Privacy Management System for Automated Compliance Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods to monitor compliance with privacy policies and ensure proper handling of personal data by organizations and their vendors, leading to potential breaches and incomplete or incorrect information being provided to avoid audits.

Innovation Solution

A computer-implemented data processing method that actively monitors user inputs and context for privacy campaigns, analyzes changes, flags abnormal inputs, and scans vendor webpages to calculate risk scores, facilitating automated actions and incident notifications to ensure compliance and proper data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If automated monitoring and analysis systems are implemented to detect abnormal inputs and ensure privacy compliance, then measurement precision and reliability of compliance monitoring are improved, but device complexity and cost increase

Engineering Contradiction:
Improvecompliance monitoring accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising processors and memory that acts as a mediator between user inputs and compliance assessment outcomes. This intermediary automatically monitors inputs, compares them against privacy policies, and generates compliance assessments without requiring direct human analysis of each input, thereby improving measurement precision while managing system complexity through automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where compliance assessments and risk scores are continuously generated based on monitored inputs and vendor information. This feedback loop enables the system to automatically adjust monitoring focus and provide real-time compliance status, improving measurement precision through iterative validation while maintaining manageable complexity through automated decision-making algorithms.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive vendor information is collected and analyzed to calculate risk scores, then reliability of vendor compliance assessment is improved, but loss of time and processing resources increase

Engineering Contradiction:
Improvevendor compliance assessment reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively collecting and storing vendor information, privacy policies, and compliance criteria before actual compliance assessment is needed. This advance preparation enables rapid risk score calculation when assessments are required, improving reliability through comprehensive data availability while reducing processing time by having analysis-ready information pre-assembled.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates and maintains copies of vendor information, privacy policies, and compliance data in structured formats that can be rapidly accessed and analyzed. By storing multiple copies and versions of critical information in optimized data structures, the system enables fast risk score calculation without requiring time-consuming data retrieval or verification during actual assessments.

Inventive Principle:
Principle #26Copying

3Productivity

If automated flagging and incident notification systems are implemented, then productivity of compliance monitoring is improved, but device complexity increases

Engineering Contradiction:
Improvecompliance monitoring efficiencyVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where the automated monitoring system independently identifies abnormal inputs, flags compliance issues, generates incident notifications, and updates risk scores without requiring manual intervention. This self-service automation improves productivity by continuously monitoring and responding to compliance events while managing complexity through rule-based decision algorithms that operate autonomously.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If detailed analysis of user inputs and context is performed to detect abnormal behavior, then measurement precision of compliance detection is improved, but loss of time for each assessment increases

Engineering Contradiction:
Improveabnormal input detection accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the compliance assessment process into distinct analytical stages: initial input monitoring, context analysis, abnormal behavior detection, and risk score calculation. By dividing the comprehensive analysis into sequential segments, the system can perform detailed measurements at each stage while managing overall assessment time through efficient progression through segments, improving detection precision without excessive time consumption.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11030563B2Privacy management systems and methods
Publication Date: 2021.06.08 ONETRUST LLC
  • US11030563B2 patent drawing
  • US11030563B2 patent drawing
  • US11030563B2 patent drawing

AI summary

Data processing systems and methods, according to various embodiments, are adapted for mapping various questions regarding a data breach from a master questionnaire to a plurality of territory-specific data breach disclosure questionnaires. The answers to the questions in the master questionnaire are used to populate the territory-specific data breach disclosure questionnaires and determine whether disclosure is required in territory. The system can automatically notify the appropriate regulatory bodies for each territory where it is determined that data breach disclosure is required.