IP Library Granted Patent US 10,242,228
Granted Patent B2
US 10,242,228 · App. 16/042,642 · Granted Mar 26, 2019

Data processing systems for measuring privacy maturity within an organization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,242,228
App. No.
16/042,642
Granted
Mar 26, 2019
Kind
B2
Abstract

A privacy compliance measurement system, according to particular embodiments, is configured to determine compliance with one or more privacy compliance requirements by an organization or sub-group of the organization. In various embodiments, the system is configured to determine a privacy maturity rating for each of a plurality of sub-groups within an organization. In some embodiments, the privacy maturity rating is based at least in part on: (1) a frequency of risks or issues identified with Privacy Impact Assessments (PIAs) performed or completed by the one or sub-groups; (2) a relative training level of members of the sub-groups with regard to privacy related matters; (3) a breadth and amount of personal data collected by the sub-groups; and/or (4) etc. In various embodiments, the system is configured to automatically modify one or more privacy campaigns based on the determined privacy maturity ratings.

Claims (74)

1. A non-transitory computer-readable medium storing computer-executable instructions for measuring a plurality of individuals' compliance with one or more privacy-related requirements, the method comprising:

determining, by one or more processors, for each of one or more pieces of computer code, one or more respective storage locations;

electronically obtaining, by one or more processors, each of the one or more pieces of computer code based on the one or more respective storage locations;

automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of privacy campaign data that the computer code collects or accesses, the privacy campaign data comprising at least a number of privacy campaigns facilitated by the one or more pieces of computer code;

in response to determining that the computer code has a particular one of the one or more privacy-related attributes: (A) executing the steps of: (i) electronically displaying one or more prompts to a first individual requesting that the first individual input information regarding the particular privacy-related attribute; (ii) receiving input information from the first individual regarding the particular privacy-related attribute; and (iii) communicating the information regarding the particular privacy-related attribute to one or more second individuals for use in conducting a privacy assessment of the computer code; (B) changing an indicator associated with the code to indicate that, before the code is launched, the particular attribute should be reviewed by one or more designated individuals; and (C) changing an indicator associated with the code to indicate that, before the code is launched, the code should be modified to not include the particular attribute;

analyzing, by one or more processors, for at least one of the plurality of individuals, one or more pieces of publicly available data associated with the at least one of the plurality of individuals, the one or more pieces of publicly available data comprising one or more pieces of publicly available data selected from the group consisting of: one or more privacy disclaimers corresponding with the one or more pieces of computer code; and one or more privacy notices associated with one of more websites corresponding to the plurality of individuals;

determining, by one or more processors, based at least in part on the one or more types of privacy campaign data that the computer code collects or accesses and the one or more pieces of publicly available data, a privacy maturity score for the plurality of individuals; and

displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device.

2. The non-transitory computer-readable medium of claim 1 , wherein analyzing the one or more pieces of publicly available data comprise one or more credit bureau databases; and

the non-transitory computer-readable medium further stores computer-executable instructions for:

accessing the one or more credit bureau databases; and

determining one or more pieces of credit data associated with an organization to which the plurality of individuals belong.

3. The non-transitory computer-readable medium of claim 1 , wherein:

the one or more pieces of publicly available data comprise the one or more privacy disclaimers corresponding with the one or more pieces of computer code; and

the non-transitory computer-readable medium further stores computer-executable instructions for:

analyzing one or more contents of the one or more privacy disclaimers; and

calculating the privacy maturity score based at least in part on the one or more contents of the one or more privacy disclaimers.

4. The non-transitory computer-readable medium of claim 3 , wherein the non-transitory computer-readable medium further stores computer-executable instructions for:

determining whether the one or more contents of the one or more privacy disclaimers comprise one or more pieces of language required by one or more regulations;

in response to determining that the one or more contents of the one or more privacy disclaimers comprise the one or more pieces of language, calculating a first privacy awareness score; and

in response to determining that that the one or more contents of the one or more privacy disclaimers do not comprise the one or more pieces of language, calculating a second privacy awareness score.

5. The non-transitory computer-readable medium of claim 1 , wherein:

the one or more pieces of publicly available data comprise one or more security certifications associated with the plurality of individuals;

the non-transitory computer-readable medium further stores computer-executable instructions for:

determining whether the at least one of the plurality of individuals holds a particular security certification based on the one or more pieces of publicly available data; and

calculating the privacy maturity score based on whether the at least one of the plurality of individuals holds the particular security certification.

6. The non-transitory computer-readable medium of claim 1 , wherein:

the non-transitory computer-readable medium further stores computer-executable instructions for:

analyzing a website associated with the computer code to identify the one or more privacy notices;

analyzing one or more contents of the one or more privacy notices; and

determining the privacy maturity score by electronically calculating the privacy maturity score based on the one or more contents of the one or more privacy notices; and

the one or more pieces of publicly available data comprise the one or more privacy notices associated with the one or more websites corresponding to the plurality of individuals.

7. The non-transitory computer-readable medium of claim 1 , wherein:

the analysis of the one or more pieces of publicly available data comprises analysis of one or more social networking websites associated with the plurality of individuals.

8. The non-transitory computer-readable medium of claim 7 , wherein:

the analysis of the one or more pieces of publicly available data comprises analysis of one or more business related job sites associated with the plurality of individuals; and

the non-transitory computer-readable medium further stores computer-executable instructions for:

determining one or more employee titles, employee roles, and available job posts associated with the plurality of individuals based on the analysis of the one or more social networking websites and the one or more business related job sites; and

calculating the privacy maturity score based on the one or more employee titles, employee roles, and available job posts.

9. A computer-implemented data processing method for measuring a particular organization's compliance with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:

determining, by one or more processors, for each of the one or more pieces of computer code, one or more respective storage locations;

electronically obtaining, by one or more processors, each of the one or more pieces of computer code based on the one or more respective storage locations;

automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of privacy campaign data that the computer code collects or accesses comprising at least a number of privacy campaigns facilitated by the one or more pieces of computer code;

in response to determining that the computer code has a particular one of the one or more privacy-related attributes: (A) executing the steps of: (i) electronically displaying one or more prompts to a first individual requesting that the first individual input information regarding the particular privacy-related attribute; (ii) receiving input information from the first individual regarding the particular privacy-related attribute; and (iii) communicating the information regarding the particular privacy-related attribute to one or more second individuals for use in conducting a privacy assessment of the computer code; (B) changing an indicator associated with the code to indicate that, before the code is launched, the particular attribute should be reviewed by one or more designated individuals; and (C) changing an indicator associated with the code to indicate that, before the code is launched, the code should be modified to not include the particular attribute;

scanning one or more publicly available data sources for one or more data records associated with the particular organization, the one or more data records comprising one or more data records selected from the group consisting of: one or more privacy disclaimers corresponding with the one or more pieces of computer code; and one or more privacy notices associated with one or more websites corresponding to the particular organization;

determining, by one or more processors, based at least in part on the one or more types of privacy campaign data that the computer code collects or accesses and the one or more data records, a privacy maturity score for the particular organization; and

displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device.

10. The computer-implemented data processing method of claim 9 , the method further comprising modifying at least one of the one or more pieces of computer code based at least in part on the privacy maturity score.

11. The computer-implemented data processing method of claim 9 , wherein the method further comprises:

analyzing a website of the one or more websites associated with the particular organization to identify the one or more privacy notices;

analyzing one or more contents of the one or more privacy notices; and

electronically calculating the privacy maturity score by electronically calculating the privacy maturity score based on the one or more contents of the one or more privacy notices; and

the one or more data records comprise the one or more privacy notices.

12. The computer-implemented data processing method of claim 9 , wherein the method further comprises:

analyzing one or more public record databases associated with the particular organization;

identifying one or more industry certifications associated with the particular organization from the one or more public record databases; and

electronically calculating the privacy maturity score by electronically calculating the privacy maturity score based on the identification of the one or more industry certifications.

13. The computer-implemented data processing method of claim 9 , wherein:

the analysis of the one or more data records comprises analysis of one or more social networking websites associated with the particular organization.

14. The computer-implemented data processing method of claim 13 , wherein:

the analysis of the one or more data records comprises analysis of one or more business related job sites associated with the particular organization; and

the method further comprises:

determining one or more employee titles, employee roles, and available job posts with the particular organization based on the analysis of the one or more social networking websites and the one or more business related job sites; and

calculating the privacy maturity score based on the one or more employee titles, employee roles, and available job posts.

15. The computer-implemented data processing method of claim 14 , wherein the method further comprises receiving one or more privacy impact assessments associated with each of the one or more pieces of computer code; and

determining the privacy maturity score for the particular organization further comprises determining the privacy maturity score based at least in part on the one or more privacy impact assessments.

16. The computer-implemented data processing method of claim 15 , wherein:

the one or more privacy impact assessments are one or more privacy impact assessments performed prior to execution of the one or more pieces of computer code as part of a privacy campaign.

17. The non-transitory computer-readable medium of claim 1 , wherein the one or more websites corresponding to the plurality of individuals comprise one or more websites that host the one or more pieces of computer code.

18. The non-transitory computer-readable medium of claim 1 , wherein the one or more privacy disclaimers corresponding with the one or more pieces of computer code comprise one or more privacy disclaimers associated with one or more software applications published by the plurality of individuals that are available to one or more customers of the plurality of individuals.

19. The computer-implemented data processing method of claim 9 , wherein the one or more websites corresponding to the particular organization comprise one or more websites that host one or more pieces of computer software made available by the particular organization.

20. The computer-implemented data processing method of claim 19 , wherein the method further comprises:

scanning the one or more websites for an indication of one or more security certifications to determine whether the particular organization holds the one or more security certifications; and

determining the privacy maturity score for the particular organization based at least in part on whether the particular organization holds the one or more security certifications.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2018
From: BARDAY, KABIR A.; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 047529/0057 →
Cited By (11)
US 1,095,590 US 1,117,300 US 1,120,942 US 12,204,564 US 12,216,794 US 12,412,140 US 12,585,817 US 12,591,828 US 12,641,108 US 12,694,044 US 12,718,167