities and related methods
In particular embodiments, a Data Access Webform Crawling System is configured to: (1) identify a webform used to collect one or more pieces of personal data; (2) robotically complete the identified webform; (3) analyze the completed webform to determine one or more processing activities that utilize the one or more pieces of personal data collected by the webform; (4) identify a first data asset in the data model that is associated with the one or more processing activities; (5) modify a data inventory for the first data asset in the data model to include data associated with the webform; and (6) modify the data model to include the modified data inventory for the first data asset.
1 . A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:
identifying an electronic form used to collect personal data for an entity;
completing and submitting the electronic form with test data; and
after completing and submitting the electronic form:
analyzing, based on the test data, computer code associated with the electronic form to identify (i) a processing activity conducted by the entity that makes use of the test data submitted with the electronic form and (ii) a storage location to which the test data is routed and stored for the entity;
identifying a data model comprising a data structure associated with the processing activity and comprising data representing the processing activity, a plurality of data assets associated with the processing activity, links between the plurality of data assets, and a plurality of data attribute inventories, wherein:
the plurality of data assets representing computing software and computing hardware that are used in at least one of collecting, processing, containing, transferring, or storing data for the entity,
each of the plurality of data attribute inventories is associated with a respective data asset of the plurality of data assets and comprises a plurality of fields that defines attributes of at least one of the computing software or the computing hardware represented by the respective data asset, the attributes comprising an asset type of the respective data asset indicating whether the respective data asset is the computing software or the computing hardware, and
each of the links represents a relationship between a first particular data asset of the plurality of data assets and a second particular data asset of the plurality of data assets and a direction of a flow of data transferred between the first particular data asset and the second particular data asset in connection with the at least one of collecting, processing, containing, transferring, or storing the data for the entity;
accessing the data model to determine a first data asset of the plurality of data assets associated with the storage location based on a first data attribute inventory of the plurality of data attribute inventories associated with the first data asset comprising a field of the plurality of fields identifying the storage location; and
modifying the first data attribute inventory associated with the first data asset in the data model to include a field defining data collected via the electronic form.
2 . The non-transitory computer-readable medium of claim 1 , wherein:
the test data comprises a dummy profile that comprises an e-mail address.
3 . The non-transitory computer-readable medium of claim 1 , wherein identifying the electronic form comprises using one or more website scanning means to identify the electronic form by scanning a plurality of websites associated with the entity.
4 . A system comprising;
a non-transitory computer-readable medium storing instructions; and
a processing device communicatively coupled to the non-transitory computer-readable medium,
wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:
accessing a data model comprising a data structure associated with a processing activity and comprising data representing the processing activity, a plurality of data assets associated with the processing activity, a plurality of links between the plurality of data assets, and a plurality of data attribute inventories, wherein:
the plurality of data assets representing computing software and computing hardware that are used in at least one of collecting, processing, containing, transferring, or storing data for an entity,
each of the plurality of links represents a relationship between a first particular data asset of the plurality of data assets and a second particular data asset of the plurality of data assets and a direction of a flow of data transferred between the first particular data asset and the second particular data asset in connection with the at least one of collecting, processing, containing, transferring, or storing the data for the entity, and
each of the plurality of data attribute inventories is associated with a respective data asset of the plurality of data assets and comprises a plurality of fields that defines inventory attributes for at least one of the computing software or the computing hardware represented by the respective data asset, the inventory attributes comprising an asset type of the respective data asset indicating whether the respective data asset is the computing software or the computing hardware;
accessing the data model to determine a first data attribute inventory from the plurality of data attribute inventories, wherein the first data attribute inventory is associated with a first data asset of the plurality of data assets;
determining, for a field of the plurality of fields of the first data attribute inventory, an attribute value for populating the field by:
identifying an electronic form used to collect personal data for the entity;
completing the electronic form using dummy data;
analyzing, based on the dummy data, the electronic form to determine the processing activity, wherein the processing activity is conducted by the entity that utilizes the dummy data from the electronic form, and a storage location to which the dummy data is routed and stored for the entity;
determining, utilizing the data model and according to the plurality of links between the plurality of data assets and directions of flow of data transferred between the plurality of data assets, that the first data asset is associated with the processing activity; and
determining the attribute value based on the dummy data from the electronic form;
in response to determining the attribute value, modifying the first data attribute inventory to include the attribute value for the field by populating the field with the attribute value; and
storing the modified first data attribute inventory in computer memory.
5 . The system of claim 4 , wherein completing the electronic form comprises submitting dummy data via the electronic form.
6 . The system of claim 5 , wherein determining the first data asset is associated with the processing activity comprises discovering the dummy data is stored on the first data asset.
7 . The system of claim 4 , wherein analyzing the electronic form to determine the processing activity that utilizes the personal data collected by the electronic form comprises analyzing computer code associated with the electronic form.
8 . The system of claim 4 , wherein the operations further comprise electronically mapping the first data asset to the processing activity that utilizes the personal data collected by the electronic form.
9 . The system of claim 8 , wherein modifying the first data attribute inventory comprises modifying the first data attribute inventory to include an indication that the processing activity operates with data stored by the first data asset.
10 . The system of claim 4 , wherein the electronic form comprises a webform.
11 . The system of claim 4 , wherein the operations further comprise linking the electronic form to the first data asset.
12 . A method comprising:
identifying, by computing hardware, an electronic form used to collect personal data for an entity;
completing and submitting the electronic form, by the computing hardware, by submitting test data via the electronic form;
after completing and submitting the electronic form, determining, by the computing hardware and based on the test data, a storage location to which the test data is routed and stored for the entity, wherein the storage location is associated with a first data asset defined in a data structure of a data model, the first data asset represents at least one of computing software or the computing hardware that is used in at least one of collecting, processing, containing, transferring, or storing data for the entity and is associated with a processing activity conducted by the entity that makes use of the test data submitted with the electronic form, wherein the data model is associated with the processing activity and comprises a data structure with data representing the processing activity, a plurality of data assets representing the computing software and the computing hardware used in connection with the processing activity, links between the plurality of data assets representing relationships between the plurality of data assets and a direction of a flow of data transferred between the plurality of data assets, and a plurality of data inventories;
in response to determining the storage location, identifying, by the computing hardware and by accessing the data model, that the first data asset is associated with the storage location; and
modifying a data inventory for the first data asset in the data model, by the computing hardware, wherein the data inventory comprises a plurality of attribute fields that defines attributes of at least one of the computing software or the computing hardware represented by the first data asset, the attributes comprising an asset type of the first data asset indicating whether the first data asset is the computing software or the computing hardware, and modifying the data inventory comprises:
determining an attribute value for an attribute field of the plurality of attribute fields for the data inventory based on the test data submitted with the electronic form;
modifying the data inventory by populating the attribute field with the attribute value to generate a modified data inventory that comprises an indication that the processing activity makes use of the data collected through the electronic form; and
modifying the data model to include the modified data inventory.
13 . The method of claim 12 , wherein identifying the electronic form used to collect the personal data for the entity comprises using one or more website scanning means to identify the electronic form by scanning a plurality of websites associated with the entity.
14 . The method of claim 12 , wherein:
the test data comprises an e-mail address; and
the method further comprises monitoring an e-mail account associated with the e-mail address for a confirmation e-mail related to completing the electronic form.
15 . The method of claim 14 further comprising extracting, by the computing hardware, the test data from the confirmation e-mail associated with the electronic form.
16 . The method of claim 15 further comprising adding, by the computing hardware, the first data asset to a third-party data repository with an electronic link to the electronic form.
17 . The non-transitory computer-readable medium of claim 3 , wherein the electronic form is hosted on a particular website of the plurality of websites.
18 . The non-transitory computer-readable medium of claim 3 , further comprising modifying the data model to include the modified first data attribute inventory to include a mapping of the first data asset to the processing activity that makes use of the test data submitted with the electronic form.
19 . The method of claim 12 , wherein modifying the data inventory further comprises adding an indication to the data inventory that the processing activity operates with data included in the first data asset in connection with the data collected through the electronic form.
20 . The method of claim 12 , wherein modifying the data model comprises generating mappings of the first data asset to a plurality of processing activities that utilize the test data submitted via the electronic form.