Data processing systems for the identification and deletion of personal data in computer systems
First Claim
Patent Images
1. A personal data processing and deletion system comprising;
- one or more processors;
one or more data assets that store a plurality of personal data associated with a plurality of data subjects, each piece of the plurality of personal data being associated with a respective particular processing activity of a plurality of processing activities undertaken by a particular organization; and
computer memory, wherein;
the computer memory stores one or more data models defining one or more data transfers among the one or more data assets; and
the data processing and deletion system is configured for;
receiving, from a first data subject on a remote computing device, a first data subject request that is a request for the particular organization to delete, from the personal data processing and deletion system, one or more pieces of personal data associated with the first data subject that the particular organization has previously obtained on the first data subject;
in response to receiving the first data subject request, identifying, based at least in part on the one or more data models and the plurality of processing activities undertaken by the organization, a respective storage location of each of the one or more pieces of personal data associated with the first data subject on the one or more data assets;
in response to identifying the storage location of each of the one or more pieces of personal data associated with the first data subject, automatically determining that a first portion of the one or more of the pieces of personal data has one or more legal bases for continued storage;
in response to determining that the first portion of the one or more of the pieces of personal data associated with the first data subject has one or more legal bases for continued storage, automatically maintaining storage of the first portion of the one or more pieces of personal data;
automatically facilitating deletion of a second portion of the one or more pieces of personal data associated with the first data subject that do not have one or more legal bases for continued storage, wherein the first portion of the one or more pieces of personal data is different from the second portion of the one or more pieces of personal data; and
automatically marking one or more memory addresses associated with the second portion of the one or more pieces of personal data associated with the first data subject as free.
2 Assignments
0 Petitions
Accused Products
Abstract
In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization'"'"'s systems, the system may: (1) automatically determine where the data subject'"'"'s personal data is stored; and (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject'"'"'s personal data from the various systems (e.g., by automatically assigning a plurality of tasks to delete data across multiple business systems to effectively delete the data subject'"'"'s personal data from the systems).
-
Citations
15 Claims
-
1. A personal data processing and deletion system comprising;
-
one or more processors; one or more data assets that store a plurality of personal data associated with a plurality of data subjects, each piece of the plurality of personal data being associated with a respective particular processing activity of a plurality of processing activities undertaken by a particular organization; and computer memory, wherein; the computer memory stores one or more data models defining one or more data transfers among the one or more data assets; and the data processing and deletion system is configured for; receiving, from a first data subject on a remote computing device, a first data subject request that is a request for the particular organization to delete, from the personal data processing and deletion system, one or more pieces of personal data associated with the first data subject that the particular organization has previously obtained on the first data subject; in response to receiving the first data subject request, identifying, based at least in part on the one or more data models and the plurality of processing activities undertaken by the organization, a respective storage location of each of the one or more pieces of personal data associated with the first data subject on the one or more data assets; in response to identifying the storage location of each of the one or more pieces of personal data associated with the first data subject, automatically determining that a first portion of the one or more of the pieces of personal data has one or more legal bases for continued storage; in response to determining that the first portion of the one or more of the pieces of personal data associated with the first data subject has one or more legal bases for continued storage, automatically maintaining storage of the first portion of the one or more pieces of personal data; automatically facilitating deletion of a second portion of the one or more pieces of personal data associated with the first data subject that do not have one or more legal bases for continued storage, wherein the first portion of the one or more pieces of personal data is different from the second portion of the one or more pieces of personal data; and automatically marking one or more memory addresses associated with the second portion of the one or more pieces of personal data associated with the first data subject as free. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A computer-implemented data processing method for processing a request to delete personal data associated with a data subject from one or more computer systems of a particular organization, the method comprising:
-
receiving, by one or more computer processors, a data subject request from a data subject that is a request for the particular organization to delete, from the personal data processing and deletion system, one or more pieces of personal data associated with the first data subject that the particular organization has previously obtained on the first data subject; and at least partially in response to receiving the data subject request; processing the data subject request by one or more computer processors; automatically identifying, by one or more computer processors, a respective storage location of each of the one or more pieces of personal data associated with the first data subject on the one or more data assets; in response to identifying the storage location of each of the one or, more pieces of personal data associated with the first data subject, automatically determining that a first portion of the one or more of the pieces of personal pieces of personal data has one or more legal bases for continued storage; in response to determining that the first portion of the one or more pieces of personal data associated with the first data subject has one or more legal bases for continued storage, automatically maintaining storage of the first portion of the one or more pieces of personal data; automatically facilitating deletion of a second portion of the one or more pieces of personal data associated with the first data subject that do not have one or more legal bases for continued storage, wherein the first portion of the one or more pieces of personal data is different from the second portion of the one or more pieces of personal data; and automatically marking one or more memory addresses associated with the second portion of the one or more pieces of personal data associated with the first data subject as free. - View Dependent Claims (10, 11, 12, 13)
-
-
14. A computer-implemented data processing method for deleting one or more pieces of personal data in response to a data subject access request, the method comprising:
-
receiving, using one or more electronic receiving means, a data subject access request from a requestor comprising one or more request parameters; processing the request by; accessing a categorized one or more data elements and a data flow, wherein the categorized one or more data elements and the data flow comprises; connecting, by one or more processors, via one or more computer networks to one or more databases; scanning, by one of more processors, the one or more databases to generate a catalog of one or more individuals and one or more pieces of personal information associated with the one or more individuals; storing the catalog in computer memory; scanning one or more data repositories based at least in part on the generated catalog to identify one or more attributes of data associated with the one or more individuals by searching one or more data fields in the one or more databases for the one or more pieces of personal information; analyzing and correlating the one or more attributes and metadata for the scanned one or more data repositories; using one or more machine learning techniques to categorize one or more data elements from the generated catalog; analyzing a data flow of the particular data attributes between the one or more data repositories; and storing the categorized one or more data elements and the data flow in the computer memory; identifying, using the categorized one or more data elements and the data flow, a respective storage location of each of the one or more pieces of personal data associated with the requestor, the one or more pieces of personal data being stored in one or more data repositories associated with a particular organization; determining whether the one or more request parameters comprise a request to delete the one or more pieces of personal data; and in response to determining that the one or more request parameters comprise the request to delete, automatically facilitating the deletion, using one or more data deletion means, the one or more pieces of personal data. - View Dependent Claims (15)
-
Specification