DATA PROCESSING SYSTEMS AND METHODS FOR EFFICIENTLY COMMUNICATING DATA FLOWS IN PRIVACY CAMPAIGNS
Data processing systems and methods for retrieving data regarding a plurality of data privacy campaigns and for using that data to assess a relative risk associated with the data privacy campaign. In various embodiments, the system may be adapted to: (1) display one or more visual summaries of one or more data flow diagrams that visually depicts key features of the data flow, such as whether data is confidential and/or encrypted; (2) allow for multiple users to be assigned responsibility for populating different respective questions that are required to define the data flow; (3) automatically assess and display a relative risk associated with each campaign; and (4) automatically set, monitor, and facilitate the timely completion of an audit schedule for each campaign.
1 . A computer-implemented data processing method for generating a data flow diagram for a privacy campaign, comprising:
displaying on a graphical user interface a prompt to create an electronic record for a privacy campaign;
receiving a command to create an electronic record for the privacy campaign;
creating an electronic record for the privacy campaign and digitally storing the record;
presenting on one or more graphical user interfaces a plurality of prompts for the input of campaign data related to the privacy campaign;
electronically receiving campaign data input by one or more users, wherein the campaign data relates to:
a description of the campaign;
one or more types of personal data related to the campaign;
a subject from which the personal data was collected;
the storage of the personal data; and
access to the personal data;
processing the campaign data by electronically associating the campaign data with the record for the privacy campaign;
generating for display a data flow diagram on a computer-generated graphical user interface, wherein the data flow diagram comprises indicators related to the accessibility and encryption of the personal data related to the campaign.
2 . The method of claim 1 , wherein the data flow diagram comprises a heading indicative of the source of the personal data, the storage destination of the personal data, and access related to the personal data.
3 . The method of claim 2 , wherein the method further comprises:
generating one or more on on-screen objects shown in the data flow diagram, wherein each object contains a hyperlink label indicative of the source of the personal data, the storage destination of the personal data, and access related to the personal data, wherein additional campaign data relating to the campaign data associated with the hyperlinked word is displayed if a cursor is moved over the hyperlink label.
4 . The method of claim 3 , wherein the method further comprises:
based on the campaign data associated with the campaign, determining whether the personal data related to each of the hyperlink labels is confidential;
if the personal data is confidential, generate an indicator indicating that the data associated with the hyperlink label is confidential.
5 . The method of claim 4 , wherein the indicator is an “open eye” icon.
6 . The method of claim 2 , wherein the method further comprises:
generating for display information relating to whether the source of the personal data includes minors, and
generating for display an indication of whether consent was given by the source of the personal data to use the sensitive information.
7 . The method of claim 6 , wherein indication of whether consent was given comprises displaying the manner in which the consent was given.
8 . The method of claim 2 , wherein the method further comprises displaying on the data flow diagram one or more parameters related to the backup and retention of the personal data in the storage destination of the personal data.
9 . The method of claim 2 , wherein the method further comprises generating on the data flow diagram data flow lines having arrows to indicate the data flow of personal data from source, to storage destination, to which entities or applications have access.
10 . The method of claim 9 , wherein the data flow lines are colored differently to indicate whether the data flow is encrypted or unencrypted.
11 . The method of claim 10 , wherein the colors of the lines are distinguishable by a viewer that suffers from color blindness.
12 . The method of claim 2 , wherein the method further comprises:
determining whether any of the data associated with the source, stored in a storage destination, being used by an entity or application, or data flow of data flowing to one or more entities or systems associated with the campaign is designated as encrypted.
13 . The method of claim 12 , wherein the method further comprises:
generating a locked lock icon to indicate encrypted data; and
generating an unlocked lock icon to indicate unencrypted data.
14 . The method of claim 13 , wherein the method further comprises:
generating a locked lock icon to indicate encrypted data flow; and
generating an unlocked lock icon to indicate unencrypted data flow.
15 . A computer-implemented data processing method for generating a data flow diagram for a privacy campaign, comprising:
electronically retrieving campaign data associated with a privacy campaign wherein the campaign data relates to:
a description of the campaign;
one or more types of personal data related to the campaign;
a subject from which the personal data was collected;
the storage of the personal data; and
access to the personal data; and
generating for display a data flow diagram on a computer-generated graphical user interface, wherein the data flow diagram comprises:
data flow lines having arrows to indicate the data flow of personal data from source, to storage destination, to which entities or applications have access;
an indicator indicating the confidentiality of the personal data related to the campaign;
an indicator indicating the encryption status of the personal data related to the campaign.
16 . The method of claim 15 , wherein the data flow lines are colored differently to indicate whether the data flow is encrypted or unencrypted.
17 . The method of claim 16 , wherein the colors of the lines are distinguishable by a viewer that suffers from color blindness.
18 . The method of claim 15 , wherein the indicator indicating confidentiality is an “open eye” icon.
19 . The method of claim 15 , wherein the indicator indicating encryption status comprises a locked lock icon.
20 . The method of claim 15 , wherein the indicator indicating encryption status comprises an unlocked lock icon.
21 . A computer-implemented data for displaying information associated with a privacy campaign, comprising:
electronically retrieving a plurality of campaign records and the campaign data associated with each record, wherein the campaign data was input by one or more users through a plurality of prompts presented on one or more graphical user interfaces;
generating for display a computer-generated user interface comprising an inventory page, wherein the inventory page displays:
a list of the plurality of campaigns;
visual indicators for one or more of the plurality of campaigns that represent an overall risk assessment, wherein the overall risk assessment is based upon an electronically calculated risk level; and
audit information for one or more of the plurality of campaigns, wherein the audit information is based upon the audit schedule.
22 . The method of claim 21 , wherein the visual indicators comprise at least one type of visual indicator selected from a group indicators consisting of:
an upward pointing arrow;
a downward pointing arrow; and
different colors for each overall risk assessment level.
23 . The method of claim 21 , wherein risk level is electronically calculated as the sum of a plurality of: a weighting factor multiplied by the relative risk rating of the factor.
24 . The method of claim 21 , wherein the audit information comprises whether an audit associated with the campaign is pending, complete, or due.
25 . The method of claim 21 , wherein whether the audit associated with the campaign is due is indicated by the number of days before the audit is to be conducted.