IP Library Granted Patent US 11,328,092
Granted Patent B2
US 11,328,092 · App. 17/347,853 · Granted May 10, 2022

Data processing systems for processing and managing data subject access in a distributed environment

Inventors: Kabir A. Barday (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA); Jason L. Sabourin (Brookhaven, GA)
Assignee: OneTrust, LLC
G06F21/6245G06F16/113G06F16/125G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,328,092
App. No.
17/347,853
Granted
May 10, 2022
Kind
B2
Abstract

In particular embodiments, a data subject request processing system may be configured to utilize one or more local storage nodes in order to process a data subject access request on behalf of a data subject. In particular embodiments, the one or more local storage nodes may be local to the data subject making the request (e.g., in the same country as the data subject, in the same jurisdiction, in the same geographic area, etc.). The system may, for example, be configured to: (1) receive a data subject access request from a data subject (e.g., via a web form); (2) identify a suitable local storage node based at least in part on the request and/or the data subject; (3) route the data subject access request to the identified local storage node; and (4) process the data subject access request at the identified local storage node.

Claims (58)

1. A system comprising:

a non-transitory computer-readable medium storing instructions; and

processing hardware communicatively coupled to the non-transitory computer-readable medium, wherein the processing hardware is configured to execute the instructions and thereby perform operations comprising:

detecting a state of a browser application executed on a user device, the state of the browser application comprising an indication of a geographic location of the user device and a data subject request parameter;

generating, based on the state of the browser application, a graphical user interface for the user device by:

identifying a local storage node based on the geographic location;

processing a data subject access request at the local storage node to identify personal data associated with a data subject based on the data subject request parameter;

storing a copy of the personal data at the local storage node; and

configuring a first interactive element on the graphical user interface, wherein the first interactive element is configured to cause the user device to access the personal data at the local storage node;

providing the graphical user interface for display on the user device; and

responsive to determining that a particular time period has passed following generation of the first interactive element,

modifying the first interactive element by configuring the first interactive element to navigate to a first display element that presents an indication of an expiration of an availability of the personal data.

2. The system of claim 1 , wherein the processing hardware is further configured for:

receiving an indication of a selection of the first interactive element; and

responsive to the selection of the first interactive element, causing deletion of the copy of the personal data form the local storage node.

3. The system of claim 2 , wherein the processing hardware is further configured for, responsive to the selection of the first interactive element, modifying the first interactive element by configuring the first interactive element to navigate to a second display element that presents an indication of an unavailability of the personal data.

4. The system of claim 1 , wherein identifying the local storage node based on the geographic location comprises determining which local storage node of a plurality of local storage nodes located in distant geographic locations comprise a location that shares the geographic location.

5. The system of claim 4 , wherein the geographic location is defined by at least one of a particular jurisdiction and a particular country.

6. A system comprising:

a non-transitory computer-readable medium storing instructions; and

processing hardware communicatively coupled to the non-transitory computer-readable medium, wherein the processing hardware is configured to execute the instructions and thereby perform operations comprising:

detecting a state of a browser application executed on a user device, the state of the browser application comprising an indication of a geographic location of the user device and a data subject request parameter;

identifying a local storage node based on the geographic location;

processing a data subject access request at the local storage node to identify personal data associated with a data subject based on the data subject request parameter;

generating, based on the state of the browser application, a graphical user interface for the user device by configuring a first interactive element on the graphical user interface and excluding a second interactive element and a third interactive element on the graphical user interface, wherein:

the first interactive element is configured, upon selection, to navigate to a display element that presents the personal data;

the second interactive element is configured, upon selection, to initiate a process for deleting the personal data; and

the third interactive element is configured, upon selection, to enable a user to modify the personal data via the graphical user interface;

providing the graphical user interface for display on the user device;

responsive to selection of the first interactive element:

configuring a fourth graphical user interface comprising the display element and providing the fourth graphical user interface to the user device; and

incrementing a personal data access counter value; and

responsive to determining that the personal data access counter value exceeds a threshold access value, modifying the display element to exclude the personal data and indicate that the personal data is no longer available for viewing.

7. The system of claim 6 , wherein the processing hardware is further configured to perform operations comprising storing a copy of the personal data at the local storage node.

8. The system of claim 7 , wherein the processing hardware is further configured for, responsive to determining that a particular time period has passed without selection of the first interactive element, modifying the display element to exclude the personal data and indicate that the personal data is no longer available for viewing.

9. The system of claim 6 , wherein the processing hardware is further configured to perform operations comprising:

responsive to selection of the first interactive element, configuring a second graphical user interface to include the second interactive element and providing the second graphical user interface to the user device.

10. The system of claim 6 , wherein the processing hardware is further configured to perform operations comprising:

receiving the data subject access request at a data subject access request management server; and

routing the data subject access request from the data subject access request management server to the local storage node for processing.

11. The system of claim 10 , wherein routing the data subject access request from the data subject access request management server to the local storage node for processing comprises routing the data subject access request from the data subject access request management server to the local storage node such that the data subject access request does not pass through any server that is located in any location other than the geographic location.

12. The system of claim 6 , wherein:

the state of the browser application further comprises a network address associated with the user device; and

determining the geographic location of the user device is based on the network address.

13. The system of claim 6 , wherein the processing hardware is further configured to perform operations comprising:

responsive to selection of the first interactive element, configuring a third graphical user interface to include the third interactive element and providing the third graphical user interface to the user device; and

responsive to selection of the third interactive element, enabling the user to modify the personal data via the graphical user interface.

14. A method comprising:

detecting, by computing hardware, a state of a browser application executed on a user device, the state of the browser application comprising an indication of a physical location of the user device and a data subject access request parameter;

identifying a local storage node based on the physical location;

processing a data subject access request at the local storage node to identify personal data associated with a data subject based on the data subject access request parameter;

generating, based on the state of the browser application, a graphical user interface for the user device by configuring a first interactive element on the graphical user interface and excluding a second interactive element on the graphical user interface, wherein:

the first interactive element is configured, upon selection, to cause a deletion of the personal data;

the second interactive element is configured to navigate to a display element that presents the personal data; and

transmitting, by the computing hardware, a first instruction to a user device to present the graphical user interface on the user device;

detecting, by the computing hardware, a selection of the first interactive element; and

in response to detecting the selection of the first interactive element, causing, by the computing hardware, the deletion of the personal data.

15. The method of claim 14 , further comprising causing storage, by the computer hardware at the local storage node, of metadata indicating the deletion of the personal data.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2021
From: BARDAY, KABIR A.; BRANNON, JONATHAN BLAKE; SABOURIN, JASON L.
To: ONETRUST, LLC
Reel/Frame 056545/0417 →
Continuity (20)
Continuation In Part 17068558 · Oct 12, 2020
Continuation 16712104 · Dec 12, 2019
Continuation In Part 16277539 · Feb 15, 2019
Continuation In Part 16159566 · Oct 12, 2018
Continuation In Part 16055083 · Aug 4, 2018
Continuation In Part 15996208 · Jun 1, 2018
Continuation In Part 15853674 · Dec 22, 2017
Continuation In Part 15619455 · Jun 10, 2017
Continuation In Part 15254901 · Sep 1, 2016
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Provisional Application 62541613 · Aug 4, 2017
Provisional Application 62537839 · Jul 27, 2017
Provisional Application 62547530 · Aug 18, 2017
Provisional Application 62572096 · Oct 13, 2017
Provisional Application 62728435 · Sep 7, 2018
Provisional Application 62631684 · Feb 17, 2018
Provisional Application 62631703 · Feb 17, 2018
Related Publication 20210312083A1 · Oct 7, 2021
Cited By (3)
US 12,301,632 US 12,340,292 US 12,719,871