Automated Data Deletion System for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack efficient methods for managing and deleting personal data across multiple computing systems, making it difficult for organizations to comply with privacy and security policies, especially in handling frequent requests from data subjects.

Innovation Solution

A computer-implemented data processing method and system that identifies and facilitates the deletion of personal data by processing requests, automatically determining storage locations, and taking actions based on identified causes, utilizing data models and intelligent identity scanning to manage and analyze data subject access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual methods are used to manage and delete personal data across multiple computing systems, then organizations can maintain control over data deletion processes, but the process becomes time-consuming and inefficient, making it difficult to comply with privacy policies when handling frequent requests

Engineering Contradiction:
Improvedata deletion efficiencyVSAvoidtime to process deletion requests
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically identifying computing devices that store personal data before deletion is requested. The processor proactively scans and locates data storage locations across the network, so when a deletion request arrives, the data is already identified and ready for immediate deletion, eliminating manual search time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically processing deletion requests without requiring manual intervention. The processor autonomously identifies storage locations, executes deletion commands across multiple devices, and manages the entire data deletion workflow independently, dramatically improving efficiency while reducing time loss

Inventive Principle:
Principle #25Self-service

2Reliability

If automated systems are implemented to process data subject requests, then processing efficiency and compliance accuracy improve, but the system complexity increases

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The processor is designed with multi-functionality to handle various data subject requests (access, deletion, modification) across different computing devices and data types through a single unified system. This universal approach ensures consistent compliance accuracy while avoiding the need for multiple separate systems, thereby limiting the increase in overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the processor continuously monitors deletion operations, verifies data removal success, and adjusts its operations based on system responses. This automated feedback loop ensures high compliance accuracy by confirming each deletion action while maintaining manageable system complexity through self-regulation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10346638B2Data processing systems for identifying and modifying processes that are subject to data subject access requests
Publication Date: 2019.07.09 ONETRUST LLC
  • US10346638B2 patent drawing
  • US10346638B2 patent drawing
  • US10346638B2 patent drawing

AI summary

In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject's personal data from the various systems; and (3) determine a cause of the request to identify one or more processing activities or other sources that result in a high number of such requests.