Local Storage Nodes for Data Subject Access Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently managing and processing personal data to comply with privacy and security policies, particularly in responding to data subject access requests and minimizing data exposure across jurisdictions.

Innovation Solution

A system that utilizes local storage nodes based on geographic location to process data subject access requests, generating a graphical user interface to facilitate user interaction for data access, archiving, and deletion, while ensuring compliance with legal and industry standards by routing requests through servers within the same geographic location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal data is processed and stored in a centralized manner to enable efficient access and management, then data processing efficiency and user access capability are improved, but data security risk and compliance complexity across jurisdictions increase

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments personal data storage and processing across multiple geographic locations using local storage nodes. Each node stores data locally while maintaining synchronization with other nodes, thereby distributing security risks and improving compliance with local data sovereignty laws while preserving efficient access through the distributed architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If data is stored and processed in multiple geographic locations to comply with data sovereignty laws, then compliance with privacy regulations is improved, but system complexity and data synchronization difficulty increase

Engineering Contradiction:
Improvecompliance with data sovereignty lawsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a synchronization mechanism that acts as an intermediary between distributed local storage nodes. This mediator coordinates data updates and ensures consistency across geographic locations, simplifying the complexity of maintaining synchronized data while complying with data sovereignty requirements in each jurisdiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If data subject access requests are processed through centralized servers, then processing speed is improved, but cross-jurisdictional data transfers and associated compliance risks increase

Engineering Contradiction:
Improverequest processing speedVSAvoidcross-jurisdictional data transfer risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent enables local storage nodes to process data subject access requests independently within their own geographic jurisdictions. This local processing capability eliminates the need to transfer personal data across borders for request fulfillment, thereby maintaining fast processing speeds while avoiding cross-jurisdictional data transfer risks and compliance issues.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11328092B2Data processing systems for processing and managing data subject access in a distributed environment
Publication Date: 2022.05.10 ONETRUST LLC
  • US11328092B2 patent drawing
  • US11328092B2 patent drawing
  • US11328092B2 patent drawing

AI summary

In particular embodiments, a data subject request processing system may be configured to utilize one or more local storage nodes in order to process a data subject access request on behalf of a data subject. In particular embodiments, the one or more local storage nodes may be local to the data subject making the request (e.g., in the same country as the data subject, in the same jurisdiction, in the same geographic area, etc.). The system may, for example, be configured to: (1) receive a data subject access request from a data subject (e.g., via a web form); (2) identify a suitable local storage node based at least in part on the request and/or the data subject; (3) route the data subject access request to the identified local storage node; and (4) process the data subject access request at the identified local storage node.