Data compliance control processing method, device and electronic equipment

By providing an operation interface to create compliance control rules and bind them to the scope of data control, the problem of inefficient data compliance control in cross-border e-commerce is solved, and the reuse and efficiency of compliance rules are achieved.

CN114331318BActive Publication Date: 2025-05-16HANGZHOU ALIBABA INT INTERNET IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111435256.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-29
Publication Date
2025-05-16
Estimated Expiration
2041-11-29

AI Technical Summary

Technical Problem

In a cross-border e-commerce environment, it is difficult for existing technologies to efficiently implement data compliance control, especially when compliance needs in different countries and regions are complex and inefficient.

Method used

Provide a data compliance control processing method, create compliance control rules for users through the operation interface, and bind them to the data control scope, generate compliance control tasks, and assign them to the executive personnel to achieve the reuse and efficiency improvement of compliance control rules.

Benefits of technology

Through this method, the reuse of compliance control rules is achieved, efficiency is improved, communication costs between legal and technical personnel are reduced, and data compliance is ensured in different countries and regions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114331318B_ABST
    Figure CN114331318B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a data compliance control processing method, device and electronic device, the method comprising: providing an operation interface for creating compliance control rules to a first user, the operation interface including operation options for selecting multiple supported data control capabilities; after receiving a request from the first user to bind data control scope information to the created compliance control rules, providing optional data control scope information for establishing a binding relationship between a target compliance control rule and a target data control scope; determining compliance control requirement information according to the binding relationship, generating a compliance control task according to the compliance control requirement and assigning it to a second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope. Through the embodiments of the present application, the implementation efficiency can be improved, and the same set of compliance control rules can be reused in different control requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to data compliance control processing methods, devices and electronic equipment. Background Art

[0002] In the cross-border e-commerce environment, countries are increasingly strengthening their control over the use of personal privacy data, data generated in specific applications, etc. As a cross-border e-commerce platform, it is necessary to help merchants provide high-quality goods to overseas consumers safely and conveniently on the premise of meeting the compliance requirements of various countries, so as to ensure that e-commerce applications are effectively carried out within the reasonable scope of the laws and regulations of various countries.

[0003] In the traditional way, the legal staff of the platform usually need to express the specific compliance requirements to the technical staff of the platform through verbal or email, and then the technical staff will implement it. For example, according to the laws and regulations of country A, all data generated in country A is not allowed to go to country B. The legal staff can express the compliance requirements verbally to the technical staff, and the technical staff can meet the above compliance requirements by configuring the data transmission link, etc.

[0004] However, oral or email communication methods are inefficient, and the configuration actions of technicians are one-time operations, making it difficult to reuse the resulting solutions for other similar management and control needs. Summary of the invention

[0005] The present application provides a data compliance control processing method, device and electronic device, which can improve implementation efficiency and realize the reuse of the same set of compliance control rules for different control needs.

[0006] This application provides the following solutions:

[0007] A data compliance control processing method, comprising:

[0008] Providing an operation interface for creating a compliance control rule to the first user, wherein the operation interface includes an operation option for selecting a plurality of supported data control capabilities, so that the compliance control rule is created by selecting at least one required data control capability;

[0009] After receiving a request from the first user to bind data control scope information to the created compliance control rule, providing optional data control scope information for establishing a binding relationship between the target compliance control rule and the target data control scope;

[0010] Compliance control requirement information is determined according to the binding relationship, and a compliance control task is generated according to the compliance control requirement and assigned to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

[0011] Among them, the data management and control capabilities include: the capabilities provided for management and control needs that may arise at multiple stages in the data life cycle; the multiple stages include: data generation, data storage, data transmission, data use, data access control, data destruction, and management of data stored on user terminal devices.

[0012] The optional data control scope information provided includes:

[0013] Provide a variety of optional data dimensions so that the target data control scope can be determined by selecting the target data dimension and attribute value; the multiple optional data dimensions include: site, country, application, and data tagging definition dimensions.

[0014] Among them, the attribute values ​​under the data labeling definition dimension include multiple data labeling definition identifiers, the data labeling definition identifiers are associated with data category labels, data mapping rules and corresponding database implementation methods, and the data mapping rules are used to map the data labeling definition identifiers to target data under the target labeling dimension, and the target labeling dimension includes databases, data tables, data columns or data rows.

[0015] Among them, it also includes:

[0016] Provides operation options for querying existing data tagging definitions;

[0017] After receiving the query request of the first user through the operation option, detailed information of the corresponding data marking definition is provided.

[0018] Among them, it also includes:

[0019] Provides options for creating new data labeling definitions;

[0020] After receiving the creation request of the first user through the operation option, an optional data category label and corresponding labeling dimension information are provided.

[0021] Among them, it also includes:

[0022] After the compliance control task is generated, an anomaly monitoring task is created to perform anomaly monitoring on the execution of the target compliance control rule.

[0023] Among them, the anomaly monitoring task is specifically used to perform anomaly monitoring on the execution of target compliance control rules for existing data and / or incremental data within the target data control scope.

[0024] If the target compliance control rules include compliance control rules related to data storage and / or data transmission, then when executing the compliance control task, the control of the target data storage link and / or data transmission link is included;

[0025] The monitoring task is specifically used to perform abnormal monitoring on the execution of target compliance control rules for all data generated in the target data storage link and / or data transmission link, wherein all data includes data generated within the target data control scope and similar data generated outside the target data control scope.

[0026] Among them, it also includes:

[0027] If an abnormal situation is monitored, an alarm message is provided to the second user corresponding to the compliance control task so as to perform abnormal processing.

[0028] Among them, it also includes:

[0029] Provide the first user with an abnormal monitoring result, wherein the abnormal monitoring result includes an identifier of the abnormal monitoring task, a corresponding target data control range, and a monitoring status, wherein if the monitoring status is abnormal, the monitoring result also includes information on the time when the abnormality occurred.

[0030] A data compliance control processing device, comprising:

[0031] An operation interface providing unit, configured to provide the first user with an operation interface for creating a compliance control rule, wherein the operation interface includes an operation option for selecting a plurality of supported data control capabilities, so that the compliance control rule is created by selecting at least one required data control capability;

[0032] A control scope information providing unit, configured to provide optional data control scope information after receiving a request from the first user to bind data control scope information to a created compliance control rule, so as to establish a binding relationship between a target compliance control rule and a target data control scope;

[0033] A compliance control task generation unit is used to determine compliance control requirement information based on the binding relationship, generate a compliance control task based on the compliance control requirement and assign it to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

[0034] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of any of the methods described above.

[0035] An electronic device, comprising:

[0036] one or more processors; and

[0037] A memory associated with the one or more processors, the memory being used to store program instructions, wherein the program instructions, when read and executed by the one or more processors, execute the steps of any of the methods described above.

[0038] According to the specific embodiments provided in this application, this application discloses the following technical effects:

[0039] Through the embodiment of the present application, an operation interface for configuring compliance control rules, binding compliance control rules with data control scope, etc. can be provided for the first user such as legal staff, so that the first user can submit specific compliance control requirements through this operation interface. In the process of submitting requirements, the compliance control rules can be created first, and then the rules can be bound to the specific data control scope (that is, the specific compliance control rules can be effective within a certain range, including the specified site, one or some specific countries under the site, the application in the site, the specific database, table, row, column, etc.). Therefore, the same compliance control rule can be bound to different data control scope information under multiple compliance control requirements, so as to achieve the reuse of the same solution between multiple similar control requirements. Specifically, in the interface for creating compliance control rules, corresponding options can be provided according to the data control capability information supported by the system, so that the first user can create specific compliance control rules by selecting the required multiple data control capabilities, avoiding the situation that the first user does not know how to describe the rules, or the described rules cannot be implemented technically. In addition, the system can directly generate corresponding compliance control tasks according to specific compliance control requirements and assign them to the second user for execution. During this process, legal staff and technical personnel do not need to communicate verbally or by email. Instead, they can directly convey and implement the needs through the system's task flow, thus improving efficiency.

[0040] In a preferred embodiment, it is also possible to monitor the implementation of specific compliance control measures. That is, the execution of compliance control tasks by a specific second user is no longer a one-time action, but rather continuous supervision of the execution of tasks. If an abnormality occurs, for example, an alarm can be sent to the corresponding responsible person so that timely measures can be taken to prevent more serious consequences.

[0041] Of course, any product implementing the present application does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0043] Figure 1 It is a schematic diagram of the system architecture provided by the embodiment of the present application;

[0044] Figure 2 is a flow chart of the method provided in the embodiment of the present application;

[0045] Figure 3 is a schematic diagram of a first interface provided in an embodiment of the present application;

[0046] Figures 4-1 to 4-3 This is a schematic diagram of an interface for selecting data management and control capabilities in data storage provided by an embodiment of the present application;

[0047] Figure 5-1 , 5-2 It is a schematic diagram of an interface for selecting data management and control capabilities in data transmission and storage provided in an embodiment of the present application;

[0048] Figure 6 is a schematic diagram of a compliance control rule query interface provided in an embodiment of the present application;

[0049] Figure 7 This is a schematic diagram of an operation interface for selecting compliance control rules provided in an embodiment of the present application;

[0050] Figure 8 This is a schematic diagram of an operation interface for querying data labeling definitions provided in an embodiment of the present application;

[0051] Fig. 9 is a schematic diagram of an abnormal monitoring result interface provided in an embodiment of the present application;

[0052] Fig.10 is a schematic diagram of a device provided in an embodiment of the present application;

[0053] Fig.11 It is a schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the present application belong to the scope of protection of this application.

[0055] In the embodiment of the present application, in order to facilitate the legal compliance control processing, a legal compliance control configuration and management system can be provided, that is, the process from the proposal of specific compliance control requirements to the technical implementation can be productized. The users of this system can include two categories, one of which is the legal staff in the cross-border e-commerce system, who are responsible for the proposal of specific compliance control requirements, and the other is the technical staff in the cross-border e-commerce system, who are responsible for the implementation of specific compliance control actions.

[0056] Through this system, it is possible to provide legal staff with operation interfaces for configuring compliance control rules, binding compliance control rules with data control scope, etc., so that legal staff can submit specific compliance control requirements through this operation interface. Correspondingly, the system can generate corresponding compliance control tasks and assign them to technical personnel for execution. In this process, there is no need for legal staff to communicate with technical personnel verbally or by email, but the requirements can be conveyed and implemented directly through the task flow of the system, thus improving efficiency. In addition, since in the process of submitting requirements, compliance control rules can be created first, and then the rules can be bound to specific data control scopes (that is, specific compliance control rules can be effective within a certain scope, including designated sites, one or some specific countries under the site, applications in the site, specific databases, tables, rows, columns, etc.), therefore, the same compliance control rule can be bound to different data control scope information under multiple compliance control requirements, so as to achieve the reuse of the same solution between multiple similar control requirements.

[0057] In addition, this method can also monitor the implementation of specific management and control measures. That is, the execution of compliance management and control tasks by specific technical staff is no longer a one-time action, but continuous supervision of the execution of tasks. If an abnormality occurs, for example, the data under control is not controlled according to the rules, an alarm can be sent to the corresponding technical staff so that the technical staff can take timely measures to prevent more serious consequences.

[0058] From the perspective of system architecture, Figure 1As shown, in the embodiment of the present application, a legal compliance control configuration and management system is provided, which may include a compliance control rule creation and management module, a compliance control rule and data control scope binding module, and a compliance control task generation module. In addition, in a preferred manner, an abnormality monitoring module may also be included. Legal personnel may create and manage compliance control rules, and bind compliance control rules to data control scopes, so as to generate specific compliance control requirements. Afterwards, the system may generate corresponding compliance control tasks and assign them to specific technical staff for execution. The execution process may specifically include encryption processing of data, configuration of data storage links, configuration of data transmission links, and the like. At the same time, the abnormality monitoring module may monitor the execution of specific compliance control tasks, determine whether specific compliance control tasks are executed, determine whether data storage links and data transmission links still have data that needs to be controlled, and the like. The specific monitoring results may be provided to legal personnel, and if an abnormality occurs, an alarm message may be provided to technical staff in a timely manner so that the abnormality is handled in a timely manner.

[0059] The specific implementation scheme provided in the embodiments of the present application is described in detail below.

[0060] Specifically, this application first provides a data compliance management and processing method, see Figure 2 , the method may specifically include:

[0061] S201: Providing an operation interface for creating compliance control rules to a first user, wherein the operation interface includes operation options for selecting a plurality of supported data control capabilities, so that compliance control rules can be created by selecting at least one required data control capability.

[0062] First, the specific compliance control configuration and management system can provide an operation interface for creating compliance control rules for legal staff (of course, in the specific implementation, compliance control rules can also be configured by other personnel. Therefore, in the embodiment of the present application, they can be collectively referred to as the first user, and correspondingly, the technical staff will be referred to as the second user) so that they can configure the rules to be created according to specific compliance control needs. For example, a site needs to launch a new application involving cross-border data transmission. At this time, the first user will have a demand to configure compliance control rules, including where the data generated in the application exists, which data cannot be transmitted to a certain country, whether there are some data that cannot be exported, whether the data needs to be encrypted or anonymized when it is saved, and so on. After generating specific demands, specific compliance control rules can be created through the system provided in the embodiment of the present application. Of course, if similar compliance control rules have been created for other compliance control needs before, they can also be directly reused in the current scenario.

[0063] Among them, when creating specific compliance control rules, it may usually involve the creation of rules at multiple stages in the data life cycle, for example, including specific rules for data storage, rules for data transmission, and so on. In specific implementation, due to the execution of specific compliance control rules, the system needs to provide corresponding technical capabilities. For example, if it is required that data from a certain country A cannot be transmitted to country B, the system needs to be able to provide the ability to control transmission between computer rooms, and so on. Therefore, in the embodiment of the present application, the data control capabilities supported in the system can be named and classified in advance, so that when the first user needs to create a compliance control rule, it can actually select some data control capabilities required in the actual control requirements from various data control capabilities. In this way, it is convenient for the first user to create rules, and it can also avoid the situation where the first user arbitrarily creates rules, but the system cannot support it. In other words, when the first user needs to create a compliance control rule, he can select a group of data control capabilities from the multiple data control capabilities supported by the system. This group of data control capabilities can constitute a compliance control rule. In addition, the compliance control rule can be named for subsequent query, editing, and use.

[0064] Among them, the specific supported compliance control capabilities may include multiple types, which can be mainly provided around the data control needs that may arise in multiple stages of the entire life cycle of the data. Among them, the multiple stages may include: data generation, data storage, data transmission, data use, data access control, data destruction, management of Cookies (data stored on user terminal devices), and so on. For example, in the above example, assuming that the data generated in country A cannot be transmitted to country B, the system can provide the ability to control the transmission between cross-border computer rooms; for example, a country C requires that all data of domestic transactions cannot be exported. At this time, data storage control capabilities can be provided, including deploying specific computer rooms within the country, and the data is located within the country to achieve data isolation. For example, regarding Cookies data (for example, after a user logs in to a website, Cookies data can be locally generated on the terminal device, including what the user has clicked on, what content has been browsed, and what transactions have been made. These data can be used for specific recommendations and other applications, including "one thousand faces for one thousand people" on multiple pages, etc.), however, Country D may have requirements on the use of Cookies, for example, it may stipulate that some Cookies data are available and some Cookies data are not available. In this case, the ability to control Cookies data can also be achieved. In addition, some countries may need to anonymize or encrypt some contact information and other data. In this case, related capabilities such as data anonymization and encryption can also be provided, etc.

[0065] In specific implementation, various capabilities supported by the system can be displayed to the first user, so that the first user can select some capabilities according to actual management and control needs to form specific compliance management and control rules. Of course, since the number of specific supported capabilities may be relatively large, they can also be displayed in categories, for example, Figure 3 As shown, it can include several major categories such as data storage, data transmission, data usage, cookie management, and other data services. Each major category can also be subdivided into multiple subcategories. For example, under the major category of data storage, it can also include anonymization, pseudonymization, and physical / logical isolation. Under the major category of data transmission, it can include cross-border transmission, cross-departmental transmission, etc. In addition, specific subcategories can be further subdivided. As the user clicks on a subcategory, more detailed content can be expanded, and the first user can choose from it, and so on. For example, Figure 4-1 After selecting "Physical / Logical Isolation" under "Data Storage", the following information is displayed: Figure 4-2 The following two more specific capabilities are shown: "Physical Isolation" and "Logical Isolation". If "Physical Isolation" is selected, the following Figure 4-3 For example, Figure 5-1 As shown, assuming that the first user selects "Cross-border transfer" under "Data transfer", the following information may be displayed: Figure 5-2 "No special requirements", "Country A - Country S", "Country C - Country S", etc. are shown.

[0066] Of course, in addition to selecting specific compliance control capabilities, you can also enter the name and scope of application of the compliance control rules in the specific interface. First, users can customize the name of the specific compliance control rules, and can choose the scope of application, including "general" and "non-general". In addition, you can also enter some content in the "Remarks" option to help manage and remember specific compliance control rules, for example, "the current rule applies to the privacy scenario of a certain country", etc.

[0067] After completing the creation of specific compliance control rules, you can save them in the system. For example, after the first user completes the selection of specific compliance management capabilities, he can click Figure 3 Click the "Save" option shown. At this time, it proves that the rule has been edited. After that, you can save the rule and set the rule to the "Created" status.

[0068] In addition, the system can also provide a query function for specific compliance control rules. For example, you can query the rule name, creator, applicable scope, status, etc. That is, users can query a certain rule name, or query the rules created by a certain creator, etc., and the system can return detailed information about the matching rules. For example, Figure 6 As shown, the information may include the name, code, selected content under each data control capability, creator, creation time, status, etc. of the specific rule. In addition, the query result page may also provide operation options such as "Edit", so that the first user can edit the created rule, including modifying the rule name, or reselecting the capability, etc.

[0069] S202: After receiving the request from the first user to bind data control scope information to the created compliance control rule, provide optional data control scope information to establish a binding relationship between the target compliance control rule and the target data control scope.

[0070] After completing the creation of the compliance control rules, you can bind the data control scope information to the created compliance control rules, that is, you can apply the created compliance control rules to specific control scenarios. The data control scope information refers to the scope of control required in the specific control scenario. Specifically, a variety of optional data control scope information can be provided to the first user so that the first user can select the data management scope accordingly. Specifically, a variety of optional data dimensions can be provided so that the target data control scope can be determined by selecting the target data dimension and attribute value. Figure 7As shown, the multiple optional data dimensions may include: site, country, application (wherein, the functional modules provided in a specific site, etc., can all be referred to as applications), data tagging definition and other dimensions, etc. When the first user selects the data control scope, he can select from the above multiple dimensions. For example, by clicking "Select site", the optional sites can be displayed through the drop-down box, and the first user can select one or more sites from them. Afterwards, if it is necessary to restrict specific countries, applications, data tagging definitions, etc., you can click "Select country", "Select application", "Option tagging" and other options in turn, and select specific countries, applications, and data tagging definitions under each dimension. For example, if a site X, a country A, an application P, and a data tagging definition Y are selected, it means that the data corresponding to the above Y generated in the site X and application P of country A needs to be controlled. Of course, in the specific implementation, you can also choose to control all the data under a site. At this time, you can only select the site, and the country, application, data tagging definition, etc. do not need to be selected, and the default is all selected. Similarly, all the data generated by a country under a site can also be controlled, and so on.

[0071] Among them, regarding the data labeling definition, it can be specifically to label the data in the database in advance in order to facilitate data selection. That is to say, due to the large amount of data generated in the system, different types of data may need to be managed using different management rules, for example, including order data, logistics data, and also some personal data of consumer users. These personal data are usually different from other data in terms of privacy protection, etc. The requirements, etc., may be different. And these data are usually scattered in multiple different databases and data tables. Therefore, in order to facilitate the selection of the data control scope, data labeling definitions can be made in advance. Specifically, data labeling definitions can be created and corresponding identifiers can be added. The specific data labeling definition identifier can be associated with a data category label (for example, it can include an application label, a privacy label, etc.). In addition, it can also be associated with a data mapping rule and a corresponding database implementation method, so that the specific data labeling definition identifier can be mapped to the target data under the target labeling dimension, and the target labeling dimension includes a database, a data table, a data column or a data row.

[0072] For example, a data labeling definition is pre-created with the identifier "***Privacy Label". The labeling definition can be associated with a data mapping rule, which can be mapped to a specific database, or to a specific data table in the database, or even to a data column or data row in the data table, etc. The data dimension to which a specific data labeling definition is mapped can be configured according to actual needs. In other words, a data range can be circled and an identifier can be given to the data range by specifying a specific database, or refining it to a data table in a specific database, or even to a data column or data row in a data table, etc., so as to facilitate the first user to select the data control range.

[0073] In this way, when selecting the control scope, if it involves controlling some data in a specific application, the identifier of this data labeling definition can be selected. Since the system stores the mapping rules associated with the specific data labeling definition, it can be mapped to the data table in the specific database, or even the specific data column or data row in the data table. That is, although the first user selects the identifier such as the name of the specific data labeling definition, the system can know which data table in which database it corresponds to, or even which data column or row, so it can achieve targeted control of some data.

[0074] The specific data labeling definition work can be completed in advance by the second user, that is, the technical staff. In order to facilitate the first user to understand the meaning of the specific data labeling definition when selecting, the system can also provide a function to query the data labeling definition. For example, specific inquiries can be made by label type, labeling dimension, label name, label code, applicable scope, etc. The displayed information can be as follows: Figure 8 As shown, it may include label type, label code, label name, labeling dimension, applicable scope, specific value content, labeling time, database implementation and other contents. In this way, the first user can know the dimension and content of the labeling data corresponding to the specific labeling definition in the back end in this way, and then determine whether the scope defined by a specific labeling definition meets the requirements of the specific compliance control scope based on the query results. In addition, the specific query results may also include the corresponding database implementation method. For example, the labeling dimension of a certain labeling definition is "column", that is, it is refined to one or several columns in a data table in a certain database. The specific database implementation may include **library & **table & **column, **column, **column; the labeling dimension of another labeling definition is "library", and the labeling definition includes all the data in the specific database. At this time, the specific database implementation may include "***library", and so on.

[0075] Of course, an operation option for creating a new data tagging definition may also be provided in the system, and after receiving the creation request of the first user through the operation option, an optional data category label and corresponding tagging dimension information may be provided. In this way, the first user may also define the tagging according to actual needs.

[0076] Of course, in addition to selecting specific sites, countries, applications, labeling definitions, and other information to determine the scope of data control, you can also provide options for selecting specific compliance control rules, for example Figure 7 After clicking this option, a list of names of the created compliance control rules can be displayed. The specific rules can support multiple selections, that is, multiple compliance control rules can be selected for the same scenario, etc. After completing the selection, you can complete the specific binding operation by clicking options such as "Save and Submit".

[0077] In specific implementation, a query function for binding results can also be provided. Specific query conditions can include the name of the labeling definition, application name, site, country, etc.

[0078] S203: Determine compliance control requirement information according to the binding relationship, generate a compliance control task according to the compliance control requirement and assign it to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

[0079] After completing the binding operation, the system can determine the specific compliance control requirements, and then generate a compliance control task and assign it to the second user for execution. In this way, the corresponding target compliance control rules can be executed within the target data control scope by executing the compliance control task. For example, specific data storage link configuration, data transmission link configuration and other related control tasks can be generated according to the compliance control requirements, and the compliance control tasks can be directly assigned to the second user in the system. It should be noted here that when performing specific task assignments, it is also possible to connect with a specific work order system to generate a specific work order. The specific second user can be a user such as a manager of a relevant technical department, and such a manager can arrange for the implementation of a specific work order, including assigning it to specific technical staff, and so on.

[0080] In an embodiment of the present application, in addition to allowing the first user to submit specific compliance control requirements through a specific system, and generating a corresponding compliance control task and assigning it to the second user, an exception monitoring task can also be created to perform exception monitoring on the execution of the target compliance control rules. That is to say, after the specific compliance control task is assigned to the second user, the second user may not execute it in a timely manner, or there may be deviations in the technical implementation when executing the compliance control task, etc., resulting in the specific data not being controlled according to the specific rules. At this time, monitoring can be carried out through a specific exception monitoring task, so that the execution of the specific compliance control task is no longer a one-time job, but can be a continuous process, and the execution of the task can be grasped in a timely manner.

[0081] Specifically, when executing a compliance control task, it may involve the control of some existing stock data that has been generated, and it may also involve the control of some newly generated incremental data. Therefore, the specific anomaly monitoring task can monitor the execution of the target compliance control rules of the stock data and / or incremental data within the target data control scope for anomalies.

[0082] It should be noted here that for the management and control rules related to data storage, data transmission, etc., when implemented technically, it may involve the configuration of data storage links, data transmission links, etc. For example, for a certain type of data, a data storage link or data transmission link may be non-compliant. At this time, the link can be cut off for the data. Specifically, when performing abnormal monitoring, in addition to whether there is data within the target data monitoring range in the non-compliant link, it is also possible to monitor whether other similar data is generated in the non-compliant link. The same type of data may specifically include data associated with the same data category label, for example, the same user privacy data, etc.

[0083] For example, in actual applications, the following situation may also exist: the regulations of a certain country A stipulate that the user privacy data of country A cannot be transmitted to country B, so the data transmission link from country A to country B is controlled. However, a new application is incubated locally in country A. When the application is launched, there is no legal staff or the legal staff is unaware of the regulations. In this case, the corresponding compliance control rules may not be configured for the application. At this time, user privacy data may appear in the data transmission link from country A to country B. At this time, although the newly incubated application may not be within the previously configured data control scope, this abnormal situation can also be monitored so that corresponding treatment measures can be taken after timely discovery.

[0084] Among them, in specific implementation, if an abnormal situation is monitored, an alarm message can be provided to the second user corresponding to the compliance control task so as to handle the abnormal situation. That is to say, in the embodiment of the present application, since the compliance control task can be created and assigned through the system provided in the embodiment of the present application, the technical person in charge corresponding to the specific compliance control task can be known, so that if an abnormality is found during the execution of a task, the corresponding person in charge can be notified in time.

[0085] In addition, the abnormal monitoring results may also be provided to the first user, for example, Fig. 9 As shown, the abnormal monitoring result includes the identification of the abnormal monitoring task, the corresponding target data control scope (associated sites, applications, etc.), and the monitoring status (including normal or abnormal), wherein, if the monitoring status is abnormal, the monitoring result may also include information such as the time when the abnormality occurred. Among them, in the "Operation" column, an operation option for viewing details can be provided. After clicking "View", the details of the specific abnormal situation can be displayed. It can also include an operation option for creating work orders (tickets). After clicking this option, you can also quickly create a work order and assign it to the corresponding handler for processing. In addition, it can also support queries on abnormal monitoring results. The specific query conditions may include the monitoring task identification, application name, site, time when the abnormality occurred, etc.

[0086] In short, through the embodiment of the present application, an operation interface for configuring compliance control rules, binding compliance control rules with data control scope, etc. can be provided for the first user such as legal staff, so that the first user can submit specific compliance control requirements through this operation interface. In the process of submitting requirements, the compliance control rules can be created first, and then the rules can be bound to the specific data control scope (that is, the specific compliance control rules can be effective within a certain range, including the specified site, one or some specific countries under the site, the application in the site, the specific database, table, row, column, etc.). Therefore, the same compliance control rule can be bound to different data control scope information under multiple compliance control requirements, so as to achieve the reuse of the same solution between multiple similar control requirements. Specifically, in the interface for creating compliance control rules, corresponding options can be provided according to the data control capability information supported by the system, so that the first user can create specific compliance control rules by selecting the required multiple data control capabilities, avoiding the situation that the first user does not know how to describe the rules, or the described rules cannot be implemented technically. In addition, the system can directly generate corresponding compliance control tasks according to specific compliance control requirements and assign them to the second user for execution. During this process, legal staff and technical personnel do not need to communicate verbally or by email. Instead, they can directly convey and implement the needs through the system's task flow, thus improving efficiency.

[0087] In a preferred embodiment, it is also possible to monitor the implementation of specific compliance control measures. That is, the execution of compliance control tasks by a specific second user is no longer a one-time action, but rather continuous supervision of the execution of tasks. If an abnormality occurs, for example, an alarm can be sent to the corresponding responsible person so that timely measures can be taken to prevent more serious consequences.

[0088] It should be noted that the embodiments of the present application may involve the use of user data. In actual applications, user-specific personal data can be used in the scheme described herein within the scope permitted by applicable laws and regulations, subject to the requirements of applicable laws and regulations of the country where the user is located (for example, with the user's explicit consent, effective notification to the user, etc.).

[0089] Corresponding to the above method embodiment, the present application embodiment also provides a data compliance control processing device, see Fig.10 , the device may include:

[0090] An operation interface providing unit 1001 is used to provide an operation interface for creating a compliance control rule to a first user, wherein the operation interface includes an operation option for selecting a plurality of supported data control capabilities, so that the compliance control rule is created by selecting at least one required data control capability;

[0091] The control scope information providing unit 1002 is configured to provide optional data control scope information after receiving a request from the first user to bind data control scope information to the created compliance control rule, so as to establish a binding relationship between the target compliance control rule and the target data control scope;

[0092] The compliance control task generation unit 1003 is used to determine the compliance control requirement information according to the binding relationship, generate a compliance control task according to the compliance control requirement and assign it to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

[0093] Among them, the data management and control capabilities include: the capabilities provided for management and control needs that may arise at multiple stages in the data life cycle; the multiple stages include: data generation, data storage, data transmission, data use, data access control, data destruction, and management of data stored on user terminal devices.

[0094] The control range information providing unit may be specifically used for:

[0095] Provide a variety of optional data dimensions, so that by selecting the target data dimensions and attribute values, the target data control scope can be determined; the multiple optional data dimensions include: site, country, application, and data tagging definition dimensions.

[0096] Among them, the attribute values ​​under the data labeling definition dimension include multiple data labeling definition identifiers, the data labeling definition identifiers are associated with data category labels, data mapping rules and corresponding database implementation methods, and the data mapping rules are used to map the data labeling definition identifiers to target data under the target labeling dimension, and the target labeling dimension includes databases, data tables, data columns or data rows.

[0097] In a specific implementation, the device may further include:

[0098] A query option providing unit, used to provide operation options for querying existing data tagging definitions;

[0099] The detail providing unit is used to provide the detail information of the corresponding data marking definition after receiving the query request of the first user through the operation option.

[0100] In addition, the device may also include:

[0101] A creation option providing unit, used for providing operation options for creating a new data labeling definition;

[0102] An optional label providing unit is used to provide optional data category labels and corresponding labeling dimension information after receiving the creation request of the first user through the operation option.

[0103] Furthermore, the device may further include:

[0104] The abnormality monitoring task generating unit is used to create an abnormality monitoring task after generating the compliance control task, so as to perform abnormality monitoring on the execution of the target compliance control rule.

[0105] Specifically, the anomaly monitoring task is specifically used to perform anomaly monitoring on the execution of target compliance control rules for existing data and / or incremental data within the target data control scope.

[0106] If the target compliance control rules include compliance control rules related to data storage and / or data transmission, then when executing the compliance control task, the control of the target data storage link and / or data transmission link is included;

[0107] The monitoring task is specifically used to perform abnormal monitoring on the execution of target compliance control rules for all data generated in the target data storage link and / or data transmission link, wherein all data includes data generated within the target data control scope and similar data generated outside the target data control scope.

[0108] In addition, the device may also include:

[0109] The exception handling unit is used to provide an alarm message to the second user corresponding to the compliance control task if an abnormal situation is detected, so as to perform exception handling.

[0110] Furthermore, the device may further include:

[0111] A monitoring result providing unit is used to provide the first user with an abnormal monitoring result, wherein the abnormal monitoring result includes an identifier of the abnormal monitoring task, a corresponding target data control range, and a monitoring status, wherein if the monitoring status is abnormal, the monitoring result also includes information on the time when the abnormality occurred.

[0112] In addition, an embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps of any one of the methods in the aforementioned method embodiments are implemented.

[0113] And an electronic device, comprising:

[0114] one or more processors; and

[0115] A memory associated with the one or more processors, the memory being used to store program instructions, wherein the program instructions, when read and executed by the one or more processors, execute the steps of the method described in any one of the aforementioned method embodiments.

[0116] in, Fig.11 The architecture of the electronic device is shown as an example, which may include a processor 1110, a video display adapter 1111, a disk drive 1112, an input / output interface 1113, a network interface 1114, and a memory 1120. The processor 1110, the video display adapter 1111, the disk drive 1112, the input / output interface 1113, the network interface 1114, and the memory 1120 may be communicatively connected via a communication bus 1130.

[0117] Among them, the processor 1110 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solution provided in this application.

[0118] The memory 1120 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1120 can store an operating system 1121 for controlling the operation of the electronic device 1100, and a basic input and output system (BIOS) for controlling the low-level operation of the electronic device 1100. In addition, a web browser 1123, a data storage management system 1124, and a data compliance control processing system 1125, etc. can also be stored. The above-mentioned data compliance control processing system 1125 can be an application program that specifically implements the operations of the aforementioned steps in the embodiment of the present application. In short, when the technical solution provided in the present application is implemented by software or firmware, the relevant program code is stored in the memory 1120 and is called and executed by the processor 1110.

[0119] The input / output interface 1113 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0120] The network interface 1114 is used to connect to a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0121] The bus 1130 comprises a pathway for transmitting information between the various components of the device (eg, the processor 1110 , the video display adapter 1111 , the disk drive 1112 , the input / output interface 1113 , the network interface 1114 , and the memory 1120 ).

[0122] It should be noted that, although the above device only shows a processor 1110, a video display adapter 1111, a disk drive 1112, an input / output interface 1113, a network interface 1114, a memory 1120, a bus 1130, etc., in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include components necessary for implementing the solution of the present application, and does not necessarily include all the components shown in the figure.

[0123] It can be known from the description of the above implementation methods that those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application can be essentially or partly contributed to the prior art in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application or certain parts of the embodiments.

[0124] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can refer to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without creative work.

[0125] The data compliance control processing method, device and electronic device provided by this application are introduced in detail above. The principles and implementation methods of this application are explained in this article using specific examples. The description of the above embodiments is only used to help understand the method and core idea of ​​this application. At the same time, for those skilled in the art, according to the idea of ​​this application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A data compliance control processing method, characterized in that: include: Providing an operation interface for creating a compliance control rule to a first user, wherein the operation interface includes an operation option for selecting a plurality of supported data control capabilities, so as to create a compliance control rule by selecting at least one required data control capability; wherein the data control capability includes: capabilities provided for control requirements that may arise at multiple stages in the data life cycle; the multiple stages include: data generation, data storage, data transmission, data use, data access control, data destruction, and management of data stored on a user terminal device; After receiving a request from the first user to bind data control scope information to the created compliance control rule, providing optional data control scope information to establish a binding relationship between the target compliance control rule and the target data control scope; wherein providing the optional data control scope information includes: providing multiple optional data dimensions, so as to determine the target data control scope by selecting the target data dimension and the attribute value; the multiple optional data dimensions include: site, country, application, and data tagging definition dimensions; Compliance control requirement information is determined according to the binding relationship, and a compliance control task is generated according to the compliance control requirement and assigned to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

2. The method according to claim 1, characterized in that The attribute values ​​under the data labeling definition dimension include multiple data labeling definition identifiers, and the data labeling definition identifiers are associated with data category labels, data mapping rules and corresponding database implementation methods. The data mapping rules are used to map the data labeling definition identifiers to target data under the target labeling dimension, and the target labeling dimension includes a database, a data table, a data column or a data row.

3. The method according to claim 2, characterized in that Also includes: Provides operation options for querying existing data tagging definitions; After receiving the query request of the first user through the operation option, detailed information of the corresponding data marking definition is provided.

4. The method according to claim 2, characterized in that: Also includes: Provides options for creating new data labeling definitions; After receiving the creation request of the first user through the operation option, an optional data category label and corresponding labeling dimension information are provided.

5. The method according to claim 1, characterized in that Also includes: After the compliance control task is generated, an anomaly monitoring task is created to perform anomaly monitoring on the execution of the target compliance control rule.

6. The method according to claim 5, characterized in that The anomaly monitoring task is specifically used to perform anomaly monitoring on the execution of target compliance control rules for existing data and / or incremental data within the target data control scope.

7. The method according to claim 6, characterized in that If the target compliance control rules include compliance control rules related to data storage and / or data transmission, then when executing the compliance control task, control of the target data storage link and / or data transmission link is included; The monitoring task is specifically used to perform abnormal monitoring on the execution of target compliance control rules for all data generated in the target data storage link and / or data transmission link, wherein all data includes data generated within the target data control scope and similar data generated outside the target data control scope.

8. The method according to claim 5, characterized in that Also includes: If an abnormal situation is monitored, an alarm message is provided to the second user corresponding to the compliance control task so as to perform abnormal processing.

9. The method according to claim 5, characterized in that Also includes: Provide the first user with an abnormal monitoring result, wherein the abnormal monitoring result includes an identifier of the abnormal monitoring task, a corresponding target data control range, and a monitoring status, wherein if the monitoring status is abnormal, the monitoring result also includes information on the time when the abnormality occurred.

10. A data compliance control processing device, characterized in that: include: An operation interface providing unit, configured to provide an operation interface for creating a compliance control rule to a first user, wherein the operation interface includes an operation option for selecting a plurality of supported data control capabilities, so as to create a compliance control rule by selecting at least one required data control capability; wherein the data control capability includes: capabilities provided for control requirements that may arise at multiple stages in a data life cycle; the multiple stages include: data generation, data storage, data transmission, data use, data access control, data destruction, and management of data stored on a user terminal device; A control scope information providing unit is configured to provide optional data control scope information after receiving a request from the first user to bind data control scope information to a created compliance control rule, so as to establish a binding relationship between a target compliance control rule and a target data control scope; wherein the providing of the optional data control scope information includes: providing a plurality of optional data dimensions, so as to determine the target data control scope by selecting a target data dimension and an attribute value; the plurality of optional data dimensions include: site, country, application, and data tagging definition dimensions; A compliance control task generation unit is used to determine compliance control requirement information based on the binding relationship, generate a compliance control task based on the compliance control requirement and assign it to the second user for execution, so that by executing the compliance control task, the corresponding target compliance control rule is executed within the target data control scope.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method described in any one of claims 1 to 9 are implemented.

12. An electronic device, characterized in that: include: one or more processors; as well as A memory associated with the one or more processors, the memory being used to store program instructions, wherein the program instructions, when read and executed by the one or more processors, execute the steps of the method described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Task information processing method, device and system

    CN111507674A

  • Data processing method, device and system

    CN113642036A