Data collection analysis for privacy risk assessment
A method includes identifying, by a processing device, a third-party service provider of a plurality of third-party service providers that is authorized by a user to access data associated with the user. A data privacy score is generated based on one or more privacy risk factors. The data privacy score is associated with the third-party service provider. The data privacy score is indicative of a level of protection and privacy the third-party service provider maintains with respect to the data. A user interface (UI) displaying at least the data privacy score associated with the third-party service provider is provided for presentation on a client device associated with the user.
1 . A method comprising:
identifying, by at least one hardware processor of a first party host system, a plurality of third-party service providers that are authorized by a user to access user data;
continuously analyzing, by the at least one hardware processor of the first party host system, handling of user data by each of the plurality of third-party service providers, wherein the continuously analyzing comprises analyzing outbound application programming interface (API) calls that require access to the user data by reviewing log data associated with the outbound API calls to determine which of the plurality of third-party service providers require access to what user data;
determining, by the at least one hardware processor of the first party host system, a data privacy score for each of the plurality of third-party service providers based on one or more privacy risk factors corresponding to handling of user data by a respective third-party service provider;
associating the data privacy score with the respective third-party service provider, wherein the data privacy score is indicative of a level of protection and privacy of the respective third-party service provider maintains with respect to the handling of the user data; and
providing, by the at least one hardware processor of the first party host system and for presentation on a client device associated with the user, a user interface (UI) displaying at least the data privacy score associated with the respective third-party service provider, the UI further comprising a data flow map that illustrates at least one of: what user data is being shared with one or more of the plurality of third-party service providers, with which of the plurality of third-party service providers the user data is being shared, or with what other entities the plurality of third-party service providers share the user data.
2 . The method of claim 1 , wherein the one or more privacy risk factors comprise one or more of data protection analysis, legal document analysis, third-party service provider notices, an allowlist, a denylist, application programming interface (API) analysis, application log analysis, user privacy preferences, or threat intelligence analysis.
3 . The method of claim 1 , further comprising:
determining that the data privacy score associated with the respective third-party service provider is lower than a threshold data privacy score; and
providing an indication for the user to cease sharing the data with the respective third-party service provider.
4 . The method of claim 1 , further comprising:
combining data privacy scores of the plurality of third-party service providers to determine an overall data privacy score associated with the user.
5 . The method of claim 1 , wherein the determining the data privacy score for each of the plurality of third-party service providers based on one or more privacy risk factors comprises:
providing documentation associated with the respective third-party service provider as input to a machine learning model, wherein the machine learning model is trained to predict, based on a given textual input, data privacy policies associated with the given textual input;
obtaining a plurality of outputs from the machine learning model, wherein the plurality of outputs indicate one or more passages within the documentation associated with the data privacy policies of the respective third-party service provider; and
analyzing the one or more passages to determine the data privacy score.
6 . The method of claim 1 , further comprising modifying the data privacy score responsive to determining that terms and conditions governing sharing of data between the user and the respective third-party service provider have expired.
7 . The method of claim 1 , further comprising:
determining that the data associated with the user has been compromised in a privacy breach; and
transmitting a notification to the client device associated with the user, wherein the notification indicates that the data associated with the user has been compromised.
8 . The method of claim 1 , wherein the UI further displays information to request revocation of authorization of the plurality of third-party service providers to access the data associated with the user.
9 . A first party host system comprising:
a memory device; and
at least one hardware processor coupled to the memory device, the at least one hardware processor to perform operations comprising:
identifying a plurality of third-party service providers that are authorized by a user to access user data;
continuously analyzing handling of user data by each of the plurality of third-party service providers, wherein the continuously analyzing comprises analyzing outbound application programming interface (API) calls that require access to the user data by reviewing log data associated with the outbound API calls to determine which of the plurality of third-party service providers require access to what user data;
determining a data privacy score for each of the plurality of third-party service providers based on one or more privacy risk factors corresponding to handling of user data by a respective third-party service provider;
associating the data privacy score with the respective third-party service provider, wherein the data privacy score is indicative of a level of protection and privacy of the respective third-party service provider maintains with respect to the handling of the user data; and
providing, for presentation on a client device associated with the user, a user interface (UI) displaying at least the data privacy score associated with the respective third-party service provider, the UI further comprising a data flow map that illustrates at least one of: what user data is being shared with one or more of the plurality of third-party service providers, with which of the plurality of third-party service providers the user data is being shared, or with what other entities the plurality of third-party service providers share the user data.
10 . The system of claim 9 , wherein the one or more privacy risk factors comprise one or more of data protection analysis, legal document analysis, third-party service provider notices, an allowlist, a denylist, application programming interface (API) analysis, application log analysis, user privacy preferences, or threat intelligence analysis.
11 . The system of claim 9 , the operations further comprising, responsive to determining that the data privacy score does not satisfy a threshold condition, providing, for presentation on the client device associated with the user, the user interface (UI) displaying an indication for the user to cease sharing the data with the respective third-party service provider.
12 . The system of claim 9 , the operations further comprising:
determining a second data privacy score for another third-party service provider authorized by the user to access the data associated with the user; and
combining the data privacy score and the second data privacy score to determine an overall data privacy score associated with the user.
13 . The system of claim 9 , wherein the determining the data privacy score based on one or more privacy risk factors comprises:
providing documentation associated with the respective third-party service provider as input to a machine learning model, wherein the machine learning model is trained to predict, based on a given textual input, data privacy policies associated with the given textual input;
obtaining a plurality of outputs from the machine learning model, wherein the plurality of outputs indicate one or more passages within the documentation associated with the data privacy policies of the respective third-party service provider; and
analyzing the one or more passages to determine the first data privacy score.
14 . The system of claim 9 , the operations further comprising modifying the data privacy score responsive to determining that terms and conditions governing sharing of data between the user and the respective third-party service provider have expired.
15 . The system of claim 9 , the operations further comprising:
determining that the data associated with the user has been compromised in a privacy breach; and
transmitting a notification to the client device associated with the user, wherein the notification indicates that the data associated with the user has been compromised.
16 . The system of claim 9 , wherein the UI further displays information to request revocation of authorization of the respective third-party service provider to access the data associated with the user.
17 . A non-transitory computer-readable storage medium comprising instructions for a server that, when executed by at least one hardware processor of a first party host system, cause the at least one hardware processor of a first party host system to perform operations comprising:
identifying a plurality of third-party service providers that is authorized by a user to access user data;
continuously analyzing handling of user data by each of the plurality of third-party service providers, wherein the continuously analyzing comprises analyzing outbound application programming interface (API) calls that require access to the user data by reviewing log data associated with the outbound API calls to determine which of the plurality of third-party service providers require access to what user data;
determining a data privacy score for each of the plurality of third-party service providers based on one or more privacy risk factors corresponding to handling of user data by a respective third-party service provider;
associating the data privacy score with the respective third-party service provider, wherein the data privacy score is indicative of a level of protection and privacy of the respective third-party service provider maintains with respect to the handling of the user data; and
providing, for presentation on a client device associated with the user, a user interface (UI) displaying at least the data privacy score associated with the respective third-party service provider, the UI further comprising a data flow map that illustrates at least one of: what user data is being shared with one or more of the plurality of third-party service providers, with which of the plurality of third-party service providers the user data is being shared, or with what other entities the plurality of third-party service providers share the user data.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the one or more privacy risk factors comprise one or more of data protection analysis, legal document analysis, third-party service provider notices, an allowlist, a denylist, application programming interface (API) analysis, application log analysis, user privacy preferences, or threat intelligence analysis.
19 . The non-transitory computer-readable storage medium of claim 17 , the operations further comprising:
determining that the data privacy score associated with the respective third-party service provider is lower than a threshold data privacy score; and
providing an indication for the user to cease sharing the data with the respective third-party service provider.
20 . The non-transitory computer-readable storage medium of claim 17 , the operations further comprising:
combining data privacy scores of the plurality of third-party service providers to determine an overall data privacy score associated with the user.