×

Data processing systems and communication systems and methods for the efficient generation of privacy risk assessments

  • US 9,892,444 B2
  • Filed: 06/10/2017
  • Issued: 02/13/2018
  • Est. Priority Date: 04/01/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented data processing method for efficiently conducting privacy risk assessments for a plurality of privacy campaigns, the method comprising, for each of the plurality of privacy campaigns:

  • presenting, by one or more processors, a threshold privacy assessment to a user that includes a first set of one or more questions for a first plurality of question/answer pairings that identify one or more privacy characteristics of a particular privacy campaign;

    receiving, by one or more processors, respective answers for the first plurality of question/answer pairings regarding the one or more privacy characteristics of the particular privacy campaign;

    determining, by one or more processors, a threshold privacy risk score for the particular privacy campaign that identifies a level of risk for one or more of the privacy characteristics indicated in the question/answer pairings, wherein determining the threshold privacy risk score for the particular privacy campaign comprises;

    electronically determining a risk level based at least in part on the one or more privacy characteristics, wherein the one or more privacy characterisitics include an indication of a nature of personal data collected by the particular privacy campaign;

    comparing, by one or more processors, the threshold privacy risk score to a threshold privacy risk value, the threshold privacy risk value indicating a pre-determined level of risk regarding the one or more privacy characteristics of the particular privacy campaign;

    determining, by one or more processors, whether the threshold privacy risk score exceeds the threshold privacy risk value;

    in response to determining that the threshold privacy risk score exceeds the threshold privacy risk value;

    providing, by one or more processors, a privacy impact assessment to the user that includes a second set of questions for a second plurality of question/answer pairings that identify one or more privacy characteristics of the particular privacy campaign, the second set of one or more questions including one or more questions that are different from questions within the first set of one or more questions; and

    determining by one or more processors, a second risk score based at least in part on the second plurality of question answer parings by;

    determining a weighting factor for each of the second plurality of question/answer parings, the second plurality of question/answer parings including;

    an indication of a physical storage location of the personal data collected as part of the particular privacy campaign; and

    an indication of a length of time that the personal data collected as part of the particular privacy campaign will be stored in the physical storage location;

    electronically determining a relative risk rating for each of the second plurality of question/answer pairings;

    electronically calculating the second risk score based upon, for each of the second plurality of question/answer pairings, the relative risk rating and the weighting factor; and

    electrically associating the second risk score with the particular privacy campaign; and

    in response to determining that the privacy risk score does not exceed the threshold privacy risk value, storing, by one or more processors, an indication that the particular privacy campaign is a low privacy risk campaign.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×