Data processing systems for measuring privacy maturity within an organization
First Claim
1. A computer-implemented data processing method for measuring a particular organization'"'"'s compliance with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:
- determining, by one or more processors, for each of the one or more pieces of computer code, one or more respective storage locations;
electronically obtaining, by one or more processors, each of the one or more pieces of computer code based on the one or more respective storage locations;
automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of privacy campaign data that the computer code collects or accesses;
retrieving, by one or more processors, for at least one individual associated with the particular organization, privacy training data comprising an amount of privacy training received by the at least one individual;
determining, by one or more processors, based at least in part on the one or more types of privacy campaign data that the computer code collects or accesses and the privacy training data, a privacy maturity score for the particular organization; and
displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device.
2 Assignments
0 Petitions
Accused Products
Abstract
A privacy compliance measurement system, according to particular embodiments, is configured to determine compliance with one or more privacy compliance requirements by an organization or sub-group of the organization. In various embodiments, the system is configured to determine a privacy maturity rating for each of a plurality of sub-groups within an organization. In some embodiments, the privacy maturity rating is based at least in part on: (1) a frequency of risks or issues identified with Privacy Impact Assessments (PIAs) performed or completed by the one or sub-groups; (2) a relative training level of members of the sub-groups with regard to privacy related matters; (3) a breadth and amount of personal data collected by the sub-groups; and/or (4) etc. In various embodiments, the system is configured to automatically modify one or more privacy campaigns based on the determined privacy maturity ratings.
940 Citations
20 Claims
-
1. A computer-implemented data processing method for measuring a particular organization'"'"'s compliance with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:
-
determining, by one or more processors, for each of the one or more pieces of computer code, one or more respective storage locations; electronically obtaining, by one or more processors, each of the one or more pieces of computer code based on the one or more respective storage locations; automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of privacy campaign data that the computer code collects or accesses; retrieving, by one or more processors, for at least one individual associated with the particular organization, privacy training data comprising an amount of privacy training received by the at least one individual; determining, by one or more processors, based at least in part on the one or more types of privacy campaign data that the computer code collects or accesses and the privacy training data, a privacy maturity score for the particular organization; and displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A non-transitory computer-readable medium storing computer-executable instructions for determining a privacy maturity of a business unit associated with an organization, the non-transitory computer-readable medium storing computer-executable instructions for:
-
electronically obtaining, by one or more processors, one or more pieces of computer code associated with the business unit; automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of personal data that the computer code collects or accesses; in response to determining that the computer code has a particular one of the one or more privacy-related attributes, executing the steps of (i) electronically displaying one or more prompts to a first individual from the business unit requesting that the first individual input information regarding the particular privacy-related attribute;
(ii) receiving information regarding the particular privacy-related attribute from the first individual; and
(iii) communicating the information regarding the particular privacy-related attribute to one or more second individuals from the business unit for use in conducting one or more privacy assessments of the computer code;accessing, by one or more processors, training data associated with one or more individuals from the business unit; determining, by one or more processors, based at least in part on the one or more types of personal data that the computer code collects or accesses and the training data, a privacy maturity score for the business unit indicating compliance of the business unit with one or more privacy-related requirements; and displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device. - View Dependent Claims (8, 9, 10, 11, 12, 13)
-
-
14. A computer-implemented data processing method for measuring a particular organization'"'"'s compliance with one or more requirements associated with one or more pieces of computer code originating from the particular organization, the method comprising:
-
determining, by one or more processors, for each of the one or more pieces of computer code, one or more respective storage locations; electronically obtaining, by one or more processors, each of the one or more pieces of computer code based on the one or more respective storage locations; automatically electronically analyzing each of the one or more pieces of computer code to determine one or more privacy-related attributes of each of the one or more pieces of computer code, each of the privacy-related attributes indicating one or more types of privacy campaign data that the computer code collects or accesses, the one or more types of privacy campaign data comprising at least one type of privacy campaign data selected from the group consisting of; a number of privacy campaigns facilitated by the one or more pieces of computer code; an amount of personal data collected by each of the one or more pieces of computer code; a type of the personal data collected by each of the one or more pieces of computer code; and a volume of the personal data transferred by the one or more pieces of computer code; retrieving, by one or more processors, one or more privacy impact assessments of the one or more pieces computer coded submitted by the particular organization; and determining, by one or more processors, based at least in part on the one or more types of privacy campaign data that the computer code collects or accesses and the one or more privacy impact assessments of the one or more pieces computer coded submitted by the particular organization, a privacy maturity score for the particular organization; and displaying, by one or more processors, the privacy maturity score on a display screen associated with a computing device. - View Dependent Claims (15, 16, 17, 18, 19, 20)
-
Specification