IP Library Granted Patent US 12,147,578
Granted Patent B2
US 12,147,578 · App. 17/717,587 · Granted Nov 19, 2024

Consent receipt management systems and related methods

Inventors: Kabir A. Barday (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA); Richard A. Beaumont (London, GB); John Mannix (London, GB)
Assignee: OneTrust, LLC
G06F21/6263G06F15/76G06F21/552G06F21/577G06F21/604G06Q10/1053H04L63/108G06F16/95
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,147,578
App. No.
17/717,587
Granted
Nov 19, 2024
Kind
B2
Abstract

A consent receipt management system is configured to: (1) automatically cause a prior, validly received consent to expire (e.g., in response to a triggering event); and (2) in response to causing the previously received consent to expire, automatically trigger a recapture of consent. In particular embodiments, the system may, for example, be configured to cause a prior, validly received consent to expire in response to one or more triggering events.

Claims (65)

1. A method comprising:

receiving, by computing hardware via a graphical user interface, information regarding a request to initiate a transaction between an entity and a data subject,

wherein the transaction involves a computing system associated with the entity performing at least one of collecting or processing personal data associated with the data subject as part of a processing activity undertaken by the entity that the data subject provides consent as part of the transaction;

receiving, by the computing hardware, a unique transaction identifier associated with the transaction;

receiving, by the computing hardware, a unique subject identifier for the data subject;

responsive to receiving the information regarding the request:

generating, by the computing hardware, a unique consent receipt key for the consent provided by the data subject as part of the transaction;

associating, by the computing hardware, a receipt definition with the unique consent receipt key, wherein the receipt definition comprises the unique transaction identifier and a purpose for the at least one of collecting or processing the personal data, wherein the personal data is identified using one or more machine learning techniques; and

generating, by the computing hardware, a consent receipt set comprising the unique subject identifier, the unique consent receipt key, and the unique transaction identifier;

storing, by the computing hardware in computer memory, the consent receipt set and the receipt definition;

detecting, by the computing hardware and based on data in the receipt definition, an occurrence of a triggering event that causes the consent to expire according to the association of the receipt definition with the unique consent receipt key; and

responsive to detecting the occurrence of the triggering event, causing, by the computing hardware, a recapture of the consent from the data subject.

2. The method of claim 1 , wherein at least a portion of the receipt definition is provided to demonstrate that the data subject has provided the consent for the at least one of collecting or processing the personal data as part of the processing activity undertaken by the entity; and

wherein associating the receipt definition with the unique consent receipt key comprises generating a link between the unique consent receipt key and metadata of the receipt definition that identifies the purpose for the at least one of collecting or processing the personal data.

3. The method of claim 1 , wherein the receipt definition further comprises a link to a privacy policy associated with the transaction and the triggering event comprises a change to the privacy policy.

4. The method of claim 1 , wherein the receipt definition further comprises a location of the data subject and the triggering event comprises a change in the location.

5. The method of claim 1 , wherein the receipt definition further comprises a retention period for the personal data and the triggering event comprises a passage of the retention period.

6. The method of claim 1 , wherein the triggering event comprises at least one of:

a passage of a particular amount of time from generation of the unique consent receipt key;

a change to the purpose for the at least one of collecting or processing the personal data;

a change to a privacy policy associated with the transaction;

a change to a rule that govern the transaction; or

a change in location of the data subject.

7. The method of claim 1 , wherein causing the recapture of the consent from the data subject comprises providing an interface to recapture the consent.

8. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium,

wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

receiving information via a graphical user interface regarding a request to initiate a transaction between an entity and a data subject, wherein the transaction involves a computing system associated with the entity performing at least one of collecting or processing personal data associated with the data subject as part of a processing activity undertaken by the entity that the data subject provides consent as part of the transaction;

receiving a unique subject identifier for the data subject via the graphical user interface;

responsive to receiving the information regarding the request:

generating a unique consent receipt key for the consent provided by the data subject as part of the transaction;

associating a receipt definition with the unique consent receipt key, wherein the receipt definition comprises a purpose for the at least one of collecting or processing the personal data, wherein the personal data is identified using one or more machine learning techniques; and

generating a consent receipt set comprising the unique subject identifier and the unique consent receipt key;

storing, in computer memory, the consent receipt set and the receipt definition;

detecting, based on data in the receipt definition, an occurrence of a triggering event that causes the consent to expire according to the association of the receipt definition with the unique consent receipt key; and

responsive to detecting the occurrence of the triggering event, causing a recapture of the consent from the data subject.

9. The system of claim 8 , wherein at least a portion of the receipt definition is provided to demonstrate that the data subject has provided the consent for the at least one of collecting or processing the personal data as part of the processing activity undertaken by the entity; and

wherein associating the receipt definition with the unique consent receipt key comprises generating a link between the unique consent receipt key and metadata of the receipt definition that identifies the purpose for the at least one of collecting or processing the personal data.

10. The system of claim 8 , wherein the receipt definition further comprises a link to a privacy policy associated with the transaction and the triggering event comprises a change to the privacy policy.

11. The system of claim 8 , wherein the receipt definition further comprises a location of the data subject and the triggering event comprises a change in the location.

12. The system of claim 8 , wherein the receipt definition further comprises a retention period for the personal data and the triggering event comprises a passage of the retention period.

13. The system of claim 8 , wherein the triggering event comprises a change to a privacy policy associated with the transaction and causing the recapture of the consent from the data subject comprises providing a second graphical user interface providing a prompt for the consent and an updated version of the privacy policy.

14. The system of claim 8 , wherein the triggering event comprises a change to the purpose for the at least one of collecting or processing the personal data and causing the recapture of the consent from the data subject comprises providing a second graphical user interface providing a prompt for the consent and an updated purpose for the at least one of collecting or processing the personal data.

15. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

receiving information regarding a request to initiate a transaction between an entity and a data subject, wherein the transaction involves a computing system associated with the entity performing at least one of collecting or processing personal data associated with the data subject as part of a processing activity undertaken by the entity that the data subject provides consent as part of the transaction;

receiving a unique transaction identifier associated with the transaction;

receiving a unique subject identifier for the data subject;

responsive to receiving the information regarding the request:

generating a unique consent receipt key for the transaction;

associating a receipt definition with the unique consent receipt key, wherein the receipt definition comprises the unique transaction identifier and a purpose for the at least one of collecting or processing the personal data, wherein the personal data is identified using one or more machine learning techniques; and

generating a consent receipt set comprising the unique subject identifier, the unique consent receipt key, and the unique transaction identifier;

detecting, based on data in the receipt definition, an occurrence of a triggering event that causes the consent to expire according to the association of the receipt definition with the unique consent receipt key; and

responsive to detecting the occurrence of the triggering event, causing a recapture of the consent from the data subject.

16. The non-transitory computer-readable medium of claim 15 , wherein at least a portion of the receipt definition is provided to demonstrate that the data subject has provided the consent for the at least one of collecting or processing the personal data as part of the processing activity undertaken by the entity; and

wherein associating the receipt definition with the unique consent receipt key comprises generating a link between the unique consent receipt key and metadata of the receipt definition that identifies the purpose for the at least one of collecting or processing the personal data.

17. The non-transitory computer-readable medium of claim 15 , wherein the receipt definition further comprises a link to a privacy policy associated with the transaction and the triggering event comprises a change to the privacy policy.

18. The non-transitory computer-readable medium of claim 15 , wherein the receipt definition further comprises a location of the data subject and the triggering event comprises a change in the location.

19. The non-transitory computer-readable medium of claim 15 , wherein the receipt definition further comprises a retention period for the personal data and the triggering event comprises a passage of the retention period.

20. The non-transitory computer-readable medium of claim 15 , wherein the triggering event comprises at least one of:

a passage of a particular amount of time from generation of the unique consent receipt key;

a change to the purpose for the at least one of collecting or processing the personal data;

a change to a privacy policy associated with the transaction;

a change to a rule that govern the transaction; or

a change in location of the data subject.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2022
From: BARDAY, KABIR A.; BRANNON, JONATHAN BLAKE; BEAUMONT, RICHARD A.; MANNIX, JOHN
To: ONETRUST, LLC
Reel/Frame 059561/0311 →
Continuity (19)
Continuation 16901654 · Jun 15, 2020
Continuation 16278119 · Feb 17, 2019
Continuation In Part 16159566 · Oct 12, 2018
Continuation In Part 16055083 · Aug 4, 2018
Continuation In Part 15996208 · Jun 1, 2018
Continuation In Part 15853674 · Dec 22, 2017
Continuation In Part 15619455 · Jun 10, 2017
Continuation In Part 15254901 · Sep 1, 2016
Provisional Application 62728435 · Sep 7, 2018
Provisional Application 62631703 · Feb 17, 2018
Provisional Application 62631684 · Feb 17, 2018
Provisional Application 62572096 · Oct 13, 2017
Provisional Application 62547530 · Aug 18, 2017
Provisional Application 62541613 · Aug 4, 2017
Provisional Application 62537839 · Jul 27, 2017
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Related Publication 20220237325A1 · Jul 28, 2022