Data processing systems for measuring privacy maturity within an organization
First Claim
1. A computer-implemented data processing method for measuring compliance of a particular organization with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:
- electronically obtaining, by one or more processors, each of the one or more pieces of computer code from one or more websites associated with the particular organization;
automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of personal data collected or accessed by the computer code;
in response to determining that the computer code has a particular attribute of the one or more privacy-related attributes, executing the steps of (i) electronically displaying one or more prompts to a first individual associated with the organization requesting that the first individual input additional information describing the particular privacy-related attribute;
(ii) receiving the additional information describing the particular privacy-related attribute from the first individual; and
(iii) communicating the additional information describing the particular privacy-related attribute to one or more second individuals associated with the organization for use in conducting a privacy assessment of the computer code;
scanning one or more publicly-available data sources for one or more pieces of credit data corresponding to the particular organization, one or more social networking websites associated with the particular organization and one or more privacy notices for the particular organization comprising one or more privacy disclaimers corresponding to the one or more websites, wherein the one or more pieces of credit data are obtained from accessing one or more credit bureau databases;
calculating, by one or more processors, based at least in part on the one or more types of personal data collected or accessed by the computer code, the one or more pieces of credit data, one or more social networking websites and the one or more privacy notices, a privacy maturity score for the particular organization indicating compliance of the organization with one or more privacy-related requirements; and
displaying, by one or more processors, the privacy maturity score for the particular organization on a display screen associated with a computing device.
2 Assignments
0 Petitions
Accused Products
Abstract
A privacy compliance measurement system, according to particular embodiments, is configured to determine compliance with one or more privacy compliance requirements by an organization or sub-group of the organization. In various embodiments, the system is configured to determine a privacy maturity rating for each of a plurality of sub-groups within an organization. In some embodiments, the privacy maturity rating is based at least in part on: (1) a frequency of risks or issues identified with Privacy Impact Assessments (PIAs) performed or completed by the one or sub-groups; (2) a relative training level of members of the sub-groups with regard to privacy related matters; (3) a breadth and amount of personal data collected by the sub-groups; and/or (4) etc. In various embodiments, the system is configured to automatically modify one or more privacy campaigns based on the determined privacy maturity ratings.
-
Citations
15 Claims
-
1. A computer-implemented data processing method for measuring compliance of a particular organization with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:
-
electronically obtaining, by one or more processors, each of the one or more pieces of computer code from one or more websites associated with the particular organization; automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of personal data collected or accessed by the computer code; in response to determining that the computer code has a particular attribute of the one or more privacy-related attributes, executing the steps of (i) electronically displaying one or more prompts to a first individual associated with the organization requesting that the first individual input additional information describing the particular privacy-related attribute;
(ii) receiving the additional information describing the particular privacy-related attribute from the first individual; and
(iii) communicating the additional information describing the particular privacy-related attribute to one or more second individuals associated with the organization for use in conducting a privacy assessment of the computer code;scanning one or more publicly-available data sources for one or more pieces of credit data corresponding to the particular organization, one or more social networking websites associated with the particular organization and one or more privacy notices for the particular organization comprising one or more privacy disclaimers corresponding to the one or more websites, wherein the one or more pieces of credit data are obtained from accessing one or more credit bureau databases; calculating, by one or more processors, based at least in part on the one or more types of personal data collected or accessed by the computer code, the one or more pieces of credit data, one or more social networking websites and the one or more privacy notices, a privacy maturity score for the particular organization indicating compliance of the organization with one or more privacy-related requirements; and displaying, by one or more processors, the privacy maturity score for the particular organization on a display screen associated with a computing device. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A non-transitory computer-readable medium storing computer-executable instructions for determining a privacy maturity of a plurality of individuals associated with an organization, the non-transitory computer-readable medium storing computer-executable instructions for:
-
electronically obtaining, by one or more processors, one or more pieces of computer code from one or more websites associated with the plurality of individuals; automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of personal data collected or accessed by the computer code; in response to determining that the computer code has a particular attribute of the one or more privacy-related attributes, executing the steps of (i) electronically displaying one or more prompts to a first individual of the plurality of individuals requesting that the first individual input additional information describing the particular privacy-related attribute;
(ii) receiving the additional information describing the particular privacy-related attribute from the first individual; and
(iii) communicating the additional information describing the particular privacy-related attribute to one or more second individuals of the plurality of individuals for use in conducting a privacy assessment of the computer code;analyzing, by one or more processors, for at least one of the plurality of individuals, pieces of publicly available data associated with the at least one of the plurality of individuals, the pieces of publicly available data comprising one or more public record databases comprising one or more social network websites, one or more pieces of credit data corresponding to an organization to which the plurality of individuals belong, and one or more privacy notices for the particular organization comprising one or more privacy disclaimers corresponding to the one or more websites associated with the plurality of individuals, wherein the one or more pieces of credit data are obtained from accessing one or more credit bureau databases; calculating, by one or more processors, based at least in part on the one or more types of personal data collected or accessed by the computer code and the pieces of publicly available data comprising the one or more pieces of credit data and the one or more privacy notices, a privacy maturity score for the plurality of individuals indicating compliance of the plurality of individuals with one or more privacy-related requirements; and displaying, by one or more processors, the privacy maturity score for the plurality of individuals on a display screen associated with a computing device. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A data processing system for determining a privacy maturity of a plurality of individuals, the system comprising:
-
one or more computer processors; computer memory operatively coupled to the computer processor, wherein the data processing system comprises; means for electronically obtaining one or more pieces of computer code from the one or more websites associated with the plurality of individuals; means for automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of personal data collected or accessed by the computer code; means for, in response to determining that the computer code has a particular attribute of the one or more privacy-related attributes, executing the steps of (i) electronically displaying one or more prompts to a first individual of the plurality of individuals requesting that the first individual input additional information describing the particular privacy-related attribute;
(ii) receiving the additional information describing the particular privacy-related attribute from the first individual; and
(iii) communicating the additional information describing the particular privacy-related attribute to one or more second individuals of the plurality of individuals for use in conducting a privacy assessment of the computer code;means for analyzing, for at least one of the plurality of individuals, pieces of publicly available data associated with the at least one of the plurality of individuals, the pieces of publicly available data comprising one or more public record databases comprising one or more social network websites, one or more pieces of credit data corresponding to an organization to which the plurality of individuals belong, and one or more privacy notices for the particular organization comprising one or more privacy disclaimers corresponding to the one or more websites associated with the plurality of individuals, wherein the one or more pieces of credit data are obtained from accessing one or more credit bureau databases; means for calculating, based at least in part on the one or more types of personal data collected or accessed by the computer code and the pieces of publicly available data comprising the one or more pieces of credit data and the one or more privacy notices, a privacy maturity score for the plurality of individuals indicating compliance of the plurality of individuals with one or more privacy-related requirements; and means for displaying the privacy maturity score for the plurality of individuals on a display screen associated with a computing device.
-
Specification