IP Library Granted Patent US 12,086,748
Granted Patent B2
US 12,086,748 · App. 17/739,364 · Granted Sep 10, 2024

Data processing systems for assessing readiness for responding to privacy-related incidents

Inventors: Trey Hecht (Atlanta, GA); Andrew Clearwater (Brunswick, ME); Jonathan Blake Brannon (Smyrna, GA); Linda Thielová (London, GB)
Assignee: OneTrust, LLC
G06Q10/0635G06F15/76G06F21/552G06F21/577G06F21/6245G06Q10/063114G06Q10/06316G06Q10/06393G06Q10/067G06Q30/018G06F16/95
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,086,748
App. No.
17/739,364
Granted
Sep 10, 2024
Kind
B2
Abstract

Data processing systems and methods, according to various embodiments, are adapted for mapping various questions regarding a data breach from a master questionnaire to a plurality of territory-specific data breach disclosure questionnaires. The answers to the questions in the master questionnaire are used to populate the territory-specific data breach disclosure questionnaires and determine whether disclosure is required in territory. The system can automatically notify the appropriate regulatory bodies for each territory where it is determined that data breach disclosure is required.

Claims (80)

1. A method comprising:

receiving, by computing hardware, information on a data breach incident involving a processing activity executed by a computing system associated with an entity;

identifying, by the computing hardware and based on the information, a data structure mapping a set of attributes to the processing activity;

determining, by the computing hardware using the data structure, a geographic location associated with the computing system, wherein the set of attributes identifies the geographic location;

determining, by the computing hardware and based on the geographic location, a required activity to address the data breach incident;

configuring, by the computing hardware, a graphical user interface to display a mechanism for the required activity, wherein the mechanism is configured so that an indication can be provided for the required activity;

receiving, by the computing hardware, the indication via the mechanism for the required activity, wherein the indication corresponds to a progress of completion of the required activity; and

responsive to receiving the indication:

generating, by the computing hardware, data breach response data identifying the progress of completion of the required activity; and

configuring, by the computing hardware and based on the data breach response data, the graphical user interface to display (i) a readiness indicator representing a readiness of the entity to address the data breach incident and (ii) a plurality of comparison readiness indicators in which each comparison readiness indicator of the plurality of comparison readiness indicators represents a readiness of a different entity to address the data breach incident.

2. The method of claim 1 , wherein the data breach response data indicates an urgency of addressing the data breach incident for the geographic location.

3. The method of claim 2 , wherein the processing activity is further executed by a second computing system, and the method further comprises:

determining, by the computing hardware using the data structure, a second geographic location associated with the second computing system, wherein the set of attributes identifies the second geographic location;

determining, by the computing hardware and based on the second geographic location, a second required activity to address the data breach incident;

configuring, by the computing hardware, the graphical user interface to display a second mechanism for the second required activity, wherein the second mechanism is configured so that a second indication can be provided for the second required activity;

receiving, by the computing hardware, the second indication via the second mechanism for the second required activity, wherein the second indication corresponds to a progress of completion of the second required activity; and

responsive to receiving the second indication:

generating, by the computing hardware, second data breach response data based on the progress of completion of the second required activity, wherein the second data breach response data indicates an urgency of addressing the data breach incident for the second geographic location; and

configuring, by the computing hardware and based on the second data breach response data, the graphical user interface to display the urgency of addressing the data breach incident for the second geographic location is higher than the urgency of addressing the data breach incident for the geographic location.

4. The method of claim 1 , wherein the data breach response data comprises at least one of whether a relevant deadline for completion of the required activity or whether the required activity was performed properly.

5. The method of claim 1 further comprising determining, by the computing hardware, a relative ranking of each readiness of the different entity to address the data breach incident, wherein the plurality of comparison readiness indicators are displayed according to the relative ranking of each readiness.

6. The method of claim 1 further comprising configuring, by the computing hardware, the graphical user interface to display an upload mechanism, wherein the upload mechanism is configured to facilitate uploading of at least one of data that has been reported to a second entity, data that has been collected for compliance, or data regarding a third entity responsible for the data breach incident.

7. The method of claim 1 , wherein:

the indication corresponding to the progress of completion of the required activity indicates a completion of the required activity, and

the method further comprises, responsive to the indication indicting the completion of the required activity, configuring, by the computing hardware, the graphical user interface to no longer display the mechanism for the required activity.

8. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium,

wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

receiving information on a data breach incident involving a data asset associated with a computing system for an entity;

identifying, based on the information, a data structure mapping a set of attributes to the data asset;

determining, using the data structure, a type of data handled by the data asset, wherein the set of attributes identifies the type of data;

determining, based on the type of data, a required activity to address the data breach incident;

configuring a graphical user interface to display a mechanism for the required activity, wherein the mechanism is configured so that an indication can be provided for the required activity;

receiving the indication via the mechanism for the required activity, wherein the indication corresponds to a progress of completion of the required activity; and

responsive to receiving the indication:

generating data breach response data identifying the progress of completion of the required activity; and

configuring, based on the data breach response data, the graphical user interface to display (i) a readiness indicator representing a readiness of the entity to address the data breach incident and (ii) a plurality of comparison readiness indicators in which each comparison readiness indicator of the plurality of comparison readiness indicators represents a readiness of a different entity to address the data breach incident.

9. The system of claim 8 , wherein the data breach response data indicates an urgency of addressing the data breach incident for the data asset.

10. The system of claim 9 , wherein the operations further comprises:

determining, using the data structure, a second data asset associated with the computing system and used in handling the type of data, wherein the data structure provides a mapping a second set of attributes to the second data asset and the second set of attributes identify the type of data;

determining, based on the second data asset, a second required activity to address the data breach incident;

configuring the graphical user interface to display a second mechanism for the second required activity, wherein the second mechanism is configured so that a second indication can be provided for the second required activity;

receiving the second indication via the second mechanism for the second required activity, wherein the second indication corresponds to a progress of completion of the second required activity; and

responsive to receiving the second indication:

generating second data breach response data based on the progress of completion of the second required activity, wherein the second data breach response data indicates an urgency of addressing the data breach incident for the second data asset; and

configuring, based on the second data breach response data, the graphical user interface to display the urgency of addressing the data breach incident for the second data asset is higher than the urgency of addressing the data breach incident for the data asset.

11. The system of claim 8 , wherein the data breach response data comprises at least one of whether a relevant deadline for completion of the required activity or whether the required activity was performed properly.

12. The system of claim 8 , wherein the operations further comprise determining a relative ranking of each readiness of the different entity to address the data breach incident, and the plurality of comparison readiness indicators are displayed according to the relative ranking of each readiness.

13. The system of claim 8 , wherein the operations further comprise configuring the graphical user interface to display an upload mechanism configured to facilitate uploading of at least one of data that has been reported to a second entity, data that has been collected for compliance, or data regarding a third entity responsible for the data breach incident.

14. The system of claim 8 , wherein:

the indication corresponding to the progress of completion of the required activity indicates a completion of the required activity, and

the operations further comprise, responsive to the indication indicting the completion of the required activity, configuring the graphical user interface to no longer display the mechanism for the required activity.

15. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

receiving information on a data breach incident involving a processing activity executed by a computing system associated with an entity;

identifying, based on the information, a data structure mapping a set of attributes to the processing activity;

determining, using the data structure, at least one of a type of data involves in the processing activity or a geographic location associated with the computing system, wherein the set of attributes identifies at least one of the type of data or the geographic location;

determining, based on at least one of the type of data or the geographic location, a required activity to address the data breach incident;

configuring a graphical user interface to display a mechanism for the required activity, wherein the mechanism is configured so that an indication can be provided for the required activity;

receiving the indication via the mechanism for the required activity, wherein the indication corresponds to a progress of completion of the required activity; and

responsive to receiving the indication:

generating data breach response data identifying the progress of completion of the required activity; and

configuring, based on the data breach response data, the graphical user interface to display (i) a readiness indicator representing a readiness of the entity to address the data breach incident and (ii) a plurality of comparison readiness indicators in which each comparison readiness indicator of the plurality of comparison readiness indicators represents a readiness of a different entity to address the data breach incident.

16. The non-transitory computer-readable medium of claim 15 , wherein:

the data breach response data indicates an urgency of addressing the data breach incident for the geographic location,

the processing activity is further executed by a second computing system, and

the operations further comprise:

determining, using the data structure, a second geographic location associated with the second computing system, wherein the set of attributes identifies the second geographic location;

determining, based on the second geographic location, a second required activity to address the data breach incident;

configuring the graphical user interface to display a second mechanism for the second required activity, wherein the second mechanism is configured so that a second indication can be provided for the second required activity;

receiving the second indication via the second mechanism for the second required activity, wherein the second indication corresponds to a progress of completion of the second required activity; and

responsive to receiving the second indication:

generating second data breach response data based on the progress of completion of the second required activity, wherein the second data breach response data indicates an urgency of addressing the data breach incident for the second geographic location; and

configuring, based on the second data breach response data, the graphical user interface to display the urgency of addressing the data breach incident for the second geographic location is higher than the urgency of addressing the data breach incident for the geographic location.

17. The non-transitory computer-readable medium of claim 15 , wherein the data breach response data comprises at least one of whether a relevant deadline for completion of the required activity or whether the required activity was performed properly.

18. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise determining a relative ranking of each readiness of the different entity to address the data breach incident, and the plurality of comparison readiness indicators are displayed according to the relative ranking of each readiness.

19. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise configuring the graphical user interface to display an upload mechanism configured to facilitate uploading of at least one of data that has been reported to a second entity, data that has been collected for compliance, or data regarding a third entity responsible for the data breach incident.

20. The non-transitory computer-readable medium of claim 15 , wherein:

the indication corresponding to the progress of completion of the required activity indicates a completion of the required activity, and

the operations further comprise, responsive to the indication indicting the completion of the required activity, configuring the graphical user interface to no longer display the mechanism for the required activity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: HECHT, TREY; CLEARWATER, ANDREW; BRANNON, JONATHAN BLAKE; THIELOVA, LINDA
To: ONETRUST, LLC
Reel/Frame 059868/0707 →
Continuity (23)
Continuation 17407765 · Aug 20, 2021
Continuation 17164029 · Feb 1, 2021
Continuation 16901662 · Jun 15, 2020
Continuation In Part 16808496 · Mar 4, 2020
Continuation In Part 16714355 · Dec 13, 2019
Continuation 16403358 · May 3, 2019
Continuation 16159634 · Oct 13, 2018
Continuation In Part 16055083 · Aug 4, 2018
Continuation In Part 15996208 · Jun 1, 2018
Continuation In Part 15853674 · Dec 22, 2017
Continuation In Part 15619455 · Jun 10, 2017
Continuation In Part 15254901 · Sep 1, 2016
Provisional Application 62861916 · Jun 14, 2019
Provisional Application 62813584 · Mar 4, 2019
Provisional Application 62728435 · Sep 7, 2018
Provisional Application 62572096 · Oct 13, 2017
Provisional Application 62547530 · Aug 18, 2017
Provisional Application 62541613 · Aug 4, 2017
Provisional Application 62537839 · Jul 27, 2017
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Related Publication 20220261717A1 · Aug 18, 2022
Cited By (1)
US 12,700,036