DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The amendment filed 5/12/2026 has been placed of record in the file.
No claims have been amended.
The double patenting rejection remains of record.
Claims 1, 2, and 5-14 are pending.
The applicant’s arguments with respect to claims 1, 2, and 5-14 have been fully considered but they are not persuasive as discussed above.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 2, and 5-14 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Barday et al. (U.S. Patent Application Publication Number 2018/0341784), hereinafter referred to as Barday.
Regarding claim 1, Barday discloses a tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Regarding claim 2, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data).
Regarding claim 5, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method, wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 6, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII).
Regarding claim 7, Barday discloses a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Regarding claim 8, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data).
Regarding claim 9, Barday discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; further including removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 10, Barday discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII).
Regarding claim 11, Barday discloses a system for responding to requests to be forgotten (paragraph 163, right to be forgotten), the system including a processor, memory coupled to the processor, and computer instructions loaded into memory that, when executed on processors, cause the processors to implement a method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Regarding claim 12, Barday discloses in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data).
Regarding claim 13, Barday discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; further including removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 14, Barday discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII).
Response to Arguments
In the remarks, the applicant has argued that Barday does not disclose a “CASB” as recited in independent claim 1. In response, it is maintained that Barday teaches the features as claimed. Barday explicitly states the servers being managed as cloud-based servers. See, again, Barday, paragraph 186. The applicant’s argument that “Barday does not use the acronym CASB” is not persuasive as the term is defined by the limitations of the claim. Here, Barday teaches the functionality as claimed (“controlling exfiltration,” “identifying one or more locations,” etc.) and, as such, is seen to meet the terms used in the claim that provide said functionality.
To the applicant’s statement about “use cases,” it is unclear how this relates to the limitations of the claim. To the applicant’s statement about Barday’s “inventors,” it is unclear how this relates to the limitations of the claim. To the applicant’s statement that Barday only uses the word cloud “to explain that a centralized repository can be hosted on a cloud-based server,” it is noted that this is incorrect and misleading. At the cited paragraph 186, Barday clearly states that all components of the system, including management servers, system servers, and the databases may be cloud-based servers.
The applicant’s argument that “the Office relies on features from alternative embodiments to formulate the rejection” is also unpersuasive. Barday explicitly states that the described “alternative embodiments” simply provide for additional features to the embodiments already described. Adding features to a disclosed embodiment is not exclusionary of the previous disclosure.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Victor Lesniewski/Primary Examiner, Art Unit 2493