IP Library Granted Patent US 10,565,236
Granted Patent B1
US 10,565,236 · App. 16/593,634 · Granted Feb 18, 2020

Data processing systems for generating and populating a data inventory

Inventors: Kabir A. Barday (Atlanta, GA); Mihir S. Karanjkar (Marietta, GA); Steven W. Finch (Kennesaw, GA); Ken A. Browne (Johns Creek, GA); Nathan W. Heard (Marietta, GA); Aakash H. Patel (Norcross, GA); Jason L. Sabourin (Brookhaven, GA); Richard L. Daniel (Atlanta, GA); Dylan D. Patton-Kuhl (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA)
Assignee: OneTrust, LLC
G06F16/288G06F15/76G06F16/254G06F17/248G06F21/552G06N20/00G06Q10/06H04L63/04H04L63/101H04L63/20H04L67/306H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,565,236
App. No.
16/593,634
Granted
Feb 18, 2020
Kind
B1
Abstract

In particular embodiments, a data processing data inventory generation system is configured to: (1) generate a data model (e.g., a data inventory) for one or more data assets utilized by a particular organization; (2) generate a respective data inventory for each of the one or more data assets; and (3) map one or more relationships between one or more aspects of the data inventory, the one or more data assets, etc. within the data model. In particular embodiments, a data asset (e.g., data system, software application, etc.) may include, for example, any entity that collects, processes, contains, and/or transfers personal data (e.g., such as a software application, “internet of things” computerized device, database, website, data-center, server, etc.). For example, a first data asset may include any software or device (e.g., server or servers) utilized by a particular entity for such data collection, processing, transfer, storage, etc.

Claims (59)

1. A computer-implemented data processing method of populating a data inventory with one or more data inventory attribute values, the method comprising:

generating, by one or more processors, the data inventory for one or more data assets used in the collection or storage of personal data;

storing, by the one or more processors, the data inventory in computer memory;

modifying, by the one or more processors, the data inventory to include one or more data fields that each define a respective data inventory attribute of a plurality of data inventory attributes;

determining, by the one or more processors, which of the one or more data fields of the data inventory are unpopulated data fields;

determining, by the one or more processors, a respective data inventory attribute value for one or more of the unpopulated data fields, wherein determining the respective data inventory attribute value for the one or more of the unpopulated data fields comprises:

requesting, by the one or more processors via an application programming interface to an application, data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields,

receiving, by the one or more processors from the application, the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields, and

determining, by the one or more processors based at least in part on the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields, the respective data inventory attribute value for the one or more of the unpopulated data fields;

in response to determining the respective data inventory attribute value for the one or more of the unpopulated data fields, modifying each of the one or more unpopulated data fields to include the respective data inventory attribute value; and

storing the modified data inventory in the computer memory.

2. The computer-implemented data processing method of claim 1 , wherein the application programming interface to the application comprises an interface to a third-party information technology system.

3. The computer-implemented data processing method of claim 1 , wherein the application programming interface to the application comprises an interface to an application executing on a remote computing device.

4. The computer-implemented data processing method of claim 1 wherein the application programming interface to the application comprises an interface to a server storing data asset assessment information associated with the one or more data assets.

5. The computer-implemented data processing method of claim 4 , wherein receiving the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields comprises receiving a subset of the data asset assessment information associated with the one or more data assets from the server.

6. The computer-implemented data processing method of claim 1 , wherein the application programming interface to the application comprises an interface to a data repository,

wherein the method further comprises analyzing the respective data inventory attribute value for the one or more of the unpopulated data fields and correlating metadata for the data repository with the respective data inventory attribute value for the one or more of the unpopulated data fields.

7. The computer-implemented data processing method of claim 1 , wherein the method further comprises using one or more machine learning techniques to categorize the data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

8. The computer-implemented data processing method of claim 7 , wherein the method further comprises requesting user feedback regarding the categorization of the data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

9. The computer-implemented data processing method of claim 8 , wherein the method further comprises assigning a confidence score to the respective data inventory attribute value for the one or more of the unpopulated data fields based, at least in part, on the categorization of the data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

10. The computer-implemented data processing method of claim 1 , wherein the method further comprises providing a software application for installation on a computing device that is networked with one or more data repositories,

wherein the application programming interface to the application comprises an interface to the software application for installation on the computing device that is networked with the one or more data repositories.

11. A data processing system for data inventory population comprising:

one or more processors;

computer memory; and

a non-transitory computer-readable medium storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

generating a data inventory for one or more data assets used in the collection or storage of personal data;

storing the data inventory in the computer memory;

modifying the data inventory to include one or more data fields that each define a respective data inventory attribute of a plurality of data inventory attributes;

determining which of the one or more data fields of the data inventory are unpopulated data fields;

determining a respective data inventory attribute value for one or more of the unpopulated data fields, wherein determining the respective data inventory attribute value for the one or more of the unpopulated data fields comprises:

requesting, via an application programming interface to an application, data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields,

receiving, from the application, the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields, and

determining, based at least in part on the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields, the respective data inventory attribute value for the one or more of the unpopulated data fields;

in response to determining the respective data inventory attribute value for the one or more of the unpopulated data fields, modifying each of the one or more unpopulated data fields to include the respective data inventory attribute value; and

storing the modified data inventory in the computer memory.

12. The data processing system of claim 11 , wherein the non-transitory computer-readable medium further stores computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

categorizing a data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields based at least in part on a confidence score.

13. The data processing system of claim 11 , wherein the one or more data assets used in the collection or storage of personal data comprises a plurality of interrelated data assets comprising one or more storage assets, one or more collection assets, and one or more transfer assets.

14. The data processing system of claim 11 , wherein the data associated with the respective data inventory attribute value for the one or more of the unpopulated data fields comprises schema details associated with a data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

15. The data processing system of claim 14 , wherein the schema details comprise one or more schema details selected from a group consisting of:

an asset ID;

a Schema ID; and

a connection string.

16. The data processing system of claim 11 , wherein the application programming interface to the application comprises an interface to a data repository, wherein the non-transitory computer-readable medium further stores computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

analyzing the data repository to determine whether the data repository is part of an existing data model of data assets; and

determining the respective data inventory attribute value for the one or more of the unpopulated data fields further based at least in part on whether the data repository is part of the existing data model of data assets.

17. The data processing system of claim 11 , wherein the non-transitory computer-readable medium further stores computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

identifying a primary data asset from among the one or more data assets; and

determining the respective data inventory attribute value for the one or more of the unpopulated data fields further based at least in part on data associated with the primary data asset.

18. The data processing system of claim 11 , wherein the non-transitory computer-readable medium further stores computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

determining a categorization for a data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields based at least in part on a confidence score associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

19. The data processing system of claim 18 , wherein the non-transitory computer-readable medium further stores computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving input from a user confirming or denying the categorization for the data inventory attribute associated with the respective data inventory attribute value for the one or more of the unpopulated data fields; and

in response to receiving the input form the user, modifying the confidence score associated with the respective data inventory attribute value for the one or more of the unpopulated data fields.

20. The data processing system of claim 11 , wherein the respective data inventory attribute value for the one or more of the unpopulated data fields is associated with a data inventory attribute selected from a group consisting of:

a storage asset inventory attribute;

a collection asset inventory attribute; and

a transfer asset inventory attribute.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2019
From: BARDAY, KABIR A.; KARANJKAR, MIHIR S.; FINCH, STEVEN W.; SABOURIN, JASON L.; BROWNE, KEN A.; HEARD, NATHAN W.; PATEL, AAKASH H.; DANIEL, RICHARD L.; PATTON-KUHL, DYLAN D.; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 050630/0917 →
Cited By (18)
US 12,190,330 US 12,204,564 US 12,216,794 US 12,259,882 US 12,265,896 US 12,277,232 US 12,287,893 US 12,288,233 US 12,299,065 US 12,353,405 US 12,381,915 US 12,412,140 US 12,536,329 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044