IP Library › Granted Patent US 10,839,099
Granted Patent B2
US 10,839,099 · App. 15/818,695 · Granted Nov 17, 2020

General data protection regulation (GDPR) infrastructure for microservices and programming model

Inventors: Matthias Vogel (Saarbrücken, DE); Thorsten Bruckmeier (Walldorf, DE); Francesco Di Cerbo (Antibes, IT)
Assignee: SAP SE
G06F21/6245G06Q50/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,099
App. No.
15/818,695
Granted
Nov 17, 2020
Kind
B2
Abstract

A system for protecting personal data is disclosed. The system includes a general data privacy regulator module having a dataflow controller configured to monitor data communicated to and from one or more business applications, and having a retention engine configured to retain personal information from the data communicated to and from the business application according to at least one data privacy regulation. The system further includes a data privacy compliance module connected with the general data privacy regulator module, and configured with the data privacy regulation to monitor the dataflow controller and report to a client computer. The system further includes a data subject privacy request module connected with the general data privacy regulator module and the data privacy compliance module, and configured to receive one or more requests from the cloud computing platform about a data subject stored by the business application and generate an action based on the one or more requests.

Claims (39)

1. A system for protecting personal data in an application hosted in a cloud computing platform, the system comprising:

at least one processor; and

at least one memory including program code which when executed by at least one processor cause at least:

a general data privacy regulator module having a dataflow controller, an authorization report module, a retention engine, and an application repository, the data flow controller configured to monitor data communicated to and from the application, the authorization report module configured to report about authorization in place to protect the personal data and to determine one or more potential users having access to the personal data, the retention engine configured to retain personal data from the data communicated to and from the application if the personal data is required by a data privacy regulation and to delete personal data not required by the data privacy regulation, the application repository storing a list of at least the application having personal data;

a data privacy compliance module connected with the general data privacy regulator module, the data privacy compliance module being configured, with the data privacy regulation, to monitor the dataflow controller and report to a client computer; and

a data subject privacy request module connected with the general data privacy regulator module and the data privacy compliance module, the data subject privacy request module being configured to receive one or more requests from the cloud computing platform about a data subject stored by the application, and generate an action based on the one or more requests, the one or more requests indicating a request for one or more of the following: information about the data subject, purpose of use of the personal data, consent information to use the personal data, a change to the personal data, withdrawal of consent to use the personal data, deletion of the personal data, anonymization of the personal data, and transport to another data controller.

2. The system in accordance with claim 1 , further comprising:

a consent form service module configured to generate an electronic consent form in accordance with legal rules, the electronic consent form being deliverable to a user related to the personal data.

3. The system in accordance with claim 1 , further comprising a system settings module configured to handle settings and changes to the settings of the general data privacy regulator module.

4. The system in accordance with claim 1 , further comprising a log services module in communication with the application and configured to provide a read access log (RAL) to log read actions by a client, and a change log (CL) to log changes to personal data.

5. The system in accordance with claim 4 , wherein the log services module further includes a security log to log security events.

6. A method for protecting personal data in an application hosted in a cloud computing platform, the method comprising:

monitoring, by a dataflow controller of a general data privacy regulator module, data communicated to and from the application, the general data privacy regulator module including the dataflow controller, an authorization report module, a retention engine, and an application repository;

reporting, by the authorization report module, about authorization in place to protect the personal data and to determine one or more potential users having access to the personal data;

retaining, by the retention engine, personal data from data communicated to and from the application if the personal data is required by a data privacy regulation and to delete personal data not required by the data privacy regulation;

storing, by the application repository, a list of at least the application having personal data;

monitoring, by a data privacy compliance module being configured with the data privacy regulation, the dataflow controller and report to a client computer, the data privacy compliance module connected with the general data privacy regulator module; and

receiving, by a data subject privacy request module connected with the general data privacy regulator module and the data privacy compliance module, one or more requests from the cloud computing platform about a data subject stored by the application, and generate an action based on the one or more requests, the one or more requests indicating a request for one or more of the following: information about the data subject, purpose of use of the personal data, consent information to use the personal data, a change to the personal data, withdrawal of consent to use the personal data, deletion of the personal data, anonymization of the personal data, and transport to another data controller.

7. The method in accordance with claim 6 , further comprising:

generating, by a consent form service module, an electronic consent form in accordance with legal rules, the electronic consent form being deliverable to a user related to the personal data.

8. The method in accordance with claim 6 , further comprising:

handling, by a system settings module, settings and changes to the settings of the general data privacy regulator module.

9. The method in accordance with claim 6 , further comprising:

providing, by a log services module in communication with the application, a read access log (RAL) to log read actions by a client, and a change log (CL) to log changes to personal data.

10. The method in accordance with claim 9 , wherein the log services module further includes a security log to log security events.

11. A non-transitory computer-readable storage medium including program code which when executed by at least one processor causes operations comprising:

monitoring, by a dataflow controller of a general data privacy regulator module, data communicated to and from the application, the general data privacy regulator module including the dataflow controller, an authorization report module, a retention engine, and an application repository;

reporting, by the authorization report module, about authorization in place to protect the personal data and to determine one or more potential users having access to the personal data;

retaining, by the retention engine, personal data from data communicated to and from the application if the personal data is required by a data privacy regulation and to delete personal data not required by the data privacy regulation;

storing, by the application repository, a list of at least the application having personal data;

monitoring, by a data privacy compliance module being configured with the data privacy regulation, the dataflow controller and report to a client computer, the data privacy compliance module connected with the general data privacy regulator module; and

receiving, by a data subject privacy request module connected with the general data privacy regulator module and the data privacy compliance module, one or more requests from the cloud computing platform about a data subject stored by the application, and generate an action based on the one or more requests, the one or more requests indicating a request for one or more of the following: information about the data subject, purpose of use of the personal data, consent information to use the personal data, a change to the personal data, withdrawal of consent to use the personal data, deletion of the personal data, anonymization of the personal data, and transport to another data controller.

12. The non-transitory computer-readable storage medium in accordance with claim 11 , further comprising:

generating, by a consent form service module, an electronic consent form in accordance with legal rules, the electronic consent form being deliverable to a user related to the personal data.

13. The non-transitory computer-readable storage medium in accordance with claim 11 , further comprising:

handling, by a system settings module, settings and changes to the settings of the general data privacy regulator module.

14. The non-transitory computer-readable storage medium in accordance with claim 11 , further comprising:

providing, by a log services module in communication with the application, a read access log (RAL) to log read actions by a client, and a change log (CL) to log changes to personal data.

15. The non-transitory computer-readable storage medium in accordance with claim 14 , wherein the log services module further includes a security log to log security events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2019
From: VOGEL, MATTHIAS; BRUCKMEIER, THORSTEN; DI CERBO, FRANCESCO
To: SAP SE
Reel/Frame 049879/0681 →
Continuity (1)
Related Publication 20190156053A1 · May 23, 2019
Cited By (22)
US 12,189,813 US 12,210,897 US 12,216,716 US 12,277,239 US 12,299,168 US 12,306,996 US 12,321,367 US 12,327,112 US 12,353,594 US 12,411,826 US 12,417,294 US 12,475,253 US 12,488,145 US 12,493,475 US 12,499,263 US 12,541,612 US 12,541,617 US 12,579,304 US 12,645,828 US 12,688,327 US 12,705,380 US 12,748,876