Data Privacy Lifecycle Management for Enterprise Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in complying with data privacy laws due to conflicting regulations regarding the retention and erasure of personal data, particularly when legal retention periods conflict with the need to restrict access and usage of such data.
Innovation Solution
Implementing a data privacy information lifecycle management tool that manages business partner data through its entire lifecycle, including blocking access and erasure, by utilizing a system that restricts access to authorized personnel and prohibits processing during the blocking period, and ensures data destruction after the retention period expires, while considering dependencies between business objects and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personal data is retained to comply with legal retention periods, then compliance with data retention regulations is improved, but data privacy and security are worsened due to continued storage of personal data
Solution Approach 1:
The patent segments personal data into two states: blocked (during retention period) and deleted (after retention period). This segmentation allows the system to comply with retention requirements while minimizing privacy risks by restricting access to blocked data and completely removing it after the retention period expires.
Solution Approach 2:
The patent implements preliminary deletion actions by automatically deleting personal data after the retention period expires. This preliminary action ensures that data is removed in advance of any potential misuse, while the blocking mechanism prevents access during the retention period, thus resolving the contradiction between retention compliance and privacy protection.
2Object-affected harmful factors
If personal data is blocked to restrict access during retention period, then data privacy is improved, but system complexity increases due to additional blocking and unblocking operations
Solution Approach 1:
The patent merges the blocking and deletion operations into a unified automated workflow managed by the EoP interface component. This consolidation reduces system complexity by integrating multiple functions into a single coordinated process, while still providing robust protection against unauthorized access during the retention period.
Solution Approach 2:
The system implements self-service blocking and unblocking operations through automated workflows that trigger based on retention period expiration. This self-service mechanism eliminates the need for manual intervention in blocking management, reducing operational complexity while maintaining strong access control during the retention period.
3Productivity
If automated workflows are implemented to manage data lifecycle, then compliance efficiency is improved, but processing time increases due to dependency checks and coordination between systems
Solution Approach 1:
The patent performs preliminary dependency checks and system coordination before executing blocking or deletion operations. This preliminary action ensures that all necessary conditions are met in advance, preventing delays during actual data processing while maintaining compliance with retention requirements and system dependencies.
Solution Approach 2:
The EoP interface component implements feedback mechanisms that monitor the status of data retention and automatically trigger appropriate actions when retention periods expire. This feedback-driven approach optimizes processing time by activating workflows only when necessary, rather than continuously checking conditions, thus improving efficiency without sacrificing compliance.
Data Source
AI summary
A system and method for managing application(s)' access to personal data of an enterprise business partner is presented. The method includes selecting business partners having personal data records stored in a database connected to an enterprise computing system, for each particular business partner identifying each application that accesses the business partner's personal data records, inquiring from each identified application if it has reached an end-of-purpose period for the personal data records. If an end-of-purpose period has been reached receiving a start-of-retention-time from the application, storing the start-of-retention-time indication in a data record associated with the particular business partner, and blocking access by the particular application to the personal data records of the particular business partner. If a start-of-retention-time indication is not received allowing continued access by the particular application to the personal data records associated with the selected business partner. Applications located in remote systems can be queried and blocked.


