Data Subject Access Request Routing via Local Storage Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently managing and processing data subject access requests across multiple geographic locations, leading to difficulties in complying with privacy and security policies, particularly in identifying and accessing personal data stored by organizations.

Innovation Solution

A data subject access request processing system comprising data subject access request management servers, local storage nodes in distinct geographic locations, and processors that receive, identify, and route requests to appropriate storage nodes for processing, enabling the management and fulfillment of data subject access requests while ensuring compliance with legal and industry standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal data is stored across multiple geographic locations to improve data accessibility and compliance, then data subject access request processing becomes more complex and costly due to interjurisdictional transfers

Engineering Contradiction:
Improvedata accessibilityVSAvoidrequest processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A centralized data subject access request management server acts as an intermediary between data subjects and distributed local storage nodes. The management server receives access requests, identifies the relevant local storage node based on geographic location, and coordinates the fulfillment process, thereby simplifying the complexity for individual components while maintaining multi-location accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system divides data storage into geographically distributed local storage nodes, each responsible for storing personal data of data subjects in its jurisdiction. This segmentation allows requests to be routed to specific nodes based on location, reducing the complexity of searching across all locations while maintaining accessibility

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If personal data is stored across multiple geographic locations to improve data accessibility, then the cost and complexity of interjurisdictional data transfers increase

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata transfer cost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The system implements local storage nodes that store personal data in the same geographic jurisdiction as the data subject. This local quality ensures that data access requests can be fulfilled within the same jurisdiction, eliminating or reducing interjurisdictional data transfers and associated costs while maintaining data accessibility

Inventive Principle:
Principle #3Local quality

3Reliability

If manual processes are used to identify and access personal data across multiple locations, then compliance with privacy policies becomes more difficult, but automation increases system complexity

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements automated identification and routing capabilities where the data subject access request management server automatically identifies the relevant local storage node based on the data subject's location and routes the request appropriately. This self-service automation ensures consistent compliance while managing complexity through centralized intelligence rather than distributed manual processes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11036882B2Data processing systems for processing and managing data subject access in a distributed environment
Publication Date: 2021.06.15 ONETRUST LLC
  • US11036882B2 patent drawing
  • US11036882B2 patent drawing
  • US11036882B2 patent drawing

AI summary

In particular embodiments, a data subject request processing system may be configured to utilize one or more local storage nodes in order to process a data subject access request on behalf of a data subject. In particular embodiments, the one or more local storage nodes may be local to the data subject making the request (e.g., in the same country as the data subject, in the same jurisdiction, in the same geographic area, etc.). The system may, for example, be configured to: (1) receive a data subject access request from a data subject (e.g., via a web form); (2) identify a suitable local storage node based at least in part on the request and/or the data subject; (3) route the data subject access request to the identified local storage node; and (4) process the data subject access request at the identified local storage node.