Data Inventory System for Personal Data Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods to manage and comply with privacy and security policies regarding personal data, particularly in identifying and responding to data subject access requests and maintaining data inventory across multiple data assets.

Innovation Solution

A computer-implemented data processing method and system that generates and populates a data model to map relationships between data assets, enabling identification of personal data, compliance with legal and industry standards, and efficient handling of data subject access requests through scanning, inventory generation, and data mapping techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to identify and manage personal data across multiple data assets, then compliance with privacy policies can be achieved, but the time and resources required increase significantly

Engineering Contradiction:
Improvecompliance with privacy policiesVSAvoidtime to identify and manage personal data
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively scanning and identifying personal data across multiple data assets before access requests are made. Data inventories are generated in advance, mapping the location and characteristics of personal data, so that when a data subject access request arrives, the system can quickly retrieve and process the information without time-consuming manual searches.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive data inventory is maintained across all data assets, then accurate identification of personal data is improved, but system complexity increases

Engineering Contradiction:
Improveaccuracy of personal data identificationVSAvoidcomplexity of data inventory system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the data inventory management into distinct components: data asset identification modules, personal data detection modules, inventory generation modules, and access request processing modules. Each component handles a specific aspect of the process, working together through standardized interfaces. This segmentation maintains comprehensive tracking across all data assets while keeping individual system components manageable and understandable.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated scanning and inventory generation is implemented, then productivity in handling data access requests increases, but computational resources and system complexity increase

Engineering Contradiction:
Improveefficiency of data access request handlingVSAvoidcomplexity of automated processing system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where data assets automatically register themselves with the data inventory system, providing metadata about their structure and content. The scanning process automatically detects personal data based on predefined criteria without requiring manual configuration for each asset. This automation increases productivity while managing complexity by eliminating the need for manual system setup and maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10438020B2Data processing systems for generating and populating a data inventory for processing data access requests
Publication Date: 2019.10.08 ONETRUST LLC
  • US10438020B2 patent drawing
  • US10438020B2 patent drawing
  • US10438020B2 patent drawing

AI summary

In particular embodiments, a data processing data inventory generation system is configured to: (1) generate a data model (e.g., a data inventory) for one or more data assets utilized by a particular organization; (2) generate a respective data inventory for each of the one or more data assets; and (3) map one or more relationships between one or more aspects of the data inventory, the one or more data assets, etc. within the data model. In particular embodiments, a data asset (e.g., data system, software application, etc.) may include any entity that collects, processes, contains, and/or transfers personal data (e.g., a software application, database, website, server, etc.). A data asset may include any software or device (e.g., server or servers) utilized by a particular entity for such data collection, processing, transfer, storage, etc. The system may then utilize the generated model to fufill a data subject access request.