×

Data processing systems for fulfilling data subject access requests and related methods

  • US 10,169,609 B1
  • Filed: 08/03/2018
  • Issued: 01/01/2019
  • Est. Priority Date: 06/10/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented data processing method for responding to a data subject access request, the method comprising:

  • receiving, by one or more computer processors, a data subject access request from a requestor comprising one or more request parameters, wherein the one or more request parameters comprise one or more pieces of personal data associated with the requestor;

    validating, by the one or more computer processors, an identity of the requestor based at least in part on the one or more request parameters;

    in response to validating the identity of the requestor, determining, by the one or more computer processors, based on fulfillment constraint data, whether the data subject access request is subject to one or more response fulfillment constraints associated with the requestor, wherein determining whether the data subject access request is subject to one or more response fulfillment constraints comprises determining whether the data subject request comprises one of a threshold quantity of data subject access requests from the requestor within a threshold time period;

    in response to determining that the data subject access request is subject to one or more response fulfillment constraints, notifying, by the one or more computer processors, the requestor that the data subject access request is subject to one or more limitations, and taking at least one action based on the data subject access request and the one or more limitations, wherein the at least one action comprises denying the data subject access request, or requesting one or more processing fees prior to fulfilling the request; and

    in response to determining that the data subject access request is not subject to one or more response fulfillment constraints;

    (1) identifying, by one or more computer processors, the one or more pieces of personal data associated with the requestor, the one or more pieces of personal data being stored in one or more data repositories associated with a particular organization, and(2) data using the one or more pieces of personal data to fulfill the data subject access request; and

    updating the fulfillment constraint data, in computer memory, to reflect that the data subject access request has been made.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×