Enterprise Data Permissions Database for GDPR Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise management systems face challenges in efficiently managing personal data to comply with regulations like GDPR, particularly in removing personal data and handling user rights, due to cumbersome processes and redundant operations across disparate systems.
Innovation Solution
An enterprise system with a permissions database and AI subsystem that consolidates personal data attributes, legal grounds, and usage purposes, allowing for efficient data access and compliance by generating records and communicating data based on request purposes, reducing redundant operations and network transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personal data is removed from disparate systems manually, then data compliance is improved, but the process becomes cumbersome and may fail
Solution Approach 1:
The patent introduces a central permissions database that acts as an intermediary between users and disparate enterprise systems. This database stores unified permission information and coordinates data access requests across multiple systems, eliminating the need for manual coordination with various IT groups while ensuring consistent compliance enforcement.
Solution Approach 2:
The system performs preliminary actions by pre-establishing permission records in the central permissions database that define how personal data should be managed across different systems. These pre-configured permission rules enable automated enforcement of compliance requirements before data access or removal operations occur, preventing compliance failures rather than reacting to them.
2Adaptability or versatility
If data is replicated across enterprise systems, then data availability is improved, but personal data may be copied back to systems where it was recently removed
Solution Approach 1:
The patent implements a feedback mechanism where the central permissions database receives notifications from disparate systems about data replication events. When a system replicates personal data, the permissions database can detect this through permission record updates and coordinate with the requesting system to ensure compliance, creating a closed-loop control system that prevents unauthorized data restoration.
Solution Approach 2:
The central permissions database serves as an intermediary that mediates between data replication operations and compliance requirements. It monitors permission changes across systems and coordinates with IT groups to ensure that replicated data maintains compliance status, preventing personal data from being copied back to systems where it should have been removed.
3Reliability
If instructions are sent to various IT groups to remove information, then data compliance is improved, but the process becomes cumbersome and time-consuming
Solution Approach 1:
The patent enables self-service by allowing users to directly request access to or removal of their personal data through an interface that communicates with the central permissions database. The system automatically processes these requests by querying the unified permission information and coordinating with relevant systems, eliminating the need for users to manually contact multiple IT groups and significantly reducing the time required for data compliance operations.
Solution Approach 2:
The central permissions database provides a universal interface that handles multiple data compliance functions (data access, data removal, permission management) across diverse enterprise systems. This multi-functional platform consolidates what would otherwise require separate manual processes with different IT groups into a single automated system that handles all compliance operations through unified permission records.
Data Source
AI summary
A system for managing personal data stored by an enterprise includes an interface, a permissions database, a processor, and non-transitory computer readable media. The interface is configured to receive a request to access at least some of the personal data, the request defining a purpose for the request. The permissions database that stores a plurality of records that define permissions associated with the personal data. The non-transitory computer readable media in communication with the processor that stores instruction code which, when executed by the processor, causes the processor to locate, within one or more disparate source databases within the enterprise, personal data associated with one or more individuals. For each individual, the processor generates a record in the permissions database that relates the individual to: a) attributes of the personal data; b) legal grounds information that defines process rights; c) one or more purposes for which the personal data may be used; and d) constraint information that defines limitations on the individual to modify or delete the personal data. The processor selects one or more records associated with a purpose that matches the purpose of the request. The processor retrieves personal data associated with attributes of the one or more records from the one or more disparate source databases. The processor then communicates, via the interface, the retrieved personal data to a requestor associated with the request.


