Data compliance report processing method and device and electronic equipment
By creating compliance scenarios in the data compliance management system, combining compliance evaluation and data circulation systems, automatic generation and update of PIA reports is achieved, solving the problems of high compliance management costs and insufficient coverage in the existing technology, and improving the automation and coverage of compliance management.
Patent Information
- Application Number
- CN202510376970.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, when enterprises conduct data compliance management, especially PIA reports generation and evaluation, there are problems such as huge workload, high cost and difficulty in covering all data circulation scenarios. Especially in data sharing and commissioning processing across legal entities, legal personnel have a large workload and business personnel have difficulty understanding legal concepts, resulting in insufficient coverage of compliance management.
By creating compliance scenarios based on business cooperation projects, structured expression of data providers, recipients and data scope, realize automatic generation and dynamic update of PIA reports, combine compliance evaluation and data circulation system, automate the management of compliance management processes, reduce the number of PIA reports and timely perceive business changes.
It realizes generation and update of PIA reports in the compliance scenario dimension, reduces compliance management costs, improves the coverage and automation of compliance management, can respond to business changes in a timely manner, reduces the number of PIA reports, and is easy to manage.
Smart Images

Figure CN120409442A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information processing technologies, and particularly to a method, apparatus, and electronic device for processing data compliance reports. Background Art
[0002] Based on the relevant requirements of relevant laws and regulations regarding the sharing of personal information, a PIA (Personal Information Protection Impact Assessment) report is a specific form recognized by the regulatory side for implementing relevant compliance management obligations. The PIA report aims to help enterprises implement the personal information security compliance impact assessment obligations stipulated by relevant laws and regulations, covering situations such as personal information collection, transmission, storage, use, provision, disclosure, cross-border transfer, and entrusted processing by enterprises. It conducts a comprehensive security compliance assessment on personal information processing activities that have a significant impact on personal rights and interests. It assists enterprises in identifying various risks, guiding them to adopt corresponding security control measures and compliance management measures, enhancing their ability to handle risks, continuously correcting the effectiveness of security control measures and compliance management measures, and ensuring that risks are controllable.
[0003] For example, for a commodity information service system (also known as an e-commerce platform, etc., mainly used to provide services in all or part of the links such as commodity information release, transaction, and payment), it may involve the cross-legal entity sharing of user personal information. For example, after a consumer places an order on an e-commerce platform, the goods need to be shipped by a cooperating logistics service provider. At this time, the e-commerce platform may need to provide the user's order information, delivery address information, contact information, etc. to the logistics service provider, which involves providing user personal information to the logistics service provider that belongs to the service trustee. Although this is also notified in writing in the personal information processing rules and meets the expectations of users when purchasing goods, as a data provider, according to legal requirements, it still has the compliance obligation to complete a PIA report.
[0004] However, the content that needs to be filled in each PIA report is often relatively large. If referring to the management methods of other compliance domains, every time the business side shares personal information data with other entities or entrusts processing, it is necessary to consult relevant legal personnel, and then after the relevant legal personnel conduct an assessment, a PIA report can be written.
[0005] However, the issue of data compliance is carried out around the entire data life cycle. In the detailed processes of data collection, sharing, storage, deletion, procurement of external data, and external data cooperation, etc., data compliance of personal information may be involved. Therefore, for enterprises such as e-commerce platforms with a large scale and high business complexity, the demand for data circulation will be huge, and hundreds or even thousands of data circulation requirements may occur every month. For legal personnel, the workload will be extremely large and will occupy a large amount of labor costs. On the other hand, since data compliance is actually a concept at the legal level, if specific business personnel need to actively initiate consultations with legal personnel, it means that the business side needs to understand the legal concepts, which will be somewhat difficult and may also lead to the omission of certain scenarios that require data compliance management, making it difficult to ensure the coverage of data compliance management actions. Summary of the Invention
[0006] The present application provides a data compliance report processing method, device, and electronic device, which can take into account the coverage and cost of data compliance management and can achieve dynamic and automated data compliance management.
[0007] The present application provides the following solutions:
[0008] A data compliance report processing method includes:
[0009] Create a target compliance scenario, where the target compliance scenario is a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes based on the legal basis of the target business cooperation project;
[0010] When the data circulation application information applicable to the target compliance scenario is obtained for the first time and the data circulation application involves personal information, execute the automatic generation process of the Personal Information Protection Impact Assessment (PIA) report to generate a PIA report for the target compliance scenario;
[0011] When new data circulation application information applicable to the target compliance scenario is obtained and the personal information involved in the new data circulation application changes compared with the personal information in the PIA report corresponding to the target compliance scenario, execute the update process of the PIA report to achieve data compliance management for multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
[0012] Among them, the target compliance scenario is actively created for the target business cooperation project before the data circulation application information applicable to the target compliance scenario is obtained for the first time;
[0013] The method further includes:
[0014] After receiving the data circulation application information, a review task is generated according to the data circulation application, so that the review task executor can determine the target compliance scenario applicable to the data circulation application and whether the data circulation application involves personal information.
[0015] Wherein, if no compliance scenario is actively created for the target business cooperation project before the data circulation application information applicable to the target compliance scenario is first obtained, the method further includes:
[0016] After receiving the data circulation application information, a review task is generated according to the data circulation application, so that after the review task executor determines that there is no applicable compliance scenario, a process for creating a compliance scenario based on the data circulation application is triggered, and a draft for creating a compliance scenario is generated according to the key information in the application data of the data circulation application to assist the person in charge of the compliance scenario to complete the creation of the compliance scenario.
[0017] Wherein, it further includes:
[0018] Before generating or updating the PIA report, automatic compliance assessment processing is also performed.
[0019] Wherein, when obtaining the data circulation application information, the application data of the data circulation application is also obtained, so that when executing the process of generating or updating the PIA report, key information is extracted from the application data and / or the scenario information of the target compliance scenario, and the key information is mapped to the evaluation content of the corresponding multiple evaluation questions in the preset evaluation form, so as to perform automatic compliance assessment according to the evaluation content in the evaluation form;
[0020] If the compliance assessment is passed, the evaluation content in the evaluation form is mapped to the corresponding report items in the PIA report template, so as to generate or update the PIA report corresponding to the target compliance scenario.
[0021] Wherein, it further includes:
[0022] When new data circulation application information applicable to the target compliance scenario is obtained and the personal information involved in the new data circulation application has not changed compared with the personal information in the PIA report corresponding to the target compliance scenario, the new data circulation application is added to the set of data circulation applications associated with the target compliance scenario, so that the PIA report corresponding to the target compliance scenario is shared by the new data circulation application and other data circulation applications that have been historically obtained and are applicable to the target compliance scenario.
[0023] A data compliance report processing device includes:
[0024] A compliance scenario creation unit for creating a target compliance scenario, which is a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes based on the legality basis of a target business cooperation project;
[0025] A PIA report generation unit for, when first obtaining data circulation application information applicable to the target compliance scenario and the data circulation application involves personal information, executing an automatic generation process of a personal information protection impact assessment (PIA) report to generate a PIA report for the target compliance scenario;
[0026] A PIA report update unit for, when obtaining new data circulation application information applicable to the target compliance scenario and the personal information involved in the new data circulation application has changed compared with the personal information in the PIA report corresponding to the target compliance scenario, executing an update process of the PIA report to achieve data compliance management of multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
[0027] A computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the steps of the method described in any one of the foregoing are implemented.
[0028] An electronic device, comprising:
[0029] One or more processors; and
[0030] A memory associated with the one or more processors, the memory being used to store program instructions, and when the program instructions are read and executed by the one or more processors, the steps of the method described in any one of the foregoing are executed.
[0031] A computer program product comprising computer programs / computer-executable instructions, and when the computer programs / computer-executable instructions are executed by a processor in an electronic device, the steps of the method described in any one of the foregoing are implemented.
[0032] According to the specific embodiments provided in this application, the following technical effects are disclosed in this application:
[0033] Through the embodiments of the present application, a compliance scenario can be created based on the legality of a specific business cooperation project to achieve a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes. In this way, PIA reports can be generated on a compliance scenario basis. Specifically, when receiving a data circulation application related to this compliance scenario for the first time, a PIA report can be generated; after a new data circulation application related to this compliance scenario is generated subsequently, if the personal information involved is updated, it can be updated based on the already generated PIA report, and all data circulation applications related to the same compliance scenario can share this updated PIA report. Through this solution, since PIA reports can be generated in the dimension of compliance scenarios, the number of PIA reports that need to be maintained in the system is reduced, and the cost is lowered. Moreover, since the compliance management system and the data circulation system can be connected, changes on the business side can be sensed in a timely manner. Therefore, the coverage of compliance management can be taken into account, and dynamic automated compliance management can be achieved.
[0034] In a preferred manner, it can not only be integrated with business processes such as internal business actual data sharing, but also structure the content of the PIA report into specific problem items to be evaluated in compliance assessment, associate the evaluation, report, and approval of data permissions, and achieve automatic generation of the report after the legal compliance assessment is completed, reducing the cost of compliance management work.
[0035] Of course, when implementing any product of the present application, it is not necessarily required to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0037] Figure 1 is a schematic diagram of the system architecture and interaction provided by the embodiments of the present application;
[0038] Figure 2 is a flowchart of the method provided by the embodiments of the present application;
[0039] Figure 3-1 is a schematic diagram of the first interface provided by the embodiments of the present application;
[0040] Figure 3-2 is a schematic diagram of the second interface provided by the embodiments of the present application;
[0041] Figure 4It is a schematic diagram of the third interface provided by the embodiment of the present application;
[0042] Figure 5 It is a schematic diagram of the device provided by the embodiment of the present application;
[0043] Figure 6 It is a schematic diagram of the electronic device provided by the embodiment of the present application. Detailed implementation manners
[0044] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art shall fall within the protection scope of the present application.
[0045] First of all, it should be noted that in the prior art, there are some applications that provide similar data compliance services. However, such threshold-free tools can usually only solve report generation, and the report content is simple, with an obvious gap from the PIA report template issued by regulatory cooperation agencies. From practical experience, such reports usually cannot be used as proof materials for compliance self-certification. If a report that can solve compliance self-certification or obtain certification is required, the support of relevant legal personnel is still needed for evaluation. In addition, from the perspective of core capabilities, report generation is only one link in the compliance management of data circulation. Usually, compliance evaluation needs to be carried out before generating a report, and the existing compliance service applications cannot complete the compliance evaluation, and this part of the work still completely depends on manual operation. Moreover, such existing compliance service applications still generate PIA reports in the dimension of specific data circulation applications. The number of PIA reports that need to be maintained in the system will be very large, and as the number of data circulations increases, the number of reports will also increase, which is not convenient for management.
[0046] The embodiment of the present application first provides a corresponding solution to the problem that in the case of generating PIA reports according to the data circulation application dimension in the above-mentioned prior art, the number of PIA reports is too large and difficult to manage. Specifically, the inventors of the present application found in the process of implementing the present application that data compliance management can actually be scenario-based management. For example, after a certain subject A and subject B reach a certain business cooperation, for the same business cooperation, it may involve multiple data circulations, and the actual data types required for each data circulation may not be exactly the same. However, since they belong to the same business cooperation, usually the same problems need to be solved.
[0047] Therefore, in the embodiments of the present application, a data compliance processing system is provided. The users targeted by this system can mainly be legal personnel responsible for data compliance management in specific enterprises, etc. Among them, if the enterprise structure is relatively complex, including many business segments that may be relatively independent of each other, etc., legal personnel responsible for data compliance management may be separately set up for each business segment, and these legal personnel can all become users of the above-mentioned data compliance processing system. In this system, the concept of a compliance scenario is proposed. After a certain business cooperation (usually a project involving cross-legal entity data circulation) is reached, relevant legal personnel, etc., can actively create a corresponding compliance scenario based on the legal basis associated with this business cooperation project (including some agreements, company operation management systems, legal obligations, etc.) to achieve a structured expression of the applicable data provider entities, data recipient entities, and applicable data scope, etc. Or, if the legal personnel do not actively create a compliance scenario, it can also be created during the approval process of a specific data circulation application, and so on.
[0048] After creating a compliance scenario, in the embodiments of the present application, a PIA report can be generated in the dimension of the compliance scenario. Of course, since the creation of a compliance scenario does not mean the occurrence of a specific data circulation event, therefore, a PIA report is not directly created for this compliance scenario after its creation. Instead, after a data circulation application related to this compliance scenario occurs, for those involving personal information in the specific data circulation application, a specific PIA report will be generated. However, for the same compliance scenario, only one PIA report needs to be generated. Subsequently, after a new data circulation application related to this compliance scenario occurs, if the personal information involved is updated, it can be updated based on the already generated PIA report, and all data circulation applications related to this compliance scenario can share this updated PIA report; in the case where the personal information has not changed, there is no need to update the PIA report, and it can directly share the same already generated PIA report with multiple data circulation applications applicable to the same compliance scenario.
[0049] Specifically, after a specific business party has a data circulation requirement, it can submit a data circulation application through a data circulation platform or the like. The data compliance processing system in the embodiments of the present application can be connected to the above-mentioned data circulation platform or the like, so that the data compliance processing system can perceive events such as application submission in the data circulation platform. After perceiving the submission event of the data circulation application, it can obtain the relevant application data of the specific data circulation application and push a review task to the relevant review task executor. During the review process, the task executor can determine whether the current data circulation application involves personal information and whether it is applicable to a certain created compliance scenario. If it involves personal information and there is an applicable compliance scenario, it can continue to determine whether there is a PIA report for this compliance scenario. If not, it can enter the PIA report generation process; otherwise, if there is already a PIA report, it can further determine whether the personal information involved in the currently received data circulation application has changed compared with the personal information already in the PIA report. If there is a change, it can enter the PIA update process; otherwise, it does not need to be updated and the already generated PIA report corresponding to this compliance scenario can be directly used.
[0050] Through the above method, the requirement of implementing compliance management obligations in an enterprise internal scenario can be achieved, and the compliance management is dynamic, capable of timely perceiving changes on the business side and thus timely updating the PIA report. That is, the generation and update of the PIA report can be carried out in units of compliance scenarios. In this way, for multiple different data circulation applications associated with the same compliance scenario, only one PIA report needs to be maintained, thereby reducing the number of PIA reports and facilitating management. Moreover, by connecting the compliance management system and the data circulation system, the compliance management system can perceive the submission of the data circulation application. Therefore, the coverage of compliance management and the management cost can be taken into account.
[0051] On the other hand, aiming at the problem that the compliance management products in the prior art can only provide the function of generating PIA reports, the embodiments of the present application can also provide an implementation solution for integrating the compliance assessment of data circulation and the generation of PIA reports in a productized manner, which can realize the simultaneous completion of the review of data permissions, the assessment of data compliance, and the generation of PIA reports. To achieve this goal, the embodiments of the present application can structure the content of the PIA report into specific problem items to be evaluated in the compliance assessment. After completing the approval of the data circulation application and determining that a PIA report for a specific compliance scenario needs to be generated or updated, key information can be extracted first according to the application data of the specific data circulation application and / or the data covered by the specific compliance scenario, and mapped to the corresponding evaluation problem items in the evaluation form, so as to obtain the evaluation content corresponding to the specific problem items, in order to complete the automated compliance assessment. Among them, specific evaluation criteria, etc. can be pre-configured or defined in the code, etc. If the evaluation passes, the evaluation content on the specific problem items in the evaluation form can be mapped to the content items in the PIA report, so as to complete the automatic filling of the specific content in the PIA report and generate the PIA report. Of course, for some content items that cannot be automatically filled, relevant legal personnel can improve them, etc.
[0052] It can be seen that through the above method, not only can it be integrated with the business processes such as the actual data circulation within the enterprise, but also the content of the PIA report can be structured into specific problem items to be evaluated in the compliance assessment, and the assessment, report, and approval of data permissions can be correlated. After the legal compliance and security assessments are completed, the report can also be automatically generated, reducing the cost of compliance management work.
[0053] From the perspective of the system architecture, see Figure 1, embodiments of the present application provide a data compliance management system. Legal personnel users can create compliance scenarios through this system. In addition, this system can be integrated with a data circulation system (which can be a dedicated data circulation center, or an online gateway, etc.). After the business party submits a data circulation application through the data circulation system, the data compliance management system can sense this application and obtain information on the specific data circulation application, including the specific type of application data, etc. Then, an approval task can be generated and pushed to the client of relevant legal personnel and other approval task executors for approval. During the approval process, legal personnel can determine whether the current data circulation application is applicable to a certain created compliance scenario and whether it involves personal information. If so, it can further be determined whether a PIA report has been generated for this compliance scenario. If not, it enters the PIA report generation process. Otherwise, it can be determined whether the personal information has changed. If it has changed, it can enter the PIA report update process. If it has not changed, the PIA report can remain unchanged. In a preferred manner, during the generation or update process of the PIA report, key information can be extracted from the application data and / or compliance scenario information and mapped to the corresponding question items in the evaluation form to obtain the evaluation content on the specific question items and complete an automatic compliance evaluation. If the evaluation passes, the evaluation content on the specific question items is mapped to the corresponding content items in the PIA report template to complete the automatic filling of the PIA report template and generate or update the PIA report.
[0054] The following details the specific implementation solutions provided by the embodiments of the present application.
[0055] First, embodiments of the present application adopt a data compliance processing method. See Figure 2 , which specifically may include:
[0056] S201: Create a target compliance scenario, where the target compliance scenario is a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes based on the legal basis of the target business cooperation project.
[0057] In embodiments of the present application, the generation and update of the PIA report can be carried out on a compliance scenario basis. Among them, the so-called compliance scenario can specifically be created for a business cooperation project. Here, the business cooperation project usually involves a project of cross-legal entity data circulation. After the business cooperation project is reached, relevant legal personnel and others can create a compliance scenario through the data compliance management system provided by the embodiments of the present application. Of course, if legal personnel fail to actively create a compliance scenario for the business cooperation project in a timely manner, they can also create a compliance scenario after receiving a specific data circulation application.
[0058] Among them, specifically when creating a compliance scenario, the legal basis of a specific business cooperation project, as well as information such as the applicable data provider entity, data recipient entity, and applicable data scope, can be submitted. That is to say, the compliance scenario in the embodiments of this application is a structured expression of the above information. Among them, the reason for submitting the legal basis information is that specific data compliance management is completed on the basis of compliance with the law. For example, it may be necessary to sign an authorization agreement with the user, sign a data sharing / entrusted processing agreement, and so on. In addition, the specific legal basis can also include the company's operation and management system, legal obligations, and so on. For example, as Figure 3-1 shown, it is an interface provided in a specific implementation manner for creating a compliance scenario. Through this interface, a user can input information such as the specific compliance scenario name, type, validity period, legal basis, etc. In addition, specific applicable scope information can also be added. For example, as Figure 3-2 shown, it shows an interface for filling in the applicable scope information in a specific implementation manner, which includes applicable business entities (including data provider entities, data recipient entities, etc.), and applicable data scope (including but not limited to data processing roles, data processing purposes, specific data types), etc. Among them, regarding the applicable data scope, a relatively broad scope can be specified only when creating a compliance scenario. When the legal affairs personnel complete the approval of a specific data circulation application, the system will automatically associate the offline table information required for the specific data circulation, etc. Or, specific offline tables can also be specified when creating a compliance scenario.
[0059] S202: When the data circulation application information applicable to the target compliance scenario is first obtained and the data circulation application involves personal information, execute the automatic generation process of the personal information protection impact assessment PIA report to generate a PIA report for the target compliance scenario.
[0060] In the case where a compliance scenario is created, the generation and update of the PIA report can be carried out in units of the compliance scenario.
[0061] Among them, in specific implementation, since the data compliance management system is connected to the data circulation system, it is possible to perceive the data circulation application information received in the data circulation system and obtain the relevant application data types. After that, the data compliance management system can generate corresponding approval tasks and push them to the corresponding approval task executors (multiple roles can perform approvals, including legal personnel, technical personnel, security personnel, etc.) for approval. Among them, during the approval process by legal personnel, since the application data of a specific data circulation application (the so-called data circulation can include data collection, transmission, provision, entrusted processing, etc.) usually also includes information such as the data provider, data recipient, business line, etc., it is possible to determine whether the current data circulation application can be associated with a certain created compliance scenario based on the specific application data, etc. If there is an applicable compliance scenario, legal personnel can select the applicable compliance scenario in the approval interface. For example, they can select the "Compliance Scenario" option as shown in Figure 4 at 41 places, and they can also select the specific compliance scenario name, etc. After determining the applicable compliance scenario, the specific compliance management system can also determine whether there is already a PIA report for this compliance scenario. If not, the currently received data circulation application belongs to the first application obtained that applies to this compliance scenario. Next, the specific PIA report generation process can be executed.
[0062] However, there is another situation. After a certain cooperation project is completed, the business side initiates a data circulation application. At this time, there is no corresponding compliance scenario created yet. After generating the approval task, when legal personnel are performing the approval, they can select the "Normal Approval without Applicable Compliance Scenario" option as shown in Figure 4 at 42 places to complete the approval. In addition, the specific data compliance management system can also trigger the process of creating a compliance scenario based on the current data circulation application and generate a draft for creating a compliance scenario according to the key information in the application data of this data circulation application to assist the person in charge of the compliance scenario to complete the creation of the compliance scenario. After completing the creation of the compliance scenario, it is also possible to determine the current data circulation application as the first received application corresponding to this compliance scenario and generate a PIA report for the corresponding compliance scenario.
[0063] S203: When new data circulation application information applicable to the target compliance scenario is obtained and the personal information involved in the new data circulation application has changed compared with the personal information in the PIA report corresponding to the target compliance scenario, execute the update process of the PIA report so as to realize the data compliance management of multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
[0064] Whether creating a compliance scenario in advance or creating a compliance scenario after receiving a specific data circulation application, an automatic PIA report generation can be performed after the first receipt of a data circulation application applicable to a certain compliance scenario. In this way, after receiving a new data circulation application applicable to a specific compliance scenario later, if the new data circulation application also involves personal information, it is possible to first compare whether the personal information involved in the new data circulation application has changed compared with the personal information in the PIA report corresponding to the applicable compliance scenario. If there is a change, an update can be made based on this PIA report. If there is no change, there is no need to update the PIA report, and the latest version of the PIA report corresponding to this compliance scenario can be directly used to complete the compliance management of the new data circulation application.
[0065] Among them, in a preferred implementation manner, an automatic compliance evaluation process can also be performed before generating or updating the PIA report. Specifically, for this purpose, when obtaining data circulation application information, the application data of the data circulation application can also be obtained. When executing the process of generating or updating the PIA report, key information can be extracted from the application data and / or the scenario information of the target compliance scenario, and the extracted key information can be mapped to the evaluation content of multiple evaluation questions corresponding to a preset evaluation form, so as to perform an automatic compliance evaluation according to the evaluation content in the evaluation form. Among them, the question items in the evaluation form can be related to the content items in the PIA report template. Therefore, after the compliance evaluation passes, the evaluation content in the evaluation form can also be directly mapped to the corresponding report items in the PIA report template, so as to generate or update the PIA report corresponding to the target compliance scenario.
[0066] It should be noted here that the PIA report is the specific content carrier for implementing the personal information protection impact assessment in laws and regulations, and its core function is compliance self-certification. Therefore, the evaluation dimensions and content need to be recognized by the regulatory authorities. The PIA report template used in the embodiments of the present application is generated by referring to the content of the PIA report issued by the regulatory cooperation agency. Therefore, it has authority in terms of content structure and evaluation dimensions, thus being able to solve the problem of compliance self-certification for regulatory inspections.
[0067] To better understand the solution provided by the embodiments of the present application, the following introduces the complete technical solution provided by the embodiments of the present application (including some optional solutions, which should not be regarded as limiting the protection scope of the present application) from the perspective of a specific processing flow.
[0068] 1. Create compliance scenarios in the data compliance management system in advance; among them, different business cooperation projects can correspond to different compliance scenarios, and different compliance scenarios can be created at different times. There may also be cases where certain business cooperation projects may not have created corresponding compliance scenarios in advance;
[0069] 2. Interface and connect the data compliance management system with the data circulation system in advance;
[0070] 3. The data compliance management system obtains data circulation application information and the application data associated with the data circulation application through the data circulation system;
[0071] 4. Generate an approval task based on the data circulation application, so that the approval task executor can determine whether there is a target compliance scenario applicable to the data circulation application and whether the data circulation application involves personal information;
[0072] 5. If there is an applicable target compliance scenario and it involves personal information, and there is no PIA report for this target compliance scenario, then go to step 6 to trigger the evaluation process; otherwise, if there is no applicable compliance scenario, go to step 12, and if there is an applicable compliance scenario and there is already a PIA report for this compliance scenario, go to step 8;
[0073] 6. In the evaluation process, key information can be extracted from the application data of the data circulation application and / or the scenario information of the target compliance scenario, and the key information can be mapped to the evaluation content of multiple evaluation questions corresponding to a preset evaluation form, and an automatic compliance evaluation can be carried out;
[0074] 7. If the evaluation passes, map the evaluation content of specific question items in the evaluation form to the corresponding report items in the PIA report template to generate a PIA report corresponding to the target compliance scenario;
[0075] 8. If there is already a PIA report for the target compliance scenario, determine whether the personal information applicable to the currently obtained data circulation application has been updated compared with the personal information in the existing PIA report, and determine whether it is necessary to update the existing PIA report; if an update is required, go to step 9, otherwise go to step 11;
[0076] 9. Trigger the evaluation process, extract key information from the application data of the currently obtained data circulation application, and map the key information to the evaluation content of multiple evaluation questions corresponding to a preset evaluation form;
[0077] 10. Map the evaluation content obtained in the evaluation process to the corresponding report items in the PIA report template, and update the content on the corresponding report items in the existing PIA report corresponding to the target compliance scenario, so that the updated PIA report is shared by the currently obtained data circulation application and other data circulation applications that were historically obtained and applicable to the target compliance scenario;
[0078] 11. If there is an existing PIA report for the target compliance scenario and the personal information associated with the currently obtained data circulation application has not been updated compared to the personal information in the PIA report, add the currently obtained data circulation application to the set of data circulation applications associated with the target compliance scenario, so that the existing PIA report corresponding to the target compliance scenario is shared by the currently obtained data circulation application and other data circulation applications that were historically obtained and applicable to the target compliance scenario;
[0079] 12. If there is no compliance scenario applicable to the currently received data circulation application, trigger a process for creating a compliance scenario based on the currently obtained data circulation application, and generate a draft for creating a compliance scenario based on the key information in the application data of the currently obtained data circulation application to assist the person in charge of the compliance scenario in completing the creation of the compliance scenario.
[0080] In summary, through the embodiments of the present application, a compliance scenario can be created based on the legality of a specific business cooperation project to achieve a structured expression of the applicable data provider entity, data recipient entity, and applicable data scope (including but not limited to data processing roles, data processing purposes, specific data types). In this way, PIA reports can be generated on a compliance scenario-by-scenario basis. Specifically, when the data circulation application related to this compliance scenario is first received, a PIA report can be generated; after a new data circulation application related to this compliance scenario is generated subsequently, if the personal information involved has been updated, it can be updated based on the already generated PIA report, and all data circulation applications related to the same compliance scenario can share this updated PIA report. Through this solution, since PIA reports can be generated at the compliance scenario dimension, the number of PIA reports that need to be maintained in the system is reduced, and the cost is lowered. Moreover, since the compliance management system and the data circulation system can be connected, changes on the business side can be sensed in a timely manner. Therefore, the coverage of compliance management can be taken into account, and dynamic automated compliance management can be achieved.
[0081] In a preferred manner, it can not only be integrated with business processes such as the actual data circulation within the enterprise, but also structure the content of the PIA report into specific issue items to be evaluated in the compliance assessment, associate the approvals of evaluation, report, and data permissions, and enable the automatic generation of the report after the legal compliance assessment is completed, thereby reducing the cost of compliance management work.
[0082] It should be noted that the embodiments of the present application may involve the use of user data. In actual applications, user-specific personal information data can be used in the solutions described herein within the scope permitted by the applicable laws and regulations of the country where it is located (for example, with the user's explicit consent, giving the user a practical notice, etc.).
[0083] Corresponding to the foregoing method embodiments, the embodiments of the present application also provide a data compliance report processing device. Refer to Figure 5 , the device may include:
[0084] A compliance scenario creation unit 501, configured to create a target compliance scenario, where the target compliance scenario is a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes based on the legal basis of the target business cooperation project;
[0085] A PIA report generation unit 502, configured to execute an automatic generation process of a personal information protection impact assessment (PIA) report when the data circulation application information applicable to the target compliance scenario is first obtained and the data circulation application involves personal information, so as to generate a PIA report for the target compliance scenario;
[0086] A PIA report update unit 503, configured to execute a PIA report update process when new data circulation application information applicable to the target compliance scenario is obtained and the personal information involved in the new data circulation application changes compared with the personal information in the PIA report corresponding to the target compliance scenario, so as to achieve data compliance management for multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
[0087] Among them, the target compliance scenario is actively created for the target business cooperation project before the data circulation application information applicable to the target compliance scenario is first obtained;
[0088] The device may further include:
[0089] A review task generation unit, configured to generate a review task according to the data circulation application information after receiving the data circulation application information, so that the review task executor determines the target compliance scenario applicable to the data circulation application and whether the data circulation application involves personal information.
[0090] If no compliance scenario is actively created for the target business cooperation project before the data circulation application information applicable to the target compliance scenario is first obtained, the device may further include:
[0091] A scenario draft generation unit, configured to generate a review task according to the data circulation application information after receiving the data circulation application information, so that after the review task executor determines that there is no applicable compliance scenario, it triggers a process of creating a compliance scenario based on the data circulation application, and generates a draft for creating a compliance scenario according to the key information in the application data of the data circulation application to assist in completing the creation of the compliance scenario.
[0092] In addition, the device may further include:
[0093] An evaluation unit, configured to perform an automatic compliance evaluation process before generating or updating the PIA report.
[0094] Specifically, the device may further include:
[0095] A first mapping unit, configured to obtain the application data of the data circulation application when obtaining the data circulation application information, so as to extract key information from the application data and / or the scenario information of the target compliance scenario when executing the process of generating or updating the PIA report, and map the key information to the evaluation content of multiple evaluation questions corresponding in a preset evaluation form, so as to perform an automatic compliance evaluation according to the evaluation content in the evaluation form;
[0096] A second mapping unit, configured to map the evaluation content in the evaluation form to the corresponding report items in the PIA report template if the compliance evaluation passes, so as to generate or update the PIA report corresponding to the target compliance scenario.
[0097] In addition, the device may further include:
[0098] A set addition unit is configured to add the new data circulation application information that is applicable to the target compliance scenario and for which the personal information involved in the new data circulation application has not changed compared to the personal information in the PIA report corresponding to the target compliance scenario to the data circulation application set associated with the target compliance scenario, so that the PIA report corresponding to the target compliance scenario is shared by the new data circulation application and other data circulation applications that have been historically obtained and are applicable to the target compliance scenario.
[0099] In addition, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps of the method described in any one of the foregoing method embodiments.
[0100] And an electronic device, including:
[0101] One or more processors; and
[0102] A memory associated with the one or more processors, the memory is used to store program instructions, and when the program instructions are read and executed by the one or more processors, the steps of the method described in any one of the foregoing method embodiments are executed.
[0103] A computer program product includes computer programs / computer-executable instructions, and when the computer programs / computer-executable instructions are executed by a processor in an electronic device, the steps of the method described in the foregoing method embodiments are implemented.
[0104] Wherein, Figure 6 Exemplarily, the architecture of the electronic device is shown, which may specifically include a processor 610, a video display adapter 611, a disk drive 612, an input / output interface 613, a network interface 614, and a memory 620. The above-mentioned processor 610, video display adapter 611, disk drive 612, input / output interface 613, network interface 614, and the memory 620 can be communicatively connected through a communication bus 630.
[0105] Wherein, the processor 610 can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solution provided by the present application.
[0106] The memory 620 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 620 can store an operating system 621 for controlling the operation of the electronic device 600, and a Basic Input / Output System (BIOS) for controlling the low-level operations of the electronic device 600. Additionally, a web browser 623, a data storage management system 624, a data compliance report processing system 625, etc. can also be stored. The above-mentioned data compliance report processing system 625 can be the application program that specifically implements the operations of the foregoing steps in the embodiments of this application. In summary, when implementing the technical solution provided in this application through software or firmware, the relevant program codes are stored in the memory 620 and are called and executed by the processor 610.
[0107] The input / output interface 613 is used to connect to an input / output module to implement information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input devices can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output devices can include a display, a speaker, a vibrator, an indicator light, etc.
[0108] The network interface 614 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module can implement communication in a wired manner (such as USB, network cable, etc.) or in a wireless manner (such as mobile network, WIFI, Bluetooth, etc.).
[0109] The bus 630 includes a path for transmitting information between various components of the device (such as the processor 610, the video display adapter 611, the disk drive 612, the input / output interface 613, the network interface 614, and the memory 620).
[0110] It should be noted that although the above device only shows the processor 610, the video display adapter 611, the disk drive 612, the input / output interface 613, the network interface 614, the memory 620, the bus 630, etc., in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of this application and does not necessarily include all the components shown in the figure.
[0111] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0112] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for a system or a system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiment. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0113] The above has introduced in detail the data compliance report processing method, device, and electronic device provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, there will be changes in the specific implementation manner and application scope according to the idea of this application. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for processing data compliance reports, characterized in that, Including: Create a target compliance scenario, which is a structured expression of applicable data provider entities, data recipient entities, and applicable data scope based on the legality basis of a target business cooperation project; When first obtaining data circulation application information applicable to the target compliance scenario and the data circulation application involves personal information, execute the automatic generation process of the Personal Information Protection Impact Assessment (PIA) report to generate a PIA report for the target compliance scenario; When obtaining new data circulation application information applicable to the target compliance scenario and the personal information involved in the new data circulation application has changed compared to the personal information in the PIA report corresponding to the target compliance scenario, execute the PIA report update process to achieve data compliance management for multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
2. The method according to claim 1, wherein: The target compliance scenario is actively created for the target business cooperation project before first obtaining data circulation application information applicable to the target compliance scenario; The method further includes: After receiving the data circulation application information, generate a review task based on the data circulation application, so that the review task executor determines the target compliance scenario applicable to the data circulation application and whether the data circulation application involves personal information.
3. The method according to claim 1, wherein: If no compliance scenario is actively created for the target business cooperation project before first obtaining data circulation application information applicable to the target compliance scenario, the method further includes: After receiving the data circulation application information, generate a review task based on the data circulation application, so that after the review task executor determines that there is no applicable compliance scenario, trigger the process of creating a compliance scenario based on the data circulation application, and generate a draft for creating a compliance scenario based on the key information in the application data of the data circulation application to assist the compliance scenario responsible person in completing the creation of the compliance scenario.
4. The method according to claim 1, wherein It further includes: Before generating or updating the PIA report, perform automatic compliance assessment processing.
5. The method according to claim 4, wherein: When obtaining the data circulation application information, also obtain the application data of the data circulation application, so that when executing the generation or update process of the PIA report, extract key information from the application data and / or the scenario information of the target compliance scenario, and map the key information to the evaluation content of multiple evaluation questions corresponding in a preset evaluation form, so as to perform automatic compliance assessment according to the evaluation content in the evaluation form; If the compliance assessment is passed, map the evaluation content in the evaluation form to the corresponding report items in the PIA report template to generate or update the PIA report corresponding to the target compliance scenario.
6. The method according to claim 1, characterized in that, It further includes: When new data circulation application information applicable to the target compliance scenario is obtained and the personal information involved in the new data circulation application has not changed compared with the personal information in the PIA report corresponding to the target compliance scenario, add the new data circulation application to the data circulation application set associated with the target compliance scenario, so that the PIA report corresponding to the target compliance scenario is shared by the new data circulation application and other data circulation applications that have been historically obtained and are applicable to the target compliance scenario.
7. A data compliance report processing device, characterized in that, including: A compliance scenario creation unit for creating a target compliance scenario, which is a structured expression of applicable data provider entities, data recipient entities, and applicable data scopes based on the legal basis of the target business cooperation project; A PIA report generation unit for, when first obtaining data circulation application information applicable to the target compliance scenario and the data circulation application involves personal information, executing an automatic generation process of a personal information protection impact assessment PIA report to generate a PIA report for the target compliance scenario; A PIA report update unit for, when obtaining new data circulation application information applicable to the target compliance scenario and the personal information involved in the new data circulation application has changed compared with the personal information in the PIA report corresponding to the target compliance scenario, executing an update process of the PIA report to achieve data compliance management of multiple data circulation applications applicable to the target compliance scenario through the same PIA report associated with the target compliance scenario.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
9. An electronic device, characterized in that, including: One or more processors; and A memory associated with the one or more processors, the memory being used to store program instructions, and when the program instructions are read and executed by the one or more processors, they execute the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program / computer-executable instructions, characterized in that, When the computer program / computer executable instructions are executed by a processor in an electronic device, they implement the steps of the method according to any one of claims 1 to 6.