Data processing systems and methods for operationalizing privacy compliance via integrated mobile applications
View Patent ↗Data processing systems and methods for receiving data regarding a plurality of data privacy campaigns and for using that data to calculate or modify a relative risk associated with the campaign based on the received data. In various embodiments, the system may be adapted to: (1) receive processing activity data input by users via a software application presented on graphical user interface for one or more privacy campaigns; (2) automatically assess and display a relative risk associated with each campaign; (3) providing a software application via which a user may provide one or more inputs, for example, capture an image; and (4) automatically update the relative risk for the campaign based on the information provided in the one or more inputs. In some embodiments, the system is configured to enable a user, via the software application, to view information related to the privacy campaign, modify that data, etc.
1. A computer-implemented data processing method for electronically receiving the input of processing activity data related to a processing activity and electronically calculating a risk level for the processing activity based on the data inputs comprising:
providing a software application for installation on a computing device;
displaying on a graphical user interface, via the software application, a prompt to create an electronic record for a processing activity, wherein the processing activity utilizes personal data collected from at least one or more persons or one or more entities;
receiving a command to create an electronic record for the processing activity;
creating an electronic record for the processing activity and digitally storing the record;
presenting, on one or more graphical user interfaces, a plurality of prompts for the input of processing data related to the processing activity;
electronically receiving processing activity data input by one or more users via the graphical user interface, wherein the processing activity data identifies each of:
a description of the processing activity;
one or more types of personal data related to the processing activity;
a subject from which the personal data was collected;
the storage of the personal data; and
access to the personal data;
processing the processing activity data by electronically associating the processing activity data with the record for the processing activity;
receiving, via the software application, one or more inputs related to processing activity, the one or more inputs comprising an image of a privacy incident captured using the computing device;
automatically scanning the image of the privacy incident;
analyzing the scanned image to identify the processing activity associated with the privacy incident;
modifying the electronic record for the processing activity based at least in part on the one or more inputs;
analyzing the image to identify one or more contents in the image;
determining, based at least in part on the one or more contents, whether to modify a risk level for the processing activity; and
in response to determining to modify the risk level, calculating an updated risk level for the processing activity by:
identifying a plurality of risk factors for the processing activity, wherein each of the plurality of risk factors has a risk rating and an associated weighting factor and the plurality of risk factors includes:
a type of the personal data collected as part of the processing activity; and
storage information for the personal data collected as part of the processing activity;
electronically modifying the risk rating for at least one of the plurality of risk factors;
after modifying the risk rating for at least one of the plurality of risk factors, electronically calculating the updated risk level for the processing activity based upon, for each respective one of the plurality of risk factors, the risk rating and the weighting factor for the risk factor; and
digitally storing the updated risk level associated with the record for the processing activity.
2. The computer-implemented data processing method of claim 1 , wherein the method further comprises:
electronically calculating the updated risk level for the processing activity based upon one or more risk factors selected from the group consisting of:
a nature of the personal data associated with the processing activity;
a physical storage location of the personal data associated with the processing activity;
a length of time that the personal data associated with the processing activity will be retained in storage; and
a type of individual from which the personal data associated with the processing activity originated; and
digitally storing the updated risk level associated with the record for the processing activity.
3. The computer-implemented data processing method of claim 1 , wherein the one or more inputs comprise one or more images of one or more privacy incident documents.
4. The computer-implemented data processing method of claim 3 , wherein:
the one or more images comprise one or more pieces of the personal data; and
the method further comprises analyzing the one or more images to identify the one or more pieces of personal data.
5. The computer-implemented data processing method of claim 4 , wherein modifying the electronic record for the processing activity based at least in part on the one or more inputs comprises adjusting the risk level associated with the processing activity based on the one or more pieces of personal data.
6. The computer-implemented data processing method of claim 4 , wherein modifying the electronic record for the processing activity based at least in part on the one or more inputs comprises modifying an audit schedule of the processing activity based on the one or more pieces of personal data.
7. The computer-implemented data processing method of claim 4 , wherein the one or more images are one or more images selected from the group consisting of:
one or more images captured with an imaging device associated with the computing device; and
one or more screenshots from a display screen associated with the computing device.
8. The computer-implemented data processing method of claim 1 , wherein:
the method further comprises measuring a privacy maturity of a particular organization;
the one or more inputs related to the processing activity comprise one or more responses to one or more training questionnaires; and
measuring the privacy maturity of the particular organization comprises modifying the measured privacy maturity based at least on part on the one or more responses.
9. The computer-implemented data processing method of claim 8 , further comprising:
modifying a risk level associated with the processing activity based at least in part on the measured privacy maturity.
10. A computer-implemented data processing method comprising:
providing a software application for installation on a computing device;
displaying on a graphical user interface, via the software application, a prompt to modify an electronic record for a processing activity, wherein the processing activity utilizes personal data collected from at least one or more persons or one or more entities;
receiving, from a user of the computing device, first information associated with the processing activity;
modifying the electronic record for the processing activity based at least in part on the first information;
receiving, via the software application, an input of second information related to the processing activity, wherein the second information comprises an image of a particular privacy incident;
scanning one or more contents of the second information;
identifying one or more keywords in the one or more contents of the second information;
determining, based at least in part on the one or more keywords identified in the second information, whether to modify a risk level for the particular processing activity; and
in response to determining to modify the risk level:
modifying at least one risk rating of a plurality of risk ratings, wherein each of the plurality of risk ratings are associated with a respective piece of the first information; and
calculating an updated risk level for the processing activity based at least in part on the modified at least one risk rating, the plurality of risk ratings, and a
weighting factor associated with each respective piece of the first information; and
displaying, on the graphical user interface, the second information associated with the processing activity, wherein:
the second information comprises information selected from a group consisting of:
one or more responses to one or more screening questions;
one or more pieces of information related to the particular privacy incident associated with the processing activity;
one or more response to one or more training quizzes.
11. The computer-implemented data processing method of claim 10 , wherein:
the first information comprises the one or more pieces of information related to the particular privacy incident; and
the method further comprises:
analyzing the one or more pieces of information related to the particular privacy incident; and
modifying an audit schedule for the processing activity based at least in part on the analysis.
12. The computer-implemented data processing method of claim 11 , wherein the one or more pieces of information related to the particular privacy incident comprise at least one unique identifier associated with the processing activity.
13. The computer-implemented data processing method of claim 12 , wherein the electronic record digitally stores processing activity data related to the processing activity, and the processing activity data identifies each of:
a description of the processing activity;
one or more types of personal data related to the processing activity;
a subject from which the personal data was collected;
a storage location of the personal data; and
one or more access permissions related to the personal data.
14. The computer-implemented data processing method of claim 13 , wherein modifying the electronic record for the processing activity based at least in part on the first information comprises populating the processing activity data in the electronic record based at least in part on the first information.
15. The computer-implemented data processing method of claim 14 , further comprising calculating the risk level for the processing activity based on the processing activity data, wherein calculating the risk level for the processing activity comprises:
electronically retrieving the processing activity data associated with the electronic record for the processing activity;
electronically determining a plurality of risk factors for the processing activity, wherein the plurality of risk factors are based upon a plurality of factors including:
a nature of the personal data associated with the processing activity;
a physical storage location of the personal data associated with the processing activity;
a length of time that the personal data associated with the processing activity will be retained in storage; and
a type of individual from which the personal data associated with the processing activity originated;
electronically assigning a weighting factor for each of the plurality of risk factors;
determining a risk rating for each of the plurality of risk factors;
electronically calculating a risk level for the processing activity based upon, for each respective one of the plurality of risk factors, the risk rating and the weighting factor for the risk factor; and
digitally storing the risk level associated with the record for the processing activity.
16. The computer-implemented data processing method of claim 14 , wherein modifying the electronic record for the processing activity based at least in part on the first information comprises:
calculating the risk level for the processing activity based on the first information; and
modifying the risk level based at least in part on the first information.
17. The computer-implemented data processing method of claim 16 , further comprising electronically determining an audit schedule for the processing activity based at least in part on the risk level.
18. The computer-implemented data processing method of claim 10 , wherein the first information associated with the processing activity comprises one or more images captured using one or more imaging devices of the computing device.
19. The computer-implemented data processing method of claim 10 , wherein the method further comprises analyzing the one or more images to identify the first information.
20. The computer-implemented data processing method of claim 19 , wherein the method further comprises analyzing the one or more images to identify the processing activity.