Data Subject Access Request Routing via Local Storage Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently managing and processing data subject access requests, particularly in complying with privacy and security policies due to the complexity of storing and retrieving personal data across multiple locations, which can lead to increased costs and time inefficiencies.

Innovation Solution

A data subject access request processing system comprising data subject management servers, local storage nodes in distinct geographic locations, and processors that receive, route, and process requests to identify and provide access to personal data, while ensuring compliance with legal and industry standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal data is stored across multiple geographic locations to comply with privacy policies, then data security and compliance are improved, but system complexity and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments personal data storage across multiple geographic locations (local storage nodes) while maintaining a centralized management structure. Each local storage node stores data subject personal data locally, dividing the storage function geographically while the centralized server coordinates access requests, thus improving security through distribution without requiring complex peer-to-peer coordination

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized data subject access request management server acts as an intermediary between data subjects and distributed local storage nodes. The server receives access requests, identifies the appropriate local storage node based on the data subject's location, and coordinates the retrieval process, simplifying the interaction model while maintaining geographic distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If personal data is stored across multiple geographic locations to comply with privacy policies, then data security and compliance are improved, but processing time and costs increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing the geographic mapping between data subjects and local storage nodes. When a data subject makes an access request, the centralized server already has the information needed to identify the correct local storage node, eliminating the need for complex real-time searches across multiple locations and enabling immediate request routing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements local quality by storing personal data at local storage nodes in the same geographic location as the data subject. This localization enables faster access since data resides nearby rather than requiring long-distance transfers, while still maintaining the security benefits of geographic distribution

Inventive Principle:
Principle #3Local quality

3Loss of energy

If personal data is stored locally at multiple nodes, then interjurisdictional transfers are reduced, but initial system setup and data distribution complexity increases

Engineering Contradiction:
Improvedata transfer costsVSAvoiddata distribution complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The system extracts the data distribution complexity from the operational phase and handles it during system initialization. A centralized management server coordinates the initial distribution of personal data to appropriate local storage nodes based on data subject locations, after which the system operates with minimal complex coordination, reducing ongoing transfer costs while limiting complexity to the setup phase

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10509920B2Data processing systems for processing data subject access requests
Publication Date: 2019.12.17 ONETRUST LLC
  • US10509920B2 patent drawing
  • US10509920B2 patent drawing
  • US10509920B2 patent drawing

AI summary

In particular embodiments, a data subject request processing system may be configured to utilize one or more local storage nodes in order to process a data subject access request on behalf of a data subject. In particular embodiments, the one or more local storage nodes may be local to the data subject making the request (e.g., in the same country as the data subject, in the same jurisdiction, in the same geographic area, etc.). The system may, for example, be configured to: (1) receive a data subject access request from a data subject (e.g., via a web form); (2) identify a suitable local storage node based at least in part on the request and/or the data subject; (3) route the data subject access request to the identified local storage node; and (4) process the data subject access request at the identified local storage node.