Policy Engine for Automated Personal Data Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently and compliantly handling requests for personal data storage and retrieval, particularly in adhering to data privacy laws, which require precise and automated management of data across multiple database objects and jurisdictions.

Innovation Solution

Implementing a policy-based system that uses policy identifiers to retrieve and apply specific data fields from multiple database objects, allowing for automated compliance with data privacy laws by defining and managing policies for data retrieval and storage, including automatic policy selection based on jurisdiction and risk tolerance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual data retrieval and management is used to handle personal data requests, then flexibility in handling individual cases is maintained, but compliance efficiency and consistency deteriorate due to the complexity and volume of data privacy laws across multiple jurisdictions

Engineering Contradiction:
Improvecompliance efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables automated self-service for compliance with data privacy laws. The policy engine automatically retrieves personal data from database objects and formats it according to applicable privacy laws without requiring manual intervention. The system self-manages the complex task of identifying applicable laws, selecting relevant data fields, and generating compliant responses, thereby improving productivity while managing complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A policy engine acts as an intermediary between the database system and data privacy law requirements. The policy engine receives requests for personal data, determines which privacy laws apply, identifies relevant database objects and fields, and generates compliant responses. This intermediary layer simplifies the overall system by centralizing the complex compliance logic and providing a standardized interface for handling diverse legal requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data retrieval is performed to ensure all possible personal data is included, then completeness of data provision is improved, but data security and privacy risk worsen due to potential exposure of sensitive information

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidprivacy risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by retrieving different sets of data fields based on the specific privacy law requirements and the context of each request. Rather than retrieving all possible data uniformly, the policy engine selectively retrieves only the data fields necessary for compliance with the applicable law. This approach ensures completeness of required data while minimizing exposure of unnecessary sensitive information, thereby reducing privacy risk.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial action by retrieving only the specific data fields needed for compliance rather than all available data. The policy engine analyzes the request and applicable laws to determine the minimum necessary data set, retrieving exactly what is required without excess. This prevents over-collection and potential exposure of sensitive information while still meeting compliance requirements.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If multiple database objects are queried to ensure all personal data is retrieved, then data completeness is improved, but operational overhead and processing time worsen

Engineering Contradiction:
Improvedata completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-defining policies that map privacy law requirements to specific database objects and fields. Before handling actual data requests, the policies are configured to identify which database objects contain relevant personal data for each type of request. When a request arrives, the pre-configured policies enable rapid retrieval from the correct sources without requiring time-consuming analysis of multiple database objects, thus maintaining completeness while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the data retrieval process by dividing it into distinct components: policy definition, database object identification, field selection, and data formatting. Each segment is handled independently and efficiently. The policy engine segments the query process to target only the specific database objects and fields relevant to the request, avoiding unnecessary queries to unrelated data sources. This segmentation reduces processing time while ensuring all necessary data is retrieved.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11907396B2Using policies to comply with a request from a person for data that pertains to a person
Publication Date: 2024.02.20 SALESFORCE INC
  • US11907396B2 patent drawing
  • US11907396B2 patent drawing
  • US11907396B2 patent drawing

AI summary

Described are methods and systems for using policies to comply with a person's request for data pertaining to the person, pursuant to applicable data privacy laws. A policy is retrieved responsive to receiving a query that includes data to identify records that store data pertaining to the person. The policy indicates first and second database objects, and respective first and second sets of fields, which store data that pertains to persons. The policy is applied. Applying the policy includes retrieving, as first values, data stored in the first set of fields of a first record associated with the data in the query, and retrieving, as second values, data stored in the second set of fields of a second record associated with the first record. The first and second values, and the names of the fields from which they were retrieved, are stored in a document.