Data Privacy Lifecycle Management for Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in complying with data privacy laws due to conflicting regulations regarding the retention and erasure of personal data, particularly when legal retention periods conflict with the need to restrict access and usage of such data.

Innovation Solution

Implementing a data privacy information lifecycle management tool that manages business partner data through its entire lifecycle, including blocking access and erasure, by utilizing a system that restricts access to authorized personnel and prohibits processing during the blocking period, and ensures data destruction after the retention period expires, while considering dependencies between business objects and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal data is retained to comply with legal retention periods, then compliance with data retention regulations is improved, but data privacy and security are worsened due to continued storage of personal data

Engineering Contradiction:
Improvecompliance with data retention regulationsVSAvoiddata privacy risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments personal data into two states: blocked (during retention period) and deleted (after retention period). This segmentation allows the system to comply with retention requirements while minimizing privacy risks by restricting access to blocked data and completely removing it after the retention period expires.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary deletion actions by automatically deleting personal data after the retention period expires. This preliminary action ensures that data is removed in advance of any potential misuse, while the blocking mechanism prevents access during the retention period, thus resolving the contradiction between retention compliance and privacy protection.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If personal data is blocked to restrict access during retention period, then data privacy is improved, but system complexity increases due to additional blocking and unblocking operations

Engineering Contradiction:
Improveunauthorized data accessVSAvoidblocking management system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the blocking and deletion operations into a unified automated workflow managed by the EoP interface component. This consolidation reduces system complexity by integrating multiple functions into a single coordinated process, while still providing robust protection against unauthorized access during the retention period.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements self-service blocking and unblocking operations through automated workflows that trigger based on retention period expiration. This self-service mechanism eliminates the need for manual intervention in blocking management, reducing operational complexity while maintaining strong access control during the retention period.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated workflows are implemented to manage data lifecycle, then compliance efficiency is improved, but processing time increases due to dependency checks and coordination between systems

Engineering Contradiction:
Improvedata lifecycle management efficiencyVSAvoidprocessing delay
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent performs preliminary dependency checks and system coordination before executing blocking or deletion operations. This preliminary action ensures that all necessary conditions are met in advance, preventing delays during actual data processing while maintaining compliance with retention requirements and system dependencies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The EoP interface component implements feedback mechanisms that monitor the status of data retention and automatically trigger appropriate actions when retention periods expire. This feedback-driven approach optimizes processing time by activating workflows only when necessary, rather than continuously checking conditions, thus improving efficiency without sacrificing compliance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9047228B2Systems and methods for data privacy and destruction
Publication Date: 2015.06.02 SAP SE
  • US9047228B2 patent drawing
  • US9047228B2 patent drawing
  • US9047228B2 patent drawing

AI summary

A system and method for managing application(s)' access to personal data of an enterprise business partner is presented. The method includes selecting business partners having personal data records stored in a database connected to an enterprise computing system, for each particular business partner identifying each application that accesses the business partner's personal data records, inquiring from each identified application if it has reached an end-of-purpose period for the personal data records. If an end-of-purpose period has been reached receiving a start-of-retention-time from the application, storing the start-of-retention-time indication in a data record associated with the particular business partner, and blocking access by the particular application to the personal data records of the particular business partner. If a start-of-retention-time indication is not received allowing continued access by the particular application to the personal data records associated with the selected business partner. Applications located in remote systems can be queried and blocked.