US2022318401A1PendingUtilityA1

Data processing systems and methods for efficiently assessing the risk of campaigns

Assignee: ONETRUST LLCPriority: Jun 10, 2016Filed: Jun 9, 2022Published: Oct 6, 2022
Est. expiryJun 10, 2036(~9.9 yrs left)· nominal 20-yr term from priority
G06F 2221/2111G06Q 50/26G06Q 30/018G06F 2201/81G06F 21/50G06F 11/3438G06F 21/60G06F 21/6245G06F 21/6263G06F 2221/2119Y02D10/00G06F 21/316G06Q 10/0635G06Q 30/0609
76
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Data processing systems and methods, according to various embodiments are adapted for efficiently processing data to allow for the streamlined assessment of the risk level associated with particular privacy campaigns. The systems may provide a centralized repository of templates of privacy-related question/answer pairings for various vendors, products (e.g., software products), and services. Different entities may electronically access the templates (which may be periodically updated and centrally audited) and customize the templates for evaluating the risk associated with the entities' respective business endeavors that involve the relevant vendors, products, or services.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by computing hardware, a completed assessment template from a vendor, wherein the completed assessment template comprises question/answer pairings regarding a product or service provided by the vendor;   conducting, by the computing hardware, an analysis of publicly available data associated with the vendor;   coordinating, by the computing hardware, an audit of the completed assessment template, wherein coordinating the audit includes calculating, based on the completed assessment template and the analysis of the publicly available data associated with the vendor, a risk rating for the product or service provided by the vendor by:
 identifying a weighting factor for each of the question/answer pairings; 
 determining a relative risk rating for each of the question/answer pairings; and 
 calculating the risk rating based upon the relative risk rating and the weighting factor for each of the question/answer pairings; and 
   after completing the audit, facilitating, by the computing hardware, an electronic transfer of the completed assessment template to a plurality of computer systems, wherein each computer system of the plurality of computer systems is associated with a respective entity of a plurality of entities and each respective entity uses the completed assessment template in conducting a computerized assessment of a respective processing activity, to be executed by the respective entity, that includes the use of the product or service provided by the vendor.   
     
     
         2 . The method of  claim 1 , wherein the audit of the completed assessment template is an audit for compliance with a policy or a standard. 
     
     
         3 . The method of  claim 1 , wherein the computerized assessment of the respective processing activity is configured to measure a maturity of the product or service in meeting a policy or standard. 
     
     
         4 . The method of  claim 1  further comprising:
 generating, by the computing hardware and based on the risk rating, a graphical user interface by configuring a navigation element on the graphical user interface, wherein the navigation element is configured for initiating a responsive action based on the risk rating; 
 transmitting, by the computing hardware, an instruction to a user device to present the graphical user interface on the user device; 
 receiving, by the computing hardware, an indication of a selection of the navigation element; and 
 responsive to receiving the indication, initiating, by the computing hardware, the responsive action. 
 
     
     
         5 . The method of  claim 4 , wherein the responsive action comprises:
 generating, by the computing hardware, a second graphical user interface comprising an indication of the risk rating; and   transmitting, by the computing hardware, a second instruction to a third-party computing device to present the second graphical user interface on the third-party computing device.   
     
     
         6 . The method of  claim 1  further comprising:
 generating, by the computing hardware, an awareness rating for the vendor based on the analyzed publicly available data, wherein the risk rating is further based on the awareness rating. 
 
     
     
         7 . The method of  claim 6 , wherein analyzing the publicly available data comprises:
 determining at least one of employee titles, employee roles, or available job posts associated with the vendor based on analyzing at least one of a social networking website or a business related job website.   
     
     
         8 . The method of  claim 6 , wherein analyzing the publicly available data comprises:
 determining the vendor has a plurality of contracts with a plurality of government entities.   
     
     
         9 . A system comprising:
 a non-transitory computer-readable medium storing instructions; and   a processing device communicatively coupled to the non-transitory computer-readable medium,   wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:
 receiving a completed template from a centralized repository of completed templates, wherein the completed template comprises question/answer pairings regarding at least one of a vendor, a product, or a service to be used as part of a set of operations performed by an entity; 
 receiving an analysis of data records associated with at least one of the vendor, the product, or the service; 
 after receiving the completed template, receiving, from the entity, a particular weighting factor that is to be applied to a particular question/answer pairing of the question/answer pairings in processing data to calculate a risk rating for the set of operations; 
 after receiving the particular weighting factor, using the particular weighting factor, content of the particular question/answer pairing, and the analysis of the data records to calculate an overall risk rating for the set of operations by:
 identifying a respective weighting factor for each of the question/answer pairings; 
 determining a relative risk rating for each of the question/answer pairings; and 
 calculating, based on the relative risk rating and the weighting factor for each of the question/answer pairings and the analysis of the data records, the overall risk rating; 
 
 determining the overall risk rating for the set of operations does not satisfy certain pre-determined criteria; and 
 responsive to determining that the risk rating for the set of operations does not satisfy the pre-determined criteria, generating an alert to a user indicating that the risk rating for the set of operations does not satisfy the pre-determined criteria. 
   
     
     
         10 . The system of  claim 9 , wherein the analysis of data records associated with at least one of the vendor, the product, or the service comprises of analysis of at least one of the vendor, the product, or the service for compliance with a policy or a standard. 
     
     
         11 . The system of  claim 9 , wherein:
 the data records are related to a government body that is associated with at least one of the vendor, the product, or the service; and   calculating the overall risk rating is also based on the government body.   
     
     
         12 . The system of  claim 9 , wherein the operations further comprise:
 analyzing a public record database associated with at least one of the vendor, the product, or the service;   identifying a certification associated with at least one of the vendor, the product, or the service from the public record database, and   calculating the overall risk rating is also based on the certification.   
     
     
         13 . The system of  claim 9 , wherein the operations further comprise:
 generating an awareness rating for at least one of the vendor, the product, or the service based on the analysis of the data records, and the overall risk rating is further based on the awareness rating.   
     
     
         14 . The system of  claim 13 , wherein the analysis of the data records comprises determining at least one of employee titles, employee roles, or available job posts associated with at least one of the vendor, the product, or the service based on analyzing at least one of a social networking website or a business related job website. 
     
     
         15 . A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:
 conducting an analysis of publicly available data associated with a vendor;   coordinating an audit of a completed assessment template from the vendor, wherein:
 the completed assessment template comprises question/answer pairings regarding a product or service provided by the vendor, and 
 coordinating the audit includes calculating, based on the completed assessment template and the analysis of the publicly available data associated with the vendor, a risk rating for the product or service provided by the vendor by:
 identifying a weighting factor for each of the question/answer pairings; 
 determining a relative risk rating for each of the question/answer pairings; and 
 calculating the risk rating based upon the relative risk rating and the weighting factor for each of the question/answer pairings; and 
 
   after completing the audit, facilitating an electronic transfer of the completed assessment template to a computer system, wherein the computer system is associated with an entity that uses the completed assessment template in conducting a computerized assessment of a processing activity, to be executed by the entity, that includes the use of the product or service provided by the vendor.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein the audit of the completed assessment template is an audit for compliance with a policy or a standard. 
     
     
         17 . The non-transitory computer-readable medium of  claim 15 , wherein the electronic transfer of the completed assessment template to the computer system is carried out through on online portal integrated with an instance of the computer system. 
     
     
         18 . The non-transitory computer-readable medium of  claim 15 , wherein the product comprises a raw material. 
     
     
         19 . The non-transitory computer-readable medium of  claim 15 , wherein the operations further comprise:
 generating an awareness rating for the vendor based on the analyzed publicly available data, wherein the risk rating is further based on the awareness rating.   
     
     
         20 . The non-transitory computer-readable medium of  claim 19 , wherein analyzing the publicly available data comprises:
 determining at least one of employee titles, employee roles, or available job posts associated with the vendor based on analyzing at least one of a social networking website or a business related job website.

Join the waitlist — get patent alerts

Track US2022318401A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.