Systems and methods for managing data incidents
First Claim
1. A method for managing a data incident, comprising:
- receiving, via a risk assessment server, in response to an occurrence of the data incident, data incident data that comprises information corresponding to the data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment;
automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the data incident is reportable from a comparison of the data incident data to privacy rules, the privacy rules comprising at least one European General Data Privacy Regulation (GDPR) rule, each rule defining requirements associated with data incident notification obligations;
generating a risk assessment guidance interface when the comparison indicates that the data incident violates at least one of the privacy rules;
wherein the risk assessment guidance interface comprises an impact summary that indicates which of the privacy rules was violated and one or more entities implicated or impacted in the data incident; and
wherein the receiving data incident data further comprises;
providing, in response to a determination of a violation of at least one of the privacy rules, one or more questions to a display device that elicits information corresponding to the data incident, the one or more questions tailored to specific criteria of the at least one of the privacy rules; and
receiving responses to the one or more questions; and
generating a notification schedule when the comparison indicates that the data incident violates and triggers a notification obligation according to the at least one European General Data Privacy Regulation (GDPR) rule; and
wherein the notification schedule comprises notification dates that are based upon a violated European General Data Privacy Regulation (GDPR) rule, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.
4 Assignments
0 Petitions
Accused Products
Abstract
According to some exemplary embodiments, the present technology is directed to methods for managing a data incident, including receiving, via a risk assessment server, in response to an occurrence of the data incident, data incident data that comprises information corresponding to the data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment, automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the data incident is reportable from a comparison of the data incident data to privacy rules, the privacy rules comprising at least one European General Data Privacy Regulation (GDPR) rule, each rule defining requirements associated with data incident notification obligations, and providing, via the risk assessment server, the risk assessment to a display device that selectively couples with the risk assessment server.
84 Citations
19 Claims
-
1. A method for managing a data incident, comprising:
-
receiving, via a risk assessment server, in response to an occurrence of the data incident, data incident data that comprises information corresponding to the data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data or personally identifiable information to an untrusted or unauthorized environment; automatically generating, via the risk assessment server, a risk assessment and decision-support guidance whether the data incident is reportable from a comparison of the data incident data to privacy rules, the privacy rules comprising at least one European General Data Privacy Regulation (GDPR) rule, each rule defining requirements associated with data incident notification obligations; generating a risk assessment guidance interface when the comparison indicates that the data incident violates at least one of the privacy rules; wherein the risk assessment guidance interface comprises an impact summary that indicates which of the privacy rules was violated and one or more entities implicated or impacted in the data incident; and
wherein the receiving data incident data further comprises;
providing, in response to a determination of a violation of at least one of the privacy rules, one or more questions to a display device that elicits information corresponding to the data incident, the one or more questions tailored to specific criteria of the at least one of the privacy rules; and
receiving responses to the one or more questions; andgenerating a notification schedule when the comparison indicates that the data incident violates and triggers a notification obligation according to the at least one European General Data Privacy Regulation (GDPR) rule; and
wherein the notification schedule comprises notification dates that are based upon a violated European General Data Privacy Regulation (GDPR) rule, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.- View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A risk assessment server for managing a data incident, the server comprising:
-
a memory for storing executable instructions; a processor for executing the instructions; input circuitry stored in memory and executable by the processor to receive in response to an occurrence of the data incident, data incident data, the data incident data comprising information corresponding to the data incident, the data incident further comprising intentional or unintentional compromise, disclosure or release of personal data, personally identifiable information, or protected health information to an untrusted or unauthorized environment; risk assessment circuitry stored in memory and executable by the processor to generate a risk assessment from a comparison of the data incident data to privacy rules, the privacy rules comprising at least one European General Data Privacy Regulation (GDPR) rule, each of the rules defining requirements associated with data incident notification laws; user interface circuitry stored in memory and executable by the processor to provide the risk assessment to a display device that selectively couples with the risk assessment server; and
wherein the receiving data incident data further comprises;
providing, in response to a determination of at least one of the privacy rules, one or more questions to the display device that elicits information corresponding to the data incident, the one or more questions tailored to specific criteria of the at least one of the privacy rules; and
receiving responses to the one or more questions;notification circuitry stored in memory and executable by the processor to generate a notification schedule when the comparison indicates that the data incident violates and triggers a notification obligation according to the at least one European General Data Privacy Regulation (GDPR) rule; and
wherein the notification schedule comprises notification dates that are based upon a violated European General Data Privacy Regulation (GDPR) rule, along with notification requirements that describe information that is to be provided to a regulatory agency or to an affected individual whose personal data has been compromised, disclosed or released as a result of the data incident.- View Dependent Claims (15, 16, 17, 18, 19)
-
Specification