Identity Validation for Data Subject Access Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods for managing and responding to data subject access requests, particularly in validating the identity of requestors and efficiently processing personal data, which is crucial for compliance with privacy and security policies.

Innovation Solution

A computer-implemented data processing method that receives and validates data subject access requests by identifying requestors through third-party data aggregation systems, confirming their identity, and taking appropriate actions related to personal data, including deletion, using intelligent identity scanning and data model generation and population techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity verification methods are used for data subject access requests, then the process is simpler to implement, but security against unauthorized access is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoididentity validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces third-party data aggregation systems as intermediaries between the requestor and the organization's data systems. These intermediaries verify the requestor's identity by checking against external data sources (credit bureaus, social media, public records) before granting access to personal data, thereby enhancing security without requiring the organization to build complex verification infrastructure from scratch

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary identity validation actions before the actual data access request is processed. By pre-verifying the requestor's identity through multiple data aggregation points and cross-referencing personal information, the system ensures that only authenticated individuals can access their own data or initiate data subject access requests

Inventive Principle:
Principle #10Preliminary action

2Productivity

If manual processing methods are used for data subject access requests, then system complexity is reduced, but processing efficiency and speed are insufficient

Engineering Contradiction:
Improverequest processing efficiencyVSAvoiddata processing system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements automated self-service mechanisms where the system automatically retrieves personal data from multiple internal and external sources, validates the requestor's identity through algorithmic cross-referencing, and processes data subject access requests without human intervention. The system serves itself by autonomously completing the entire workflow from verification to data delivery

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system merges multiple data aggregation functions, identity verification processes, and data retrieval operations into a single integrated automated workflow. By combining these previously separate manual processes into one unified system, the patent achieves high processing efficiency while managing complexity through systematic integration

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If comprehensive personal data is collected for identity validation, then validation accuracy is improved, but privacy risks and data exposure increase

Engineering Contradiction:
Improveidentity validation accuracyVSAvoidprivacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by collecting and processing different types of personal data at different stages of the verification process. Sensitive information is only accessed and processed after initial verification steps confirm the requestor's legitimate interest, thereby reducing unnecessary exposure of sensitive data while maintaining validation accuracy

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Third-party data aggregation systems serve as privacy-protecting intermediaries that handle the collection and processing of sensitive personal data. These intermediaries mask and secure the data during verification, allowing accurate identity validation without requiring the organization to directly handle or store sensitive personal information

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10705801B2Data processing systems for identity validation of data subject access requests and related methods
Publication Date: 2020.07.07 ONETRUST LLC
  • US10705801B2 patent drawing
  • US10705801B2 patent drawing
  • US10705801B2 patent drawing

AI summary

In particular embodiments, a computer-implemented data processing method for responding to a data subject access request comprises: (A) receiving a data subject access request from a requestor comprising one or more request parameters; (B) validating an identity of the requestor by prompting the requestor to identify information associated with the requestor; (C) in response to validating the identity of the requestor, processing the request by identifying one or more pieces of personal data associated with the requestor, the one or more pieces of personal data being stored in one or more data repositories associated with a particular organization; and (D) taking one or more actions based at least in part on the data subject access request, the one or more actions including one or more actions related to the one or more pieces of personal data.