DATA PROCESSING SYSTEMS AND METHODS FOR IMPLEMENTING AUDIT SCHEDULES FOR PRIVACY CAMPAIGNS
Data processing systems and methods for retrieving data regarding a plurality of data privacy campaigns and for using that data to assess a relative risk associated with the data privacy campaign. In various embodiments, the system may be adapted to: (1) display one or more visual summaries of one or more data flow diagrams that visually depicts key features of the data flow, such as whether data is confidential and/or encrypted; (2) allow for multiple users to be assigned responsibility for populating different respective questions that are required to define the data flow; (3) automatically assess and display a relative risk associated with each campaign; and (4) automatically set, monitor, and facilitate the timely completion of an audit schedule for each campaign.
1 . A computer-implemented data processing method for assigning an audit schedule for a privacy audit associated with a privacy campaign comprising:
displaying on a graphical user interface a prompt to create an electronic record for a privacy campaign;
receiving a command to create an electronic record for the privacy campaign;
creating an electronic record for the privacy campaign and digitally storing the record;
presenting on one or more graphical user interfaces a plurality of prompts for the input of campaign data related to the privacy campaign;
electronically receiving campaign data input by one or more users, wherein the campaign data relates to:
a description of the campaign;
one or more types of personal data related to the campaign;
a subject from which the personal data was collected;
the storage of the personal data; and
access to the personal data;
processing the campaign data by electronically associating the campaign data with the record for the privacy campaign;
digitally storing the campaign data associated with the record for the campaign;
assigning a privacy audit schedule for the campaign based on the risk associated with the campaign, wherein the audit schedule comprises a timeframe until the scheduled privacy audit.
2 . The method of claim 1 , wherein the risk associated with the campaign comprises a risk level for the campaign.
3 . The method of claim 1 , wherein the risk associated with the campaign comprises an overall risk assessment for the campaign.
4 . The method of claim 2 , wherein the audit schedule is a default audit schedule predetermined for the risk associated with the campaign.
5 . The method of claim 3 , wherein the default audit schedule is based on privacy laws.
6 . The method of claim 4 , wherein the default audit schedule is a modifiable.
7 . The method of claim 1 , wherein the method further comprises:
receiving an input to modify the audit schedule assigned to the campaign; and
determining whether the audit schedule assigned to the campaign is modifiable.
8 . The method of claim 7 , wherein the method further comprises:
if the audit schedule assigned to the campaign is modifiable, modifying the audit schedule for the campaign.
9 . The method of claim 7 , wherein the method further comprises:
if the audit schedule is not modifiable, electronically displaying an indication that the audit schedule is not modifiable;
receiving a request to modify the audit schedule for the campaign; and
sending an electronic message to persons having the authority to grant permission to modify the audit schedule.
10 . The method of claim 1 , wherein the method further comprises:
determining whether a threshold amount of time until the privacy audit has been reached;
if the threshold has been reached, generating an electronic alert indicating that the privacy audit deadline is in the threshold amount of time.
11 . The method of claim 1 , wherein the method further comprises:
receiving an electronic confirmation that the scheduled privacy audit has been completed;
resetting the audit schedule's timeframe until the next privacy audit.
12 . The method of claim 11 , wherein the electronic confirmation received is based upon an electronic verification generated when all portions of the audit have been verified as completed by one or more collaborators.
13 . The method of claim 11 , wherein the method further comprises:
receiving documentation related to the compliance of the privacy campaign;
electronically associating the documentation received with the record of the campaign;
digitally storing the documentation associated with the record for the campaign in an electronic storage device.
14 . The method of claim 1 , wherein the method further comprises:
determining if the scheduled privacy audit is overdue based on whether an electronic confirmation that the scheduled privacy audit has been completed has been received; and
if the scheduled privacy audit is overdue, generating an electronic alert indicating that the privacy audit is overdue.
15 . The method of claim 1 , wherein the method further comprises:
electronically retrieving the campaign record and the campaign data associated with the record; and
generating for display a computer-generated user interface comprising an inventory page, wherein the inventory page displays a list of a plurality of campaigns and audit information for one or more of the plurality of campaigns.
16 . The method of claim 15 , wherein the audit information comprises whether an audit associated with the campaign is pending, complete, or due.
17 . The method of claim 16 , wherein whether the audit associated with the campaign is due is indicated by the number of days before the audit is to be conducted.
18 . (canceled)
19 . (canceled)
20 . (canceled)
21 . (canceled)
22 . (canceled)
23 . (canceled)