×

Data processing systems for the identification and deletion of personal data in computer systems

  • US 10,346,637 B2
  • Filed: 08/03/2018
  • Issued: 07/09/2019
  • Est. Priority Date: 06/10/2016
  • Status: Active Grant
First Claim
Patent Images

1. A personal data processing and deletion system comprising;

  • one or more processors;

    one or more data assets that store a plurality of personal data associated with a plurality of data subjects, each piece of the plurality of personal data being associated with a respective particular processing activity of a plurality of processing activities undertaken by a particular organization; and

    computer memory, wherein;

    the computer memory stores one or more data models defining one or more data transfers among the one or more data assets; and

    the data processing and deletion system is configured for;

    receiving, from a first data subject on a remote computing device, a first data subject request that is a request for the particular organization to delete, from the personal data processing and deletion system, one or more pieces of personal data associated with the first data subject that the particular organization has previously obtained on the first data subject;

    in response to receiving the first data subject request, identifying, based at least in part on the one or more data models and the plurality of processing activities undertaken by the organization, a respective storage location of each of the one or more pieces of personal data associated with the first data subject on the one or more data assets;

    in response to identifying the storage location of each of the one or more pieces of personal data associated with the first data subject, automatically determining that a first portion of the one or more of the pieces of personal data has one or more legal bases for continued storage;

    in response to determining that the first portion of the one or more of the pieces of personal data associated with the first data subject has one or more legal bases for continued storage, automatically maintaining storage of the first portion of the one or more pieces of personal data;

    automatically facilitating deletion of a second portion of the one or more pieces of personal data associated with the first data subject that do not have one or more legal bases for continued storage, wherein the first portion of the one or more pieces of personal data is different from the second portion of the one or more pieces of personal data; and

    automatically marking one or more memory addresses associated with the second portion of the one or more pieces of personal data associated with the first data subject as free.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×