Data processing systems and methods for automatically protecting sensitive data within privacy management systems

    公开(公告)号:US11544409B2

    公开(公告)日:2023-01-03

    申请号:US17499595

    申请日:2021-10-12

    申请人: OneTrust, LLC

    摘要: In particular embodiments, a sensitive data management system is configured to remove sensitive data after a period of non-use. Credentials used to access remote systems and/or third-party systems are stored with metadata that is updated with each use of the credentials. After a period of non-use, determined based on credential metadata, the credentials are deleted. Personal data retrieved to process a consumer request is stored with metadata that is updated with each use of the personal data. After a period of non-use, determined based on personal data metadata, the personal data is deleted. The personal data is also deleted if the system determines that the process or system that caused the personal data to be retrieved is no longer in use. An encrypted version of personal data may be stored for later use in verifying proper consumer request fulfillment.

    DATA PROCESSING SYSTEMS AND METHODS FOR USING A DATA MODEL TO SELECT A TARGET DATA ASSET IN A DATA MIGRATION

    公开(公告)号:US20220391122A1

    公开(公告)日:2022-12-08

    申请号:US17887771

    申请日:2022-08-15

    申请人: OneTrust, LLC

    IPC分类号: G06F3/06

    摘要: A chat robot may be used to facilitate interaction with a user in the determination of whether to initiate and process a data subject access request (DSAR). At a DSAR submission webpage, the chatbot may interact with a user to determine the information the user is in need of and/or the actions that the user may take. The chatbot may provide the information, avoiding the processing overhead of submission and fulfillment of a DSAR. In addition, data stored on a data asset may be migrated to another data asset while maintaining compliance to applicable regulations. Based on the type of data stored by that data asset and the applicable regulations, requirements, and/or restrictions that relate to a transfer of that type data from that data asset, a target data asset may be determined. The data stored on the data asset may then be transferred to the target data asset.

    SYSTEMS AND METHODS FOR DETECTING PREJUDICE BIAS IN MACHINE-LEARNING MODELS

    公开(公告)号:US20220108222A1

    公开(公告)日:2022-04-07

    申请号:US17494220

    申请日:2021-10-05

    申请人: OneTrust, LLC

    IPC分类号: G06N20/00

    摘要: Aspects of the present invention provide methods, apparatuses, systems, computing devices, computing entities, and/or the like for detecting prejudice bias in machine-learning models and/or data sets used in training, testing, and/or validating the models. In accordance various aspects, a method is provided comprising: receiving a data set used for training, testing, and/or validating a model that comprises data instances; generating, using a classification model, a prediction of applicability for each sub-category of a plurality of sub-categories for each bias category of a plurality of bias categories for each data instance; determining that a particular sub-category for a particular bias category is applicable to a proportion of the data set, wherein predictions of applicability for the particular sub-category generated for the proportion of the data set satisfies a threshold; and determining, based on the proportion, that the data set has a prejudice bias with respect to the particular bias category.

    DATA PROCESSING SYSTEMS AND METHODS FOR AUTOMATICALLY PROTECTING SENSITIVE DATA WITHIN PRIVACY MANAGEMENT SYSTEMS

    公开(公告)号:US20220035952A1

    公开(公告)日:2022-02-03

    申请号:US17499595

    申请日:2021-10-12

    申请人: OneTrust, LLC

    IPC分类号: G06F21/62 G06F3/0482

    摘要: In particular embodiments, a sensitive data management system is configured to remove sensitive data after a period of non-use. Credentials used to access remote systems and/or third-party systems are stored with metadata that is updated with each use of the credentials. After a period of non-use, determined based on credential metadata, the credentials are deleted. Personal data retrieved to process a consumer request is stored with metadata that is updated with each use of the personal data. After a period of non-use, determined based on personal data metadata, the personal data is deleted. The personal data is also deleted if the system determines that the process or system that caused the personal data to be retrieved is no longer in use. An encrypted version of personal data may be stored for later use in verifying proper consumer request fulfillment.