Data Transfer Risk Identification via Preliminary Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack efficient methods to manage and secure personal data transfers, leading to increased risks of unauthorized access and non-compliance with privacy and security policies, especially in minimizing data processing by entities not actively engaged with individuals.

Innovation Solution

A method involving computing hardware that evaluates data transfer risks by analyzing data models, performing assessments using data transfer rules, and taking actions such as generating secure links, terminating data transfers, or encrypting data, based on risk ratings and user approvals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data transfer rules are enforced to minimize data processing by entities not actively engaged with individuals, then data security and compliance are improved, but data transfer efficiency and operational flexibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary risk assessments and establishes secure links before data transfers occur. By pre-evaluating transfer risks and pre-establishing secure communication channels, the system ensures compliance with data transfer rules while maintaining efficient data flow without requiring repeated security checks during actual transfers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary risk assessment mechanism that mediates between data security requirements and transfer efficiency. This intermediary layer evaluates transfer risks, determines appropriate security measures, and facilitates approved transfers, thereby balancing security enforcement with operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive risk assessments are performed on all data transfers, then unauthorized access risks are reduced, but system complexity and processing time increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different levels of risk assessment scrutiny to different data transfers based on their specific characteristics. High-risk transfers receive comprehensive assessment while low-risk transfers undergo streamlined evaluation. This localized quality approach ensures thorough unauthorized access prevention where needed while reducing unnecessary complexity for routine transfers.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts assessment parameters and security measures based on transfer risk ratings. By changing parameters such as assessment depth, security link requirements, and monitoring intensity according to the specific risk level of each transfer, the system prevents unauthorized access effectively while avoiding uniform complexity across all transfers.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure links and encryption are implemented for all data transfers, then data protection is enhanced, but computational overhead and transfer speed decrease

Engineering Contradiction:
Improvedata protectionVSAvoidtransfer speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Secure links and encryption protocols are established in advance during the risk assessment phase. By pre-configuring security measures before actual data transfers, the system minimizes computational overhead during the transfer process itself, thereby maintaining both strong data protection and acceptable transfer speeds.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies encryption and secure link measures selectively based on risk assessments rather than universally. For low-risk transfers, minimal or no additional security measures are applied beyond baseline protections. This partial action approach ensures adequate data protection while avoiding unnecessary computational overhead that would reduce transfer speed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230161906A1Data processing systems for data transfer risk identification and related methods
Publication Date: 2023.05.25 ONETRUST LLC
  • US20230161906A1 patent drawing
  • US20230161906A1 patent drawing
  • US20230161906A1 patent drawing

AI summary

A data processing central consent repository system may be configured to, for example: (1) identify a form used to collect one or more pieces of personal data, (2) determine a data asset of a plurality of data assets of the organization where input data of the form is transmitted, (3) add the data asset to the third-party data repository with an electronic link to the form, (4) in response to a user submitting the form, create a unique subject identifier to submit to the third-party data repository and, along with the form data provided by the user in the form, to the data asset, (5) submit the unique subject identifier and the form data provided by the user to the third-party data repository and the data asset, and (6) digitally store the unique subject identifier and the form data in the third-party data repository and the data asset.