Prosecution Insights
Last updated: October 02, 2026
Application No. 18/793,179

DATA SUBJECT REQUEST TIERING

Non-Final OA §103
Filed
Aug 02, 2024
Priority
Jun 29, 2020 — continuation of 12/086,285
Examiner
SUH, ANDREW
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Wells Fargo Bank, N.A.
OA Round
3 (Non-Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
149 granted / 187 resolved
+21.7% vs TC avg
Strong +40% interview lift
Without
With
+39.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
8 currently pending
Career history
199
Total Applications
across all art units

Statute-Specific Performance

§101
9.0%
-31.0% vs TC avg
§103
54.5%
+14.5% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
19.4%
-20.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 187 resolved cases

Office Action

§103
DETAILED ACTION Responsive to the Applicant reply filed on 06/24/2026, Applicant' s amendments to claims have been entered and respective arguments carefully considered and responded in following: On this Office Action, claims 1-20, consisting of independent claims 1 and 11. Claims 1-20 are pending. Claims 1-20 are rejected under the 35 USC § 103. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/24/2026 has been entered. Response to Amendment The amendment filed 06/24/2026 has been entered. Claims 1 and 11 have been amended. Response to Arguments Applicant’s arguments with respect to claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. For a comprehensive understanding of rejection, please refer to the 35 U.S.C. § 103 section below. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 5, 7-11, 15 and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Shah et al. (US 20210133269 A1, hereinafter “Shah”) in view of Jain et al. (US 20210157849 A1, hereinafter “Jain”). Regarding claim 1, (Currently Amended) Shah discloses a system for categorizing personal data held by a business in response to data subject requests under privacy regulations, the system comprising: a processor; and a system memory encoding instructions which, when executed by the processor, cause the system to (Shah: [0076] Generally, a processor will receive instructions and data from a read only memory or a random access memory or both): receive a data subject request from a requester for a data disclosure report, the data subject request including a request under the privacy regulations that obligates an entity to disclose the personal data held by the entity about the requester (Shah: [0065] By applying identity-based or object-level security policies, if a user is not authorized to access data for any of the different information elements within the card, the system will generate the card to show a dash, a blank area, or other indication that the data is not available; [0071] in operation 805, client device 110 may receive login information for a user, such as primary user 105 a shown in FIG. 1. … In operation 825, client device 110 may receive a request for additional or alternative information from the logged-in user; [0031] Client device may connect to a server, such as server 125 depicted in FIG. 1, by way of a network 120. Server 125 may have access to at least one source database 130 for an organization; [0034] information cards are presented on client device 110 as cards that may include information obtained from source database 130 (See para.[0035] regarding information on the cards)); receive the personal data associated with the data subject request from at least one source application of the entity (Shah: [0071] in operation 805, client device 110 may receive login information for a user, such as primary user 105 a shown in FIG. 1. … In operation 835, client device 110 may receive user information for additional users associated with the shared display, such as an additional user 105 b viewing the contents of the shared display, as shown in FIG. 1; [0040] If additional users are detected, then the displayed information cards may be modified to include additional information cards or to obscure sensitive information displayed on one or more information cards), wherein at least one aspect of the personal data includes sensitive data (Shah: [0040] If additional users are detected, then the displayed information cards (See para.[ 0035] regarding information on the cards) may be modified to include additional information cards or to obscure sensitive information displayed on one or more information cards); in response to receiving the request for the data disclosure report including theShah: [0071] if at least one user viewing the shared display is not authorized to access data for any of the different information elements within an information card, the system may generate the information card to show a dash, a blank area, a solid color, or other indication that the data is not available. Subsequently, in operation 855, client device 110 may transmit the updated and/or additional data cards to shared display). Shah discloses , in paragraph [0071], that “In operation 845, client device 110 may determine whether to filter the displayed information.” For example, Shah discloses, two predetermined tier levels: (1) authorized to view the personal information and (2) not authorized to view the personal information. In a same field of endeavor, Jain further teaches the system, wherein assign, using a tiering logic, a tier level to the at least one aspect of the personal data (Jain: [0061] method 500 may initiate with operation 502, where data is analyzed to determine a sensitivity level for the data. In one embodiment, the data may include an instance of data such as a file, an object, etc.; [0063] analyzing the data may include determining metadata associated with the data. For example, the metadata may describe one or more aspects of the data (e.g., one or more keywords found in the data, one or more instances of predetermined information (e.g., a phone number, social security number (SSN), etc.); [0070] method 500 may proceed with operation 504, where an audit level is assigned to the data, based on the sensitivity level. In one embodiment, the audit level may be assigned to the data by applying the sensitivity level to one or more predetermined policies (See para.[0071] regarding a first/second audit level)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the system storing card-specific information disclosed by Shah with the teachings of Jain to assign, using a tiering logic, a tier level to the at least one aspect of the personal data. One of ordinary skill in the art would have been motivated to make this modification because this enables previously unattainable levels of auditing and data insight for data security (para.[0112]). Regarding claim 5, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. Shah discloses the system of claim 1, wherein the system is further configured to store the personal data, including an element data and associated data values for each aspect of the personal data received from the at least one source application (Shah: [0031] Client device may connect to a server, such as server 125 depicted in FIG. 1, by way of a network 120. Server 125 may have access to at least one source database 130 for an organization; [0032] the application may allow the client device 110 to obtain and provide information from the source database 130 through information cards that can be dynamically adjusted based on the actions or conditions detected on the client device 110; [0034] information cards are presented on client device 110 as cards that may include information obtained from source database 130 (See para.[0035] regarding information on the cards)). Regarding claim 7, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. Shah discloses the system of claim 1, wherein providing the predetermined level of detail of the personal data requires a receipt of a user authentication (Shah: [0071] if at least one user viewing the shared display is not authorized to access data for any of the different information elements within an information card, the system may generate the information card to show a dash, a blank area, a solid color, or other indication that the data is not available. Subsequently, in operation 855, client device 110 may transmit the updated and/or additional data cards to shared display). Regarding claim 8, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. Shah discloses the system of claim 1, wherein the system is further configured to associate usage information to the personal data, including a reason that the at least one source application of the entity stores the personal data (Shah: [0032] the application may allow the client device 110 to obtain and provide information from the source database 130 through information cards that can be dynamically adjusted based on the actions or conditions detected on the client device 110; [0034] information cards are presented on client device 110 as cards that may include information obtained from source database 130; [0035] For example, one template may be used for a person, another template may be used for a company, another template may be used for a location (e.g., a particular store or region), and so on. Different card templates 142 may also be defined and used for entities having different semantic relationships with the user 105 a, the user's organization, or others. For example, a first template may be used for companies that are customers, and may specify a first set of statistical measures to display in a card. A second template for suppliers may specify a different set of statistical measures to display in a card). Regarding claim 9, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. Shah discloses the system of claim 1, wherein a level of detail of data values provided in the data disclosure report is dependent on a user authentication protocol (Shah: [0071] For example, additional user 105 b may not have access permission for some of the information to be displayed in the initial set of data cards or the additional data cards. If client device 110 determines that some information should be filtered, then, in operation 850, client device 110 may filter the displayed information based on the user information for the additional users. For example, if at least one user viewing the shared display is not authorized to access data for any of the different information elements within an information card, the system may generate the information card to show a dash, a blank area, a solid color, or other indication that the data is not available). Regarding claim 10, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. Shah discloses the system of claim 9, wherein the user authentication protocol is a user login on a user interface or a user authenticated phone call (Shah: [0071] in operation 805, client device 110 may receive login information for a user, such as primary user 105 a shown in FIG. 1. … client device 110 may receive user information for additional users associated with the shared display, such as an additional user 105 b viewing the contents of the shared display, as shown in FIG. 1). Regarding claims 11, 15 and 17-20, they are method claims that corresponds to claims 1, 5 and 7-10. Therefore, the claim is rejected for at least the same reasons as the system in claims 1, 5 and 7-10. Claims 2-4 and 12-14 are rejected under 35 U.S.C. 103 as being unpatentable over Shah et al. (US 20210133269 A1, hereinafter “Shah”) in view of Jain et al. (US 20210157849 A1, hereinafter “Jain”) as applied to claims above, and further in view of Burgess (US 20200159949 A1). Regarding claim 2, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. However, the combination does not discloses Burgess, in a same field of endeavor, teaches the system of claim 1, wherein if the at least one aspect of the personal data is categorized in a first tier, the predetermined level of detail of the personal data provided includes an element data and no specific data values (Burgess: See Fig. 1d (“a first tier”) and [0026] In the embodiment show in FIG. 1d , the agent has attempted to bypass data obfuscation method 200; as a result, protective analytics engine 110 has completely obscured desktop 150 with data field block 152 (“an element data and no specific data values”) until protective analytics engine 110 has restarted data obfuscation method 200). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the system storing card-specific information disclosed by Shah with the teachings of Burgess to include the predetermined level of detail of the personal data provided that includes an element data and no specific data values if the at least one aspect of the personal data is categorized in a first tier. One of ordinary skill in the art would have been motivated to make this modification because the system may compare the received credential or credentials to at least one protective analytics rule and determines that it has received inappropriate credentials from the viewer (para. 0046). Regarding claim 3, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. However, the combination does not discloses Burgess, in a same field of endeavor, teaches the system of claim 1, wherein if the at least one aspect of the personal data is categorized in a second tier, the predetermined level of detail of the personal data provided includes an element data and a redacted set of data values (Burgess: See Fig. 1b (“second tier”) and [0026] In FIG. 1b , a standard desktop 150 displays various desktop data fields 151, with two desktop data fields 151 having data field blocks 152 obscuring sensitive data 153 (“an element data and a redacted set of data values”)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the system storing card-specific information disclosed by Shah with the teachings of Burgess to include the predetermined level of detail of the personal data provided that includes an element data and a redacted set of data values if the at least one aspect of the personal data is categorized in a first tier if the at least one aspect of the personal data is categorized in a second tier. One of ordinary skill in the art would have been motivated to make this modification because the system may compare the received credential or credentials to at least one protective analytics rule and determines that it has received inappropriate credentials from the viewer (para. 0046). Regarding claim 4, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. However, the combination does not discloses Burgess, in a same field of endeavor, teaches the system of claim 1, wherein if the at least one aspect of the personal data is categorized in a third tier, the predetermined level of detail of the personal data provided includes an element data and a set of data values (Burgess: See Fig. 1c (“third tier”) and [0026]In FIG. 1c , the data field block 152 obscuring one desktop data field 151 has been removed, allowing access to sensitive data 153 (“an element data and a set of data values”)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the system storing card-specific information disclosed by Shah with the teachings of Burgess to include the predetermined level of detail of the personal data provided that includes an element data and a set of data values if the at least one aspect of the personal data is categorized in a third tier. One of ordinary skill in the art would have been motivated to make this modification because the system may compare the received credential or credentials to at least one protective analytics rule and determines that it has received inappropriate credentials from the viewer (para. 0046). Regarding claims 12-14, they are method claims that corresponds to claims 2-4. Therefore, the claim is rejected for at least the same reasons as the system in claims 2-4. Claims 6 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Shah et al. (US 20210133269 A1, hereinafter “Shah”) in view of Jain et al. (US 20210157849 A1, hereinafter “Jain”) as applied to claims above, and further in view of Mohler et al. (US 20090158441 A1, hereinafter “Mohler”). Regarding claim 6, (Original) the combination of Shah and Jain discloses all elements of the current invention as stated above. However, the combination does not discloses Mohler, in a same field of endeavor, teaches the system of claim 5, wherein the system stores the personal data, including the element data and associated data values, for a predetermined period of time (Mohler: [0008] In accordance with an exemplary embodiment, information is identified as sensitive and a lapsed time job (Chron Job) is created that will allow the deletion of sensitive information after a period of time (“stores the personal data for a predetermined period of time”). Once information is identified as sensitive, the information could be partitioned into folders, directories or the like, then entered into the Chron Job for automatic deletion). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the system storing card-specific information disclosed by Shah with the teachings of Mohler to stores the personal data, including the element data and associated data values, for a predetermined period of time. One of ordinary skill in the art would have been motivated to make this modification because deleting sensitive data after a specific period of time (known as data minimization) provides significant benefits including enhanced security, improved regulatory compliance, and reduced operational costs. Regarding claim 16, it is method claims that corresponds to claim 6. Therefore, the claim is rejected for at least the same reasons as the system in claim 6. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Lindsay (US 20220067206 A1): a method 700 for securing data can include receiving, by a tokenization system from a first client computing system, a request for data anonymization (701). In some embodiments, the request referencing a single field of data, file, record, or document having multiple data fields that contain values of interest for the data anonymization. The tokenization system can perform a tokenization operation on the input single field of data, file, record, or document (703). In some embodiments, the tokenization operation can include generating a corresponding token for replacing a value of interest in one of the multiple data fields. The tokenization system can store the value of interest from the input single field of data, file, record, or document with the corresponding token in a secure data vault (705). The tokenization system can return the anonymized version of the single field of data, file, record, or document to the first client computing system (707). Whipple, JR. (US 20230409740 A1): [0031] If, at block 215, it is determined that the intended recipient has submitted the acceptance code back to the permissions module 130 when logged into the system 100, then the permissions module 130 modifies the data structure 145 associated with the intended recipient, at block 220. The data structure 145 is modified to reflect that: (i) the intended recipient has authorized the Initiator to communicate with the intended recipient through the system 100, and (ii) the approved method(s) of communication (e.g., phone, email, etc.). Balakrishna et al. (US 20200134240 A1): [0039] Referring to block 212, the security level detection module 172 processes the data signal from the ID tag 152 a and determines the security level associated with the ID tag 152 a. Security level detection is described in more detail above with reference to the security level detection module 172. Brannon et al. (US 20220277103 A1): [0105] As shown in FIG. 2B, a Data Subject Access Request Routing Module 1000, according to particular embodiments, is adapted for executing the steps of: (1) at Step 1050, presenting, by at least one computer processor, a first webform on a first website, the first webform being adapted to receive data subject access requests and to route the requests to a first designated individual (e.g., an individual who is associated with a first sub-organization of a particular organization— e.g., an employee of the first sub-organization) for processing (in various embodiments, “presenting a webform on a website” may comprise, for example: (A) providing a button, link, or other selectable indicium on the website that, when selected, causes the system to display the webform, or (B) displaying the webform directly on the website); (2) at Step 1100 presenting, by at least one computer processor, a second webform on a second website, the second webform being adapted to receive data subject access requests and to route the requests to a second designated individual (e.g., an individual who is associated with a second sub-organization of a particular organization—e.g., an employee of the second sub-organization) for processing; (3) at Step 1150, receiving, by at least one computer processor, via the first webform, a first data subject access request; (4) at Step 1200, at least partially in response to the receiving the first data subject access request, automatically routing the first data subject access request to the first designated individual for handling; (5) at Step 1250, at least partially in response to the receiving the second data subject access request, automatically routing the second data subject access request to the second designated individual for handling; and (6) at Step 1300, communicating, via a single user interface, a status of both the first data subject access request and the second data subject access request. Chen et al. (US 20210182429 A1):[0048] At operation 206, the content server 102 queries the submitting user 104 to indicate an extracted item or items of sensitive material that is to be obscured. This can include providing some or all of the extracted item or items of sensitive material to the submitting user 104. The submitting user 104 may indicate whether an item of sensitive material is to be obfuscated. If any items of sensitive material are to be obfuscated at operation 208, the content server 102 receives requesting user role data at operation 210. The requesting user role data indicates which requesting user roles will receive obfuscated versions of the item or items identified for obfuscation at operation 206. In some examples, the content server 102 queries the submitting user 104 to indicate the requesting user role or roles for which the identified item or items of sensitive material will be obfuscated. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANDREW SUH whose telephone number is (571)270-5524. The examiner can normally be reached 9:00 AM- 5:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANDREW SUH/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Show 3 earlier events
Dec 18, 2025
Applicant Interview (Telephonic)
Dec 19, 2025
Examiner Interview Summary
Dec 24, 2025
Response Filed
Mar 24, 2026
Final Rejection mailed — §103
May 22, 2026
Response after Non-Final Action
Jun 24, 2026
Request for Continued Examination
Jun 28, 2026
Response after Non-Final Action
Jul 27, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750214
SYSTEMS AND METHODS FOR ENHANCED SECURITY USING LOW ENTROPY SECRETS ON INSECURE ENVIRONMENTS
1y 9m to grant Granted Sep 29, 2026
Patent 12744661
SECURELY SHARING DATA AND ACCESS PERMISSIONS IN A CLOUD ENVIRONMENT
4y 0m to grant Granted Sep 22, 2026
Patent 12732538
SYSTEMS AND METHODS FOR UTILIZING USER PROFILE DATA TO PROTECT AGAINST PHISHING ATTACKS
4y 3m to grant Granted Sep 08, 2026
Patent 12730913
DISSEMINATION AND TRACKING OF DOCUMENTS WITH DOWNSTREAM CONTROL
1y 11m to grant Granted Sep 08, 2026
Patent 12730936
ANONYMIZED INTERFACE FOR TICKET BASED AUTHENTICATION
1y 11m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+39.5%)
2y 9m (~7m remaining)
Median Time to Grant
High
PTA Risk
Based on 187 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month