IP Library Patent Application 15619237
Patent Application
App. No. 15/619,237

DATA PROCESSING AND COMMUNICATION SYSTEMS AND METHODS FOR OPERATIONALIZING PRIVACY COMPLIANCE AND REGULATION AND RELATED SYSTEMS AND METHODS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/619,237
Filed
Jun 9, 2017
Art Unit
3629
USPC
705/325
Abstract

A privacy compliance oversight system, according to particular embodiments, is configured to facilitate review and oversight of privacy campaign information by a third-party regulator. The system may implement this oversight by: (1) flagging a particular privacy campaign, project, or other activity for review by a third-party regulators; (2) in response to flagging the particular privacy campaign, project, or other activity for review, preparing campaign data associated with the particular privacy campaign, project, or other activity for review by the third-party regulator; (3) providing the third party regulator with access to the privacy campaign data; (4) receiving one or more pieces of feedback associated with the particular privacy campaign, project, or other activity from the third-party regulators; and (5) in response to receiving the one or more pieces of feedback, modifying the privacy campaign data to include the one or more pieces of feedback.

Claims (75)

1 . A computer-implemented data processing method for facilitating third-party regulatory oversight of a privacy compliance system associated with an organization, the method comprising:

flagging, by one or more processors, a particular project undertaken by the organization that includes the use of personal data for review, wherein:

the privacy compliance system digitally stores an electronic record associated with the particular project, the electronic record comprising:

one or more types of personal data collected as part of the project;

a subject from which the personal data was collected;

a storage location of the personal data; and

one or more access permissions associated with the personal data;

in response to flagging the particular project, preparing, by one or more processors, the electronic record for review by a third-party regulator;

providing, by one or more processors, the third-party regulator with access to the electronic record;

receiving, from the third-party regulator, by one or more processors, one or more pieces of feedback associated with the project; and

in response to receiving the one or more pieces of feedback, modifying, by one or more processors, the electronic record to include the one or more pieces of feedback.

2 . The computer-implemented data processing method of claim 1 , the method further comprising:

receiving, by one or more processors, a request for review of the project from an individual associated with the organization; and

the step of flagging the particular project undertaken by the organization that includes the use of personal data in response to the request.

3 . The computer-implemented data processing method of claim 1 , the method further comprising:

the step of automatically flagging the particular project undertaken by the organization for review, by one or more processors, based at least in part on at least one aspect of the electronic record selected from the group consisting of:

one or more types of personal data related to the project;

a subject from which the personal data was collected;

a storage location of the personal data; and

one or more access permissions associated with the personal data.

4 . The computer-implemented data processing method of claim 1 , the method further comprising automatically flagging the particular project undertaken by the organization for review, by one or more processors, in response to initiation of the project by the organization and creation of the electronic record.

5 . The computer-implemented data processing method of claim 1 , wherein preparing the electronic record for review by the third-party regulator comprises using one or more machine translation techniques on at least a portion of the electronic record to translate the personal data from a first human language to a second human language.

6 . The computer-implemented data processing method of claim 1 , wherein providing the third-party regulator with access to the electronic record comprises providing access to the third-party regulator, via one or more graphical user interfaces, to at least a portion of the privacy compliance system, the at least a portion of the privacy compliance system comprising the electronic record.

7 . The computer-implemented data processing method of claim 6 , wherein providing the third-party regulator with access to the electronic record comprises:

generating a secure link between the electronic record and a computing device associated with the third-party regulator; and

providing access, to the third-party regulator via the secure link, to the electronic record.

8 . The computer-implemented data processing method of claim 7 , wherein:

the one or more pieces of feedback comprise approval of the storage location of the personal data; and

the method further comprises:

modifying the electronic record to include the approval; and

implementing the project by collecting one or more pieces of personal data and storing the one or more pieces of personal data in the storage location.

9 . The computer-implemented data processing method of claim 1 , wherein preparing the electronic record for review by a third-party regulator comprises modifying and exporting the electronic record into a standardized format.

10 . A computer-implemented data processing method for electronically facilitating third-party regulation of a privacy campaign, the method comprising:

displaying, on a graphical user interface, a prompt to create an electronic record for a privacy campaign;

receiving a command to create an electronic record for the privacy campaign;

creating an electronic record for the privacy campaign comprising campaign data and digitally storing the record in memory, the campaign data comprising:

a description of the campaign;

one or more types of personal data related to the campaign;

a subject from which the personal data was collected;

a storage location of the personal data; and

one or more access permissions associated with the personal data;

processing the campaign data by electronically associating the campaign data with the record for the privacy campaign;

digitally storing the campaign data associated with the record for the campaign;

identifying, by one or more processors, one or more pieces of campaign data that require third-party regulator approval;

exporting, by a processor, the identified one or more pieces of campaign data for review by the third-party regulator;

displaying, on a graphical user interface, the one or more pieces of campaign data to the third-party regulator and a prompt to provide feedback regarding the one or more pieces of campaign data;

receiving, from the third-party regulator, via the graphical user interface, feedback regarding the one or more pieces of campaign data; and

modifying the electronic record for the privacy campaign to include the feedback.

11 . The computer-implemented data processing method of claim 10 , wherein exporting the identified one or more pieces of campaign data for review by the third-party regulator comprises exporting the identified one or more pieces of campaign data into a standardized format and transmitting the identified one or more pieces of campaign data to a computing device associated with the third party-regulator via one or more computer networks.

12 . The computer-implemented data processing method of claim 10 , wherein exporting the identified one or more pieces of campaign data for review by the third-party regulator comprises:

generating a secure link between the electronic record for the privacy campaign and a computing device associated with the third-party regulator; and

providing access, to the third-party regulator via the secure link, to at least a portion of the electronic record for the privacy campaign, the at least a portion of the electronic record for the privacy campaign comprising the identified one or more pieces of campaign data for review.

13 . The computer-implemented data processing method of claim 10 , further comprising:

generating a log of actions taken by the third-party regulator while accessing the at least a portion of the electronic record for the privacy campaign via the secure link; and

associating, in memory, the log with the electronic record for the privacy campaign.

14 . The computer-implemented data processing method of claim 10 , wherein:

identifying the one or more pieces of campaign data that require third-party regulator approval comprises receiving a request from a user for the third-party regulator to review the one or more pieces of campaign data.

15 . A computer-implemented data processing method for electronically performing third-party oversight of one or more privacy assessments of computer code, the method comprising:

flagging the computer code for third-party oversight, the computer code being stored in a location;

electronically obtaining the computer code based on the location provided;

automatically electronically analyzing the computer code to determine one or more privacy-related attributes of the computer code, each of the privacy-related attributes indicating one or more types of personal information that the computer code collects or accesses;

generating a list of the one or more privacy-related attributes;

transmitting the list of the one or more privacy-related attributes to a computing device associated with a third-party regulator;

electronically displaying one or more prompts to the third-party regulator, each prompt informing the third-party regulator to input information regarding one or more of the one or more privacy-related attributes; and

communicating the information regarding the one or more privacy-related attributes to one or more second individuals for use in conducting a privacy assessment of the computer code.

16 . The computer-implemented data processing method of claim 15 , the method further comprising using one or more machine translation techniques to translate the list of the one or more privacy-related attributes from a first language to a second language.

17 . The computer-implemented data processing method of claim 15 , wherein transmitting the list of the one or more privacy-related attributes to a computing device associated with a third-party regulator comprises transmitting the list of the one or more privacy-related attributes via a secure link.

18 . The computer-implemented data processing method of claim 15 , further comprising automatically modifying the computer code based at least in part on the information regarding the one or more of the one or more privacy-related attributes.

19 . The computer-implemented data processing method of claim 15 , further comprising:

receiving, by one or more processors, a request for third-party oversight of the computer code; and

flagging the computer code for third-party oversight in response to the request.

20 . The computer-implemented data processing method of claim 19 , wherein:

the computer code is associated with an organization;

the request is an expedited request; and

the method further comprises reducing a number of expedited requests available to the organization in response to the expedited request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2017
From: BARDAY, KABIR A.
To: ONETRUST, LLC
Reel/Frame 042727/0293 →