IP Library Patent Application 18116791
Patent Application
App. No. 18/116,791

DATA-PROCESSING CONSENT REFRESH, RE-PROMPT, AND RECAPTURE SYSTEMS AND RELATED METHODS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/116,791
Abstract

In various embodiments, a Consent Refresh, Re-Prompt, and Recapture System is configured to interface with a Consent Receipt Management System in order to, for example: ( 1 ) monitor previously provided consent by one or more data subjects that may be subject to future expiration; ( 2 ) monitor a data subject's activity to anticipate the data subject attempting an activity that may require a level of consent (e.g., for the processing of particular data subject data) that is higher than the system has received; and/or ( 3 ) identify other changes in circumstances or triggering events for a data subject that may warrant a refresh or recapture (e.g., or attempted capture) of a particular required consent (e.g., required to enable an entity to properly or legally execute a transaction with a data subject). The system may then be configured to automatically refresh, re-prompt for, and/or recapture consent as necessary.

Claims (70)

1 . A method comprising:

providing, by computing hardware, a user interface for initiating a transaction between an entity and a data subject;

receiving, by the computing hardware from a first computing device, a request from a data subject to initiate a transaction between the entity and the data subject;

in response to the request:

prompting, by the computing hardware, the data subject to provide consent to the entity for processing personal data associated with the data subject as part of the transaction; and

generating, by the computing hardware, a unique consent receipt key based on the consent;

receiving, by the computing hardware, a unique subject identifier for the data subject;

causing initiation, by the computing hardware, of a virtual browsing session on a second computing device, wherein the first computing device is different from the second computing device;

causing, by the computing hardware, access of a webpage hosting the user interface using a virtual browser during the virtual browsing session;

causing a capture, by the computing hardware via the virtual browsing session, of the user interface in an unfilled state; and

electronically associating, by the computing hardware, the unique subject identifier, the unique consent receipt key, a unique transaction identifier for the transaction, an indication of the consent, and the capture of the user interface.

2 . The method of claim 1 , wherein causing the capture of the user interface in the unfilled state comprises at least one of capturing one or more images of the user interface, capturing computer code associated with the user interface, or capturing a network link via which the user interface is accessible.

3 . The method of claim 1 , wherein:

the transaction involves providing, to the first computing device, access to computer-specific functionality; and

the method further comprises enabling, by the computing hardware, the access to the computer-specific functionality to the first computing device in response to the request.

4 . The method of claim 3 , further comprising causing, by the computing hardware, a modification to the access to the computer-specific functionality in response to a triggering event.

5 . The method of claim 4 , wherein the method further comprises re-prompting the data subject for the consent in response to the triggering event.

6 . The method of claim 5 , wherein the triggering comprises at least one of a change in a location of the first computing device, a determination that the first computing device has accessed at least a particular number of additional webpages on a particular website that includes the webpage, or a passage of a particular amount of time from generation of the unique consent receipt key.

7 . The method of claim 1 , wherein:

the indication of consent comprises a lack of consent; and

the method further comprises preventing, based on the lack of consent, the first computing device from accessing the computer-specific functionality under the transaction.

8 . A system comprising:

a non-transitory computer-readable medium storing instructions; and

processing hardware communicatively coupled to the non-transitory computer-readable medium, wherein the processing hardware is configured to execute the instructions and thereby perform operations comprising:

providing, at a webpage, a user interface for accessing computer-specific functionality via the webpage;

receiving, from a first computing device, a request to access the computer-specific functionality via the webpage;

responsive to the request:

prompting, via the user interface, a user of the first computing device to provide consent to processing of personal data associated with the user in order to access the computer-specific functionality; and

generating a consent receipt set based on the consent, the consent receipt set comprising a user identifier identifying the user and an indication of the consent;

accessing, by a second computing device, the user interface;

generating a user interface profile that identifies a manner in which the user interface captured the consent; and

linking the user interface profile to the consent receipt set.

9 . The system of claim 8 , wherein:

accessing the user interface comprises:

initiating, by the second computing device, a virtual browsing session; and

accessing, by the second computing device, the webpage using a virtual browser during the virtual browsing session; and

generating the user interface profile that identifies the manner in which the user interface captured the consent comprises capturing, by the second computing device during the virtual browsing session, a copy of the user interface.

10 . The system of claim 9 , wherein capturing the copy of user interface comprises at least one of capturing one or more images of the user interface, capturing computer code associated with the user interface, or capturing a network link via which the user interface is accessible.

11 . The system of claim 8 , wherein the operations further comprise providing, to the first computing device, access to the computer-specific functionality via the webpage in response to the request.

12 . The system of claim 8 , wherein the operations further comprise:

identifying a triggering event; and

responsive to identifying the triggering event:

modifying the consent receipt set such that the indication of the consent indicates an expiration of the consent; and

re-prompting the data subject to provide the consent.

13 . The system of claim 12 , wherein the triggering comprises at least one of a change in a location of the first computing device, a determination that the first computing device has accessed at least a particular number of additional webpages on a particular website that includes the webpage, or a passage of a particular amount of time from generation of the consent receipt set.

14 . A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

receiving a first indication of a request from a first computing device to access computer-specific functionality via webpage;

receiving a second indication of consent, from the first computing device via a user interface at the webpage, related to processing of personal data associated with a user of the computing device in order to access the computer-specific functionality; and

responsive to at least one of the first indication or the second indication:

generating a consent receipt set based on the consent, the consent receipt set comprising a user identifier identifying the user and the second indication of the consent;

causing access to the user interface by a second computing device;

generating a user interface profile that identifies a manner in which the user interface captured the consent; and

linking the user interface profile to the consent receipt set.

15 . The non-transitory computer-readable medium of claim 14 , wherein:

causing access to the user interface by the second computing device comprises:

causing the second computing device to initiate a virtual browsing session; and

causing the second computing device to access the webpage using a virtual browser during the virtual browsing session; and

generating the user interface profile that identifies the manner in which the user interface captured the consent comprises causing the second computing device to capture the user interface in an unfilled state during the virtual browsing session.

16 . The non-transitory computer-readable medium of claim 15 , wherein causing the second computing device to capture the user interface in the unfilled state during the virtual browsing session comprises at least one of causing the second computing device to capture one or more images of the user interface, causing the second computing device to capture computer code associated with the user interface, or causing the second computing device to capture a network link via which the user interface is accessible.

17 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

determining, based on the computer-specific functionality, that the consent is subject to an expiration condition;

receiving a third indication of an occurrence of the expiration condition; and

responsive to the third indication, modifying the second indication of the consent to reflect the occurrence of the expiration condition.

18 . The non-transitory computer-readable medium of claim 17 , the operations further comprising responsive to the third indication:

at least temporarily preventing the first computing device from accessing the computer-specific functionality; and

causing a recapture of the consent.

19 . The non-transitory computer-readable medium of claim 17 , wherein the expiration condition comprises at least one of a change in location of the first computing device, a passage of time since generation of the consent receipt set, or a change in the computer-specific functionality.

20 . The non-transitory computer-readable medium of claim 14 , wherein:

the second indication of the consent comprises a lack of consent; and

the operations further comprise preventing, based on the lack of consent, the first computing device from accessing the computer-specific functionality.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2023
From: BRANNON, JONATHAN BLAKE; HILL, CASEY; JONES, KEVIN; BEAUMONT, RICHARD A.
To: ONETRUST, LLC
Reel/Frame 062877/0517 →