Automated Data Deletion System with Verification Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inadequate for timely and efficient compliance with data subject access requests, particularly for large corporations with data stored across multiple platforms, leading to potential security breaches and non-compliance with regulations.

Innovation Solution

A computer-implemented method that accesses and scans data assets to generate a catalog of privacy campaigns and personal information, identifies unassociated personal data, and automatically removes or deletes it, while also providing a privacy data report and managing data retention metrics to ensure compliance with data protection regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored across multiple platforms for operational needs, then data accessibility and functionality are improved, but compliance with data subject access requests becomes more difficult and time-consuming

Engineering Contradiction:
Improvedata accessibilityVSAvoidcompliance time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system segments data management by creating separate data assets grouped into data asset groups, each with specific purposes. This segmentation allows the automated system to efficiently identify and process only relevant data portions for each access request, rather than searching across all data platforms manually.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated compliance system as an intermediary between data subject access requests and distributed data assets. This intermediary uses machine learning models and data catalogs to automatically navigate multiple platforms, identify relevant data, and coordinate deletions across systems without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data scanning is performed to identify all personal data, then data identification accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata identification accuracyVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by creating data catalogs and grouping data assets before access requests are received. Data is pre-tagged, classified, and organized into data asset groups with defined purposes, enabling rapid identification during compliance operations without requiring comprehensive scanning at request time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical searching and identification processes with automated machine learning models and algorithms. These computational systems efficiently scan and analyze data across multiple platforms, identifying personal data and its purposes with high accuracy and speed far exceeding manual capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If manual processes are used for data identification and deletion, then system complexity is reduced, but productivity and compliance efficiency decrease

Engineering Contradiction:
Improvesystem complexityVSAvoidcompliance efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The automated compliance system operates autonomously to fulfill data subject access requests without requiring manual human intervention for each request. The system self-manages the entire workflow from receiving requests to identifying relevant data across platforms to coordinating deletions, dramatically improving compliance efficiency and productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the compliance process from static manual procedures to dynamic automated operations. Machine learning models continuously learn from data patterns, and the system adapts its identification and deletion strategies based on accumulated experience, improving efficiency while managing complexity through intelligent automation.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If data retention periods are extended for business purposes, then operational flexibility is improved, but privacy and security risks increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidprivacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic data retention management where data is kept in active data asset groups only as long as needed for specific purposes. When data is no longer required for its original purpose or when deletion is requested, the system automatically removes it. This dynamic approach maintains operational flexibility while minimizing privacy risks through purpose-limited retention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The automated compliance system continuously monitors data retention status and provides feedback on data lifecycle management. The system tracks which data assets are retained, for what purposes, and for how long, enabling organizations to maintain appropriate retention periods that balance operational needs with privacy protection requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11120162B2Data processing systems for data testing to confirm data deletion and related methods
Publication Date: 2021.09.14 ONETRUST LLC
  • US11120162B2 patent drawing
  • US11120162B2 patent drawing
  • US11120162B2 patent drawing

AI summary

In particular embodiments, a Personal Data Deletion System is configured to: (1) at least partially automatically identify and delete personal data that an entity is required to erase under one or more of the conditions discussed above; and (2) perform one or more data tests after the deletion to confirm that the system has, in fact, deleted any personal data associated with the data subject. The system may, for example, be configured to test to ensure the data has been deleted by: (1) submitting a unique token of data through a form to a system; (2) in response to passage of an expected data retention time, test the system by calling into the system after the passage of the data retention time to search for the unique token.