Customized Privacy Training System for Vendor Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in ensuring compliance with privacy policies and regulations due to limited control over vendors and incomplete or incorrect information provided to avoid audits, leading to a need for improved systems to monitor compliance and assess vendor risk effectively.

Innovation Solution

A system and method for generating customized training content and assessing vendor risk, involving a risk management system that establishes communication sessions, updates role attributes, and generates training content based on trainee parameters, contextual information, and source content customization, while providing access through a graphical user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations implement privacy impact assessments and data protection risk assessments, then compliance with privacy regulations is improved, but the complexity of monitoring and assessing vendor risk increases

Engineering Contradiction:
Improvecompliance with privacy regulationsVSAvoidcomplexity of monitoring and assessing vendor risk
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments vendor risk assessment into multiple components including privacy policy analysis, data processing activities evaluation, and compliance monitoring. This segmentation allows organizations to systematically assess different aspects of vendor compliance without being overwhelmed by the overall complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that acts as a mediator between organizations and vendors for privacy compliance monitoring. This intermediary automatically collects vendor information, performs risk assessments, and provides compliance reports, thereby reducing the direct complexity burden on organizations while maintaining reliable compliance monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations conduct frequent privacy audits and risk assessments, then compliance reliability is improved, but the time and resources required increase

Engineering Contradiction:
Improvecompliance monitoring effectivenessVSAvoidtime required for audits and assessments
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing vendor privacy policies and data processing information before formal audits are needed. This preliminary monitoring prepares compliance data in advance, making actual audit processes faster and more efficient while maintaining high compliance reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring of vendor privacy compliance rather than periodic discrete audits. This continuous action maintains up-to-date compliance information without requiring repeated time-intensive audit processes, as the system continuously tracks changes in vendor policies and practices.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If organizations require complete and accurate information from vendors, then assessment precision is improved, but vendors may provide incomplete information to avoid audits

Engineering Contradiction:
Improveaccuracy of vendor risk assessmentVSAvoidincomplete or incorrect information provided by vendors
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback mechanisms where vendors receive automated notifications and reminders to update their privacy policy information and data processing activities. This feedback loop encourages vendors to provide complete and accurate information by showing them the direct connection between their responses and their compliance status, reducing the incentive to provide incomplete information.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables vendors to self-report and update their privacy compliance information directly through the system. This self-service approach allows vendors to maintain their own compliance profiles, reducing the need for intrusive audits while ensuring information accuracy through vendor-owned data entry and verification.

Inventive Principle:
Principle #25Self-service

4Reliability

If organizations implement comprehensive vendor risk assessment systems, then compliance reliability is improved, but the cost and resource requirements increase

Engineering Contradiction:
Improvevendor compliance assuranceVSAvoidresources required for implementation
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system requires vendors to self-report their privacy policies and data processing activities, eliminating the need for expensive external audit firms. Vendors maintain their own compliance profiles in the system, reducing organizational resource requirements while maintaining comprehensive compliance monitoring through automated verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent utilizes automated copying and analysis of vendor-provided privacy policy documents and data processing information. Instead of manual review requiring expensive human resources, the system automatically copies vendor submissions, analyzes them against compliance criteria, and generates assessment reports, significantly reducing implementation and maintenance costs.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20220245539A1Data processing systems and methods for customizing privacy training
Publication Date: 2022.08.04 ONETRUST LLC
  • US20220245539A1 patent drawing
  • US20220245539A1 patent drawing
  • US20220245539A1 patent drawing

AI summary

Data processing systems and methods, according to various embodiments, are adapted for performing a process of procuring a vendor and sub-processes associated therewith, such as performing vendor risk assessments and providing training specific to the procurement of that particular vendor. Training requirements for the user procuring the vendor and/or for the vendor itself are determined and any deficiencies in current, valid training requirements are identified. Training to address any identified deficiencies is provided as part of the vendor procurement process. Training may be customized based on trainee and/or organization attributes to improve the effectiveness of such training.