US 11,886,616 B2
Systems and methods for tracking data protection compliance of entities that use personally identifying information (PII)
Stephanie Detchemendy, Wentzville, MO (US)
Assigned to MASTERCARD INTERNATIONAL INCORPORATED, Purchase, NY (US)
Filed by Mastercard International Incorporated, Purchase, NY (US)
Filed on Feb. 15, 2023, as Appl. No. 18/169,470.
Application 18/169,470 is a continuation of application No. 16/855,748, filed on Apr. 22, 2020, granted, now 11,586,763.
Prior Publication US 2023/0195929 A1, Jun. 22, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/62 (2013.01)
CPC G06F 21/6245 (2013.01) 20 Claims
OG exemplary drawing
 
1. A computing system for tracking data protection compliance of a plurality of entities using personally identifying information (“PII”), the computing system comprising a server in communication with a user computing device associated with a user and a requesting entity computing device associated with a requesting entity, the server comprising:
a memory device for storing data, wherein the memory device includes a user profile associated with the user; and
at least one processor communicatively coupled to the memory device, the at least one processor configured to:
receive, from the requesting entity computing device, a PII consent request for access to a requested PII set of the user, the PII consent request identifying a reason code associated with the requested PII set;
determine, based on the PII consent request, at least one PII item associated with the reason code;
transmit, to the requesting entity, a notification indicating user consent for the requesting entity to retrieve the at least one PII item from a third-party PII storage entity;
update, in the memory device, the user profile to track the requesting entity with the at least one PII item;
receive, from the user computing device, a PII removal request indicating that the user revokes the user consent previously provided to the requesting entity;
transmit, to the requesting entity, a removal notification including (i) the revoked user consent, (ii) an identification of the at least one PII item to be removed;
monitor the requesting entity to determine a duration of time the requesting entity spent implementing the removal notification;
receive, from the requesting entity, a removal compliance response in response to the removal notification, the removal compliance response indicating that the at least one PII item has been removed; and
generate a consent recommendation associated with the requesting entity based on the monitoring.