US2021201374A1PendingUtilityA1

Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments

Assignee: ONETRUST LLCPriority: Apr 1, 2016Filed: Mar 18, 2021Published: Jul 1, 2021
Est. expiryApr 1, 2036(~9.7 yrs left)· nominal 20-yr term from priority
Inventors:Kabir A. Barday
G06Q 30/0609G06Q 10/063114G06Q 10/0635G06Q 50/265
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Data processing computer systems and methods are disclosed for generating an electronic record for a privacy campaign that may include campaign data and a risk level for the privacy campaign. The risk level may be calculated using the campaign data and weighting factors. The weighting factors may be user customizable. Each piece of campaign data may have a relative risk rating that may also be user customizable and that may be used in calculating the risk level for the privacy campaign.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented data processing method for performing a privacy audit for a privacy campaign, the data processing method comprising:
 determining, by one or more computer processors, one or more of risk factors for a privacy campaign;   calculating, by one or more computer processors, a risk value for the privacy campaign based at least in part on the one or more risk factors;   determining, by one or more computer processors, a privacy audit schedule for the privacy campaign based at least in part on the risk value for the privacy campaign;   receiving, by one or more computer processors, a request to modify the privacy audit schedule for the privacy campaign;   at least partially in response to receiving the request to modify the privacy audit schedule for the privacy campaign, determining, by one or more computer processors, whether authorization of user modification of the privacy audit schedule for the privacy campaign is required;   at least partially in response to determining that the authorization of the user modification of the privacy audit schedule for the privacy campaign is required, generating, by one or more computer processors, a graphical user interface comprising a user-selectable control that, when activated, automatically generates a request for the authorization of the user modification of the privacy audit schedule for the privacy campaign;   presenting, by one or more computer processors on a display device, the graphical user interface;   receiving, by one or more computer processors, an indication of the authorization of the user modification of the privacy audit schedule for the privacy campaign;   at least partially in response to receiving the authorization of the user modification of the privacy audit schedule for the privacy campaign, soliciting, by one or more computer processors, one or more user modifications to the privacy audit schedule for the privacy campaign;   receiving, by one or more computer processors, the one or more user modifications to the privacy audit schedule for the privacy campaign;   generating, by one or more computer processors, based at least in part on the user modifications to the privacy audit schedule for the privacy campaign, a modified privacy audit schedule for the privacy campaign; and   auditing, by one or more computer processors, the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign.   
     
     
         2 . The computer-implemented data processing method of  claim 1 , wherein one or more of the one or more of risk factors for the privacy campaign are selected from a group of risk factors consisting of:
 (a) a type of data associated with the privacy campaign;   (b) a storage location of data associated with the privacy campaign;   (c) a length of time that data associated with the privacy campaign will be retained; and   (d) a jurisdiction associated with one or more data subjects associated with the privacy campaign.   
     
     
         3 . The computer-implemented data processing method of  claim 1 , wherein the privacy audit schedule for the privacy campaign comprises a first period of time between each audit performed for the privacy campaign. 
     
     
         4 . The computer-implemented data processing method of  claim 3 , wherein the request to modify the privacy audit schedule for the privacy campaign comprises a request to change the first time period to a second time period. 
     
     
         5 . The computer-implemented data processing method of  claim 1 , wherein determining the privacy audit schedule for the privacy campaign based at least in part on the risk value for the privacy campaign comprises:
 determining, by one or more computer processors, whether the risk value for the privacy campaign exceeds a threshold; and   determining, by one or more computer processors, the privacy audit schedule for the privacy campaign based at least in part on determining that the risk value for the privacy campaign exceeds the threshold.   
     
     
         6 . The computer-implemented data processing method of  claim 1 , wherein determining the privacy audit schedule for the privacy campaign based at least in part on the risk value for the privacy campaign comprises selecting, by one or more computer processors, a default privacy audit schedule as the privacy audit schedule for the privacy campaign. 
     
     
         7 . The computer-implemented data processing method of  claim 1 , further comprising transmitting, by one or more computer processors, a notification to an administrator of the request for the authorization of the user modification of the privacy audit schedule for the privacy campaign. 
     
     
         8 . A non-transitory computer-readable storage medium comprising computer-executable instructions for performing a privacy audit for a privacy campaign, the computer-executable instructions comprising instructions for:
 determining, by one or more computer processors, one or more of risk factors for a privacy campaign;   calculating, by one or more computer processors, a risk value for the privacy campaign based at least in part on the one or more risk factors;   determining, by one or more computer processors, a privacy audit schedule for the privacy campaign based at least in part on the risk value for the privacy campaign, wherein the privacy audit schedule comprises a first audit time interval;   receiving, by one or more computer processors, a request to modify the privacy audit schedule for the privacy campaign;   at least partially in response to receiving the request to modify the privacy audit schedule for the privacy campaign, determining, by one or more computer processors, whether authorization of user modification of the privacy audit schedule for the privacy campaign is required;   at least partially in response to determining that the authorization of the user modification of the privacy audit schedule for the privacy campaign is required, generating, by one or more computer processors, a graphical user interface comprising a user-selectable control that, when activated, automatically generates a request for the authorization of the user modification of the privacy audit schedule for the privacy campaign;   presenting, by one or more computer processors on a display device, the graphical user interface;   receiving, by one or more computer processors, a response to the request for the authorization of the user modification of the privacy audit schedule for the privacy campaign;   determining, by one or more computer processors, whether the response comprises the authorization of the user modification of the privacy audit schedule for the privacy campaign;   at least partially in response to determining that the response does not comprise the authorization of the user modification of the privacy audit schedule for the privacy campaign:
 retaining, by one or more computer processors, the privacy audit schedule for the privacy campaign; and 
 periodically initiating, by one or more computer processors, an audit of the privacy campaign based at least in part on the privacy audit schedule for the privacy campaign; and 
   at least partially in response to determining that the response comprises the authorization of the user modification of the privacy audit schedule for the privacy campaign:
 soliciting, by one or more computer processors, a second audit time interval; 
 receiving, by one or more computer processors, the second audit time interval; 
 generating, by one or more computer processors, a modified privacy audit schedule for the privacy campaign using the second audit time interval; and 
 periodically initiating, by one or more computer processors, an audit of the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign. 
   
     
     
         9 . The non-transitory computer-readable storage medium of  claim 8 , wherein periodically initiating the audit of the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign comprises:
 determining, by one or more computer processors, whether a period of time equal to the second audit time interval has passed since a most recent audit of the privacy campaign; and   at least partially in response to determining that the period of time equal to the second audit time interval has passed since the most recent audit of the privacy campaign, initiating, by one or more computer processors, the audit of the privacy campaign.   
     
     
         10 . The non-transitory computer-readable storage medium of  claim 8 , wherein periodically initiating the audit of the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign comprises:
 determining, by one or more computer processors, whether a period of time equal to the second audit time interval has passed since a most recent audit of the privacy campaign; and   at least partially in response to determining that the period of time equal to the second audit time interval has passed since the most recent audit of the privacy campaign, generating, by one or more computer processors, an electronic alert comprising an indication that the period of time equal to the second audit time interval has passed since the most recent audit of the privacy campaign.   
     
     
         11 . The non-transitory computer-readable storage medium of  claim 10 , wherein the electronic alert is a communication selected from a group of communications consisting of:
 (a) an email;   (b) an instant message; and   (c) a text message.   
     
     
         12 . The non-transitory computer-readable storage medium of  claim 10 , wherein periodically initiating the audit of the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign further comprises:
 at least partially in response to determining that the period of time equal to the second audit time interval has not passed since the most recent audit of the privacy campaign, generating, by one or more computer processors, an electronic alert comprising an indication of a period of time until the period of time equal to the second audit time interval will have passed since the most recent audit of the privacy campaign.   
     
     
         13 . The non-transitory computer-readable storage medium of  claim 8 , wherein the computer-executable instructions further comprise instructions for receiving, by one or more computer processors, an indication that the audit of the privacy campaign has been completed. 
     
     
         14 . The non-transitory computer-readable storage medium of  claim 13 , wherein the indication that the audit of the privacy campaign has been completed comprises one or more pieces of evidence of completion, wherein each of the one or more pieces of evidence of completion is associated with a respective portion of the audit of the privacy campaign. 
     
     
         15 . A data processing computer system for performing a privacy audit for a privacy campaign, the data processing computer system comprising:
 one or more computer processors; and   a computer memory comprising a non-transitory computer-readable medium that stores computer-executable instructions that, when executed by the one or more computer processors, cause the one or more computer processors to perform operations comprising:
 determining one or more of risk factors for a privacy campaign; 
 determining a relative risk rating for each of the one or more of risk factors; 
 determining a weighting factor for each of the one or more of risk factors; 
 calculating a risk value for the privacy campaign based at least in part on the relative risk rating for each of the one or more of risk factors and the weighting factor for each of the one or more of risk factors; 
 determining a privacy audit schedule for the privacy campaign based at least in part on the risk value for the privacy campaign; 
 receiving a request to modify the privacy audit schedule for the privacy campaign; 
 at least partially in response to receiving the request to modify the privacy audit schedule for the privacy campaign, determining whether authorization of user modification of the privacy audit schedule for the privacy campaign is required; 
 at least partially in response to determining that the authorization of the user modification of the privacy audit schedule for the privacy campaign is required, generating a graphical user interface comprising a user-selectable control that, when activated, automatically generates a request for the authorization of the user modification of the privacy audit schedule for the privacy campaign; 
 presenting the graphical user interface to a user on a display device; 
 receiving an indication of the authorization of the user modification of the privacy audit schedule for the privacy campaign; 
 at least partially in response to receiving the authorization of the user modification of the privacy audit schedule for the privacy campaign, soliciting one or more user modifications to the privacy audit schedule for the privacy campaign from the user; 
 receiving the one or more user modifications to the privacy audit schedule for the privacy campaign; 
 generating, based at least in part on the user modifications to the privacy audit schedule for the privacy campaign, a modified privacy audit schedule for the privacy campaign; and 
 periodically initiating an audit of the privacy campaign based at least in part on the modified privacy audit schedule for the privacy campaign. 
   
     
     
         16 . The data processing computer system of  claim 15 , wherein the risk value for the privacy campaign is a numerical risk value. 
     
     
         17 . The data processing computer system of  claim 15 , wherein at least one of the privacy audit schedule for the privacy campaign and the modified privacy audit schedule for the privacy campaign is based at least in part on one or more privacy laws. 
     
     
         18 . The data processing computer system of  claim 15 , wherein the operations further comprise:
 determining whether the audit of the privacy campaign is to be performed within a threshold period of time from a current time; and   at least partially in response to determining that the audit of the privacy campaign is to be performed within the threshold period of time from the current time, generating an electronic alert indicating that the audit of the privacy campaign is to be performed within the threshold period of time from the current time.   
     
     
         19 . The data processing computer system of  claim 15 , wherein the operations further comprise:
 receiving an indication that the audit of the privacy campaign has been completed; and   at least partially in response to receiving the indication that the audit of the privacy campaign has been completed, updating the modified privacy audit schedule for the privacy campaign to reflect that the audit of the privacy campaign has been completed.   
     
     
         20 . The data processing computer system of  claim 15 , wherein the weighting factor for each of the one or more of risk factors is selected from a group of factors consisting of:
 (a) a type of data associated with the respective risk factor;   (b) a storage location of data associated with the respective risk factor;   (c) a length of time that data associated with the respective risk factor will be retained in storage; and   (d) a jurisdiction of a data subject associated with data associated with the respective risk factor.

Join the waitlist — get patent alerts

Track US2021201374A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.