Data processing systems for fulfilling data subject access requests and related methods
Abstract
In various embodiments, before a data subject request can be processed, the data subject's identity may need to be verified. In various embodiments, the system provides a mechanism to automatically detect the type of authentication required for a particular data subject based on the type of Data Subject Access Request being made and automatically issues a request to the data subject to verify their identity against that form of identification. For example, a subject rights request might only require two types of authentication, but a deletion request may require four types of data to verify authentication. The system may automatically detect which is type of authentication is required based on the DSAR and send an appropriate request to the data subject to verify their identity.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method in which one or more computing devices perform operations comprising:
receiving a data subject access request to access data for a data subject from a requestor, wherein the data subject access request comprises an identifying characteristic for the data subject; determining whether the data subject exist based at least in part on the identifying characteristic for the data subject; responsive to determining the data subject exists, providing a plurality of knowledge-based authentication questions configured to validate the requestor as the data subject; receiving a response to at least one of the plurality of knowledge-based authentication questions from the requestor; determining whether the requestor is the data subject based at least in part on the response provided by the requestor to the at least one of the plurality of knowledge-based authentication questions being correct; and responsive to determining the requestor is the data subject:
providing an authentication token to the requestor; and
sending an electronic correspondence to the requestor, wherein the electronic correspondence comprises a link that the requestor may select to gain access to the data by providing the authentication token.
2 . The method of claim 1 , wherein the link is configured to open a graphical user interface to gain access to the data, and the graphical user interface is configured to request the requestor to provide the authentication token to access the data.
3 . The method of claim 2 , wherein the graphical user interface comprises a website that is accessible via the link through a browser executing on a computing device being used by the requestor.
4 . The method of claim 2 , wherein the operations further comprise:
generating a unique identifier for the data subject access request; and providing the unique identifier along with the authentication token to the requestor, wherein the graphical user interface requests the requestor to provide the unique identifier along with the authentication token to access the data.
5 . The method of claim 1 , wherein providing the plurality of knowledge-based authentication questions comprises providing the plurality of knowledge-based authentication questions for display on a graphical user interface so that the requestor can provide the response to the at least one of the plurality of knowledge-based authentication questions.
6 . The method of claim 1 , wherein the operations further comprise:
providing the identifying characteristic for the data subject to a third-party system; receiving third-party data for the data subject from the third-party system; and generating the plurality of knowledge-based authentication questions based at least in part on the third-party data, wherein the third-party data comprises a correct response to each of the plurality of knowledge-based authentication questions.
7 . The method of claim 1 , the operations further comprising:
identifying a type for the data subject access request; and determining, based at least in part on the type, a number of the plurality of knowledge-based authentication questions required to be answered with a correct response to validate the requestor as the data subject.
8 . A system comprising:
a non-transitory computer-readable medium storing instructions; and a processing device communicatively coupled to the non-transitory computer-readable medium, wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:
receiving a data subject access request to access personal data from a requestor;
responsive to receiving the data subject access request, providing a knowledge-based authentication question for display via a graphical user interface to the requestor, the knowledge-based authentication question configured to validate the requestor as a data subject associated with the personal data;
requesting a response to the knowledge-based authentication question from the requestor through the graphical user interface;
receiving the response to the knowledge-based authentication question from the requestor;
determining whether the requestor is the data subject based at least in part on the response provided by the requestor to the knowledge-based authentication question being correct; and
responsive to determining the requestor is the data subject:
providing an authentication token to the requestor through a first electronic correspondence; and
providing a link to the requestor through a second electronic correspondence, wherein the link is configured to be selected by the requestor to gain access to the personal data by providing the authentication token.
9 . The system of claim 8 , wherein the data subject access request comprises an identifying characteristic for the data subject and the operations further comprise:
determining whether the data subjects exist based at least in part on the identifying characteristic for the data subject, in which the knowledge-based authentication question is provided for display via the graphical user interface in response to determining the data subject exists.
10 . The system of claim 9 , wherein the operations further comprise determining whether the data subject exists by submitting the identifying characteristic for the data subject to a credit reporting agency to confirm that an individual with the identifying characteristic exists.
11 . The system of claim 8 , wherein the link is configured to open a second graphical user interface to gain access to the personal data, and the graphical user interface is configured to request the requestor to provide the authentication token to access the personal data.
12 . The system of claim 8 , wherein the operations further comprise:
providing the identifying characteristic for the data subject to a third-party system; receiving third-party data for the data subject from the third-party system; and generating the knowledge-based authentication question based at least in part on the third-party data, wherein the third-party data comprises the response to the knowledge-based authentication question.
13 . The system of claim 8 , wherein the operations further comprise:
receiving an image of an identifying document via the graphical user interface, in which determining whether the requestor is the data subject is also based at least in part on the image of the identifying document.
14 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by processing hardware, configure the processing hardware to perform operations comprising:
receiving a data subject access request to access personal data of a data subject from a requestor; generating a knowledge-based authentication question based at least in part on the data subject access request, wherein the knowledge-based authentication question is configured to validate the requestor as the data subject and is provided for display via a graphical user interface to the requestor to request a response from the requestor; receiving the response to the knowledge-based authentication question from the requestor; determining whether the requestor is the data subject based at least in part on the response provided by the requestor to the knowledge-based authentication question being correct; and responsive to determining the requestor is the data subject:
providing an authentication token to the requestor through an electronic correspondence; and
providing a link to the requestor, wherein the link is configured to be selected by the requestor to gain access to the personal data by providing the authentication token.
15 . The non-transitory computer-readable medium of claim 14 , wherein the data subject access request comprises an identifying characteristic for the data subject and the operations further comprise:
determining whether the data subject exists based at least in part on the identifying characteristic for the data subject, in which the knowledge-based authentication question is generated in response to the determining the data subject exist.
16 . The non-transitory computer-readable medium of claim 15 , wherein determining whether the data subject exist comprises submitting the identifying characteristic for the data subject to a third-party external system to confirm that an individual with the identifying characteristic exist.
17 . The non-transitory computer-readable medium of claim 14 , wherein the link is configured to open a second graphical user interface to gain access to the personal data, and the graphical user interface is configured to request the requestor to provide the authentication token to access the personal data.
18 . The non-transitory computer-readable medium of claim 14 , wherein the data subject access request comprises an identifying characteristic for the data subject and the operations further comprise:
providing the identifying characteristic for the data subject to a third-party external system; and receiving third-party data for the data subject from the third-party external system, in which the third-party data comprises the response to the knowledge-based authentication question and the knowledge-based authentication question is generated based at least in part on the third-party data.
19 . The non-transitory computer-readable medium of claim 14 , wherein the operations further comprise:
receiving an image of an identifying document for the requestor via the graphical user interface, is which determining whether the requestor is the data subject is also based at least in part on the image of the identifying document.
20 . A computing system comprising:
means for determining whether a data subject exists based at least in part on an identifying characteristic provided for the data subject in a data subject access request to access data associated with the data subject received from a requestor; means for determining the requestor is the data subject based at least in part on a response provided by the requestor to a knowledge-based authentication question configured to validate the requestor as the data subject; and responsive to determining the data subject exists and the requestor is the data subject:
providing an authentication token to the requestor; and
providing a link to the requestor that the requestor may select to gain access to the data by providing the authentication token.Join the waitlist — get patent alerts
Track US2021256157A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.