-
公开(公告)号:US20230385449A1
公开(公告)日:2023-11-30
申请号:US17867642
申请日:2022-07-18
Applicant: SAP SE
Inventor: Carsten Pluder , Diane Schmidt , Volker Lehnert , Martina Knoedler , Thorsten Bruckmeier , Philipp Alexander Zikesch , Bernhard Drittler , Matthias Vogel , Katrin Ludwig , Naved Ahmed , Saritha Palli , Shweta Sureshchandra Gupta , Arun Kumar Gowd , Dev Karan Ahuja , Shwetha H S
CPC classification number: G06F21/6254 , G06F21/6209 , G06F21/78
Abstract: Systems and processes for managing access to personal data based on a purpose for storing the personal data are provided. In a method for managing personal data access, personal data for a data subject corresponding to a first data category is received, and an operation is executed in a purpose agent to associate one or more purposes to the personal data, where the one or more purposes are assigned to the first data category and include at least a first purpose. The personal data may be stored in a data storage system, and the stored personal data may be designated as being associated with the one or more purposes. Access to the personal data may be controlled based on the one or more purposes.
-
公开(公告)号:US11714828B2
公开(公告)日:2023-08-01
申请号:US17186934
申请日:2021-02-26
Applicant: SAP SE
Inventor: Benny Rolle , Matthias Vogel , Carsten Pluder , Ufuoma Ighoroje , Carlo Fuerst , Iwona Luther
CPC classification number: G06F16/273
Abstract: The present disclosure involves systems, software, and computer implemented methods for aligned purpose disassociation in a multi-system landscape. One example method includes receiving, from multiple systems, a can-disassociate status for a purpose for an object instance. The status from a respective system can be an affirmative status that indicates that the system can disassociate the purpose from the instance or a negative status that indicates that the system cannot disassociate the purpose from the instance. The received statuses are evaluated to determine a central disassociate purpose decision for the purpose for the instance. The central disassociate purpose decision can be to disassociate the purpose from the instance when no system has the negative status and to not disassociate the purpose from the instance when at least one system has the negative status. The central disassociate purpose decision is provided to at least some of the multiple systems.
-
公开(公告)号:US20230177186A1
公开(公告)日:2023-06-08
申请号:US17457797
申请日:2021-12-06
Applicant: SAP SE
Inventor: Ufuoma Ighoroje , Benny Rolle , Matthias Vogel , Carsten Pluder
IPC: G06F21/62 , G06F16/903
CPC classification number: G06F21/6218 , G06F16/90335
Abstract: The present disclosure involves systems, software, and computer implemented methods for integrated data privacy services. An example method includes determining to initiate an integrated end of purpose protocol for an object. An end-of-purpose query is provided to multiple applications that requests each application to determine whether the application is able to block the object. End-of-purpose statuses are received, in response to the end-of-purpose query, that each indicate whether a respective application is able to block the object. The end-of-purpose statuses are evaluated to determine whether an aligned end of purpose has been reached for the object. In response to determining that the aligned end of purpose has been reached for the object, a block command is provided to each application that instructs the application to locally block the object in the application.
-
公开(公告)号:US10409790B2
公开(公告)日:2019-09-10
申请号:US14727838
申请日:2015-06-01
Applicant: SAP SE
Inventor: Volker Lehnert , Carsten Pluder
Abstract: Various embodiments of systems and methods to determine data retention rules for data entities are described herein. In one aspect, the data entities are obtained. Usage statuses of the data entities are determined. One or more purpose of data corresponding to the one or more data entities is received. Further, legal entities corresponding to the one or more data entities are identified based on line organization attributes and the usage statuses. Process object attributes associated with the one or more data entities are identified based on the legal entities. Retention rules for the one or more data entities are determined based on the one or more purpose of data, the legal entities and the process object attributes.
-
公开(公告)号:US20250124160A1
公开(公告)日:2025-04-17
申请号:US18487293
申请日:2023-10-16
Applicant: SAP SE
Inventor: Benny Rolle , Stefan Hesse , Matthias Vogel , Carsten Pluder
IPC: G06F21/62 , H04L41/5074
Abstract: The present disclosure involves systems, software, and computer implemented methods for automating handling of data subject requests for data privacy integration protocols. One example method includes receiving a ticket for performing a data privacy integration protocol for a data subject. A work package that includes a work package parameter that is based on a ticket parameter is provided to responder applications. Processing of the work package by responder applications includes determining, for at least one object associated with the data subject, purposes associated with the object. The responder application determines, for each purpose, a purpose setting that corresponds to the work package parameter. The responder application processes the work package based on the work package parameter and the purpose settings and provides feedback to a data privacy integration service, which processes the feedback, to continue the data privacy integration protocol for the ticket.
-
公开(公告)号:US12072993B2
公开(公告)日:2024-08-27
申请号:US17457797
申请日:2021-12-06
Applicant: SAP SE
Inventor: Ufuoma Ighoroje , Benny Rolle , Matthias Vogel , Carsten Pluder
IPC: G06F21/62 , G06F16/903
CPC classification number: G06F21/6218 , G06F16/90335 , G06F21/629
Abstract: The present disclosure involves systems, software, and computer implemented methods for integrated data privacy services. An example method includes determining to initiate an integrated end of purpose protocol for an object. An end-of-purpose query is provided to multiple applications that requests each application to determine whether the application is able to block the object. End-of-purpose statuses are received, in response to the end-of-purpose query, that each indicate whether a respective application is able to block the object. The end-of-purpose statuses are evaluated to determine whether an aligned end of purpose has been reached for the object. In response to determining that the aligned end of purpose has been reached for the object, a block command is provided to each application that instructs the application to locally block the object in the application.
-
公开(公告)号:US20230185938A1
公开(公告)日:2023-06-15
申请号:US17546351
申请日:2021-12-09
Applicant: SAP SE
Inventor: Diane Schmidt , Carsten Pluder
IPC: G06F21/62
CPC classification number: G06F21/6218
Abstract: Computer-readable media, methods, and systems are disclosed for providing purpose-based processing of data. A purpose agent assigns one or more purposes to a set of data such that access to the set of data may be restricted to a select few specifically authorized entities based on an assigned purpose. A retention period for storing the data is determined based on the assigned purpose. When the retention period expires the data is deleted from a data store.
-
公开(公告)号:US20230177213A1
公开(公告)日:2023-06-08
申请号:US17457811
申请日:2021-12-06
Applicant: SAP SE
Inventor: Benny Rolle , Ufuoma Ighoroje , Matthias Vogel , Geetha Gopalakrishnan , Tobias Schmidt , Antsa Andriamboavonjy , Dharshan A , Carsten Pluder
IPC: G06F21/62 , G06F16/11 , H04L67/566
CPC classification number: G06F21/629 , G06F16/125 , G06F16/113 , H04L67/2833
Abstract: The present disclosure involves systems, software, and computer implemented methods for integrated data privacy services. An example method includes receiving, from a requesting application in a landscape that includes a set of multiple applications, a data subject information request for a data subject. A set of target applications is determined from the set of multiple applications. The data subject information request is provided to each target application in the set of target applications. A data subject information response is received from each of the target applications. Each data subject information response includes application data for the data subject that was retrieved by a respective target application in response to the data subject information request. The received data subject information responses are aggregated to generate an aggregated data subject information response. The aggregated data subject information response is provided to the requesting application in response to the data subject information request.
-
公开(公告)号:US20230177189A1
公开(公告)日:2023-06-08
申请号:US17457827
申请日:2021-12-06
Applicant: SAP SE
Inventor: Ufuoma Ighoroje , Benny Rolle , Matthias Vogel , Carsten Pluder , Karl Tillmann Rendel
IPC: G06F21/62 , G06F16/903
CPC classification number: G06F21/6218 , G06F16/90335
Abstract: The present disclosure involves systems, software, and computer implemented methods for integrated data privacy services. An example method includes sending a block command for an object to each application in a multiple-application landscape that includes a master data distribution application. A blocking status is received from each application that indicates whether the application successfully blocked the object in response to the block command. An overall blocking status is determined based on the received blocking statuses. In response to determining that at least one application failed to block the object, an unblock command is sent to each application. An unblocking status is received from each application and an overall unblocking status is determined. In response to determining that at least one application failed to unblock the object, a redistribution request is sent to the master data distribution application to redistribute the object to applications that failed to unblock the object.
-
公开(公告)号:US10754932B2
公开(公告)日:2020-08-25
申请号:US15636677
申请日:2017-06-29
Applicant: SAP SE
Inventor: Joerg Wiederspohn , Volker Lehnert , Carsten Pluder , Bjoern Christoph
IPC: G06Q10/10 , G06Q30/02 , G06Q30/06 , G06Q10/04 , G06Q10/06 , G06F21/31 , G16B50/00 , G16H10/60 , G06F21/62 , G06Q50/24 , G06Q50/18 , G16H40/20
Abstract: A consent management system (CMS) manages a number of individual consent data records of data subjects. The CMS stores predefined consent templates to be instantiated when an individual consent data record is created. The CMS represents a centralized system for management of individual consent data records that are created, stored, and maintained in relation to provided consent by data subjects for purposes of operations related to stored personal data records by associated application systems. The CMS may run on an on-premise, cloud, or personal device computing platform.
-
-
-
-
-
-
-
-
-