IP Library Granted Patent US 10,169,788
Granted Patent B2
US 10,169,788 · App. 15/894,809 · Granted Jan 1, 2019

Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments

Inventor: Kabir A. Barday (Atlanta, GA)
Assignee: OneTrust, LLC
G06Q30/0609G06Q10/0635G06Q10/063114G06Q50/265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,169,788
App. No.
15/894,809
Granted
Jan 1, 2019
Kind
B2
Abstract

Data processing computer systems, in various embodiments, are adapted for: (1) presenting a threshold privacy assessment that includes a first set of privacy-related questions for a privacy campaign; (2) receiving respective answers to the first set of questions; (3) using this initial set of answers to calculate an initial privacy risk score for the privacy campaign; (4) determining whether the privacy risk score exceeds the threshold privacy risk value; (5) in response to the privacy risk score exceeding the threshold privacy risk value, providing one or more supplemental questions to the user to facilitate the completion of a full privacy impact assessment. In some embodiments, in response to determining that the privacy risk score does not exceed the threshold privacy risk value, the systems and methods provide an indication that the particular privacy campaign is a relatively low privacy campaign.

Claims (63)

1. A computer-implemented data processing method for efficiently conducting privacy risk assessments for a plurality of privacy campaigns, the method comprising, for each of the plurality of privacy campaigns:

presenting, by one or more processors, a threshold privacy assessment to a user that includes a first set of one or more questions for a first plurality of question/answer pairings that identify one or more privacy characteristics of a particular privacy campaign;

receiving, by one or more processors, respective answers for the first plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign;

determining, by one or more processors, a threshold privacy risk score for the particular privacy campaign that identifies a level of risk for one or more of the privacy characteristics indicated in the question/answer pairings, wherein determining the threshold privacy risk score for the particular privacy campaign comprises determining a risk level based at least in part on the one or more privacy characteristics;

comparing, by one or more processors, the threshold privacy risk score to a threshold privacy risk value, the threshold privacy risk value indicating a pre-determined level of risk regarding the one or more privacy characteristics of the particular privacy campaign;

determining, by one or more processors, whether the threshold privacy risk score exceeds the threshold privacy risk value;

in response to determining that the threshold privacy risk score exceeds the threshold privacy risk value:

providing, by one or more processors, a privacy impact assessment to the user that includes a second set of questions for a second plurality of question/answer pairings that identify one or more privacy characteristics of the particular privacy campaign, the second set of one or more questions including one or more questions that are different from questions within the first set of one or more questions; and

determining, by one or more processors, a second risk score based at least in part on the second plurality of question/answer pairings by:

determining a weighting factor for each of the second plurality of question/answer pairings, the second plurality of question/answer pairings including:

a nature of personal data collected as part of the particular privacy campaign;

electronically determining a relative risk rating for each of the second plurality of question/answer pairings;

electronically calculating the second risk score based upon, for each of the second plurality of question/answer pairings, the relative risk rating and the weighting factor; and

electronically associating the second risk score with the particular privacy campaign.

2. The computer-implemented data processing method of claim 1 , wherein the second plurality of question/answer pairings further includes at least one additional question/answer pairing related to one or more privacy characteristics selected from the group consisting of:

a physical storage location of the personal data collected as part of the particular privacy campaign;

a length of time that the personal data collected as part of the particular privacy campaign will be retained in storage; and

a country of residence of at least one data subject from which the personal data was collected as part of the particular privacy campaign.

3. The computer-implemented data processing method of claim 1 , the method further comprising automatically initiating the privacy impact assessment that includes the second set of questions in response to determining that the threshold privacy risk score exceeds the threshold privacy risk value.

4. The computer-implemented data processing method of claim 1 , wherein the second plurality of question/answer pairings comprises a greater number of question/answer pairings than the first plurality of question/answer pairings.

5. The computer-implemented data processing method of claim 1 , wherein determining the threshold privacy risk score for the particular privacy campaign comprises determining a risk level based at least in part on the one or more privacy characteristics by assigning a weighting factor to each of the one or more privacy characteristics.

6. The computer-implemented data processing method of claim 1 , the system is configured to receive the threshold privacy risk value from one or more privacy officers associated with the privacy campaign.

7. The computer-implemented data processing method of claim 6 , wherein the system is configured adjusted the threshold privacy risk value based on a type of campaign for the particular privacy campaign.

8. The computer-implemented data processing method of claim 1 , wherein:

the respective answers for the first plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign comprise an indication of a particular type of personal data collected as part of the particular privacy campaign; and

the method further comprises:

assigning a risk level to the particular type of personal data that exceeds the threshold privacy risk value; and

automatically initiating the privacy impact assessment that includes the second set of questions in response to the respective answers for the first plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign comprising the indication that the particular type of personal data is collected as part of the particular privacy campaign.

9. The computer-implemented data processing method of claim 1 , wherein the particular type of personal data comprises credit card information.

10. A computer-implemented data processing method for efficiently conducting privacy risk assessments for a plurality of privacy campaigns, the method comprising, for each of the plurality of privacy campaigns:

presenting, by one or more processors, a threshold privacy assessment to a user that includes a first set of one or more questions for a first plurality of question/answer pairings that identify one or more privacy characteristics of the particular privacy campaign;

receiving, by one or more processors, respective answers for the first plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign;

determining, by one or more processors, a privacy risk score for the particular privacy campaign that identifies a level of risk for one or more of the privacy characteristics indicated in the first plurality of question/answer pairings;

comparing, by one or more processors, the privacy risk score to a threshold privacy risk value, the threshold privacy risk value indicating a pre-determined level of risk regarding the one or more privacy characteristics of the particular privacy campaign;

determining, by one or more processors, that the privacy risk score exceeds the threshold privacy risk value;

providing, by one or more processors and to one or more privacy officers, (1) a first selection option to initiate a privacy impact assessment to be provided to the user that includes a second set of questions for a second plurality of question/answer pairings that identify one or more privacy characteristics of the particular privacy campaign, the second set of one or more questions includes one or more questions that are supplemental to the first set of one or more questions and (2) a second selection option to indicate that the particular privacy campaign is a low privacy risk campaign;

in response to receiving an indication of selection of the first selection option by the one or more privacy officers, providing, by one or more processors, the full privacy impact assessment to the user;

in response to providing the full privacy assessment to the user:

receiving, by one or more processors, respective answers for the second plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign;

using one or more computer processors to calculate a risk score based on the respective answers for the second plurality of question/answer pairings and the one or more privacy characteristics of the particular privacy campaign, wherein calculating the risk score comprises:

electronically identifying a weighting factor for each of the second plurality of question/answer pairings, wherein the one or more privacy characteristics include:

a number of individuals having access to the personal data associated with the particular privacy campaign; and

a type of individual from which the personal data associated with the particular privacy campaign originated; and

electronically identifying a relative risk rating for each of the second plurality of question/answer pairings; and

electronically calculating the risk score based upon, for each respective one of the second plurality of question/answer pairings, the relative risk rating, and the weighting factor; and

in response to receiving an indication of selection of the second selection option by the one or more privacy officers, storing, by one or more processors, an indication that the particular privacy campaign is a low privacy risk campaign.

11. The computer-implemented data processing method of claim 10 , wherein the privacy risk score is determined by associating a weighting factor with each question in the first set of questions.

12. The computer-implemented data processing method of claim 11 , wherein associating a weighting factor for each question in the first set of questions further comprises:

determining that a first question in the first set of questions identifies a greater privacy impact than a second question in the first set of questions; and

assigning a weight to the first question in the first set of questions that is greater than a weight to be assigned to the second question in the first set of questions.

13. The computer-implemented data processing method of claim 10 , wherein determining the privacy risk score for the particular campaign further comprises:

determining that a question in a particular question/answer pairing for the first plurality of question/answer pairings includes an answer, for the particular question/answer pairing, that provides a particular response; and

automatically determining that the privacy risk score for the particular privacy campaign exceeds the threshold privacy risk value in response to determining that the question in the particular question/answer pairing for the first plurality of question/answer pairings includes the answer that provides the particular response.

14. The computer-implemented data processing method of claim 13 , wherein the threshold privacy risk value is based at least in part on a type of campaign for the particular privacy campaign.

15. The computer-implemented data processing method of claim 14 , wherein the one or more privacy characteristics comprise a nature of the personal data collected as part of the particular privacy campaign.

16. The computer-implemented data processing method of claim 10 , wherein the first plurality of question/answer pairings include one or more answers that indicate a physical storage location of personal data collected as part of the particular privacy campaign.

17. The computer-implemented data processing method of claim 10 , wherein:

the second plurality of question/answer pairings include one or more answers that indicate a country to which the personal data collected as part of the particular privacy campaign will be transferred; and

the one or more privacy characteristics comprise inter-country transfer data for the personal data collected as part of the particular privacy campaign.

18. The computer-implemented data processing method of claim 10 , wherein:

the first plurality of question/answer pairings include one or more answers that indicate purpose of collecting the personal data collected as part of the particular privacy campaign; and

determining the privacy risk score for the particular privacy campaign that identifies a level of risk for one or more of the privacy characteristics indicated in the first plurality of question/answer pairings comprises determining the privacy risk score based at least in part on the purpose of collecting the personal data.

19. The computer-implemented data processing method of claim 10 , the method further comprising automatically providing, by one or more computer processors, the full privacy assessment to the user in response to determining that the privacy risk score exceeds the threshold privacy risk value.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2024
From: CHENNUR, RAJANANDINI
To: ONETRUST, LLC
Reel/Frame 067237/0784 →
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2018
From: BARDAY, KABIR A.
To: ONETRUST, LLC
Reel/Frame 044905/0654 →
Continuity (8)
Continuation 15619459 · Jun 10, 2017
Continuation In Part 15256419 · Sep 2, 2016
Continuation 15169643 · May 31, 2016
Provisional Application 62317457 · Apr 1, 2016
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Related Publication 20180182008A1 · Jun 28, 2018