US2023205836A1PendingUtilityA1

Data-processing consent refresh, re-prompt, and recapture systems and related methods

Assignee: ONETRUST LLCPriority: Jun 10, 2016Filed: Mar 2, 2023Published: Jun 29, 2023
Est. expiryJun 10, 2036(~9.9 yrs left)· nominal 20-yr term from priority
G06F 40/174G06F 16/951G06F 16/9577G06F 16/9574G06F 16/972G06F 21/6245G06F 21/6218G06F 40/30
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In various embodiments, a Consent Refresh, Re-Prompt, and Recapture System is configured to interface with a Consent Receipt Management System in order to, for example: (1) monitor previously provided consent by one or more data subjects that may be subject to future expiration; (2) monitor a data subject's activity to anticipate the data subject attempting an activity that may require a level of consent (e.g., for the processing of particular data subject data) that is higher than the system has received; and/or (3) identify other changes in circumstances or triggering events for a data subject that may warrant a refresh or recapture (e.g., or attempted capture) of a particular required consent (e.g., required to enable an entity to properly or legally execute a transaction with a data subject). The system may then be configured to automatically refresh, re-prompt for, and/or recapture consent as necessary.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 providing, by computing hardware, a user interface for initiating a transaction between an entity and a data subject;   receiving, by the computing hardware from a first computing device, a request from a data subject to initiate a transaction between the entity and the data subject;   in response to the request:
 prompting, by the computing hardware, the data subject to provide consent to the entity for processing personal data associated with the data subject as part of the transaction; and 
 generating, by the computing hardware, a unique consent receipt key based on the consent; 
   receiving, by the computing hardware, a unique subject identifier for the data subject;   causing initiation, by the computing hardware, of a virtual browsing session on a second computing device, wherein the first computing device is different from the second computing device;   causing, by the computing hardware, access of a webpage hosting the user interface using a virtual browser during the virtual browsing session;   causing a capture, by the computing hardware via the virtual browsing session, of the user interface in an unfilled state; and   electronically associating, by the computing hardware, the unique subject identifier, the unique consent receipt key, a unique transaction identifier for the transaction, an indication of the consent, and the capture of the user interface.   
     
     
         2 . The method of  claim 1 , wherein causing the capture of the user interface in the unfilled state comprises at least one of capturing one or more images of the user interface, capturing computer code associated with the user interface, or capturing a network link via which the user interface is accessible. 
     
     
         3 . The method of  claim 1 , wherein:
 the transaction involves providing, to the first computing device, access to computer-specific functionality; and   the method further comprises enabling, by the computing hardware, the access to the computer-specific functionality to the first computing device in response to the request.   
     
     
         4 . The method of  claim 3 , further comprising causing, by the computing hardware, a modification to the access to the computer-specific functionality in response to a triggering event. 
     
     
         5 . The method of  claim 4 , wherein the method further comprises re-prompting the data subject for the consent in response to the triggering event. 
     
     
         6 . The method of  claim 5 , wherein the triggering comprises at least one of a change in a location of the first computing device, a determination that the first computing device has accessed at least a particular number of additional webpages on a particular website that includes the webpage, or a passage of a particular amount of time from generation of the unique consent receipt key. 
     
     
         7 . The method of  claim 1 , wherein:
 the indication of consent comprises a lack of consent; and   the method further comprises preventing, based on the lack of consent, the first computing device from accessing the computer-specific functionality under the transaction.   
     
     
         8 . A system comprising:
 a non-transitory computer-readable medium storing instructions; and   processing hardware communicatively coupled to the non-transitory computer-readable medium, wherein the processing hardware is configured to execute the instructions and thereby perform operations comprising:
 providing, at a webpage, a user interface for accessing computer-specific functionality via the webpage; 
 receiving, from a first computing device, a request to access the computer-specific functionality via the webpage; 
 responsive to the request:
 prompting, via the user interface, a user of the first computing device to provide consent to processing of personal data associated with the user in order to access the computer-specific functionality; and 
 generating a consent receipt set based on the consent, the consent receipt set comprising a user identifier identifying the user and an indication of the consent; 
 
 accessing, by a second computing device, the user interface; 
 generating a user interface profile that identifies a manner in which the user interface captured the consent; and 
 linking the user interface profile to the consent receipt set. 
   
     
     
         9 . The system of  claim 8 , wherein:
 accessing the user interface comprises:
 initiating, by the second computing device, a virtual browsing session; and 
 accessing, by the second computing device, the webpage using a virtual browser during the virtual browsing session; and 
   generating the user interface profile that identifies the manner in which the user interface captured the consent comprises capturing, by the second computing device during the virtual browsing session, a copy of the user interface.   
     
     
         10 . The system of  claim 9 , wherein capturing the copy of user interface comprises at least one of capturing one or more images of the user interface, capturing computer code associated with the user interface, or capturing a network link via which the user interface is accessible. 
     
     
         11 . The system of  claim 8 , wherein the operations further comprise providing, to the first computing device, access to the computer-specific functionality via the webpage in response to the request. 
     
     
         12 . The system of  claim 8 , wherein the operations further comprise:
 identifying a triggering event; and   responsive to identifying the triggering event:
 modifying the consent receipt set such that the indication of the consent indicates an expiration of the consent; and 
 re-prompting the data subject to provide the consent. 
   
     
     
         13 . The system of  claim 12 , wherein the triggering comprises at least one of a change in a location of the first computing device, a determination that the first computing device has accessed at least a particular number of additional webpages on a particular website that includes the webpage, or a passage of a particular amount of time from generation of the consent receipt set. 
     
     
         14 . A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:
 receiving a first indication of a request from a first computing device to access computer-specific functionality via webpage;   receiving a second indication of consent, from the first computing device via a user interface at the webpage, related to processing of personal data associated with a user of the computing device in order to access the computer-specific functionality; and   responsive to at least one of the first indication or the second indication:
 generating a consent receipt set based on the consent, the consent receipt set comprising a user identifier identifying the user and the second indication of the consent; 
 causing access to the user interface by a second computing device; 
 generating a user interface profile that identifies a manner in which the user interface captured the consent; and 
 linking the user interface profile to the consent receipt set. 
   
     
     
         15 . The non-transitory computer-readable medium of  claim 14 , wherein:
 causing access to the user interface by the second computing device comprises:
 causing the second computing device to initiate a virtual browsing session; and 
 causing the second computing device to access the webpage using a virtual browser during the virtual browsing session; and 
   generating the user interface profile that identifies the manner in which the user interface captured the consent comprises causing the second computing device to capture the user interface in an unfilled state during the virtual browsing session.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein causing the second computing device to capture the user interface in the unfilled state during the virtual browsing session comprises at least one of causing the second computing device to capture one or more images of the user interface, causing the second computing device to capture computer code associated with the user interface, or causing the second computing device to capture a network link via which the user interface is accessible. 
     
     
         17 . The non-transitory computer-readable medium of  claim 15 , wherein the operations further comprise:
 determining, based on the computer-specific functionality, that the consent is subject to an expiration condition;   receiving a third indication of an occurrence of the expiration condition; and   responsive to the third indication, modifying the second indication of the consent to reflect the occurrence of the expiration condition.   
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , the operations further comprising responsive to the third indication:
 at least temporarily preventing the first computing device from accessing the computer-specific functionality; and   causing a recapture of the consent.   
     
     
         19 . The non-transitory computer-readable medium of  claim 17 , wherein the expiration condition comprises at least one of a change in location of the first computing device, a passage of time since generation of the consent receipt set, or a change in the computer-specific functionality. 
     
     
         20 . The non-transitory computer-readable medium of  claim 14 , wherein:
 the second indication of the consent comprises a lack of consent; and   the operations further comprise preventing, based on the lack of consent, the first computing device from accessing the computer-specific functionality.

Join the waitlist — get patent alerts

Track US2023205836A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.