Data processing systems for data transfer risk identification and related methods
First Claim
Patent Images
1. A computer-implemented data processing method for assessing a risk associated with one or more data transfers between two or more data assets, the method comprising:
- identifying two or more data assets associated with a particular entity;
analyzing the two or more data assets to identify one or more data elements stored in the identified two or more data assets by using at least one data model to identify the one or more data elements stored in the identified two or more data assets, the at least one data model comprising;
a respective digital inventory for each of the two or more data assets, each respective digital inventory comprising transfer data associated with each respective data asset and one or more inventory attributes selected from the group consisting of;
one or more processing activities associated with each respective data asset; and
one or more pieces of personal data associated with each respective data asset; and
a data map identifying one or more electronic associations between at least two of the two or more data assets; and
defining a plurality of physical locations and identifying, for each of the identified two or more data assets, a respective particular physical location of the plurality of physical locations;
analyzing the identified one or more data elements to determine one or more data transfers between the two or more data assets in different particular physical locations, wherein analyzing the identified one or more data elements to determine the one or more data transfers between the two or more data assets in different particular physical locations comprises analyzing the identified one or more data elements to determine one or more data transfers based at least in part on the transfer data;
creating a data transfer record for a data transfer between a first asset in a first location and a second asset in a second location;
accessing a set of data transfer rules that are associated with the data transfer record;
performing a data transfer assessment based at least in part on applying the set of data transfer rules on the data transfer record;
identifying one or more data transfer risks associated with the data transfer record, based at least in part on the data transfer assessment;
calculating a risk score for the data transfer based at least in part on the one or more data transfer risks associated with the data transfer record;
digitally storing the risk score for the data transfer;
comparing the risk score for the data transfer to a threshold risk score;
determining that the risk score for the data transfer is a greater risk than the threshold risk score; and
in response to determining that the risk score for the data transfer is a greater risk than the threshold risk score, taking one or more actions selected from the group consisting of;
providing the data transfer record to one or more individuals for review of the data transfer record; and
automatically terminating the data transfer.
2 Assignments
0 Petitions
Accused Products
Abstract
In particular embodiments, a Data Transfer Risk Identification System may be configured to analyze one or more data systems (e.g., data assets), identify data transfers between/among those systems, apply data transfer rules to each data transfer record, perform a data transfer assessment on each data transfer record based on the data transfer rules to be applied to each data transfer record, and calculate a risk score for the data transfer based at least in part on the one or more data transfer risks associated with the data transfer record.
932 Citations
15 Claims
-
1. A computer-implemented data processing method for assessing a risk associated with one or more data transfers between two or more data assets, the method comprising:
-
identifying two or more data assets associated with a particular entity; analyzing the two or more data assets to identify one or more data elements stored in the identified two or more data assets by using at least one data model to identify the one or more data elements stored in the identified two or more data assets, the at least one data model comprising; a respective digital inventory for each of the two or more data assets, each respective digital inventory comprising transfer data associated with each respective data asset and one or more inventory attributes selected from the group consisting of; one or more processing activities associated with each respective data asset; and one or more pieces of personal data associated with each respective data asset; and a data map identifying one or more electronic associations between at least two of the two or more data assets; and defining a plurality of physical locations and identifying, for each of the identified two or more data assets, a respective particular physical location of the plurality of physical locations; analyzing the identified one or more data elements to determine one or more data transfers between the two or more data assets in different particular physical locations, wherein analyzing the identified one or more data elements to determine the one or more data transfers between the two or more data assets in different particular physical locations comprises analyzing the identified one or more data elements to determine one or more data transfers based at least in part on the transfer data; creating a data transfer record for a data transfer between a first asset in a first location and a second asset in a second location; accessing a set of data transfer rules that are associated with the data transfer record; performing a data transfer assessment based at least in part on applying the set of data transfer rules on the data transfer record; identifying one or more data transfer risks associated with the data transfer record, based at least in part on the data transfer assessment; calculating a risk score for the data transfer based at least in part on the one or more data transfer risks associated with the data transfer record; digitally storing the risk score for the data transfer; comparing the risk score for the data transfer to a threshold risk score; determining that the risk score for the data transfer is a greater risk than the threshold risk score; and in response to determining that the risk score for the data transfer is a greater risk than the threshold risk score, taking one or more actions selected from the group consisting of; providing the data transfer record to one or more individuals for review of the data transfer record; and automatically terminating the data transfer. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A computer-implemented data processing method for assessing a risk associated with one or more data transfers between two or more data assets, the method comprising:
-
identifying two or more data assets associated with a particular entity; analyzing the two or more data assets to identify one or more data elements stored in the identified two or more data assets by using at least one data model to identify the one or more data elements stored in the identified two or more data assets, the at least one data model comprising; a respective digital inventory for each of the two or more data assets, each respective digital inventory comprising transfer data associated with each respective data asset and one or more inventory attributes selected from the group consisting of; one or more processing activities associated with each respective data asset; and one or more pieces of personal data associated with each respective data asset; and a data map identifying one or more electronic associations between at least two of the two or more data assets; and defining a plurality of physical locations and identifying, for each of the identified two or more data assets, a respective particular physical location of the plurality of physical locations; analyzing the identified one or more data elements to determine one or more data transfers between the two or more data assets in different particular physical locations, wherein analyzing the identified one or more data elements to determine the one or more data transfers between the two or more data assets in different particular physical locations comprises analyzing the identified one or more data elements to determine one or more data transfers based at least in part on the transfer data; accessing a data transfer record for a data transfer between a first asset in a first location and a second asset in a second location; accessing a set of data transfer rules that are associated with the data transfer record, wherein the set of data transfer rules comprise; one or more privacy law frameworks of the one or more of the first location and the second location, and one or more entity frameworks of one or more of (i) an entity associated with the first data asset and (ii) an entity associated with the second data asset; performing a data transfer assessment based at least in part on applying the set of data transfer rules on the data transfer record; identifying one or more data transfer risks associated with the data transfer record, based at least in part on the data transfer assessment; calculating a risk score for the data transfer based at least in part on the one or more data transfer risks associated with the data transfer record; digitally storing the risk score for the data transfer; comparing the risk score for the data transfer to a threshold risk score; determining that the risk score for the data transfer is a greater risk than the threshold risk score; and in response to determining that the risk score for the data transfer is a greater risk than the threshold risk score, taking one or more actions selected from the group consisting of; providing the data transfer record to one or more individuals for review of the data transfer record; and automatically terminating the data transfer. - View Dependent Claims (8, 9, 10, 11)
-
-
12. A computer-implemented data processing method for assessing a risk associated with one or more data transfers between two or more data assets, the method comprising:
-
identifying two or more data assets associated with a particular entity; analyzing the two or more data assets to identify one or more data elements stored in the identified two or more data assets by using at least one data model to identify the one or more data elements stored in the identified two or more data assets, the at least one data model comprising; a respective digital inventory for each of the two or more data assets, each respective digital inventory comprising transfer data associated with each respective data asset and one or more inventory attributes selected from the group consisting of; one or more processing activities associated with each respective data asset; and one or more pieces of personal data associated with each respective data asset; and a data map identifying one or more electronic associations between at least two of the two or more data assets; and defining a plurality of physical locations and identifying, for each of the identified two or more data assets, a respective particular physical location of the plurality of physical locations; analyzing the identified one or more data elements to determine one or more data transfers between the two or more data assets in different particular physical locations, wherein analyzing the identified one or more data elements to determine the one or more data transfers between the two or more data assets in different particular physical locations comprises analyzing the identified one or more data elements to determine one or more data transfers based at least in part on the transfer data, wherein the one or more data transfers comprise a data transfer between; a first asset of the two or more data assets in a first location of the plurality of physical locations; and a second asset of the two or more data assets in a second location of the plurality of physical locations; accessing a data transfer record for the data transfer between the first asset in the first location and the second asset in the second location; accessing a set of data transfer rules that are associated with the data transfer record; performing a data transfer assessment based at least in part on applying the set of data transfer rules on the data transfer record; identifying one or more data transfer risks associated with the data transfer record, based at least in part on the data transfer assessment; calculating a risk score for the data transfer based at least in part on the one or more data transfer risks associated with the data transfer record; digitally storing the risk score for the data transfer; comparing the risk score for the data transfer to a threshold risk score; determining that the risk score for the data transfer is a greater risk than the threshold risk score; and in response to determining that the risk score for the data transfer is a greater risk than the threshold risk score, taking one or more actions selected from the group consisting of; providing the data transfer record to one or more individuals for review of the data transfer record; and automatically terminating the data transfer. - View Dependent Claims (13, 14, 15)
-
Specification