IP Library Granted Patent US 10,839,102
Granted Patent B2
US 10,839,102 · App. 16/505,426 · Granted Nov 17, 2020

Data processing systems for identifying and modifying processes that are subject to data subject access requests

Inventors: Kabir A. Barday (Atlanta, GA); Jason L. Sabourin (Brookhaven, GA); Jonathan Blake Brannon (Smyrna, GA); Mihir S. Karanjkar (Marietta, GA); Kevin Jones (Atlanta, GA)
Assignee: OneTrust, LLC
G06F21/6245G06F11/3409G06F11/3476G06F15/76G06F21/552G06F2221/2139G06F2221/2141G06F2221/2143H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,102
App. No.
16/505,426
Granted
Nov 17, 2020
Kind
B2
Abstract

In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject's personal data from the various systems; and (3) determine a cause of the request to identify one or more processing activities or other sources that result in a high number of such requests.

Claims (19)

1. A computer-implemented data processing method for identifying one or more patterns of related requests to delete personal data associated with one or more data subject from one or more computer systems of an organization, the method comprising:

analyzing, by one or more processors, (i) first metadata associated with a request from a data subject to delete the personal data associated with a data subject from one or more computer systems of an organization, and (ii) second metadata associated with a plurality of additional requests from a plurality of data subjects to delete the personal data associated with each respective data subject of the plurality of data subjects from the one or more computer systems;

identifying a processing activity of a plurality of processing activities from (i) the first metadata associated with the request from the data subject to delete the personal data associated with the data subject from one or more computer systems of the organization a particular number of the plurality of data subject requests, and (ii) the second metadata associated with the plurality of additional requests from the plurality of data subjects to delete the personal data associated with each respective data subject of the plurality of data subjects from the one or more computer systems;

comparing, by one or more processors, a number of occurrences of each processing activity of the plurality of processing activities to a threshold processing activity number of occurrences;

determining, by one or more processors, that a number of occurrences of a particular processing activity is greater than the threshold processing activity number of occurrences; and

in response to determining that the number of occurrences of the particular processing activity is greater than the threshold processing activity number of occurrences, automatically generating an alert indicating that the number of occurrences of the particular processing activity is greater than the threshold processing activity number of occurrences.

2. The computer-implemented data processing method of claim 1 , further comprising:

in response to automatically generating an alert indicating that the number of occurrences of the particular processing activity is greater than the threshold processing activity number of occurrences, automatically modifying the particular processing activity to change at least one type of personal data collected as part of the particular processing activity.

3. The computer-implemented data processing method of claim 1 , wherein the automatically generated alert is provided to one or more privacy officers of the organization.

4. The computer-implemented data processing method of claim 1 , wherein the threshold processing activity number of occurrences is based at least in part on a particular percentage of the plurality of data subjects for whom the system processed data as part of the particular processing activity has submitted one of the plurality of data subject requests.

5. The computer-implemented data processing method of claim 1 , wherein the threshold processing activity number of occurrences is based at least in part on a particular number of the plurality of data subjects for whom the system processed data as part of the particular processing activity has submitted one of the plurality of data subject requests.

6. The computer-implemented data processing method of claim 1 , wherein the threshold processing activity number of occurrences is automatically set based at least in part on a type of the particular processing activity.

7. The computer-implemented data processing method of claim 1 , wherein the threshold processing activity number of occurrences is adjustable by one or more privacy officers of the organization.

8. The computer-implemented data processing method of claim 1 , the method further comprising:

identifying at least one data subject associated with the particular processing activity that has not submitted one of the plurality of data subject requests; and

in response to identifying the at least one data subject, prompting the at least one data subject to provide consent for storage of personal data associated with the at least one data subject as part of the particular processing activity.

9. The computer-implemented data processing method of claim 1 , the method further comprising:

determining whether the organization has recently modified the particular processing activity; and

in response to determining that the organization has recently modified the particular processing activity, automatically modifying the particular processing activity to change a type of personal data collected as part of the particular processing activity.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2019
From: BARDAY, KABIR A.; KARANJKAR, MIHIR S.; SABOURIN, JASON L.; JONES, KEVIN; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 049717/0591 →
Continuity (12)
Continuation 16055998 · Aug 6, 2018
Continuation In Part 15996208 · Jun 1, 2018
Continuation In Part 15853674 · Dec 22, 2017
Continuation In Part 15619455 · Jun 10, 2017
Continuation In Part 15254901 · Sep 1, 2016
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Provisional Application 62541613 · Aug 4, 2017
Provisional Application 62537839 · Jul 27, 2017
Provisional Application 62547530 · Aug 18, 2017
Related Publication 20190332802A1 · Oct 31, 2019
Cited By (1)
US 12,719,871