Geographic Verification for Data Subject Access Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inadequate for timely and efficient compliance with data subject access requests, particularly for large corporations that store data across multiple platforms and locations, leading to challenges in providing required information within regulatory timelines.

Innovation Solution

A computer-implemented data processing method and system that verifies a data subject's association with a particular geographic location by prompting for additional information, generating secure links, and accessing third-party data aggregation systems to confirm location and process data subject access requests, including actions related to personal data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored across multiple platforms and locations, then data storage capacity and accessibility are improved, but the time and complexity required to process data subject access requests increase

Engineering Contradiction:
Improvedata storage capacityVSAvoidrequest processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system segments the distributed data storage architecture into identifiable components while implementing a centralized verification mechanism. Data subjects can access their information across multiple platforms through a unified verification process that segments the verification tasks and assigns them to appropriate data holders, resolving the contradiction between distributed storage and centralized access efficiency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification system that mediates between data subjects and multiple data holders. This intermediary coordinates the verification process across different platforms and locations, enabling efficient access to distributed data without requiring the data subject to interact with each platform separately, thus reducing processing time while maintaining storage versatility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If verification processes require additional information from data subjects, then verification accuracy is improved, but the complexity and time required for verification increase

Engineering Contradiction:
Improveverification accuracyVSAvoidverification process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing verification criteria and acceptable information formats before the actual verification process. Data subjects are provided with guidance on what information is needed in advance, allowing them to prepare appropriate verification data, which reduces the complexity of the interaction while maintaining high verification accuracy through pre-defined standards

Inventive Principle:
Principle #10Preliminary action

3Productivity

If comprehensive personal data is collected and stored, then data subject access request fulfillment capability is improved, but security risks and compliance requirements increase

Engineering Contradiction:
Improverequest fulfillment capabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a self-service verification system where data subjects autonomously provide verification information and initiate access requests. This reduces the need for manual processing and minimizes human intervention points that could introduce security risks, while the system automatically fulfills compliant requests, maintaining high fulfillment capability with reduced security exposure

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11210420B2Data subject access request processing systems and related methods
Publication Date: 2021.12.28 ONETRUST LLC
  • US11210420B2 patent drawing
  • US11210420B2 patent drawing
  • US11210420B2 patent drawing

AI summary

In particular embodiments, a computer-implemented data processing method for responding to a data subject access request comprises: (A) receiving a data subject access request from a requestor comprising one or more request parameters; (B) determining that the data subject is associated with a particular geographic location; (C) verifying that the data subject is associated with the particular geographic location; (D) in response to verifying that the data subject is associated with the particular geographic location, processing the request by identifying one or more pieces of personal data associated with the data subject; and (E) taking one or more actions based at least in part on the data subject access request, the one or more actions including one or more actions related to the one or more pieces of personal data.