Orphaned Data Identification System for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inadequate for timely compliance with data subject access requests, particularly for large corporations that store data across multiple platforms, leading to challenges in identifying and removing personal data not associated with active privacy campaigns.

Innovation Solution

A computer-implemented method that accesses and scans data assets to generate a catalog of privacy campaigns and personal information, identifies data not associated with these campaigns, and automatically removes or flags it for deletion, ensuring compliance with data protection regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual identification and removal of orphaned personal data is performed, then data accuracy and compliance precision are improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvecompliance precisionVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically scanning data assets, comparing them against the privacy campaign catalog, identifying orphaned personal data, and removing them without human intervention. The processor executes the complete workflow autonomously, from data discovery to compliance enforcement, eliminating manual labor while maintaining high precision through systematic algorithmic comparison

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical operations with automated computational processes. Instead of human operators manually searching through data assets to identify orphaned personal data, the system uses processors to scan, compare, and identify data automatically. This substitution of mechanical human labor with computational mechanisms dramatically reduces time consumption while preserving compliance precision

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive scanning of all data assets is performed to identify orphaned personal data, then identification completeness is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improveidentification completenessVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the comprehensive data asset scanning task into manageable components: first generating a catalog of privacy campaigns, then scanning data assets to identify personal data, and finally comparing the two sets to identify orphaned data. This segmentation allows the system to achieve complete identification without overwhelming complexity, as each segment handles a specific aspect of the overall task

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by first generating a comprehensive catalog of privacy campaigns and their associated personal data before conducting the identification process. This pre-prepared catalog serves as a reference framework that simplifies the subsequent scanning and comparison operations, enabling complete identification without requiring complex real-time analysis

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated removal of orphaned personal data is implemented, then productivity and compliance speed are improved, but risk of erroneous deletion increases

Engineering Contradiction:
Improvecompliance speedVSAvoiddeletion accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback by continuously comparing identified orphaned personal data against the privacy campaign catalog and compliance criteria before execution of deletion. The processor verifies each identified data item against multiple conditions, ensuring it truly is orphaned (not associated with any active privacy campaign) before removal. This feedback mechanism maintains high reliability by preventing erroneous deletion while preserving automated productivity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary verification and validation actions before actual data deletion occurs. The identification process includes multiple comparison steps against the privacy campaign catalog, ensuring that only confirmed orphaned data is marked for removal. This preliminary action layer protects against erroneous deletion while maintaining the speed benefits of automation

Inventive Principle:
Principle #10Preliminary action

4Quantity of substance

If multiple data assets across different platforms are scanned, then data coverage and compliance thoroughness are improved, but operational complexity and resource requirements increase

Engineering Contradiction:
Improvedata coverageVSAvoidoperational complexity
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The system achieves universality by designing a single automated processing framework that can scan and analyze multiple types of data assets across different platforms simultaneously. The processor executes the same identification logic regardless of the data asset type or platform, making the system adaptable to diverse data environments without requiring separate manual processes for each platform, thereby reducing operational complexity while maintaining comprehensive coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10586075B2Data processing systems for orphaned data identification and deletion and related methods
Publication Date: 2020.03.10 ONETRUST LLC
  • US10586075B2 patent drawing
  • US10586075B2 patent drawing
  • US10586075B2 patent drawing

AI summary

In particular embodiments, an Orphaned Data Action System is configured to analyze one or more data systems (e.g., data assets), identify one or more pieces of personal data that are one or more pieces of personal data that are not associated with one or more privacy campaigns of the particular organization, and notify one or more individuals of the particular organization of the one or more pieces of personal data that are one or more pieces of personal data that are not associated with one or more privacy campaigns of the particular organization.