Data Subject Access Request Processing via Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inadequate for timely and efficient compliance with data subject access requests, particularly for large corporations that store data across multiple platforms and locations, leading to challenges in providing required information within regulatory timelines.

Innovation Solution

A computer-implemented data processing method and system that verifies a data subject's association with a particular geographic location by receiving additional information, confirming their identity through secure links and third-party data aggregation systems, and processing requests to identify and manage personal data stored within the organization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Volume of stationary object

If data is stored across multiple platforms and locations for large corporations, then data storage capacity and accessibility are improved, but the time required to locate and process data subject access requests increases

Engineering Contradiction:
Improvedata storage capacityVSAvoidprocessing time for data subject access requests
Core Design Contradiction:
Volume of stationary objectVSLoss of time

Solution Approach 1:

The system segments the distributed data storage environment into manageable units by implementing location-based verification that operates independently across different geographic locations and platforms. This allows parallel processing of verification requests without requiring centralized data aggregation, thus maintaining storage capacity while reducing processing time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary verification of the data subject's location and identity before initiating the data retrieval process. By pre-verifying the requestor's credentials and location status, the system eliminates delays that would occur during actual data processing, enabling faster compliance with data subject access requests across distributed platforms.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If verification processes are enhanced by collecting additional information from data subjects, then identity verification accuracy is improved, but the complexity of the verification process increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidverification process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces a location verification server as an intermediary that manages the collection and validation of additional verification information. This intermediary coordinates between the data subject, third-party data aggregation systems, and the organization's data systems, simplifying the overall process complexity while maintaining high verification accuracy through structured information flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where verification results from third-party data aggregation systems are continuously refined based on additional information provided by the data subject. This iterative verification process improves accuracy by cross-referencing multiple data sources while managing complexity through automated feedback mechanisms that guide the verification workflow.

Inventive Principle:
Principle #23Feedback

3Reliability

If secure links and third-party data aggregation systems are used for verification, then security and reliability of identity confirmation are improved, but the device and system complexity increases

Engineering Contradiction:
Improveidentity confirmation reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs third-party data aggregation systems as intermediaries that specialize in secure verification operations. These external systems handle the complexity of secure communication protocols and data validation, allowing the organization's system to maintain high reliability without bearing the full burden of implementation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements universal verification protocols that can interface with multiple different third-party data aggregation systems through standardized communication interfaces. This multi-functionality approach allows the system to leverage various secure verification providers without increasing complexity, as the same verification framework works across different platforms and data sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11334682B2Data subject access request processing systems and related methods
Publication Date: 2022.05.17 ONETRUST LLC
  • US11334682B2 patent drawing
  • US11334682B2 patent drawing
  • US11334682B2 patent drawing

AI summary

In particular embodiments, computer-implemented data processing, systems, and method configured to: receive a request to initiate a transaction between an entity and a data subject, generate (i) a consent receipt for the transaction comprising at least a unique subject identifier and a unique consent receipt key and (ii) a unique cookie to identify the data subject's transaction initiated by the data subject, store the consent receipt for the transaction and the unique cookie, receive a data subject access request from the data subject, verify an identity of the data subject based at least in part on the unique cookie process the request, process the request by identifying one or more pieces of personal data associated with the data subject, and taking one or more actions based at least in part on the data subject access request.