Systems and methods for consent management

Through a centralized consent management system, the inefficiency of users to manage consent information between multiple services is solved, and more efficient and transparent user consent management is achieved.

CN113366514BActive Publication Date: 2025-06-10KONINKLIJKE PHILIPS NV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980090387.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-01-04
Filing Date
2019-12-31
Publication Date
2025-06-10
Estimated Expiration
2039-12-31

AI Technical Summary

Technical Problem

The prior art is difficult to effectively manage the user's consent information between multiple services, resulting in users needing to frequently access various services to manage consent, which is inefficient.

Method used

Provide a centralized consent management system through which users can manage their consent information in multiple services. The system can automatically synchronize and control user consent information, providing a unified interface to improve management efficiency.

Benefits of technology

By centrally managing user consent information, the transparency and efficiency of user consent management are improved, the user's operational needs between multiple services are reduced, and the risk of human error is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113366514B_ABST
    Figure CN113366514B_ABST
Patent Text Reader

Abstract

The present invention provides a consent management system for managing user consent for multiple services. The system includes a consent management unit that is adapted to register multiple services for a user and obtain user consent information associated with the user. The consent management unit is further adapted to control consent operations for the multiple services registered for the user based on the user consent information associated with the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of data privacy and user consent, and more particularly to the field of consent management. Background Art

[0002] Privacy regulations typically require user consent to record the privacy preferences of data subjects regarding how their consent information (e.g., their personal data) is processed. Examples of data subjects include users of services, patients of medical services, or individuals with corresponding sets of recorded information.

[0003] Typically, to register for a regular service, a user provides consent for the service to process his / her personal data. The service can then store information about this consent as a legal basis for processing the user's consent information. If the service's privacy terms are updated, the service is usually required to notify the user (e.g., via email communication or directly through the service) in order to seek the user's consent again.

[0004] A user may be registered for multiple services. These services typically store user consent information and the user's consent to process the consent information. For services that a user frequently accesses and uses, it is easy to obtain notifications about updates (e.g., to the service's privacy notice). Additionally, requests for input from the user (e.g., the user's response to a privacy notice update) can be regularly delivered to and recognized by the user. However, for services that a user infrequently accesses and / or uses, it may be difficult to transparently and effectively notify the user and receive the user's input in response to such requests. This can affect the efficiency of how the service is used and thus the efficiency of the service itself.

[0005] Typically, a user needs to access each of the different services to manage his / her consent and the corresponding user consent information for each service. This approach requires the user's time to complete repetitive tasks, resulting in a cumbersome and inefficient process.

[0006] Therefore, there is still a need to optimize the process of managing user consent and the corresponding user consent information required by privacy-related regulations across multiple services registered for a user. Summary of the Invention

[0007] The present invention is defined by the claims.

[0008] According to an example aspect of the present invention, there is provided a consent management system for managing user consent for multiple services, the system comprising: a consent management unit adapted to: register multiple services for a user; obtain user consent information associated with the user; and control consent operations for the multiple services registered for the user based on the user consent information associated with the user.

[0009] Concepts for managing user consent for multiple services are presented. One such concept can provide a centralized (or intermediate) consent management system that acts as a unified interface for a user to access their consent-related preferences and / or permissions. The consent management system can assign / link multiple services to the user, and this can then enable the system to centrally control the user consent-related operations for multiple services. In this way, a single point or node can be provided for managing user consent for multiple services in a transparent and efficient manner.

[0010] A single resource or service is presented that provides management of user consent and corresponding user consent information for multiple services registered for a user. The single resource or service enables the user to access all user consent information related to the multiple registered services. The user can manage and control user consent-related operations for the multiple registered services from a single centralized resource or service.

[0011] This can allow for improved communication efficiency between the user and the multiple services registered for the user. This can lead to improved transparency and efficiency in managing user consent and user consent information for multiple services. Thus, different from conventional methods, it may not be necessary for the user to access multiple services to retrieve and manage the user consent and user consent information corresponding to each service. Instead, the user can access and manage the user consent and user consent information through a centralized system.

[0012] In an embodiment, the consent operation can include an operation of adopting data privacy preference information associated with the user. In this way, the consent management system can be enabled to manage user consent and dispose of user permissions regarding data privacy for the services registered for the user.

[0013] For example, the operation of adopting the data privacy preference information can include at least one of the following: responding to a user request from the user; responding to a service request from the multiple services; and determining whether the user consent information associated with the user is consistent with the data access requirements of the service. In this way, the consent management system can be enabled to manage requests from both the user and the registered services. Thus, the user can access all service requests in a unified interface. This can eliminate the need for the user to access multiple individual services to receive and manage service requests.

[0014] User consent information can be the user's privacy preferences regarding how the service can process data corresponding to the user. For example, user consent information includes user privacy settings that can define preferences set by the user regarding how user data is collected, processed, disclosed, disposed of, and / or managed by the service. User consent information can also include at least one of the following: user privacy preferences regarding the purpose of processing user data, user privacy preferences regarding how user data is shared by the service (e.g., with whom, when, and / or why), user privacy preferences regarding receiving communications from the service, user privacy preferences regarding the service's reporting process for data breaches, user privacy preferences regarding the service's data retention policy, and user privacy preferences regarding how user data is stored by the service.

[0015] User data can include at least one of the following: personal details corresponding to the user, information that can be used to identify the user, content provided by the user to the service, and information in or about the content provided by the user to the service (e.g., metadata). For example, user data includes, but is not limited to, at least one of the following: the user's name, address, date of birth, marital status, contact information, ID issuance and expiration dates, financial records, credit information, medical history, travel information, Internet usage information, and intent to obtain goods and services.

[0016] In this way, the consent operation controlled by the consent management unit can adopt the user consent information described in the above embodiments.

[0017] Additionally, the user may be able to provide user requests for multiple services from a unified interface, thereby improving the efficiency of submitting user requests. This can be particularly beneficial for services that the user does not access frequently, as the system can improve the communication efficiency between the user and the services.

[0018] The consent management system can be enabled to perform an automatic comparison between the user consent information and the data access requirements of the service in order to determine the consistency between the two. This can alleviate the need for the user to manually perform the comparison and can reduce the risk of human error in the comparison (e.g., due to overlooking details).

[0019] In an embodiment, in response to a user request from the user, the consent management unit can be adapted to: receive the user request from the user; request the multiple services to complete the user request; and synchronize the user consent information between the consent management system and the multiple services. In this way, the consent management system can enable the user to provide user requests for multiple services through a single unified interface (the consent management system).

[0020] In addition, the consent management system can reduce the risk of inconsistency between the user consent information registered at the consent management system and the user consent information registered at multiple services.

[0021] In an embodiment, the user request may include one or more of the following: updating the user consent; revoking the user consent; correcting the user consent information; and deleting the user consent information. Thus, the consent management system can be enabled to manage and control the user consent and the corresponding user consent information (e.g., data linked to the user consent) at multiple services based on the request provided by the user.

[0022] In an embodiment, in response to a service request, the consent management unit may be adapted to: receive the service request from the multiple services; notify the user of the update; receive a user response; and respond to the multiple services according to the user response. Thus, the consent management system can enable the user to access all notifications received from the services in a unified interface, thereby improving the communication efficiency between the services and the user. The user can also provide a response corresponding to the service request to the multiple services. For example, the consent management system can provide the response submitted by the user to the multiple services.

[0023] In an embodiment, the service request may include one or more of the following: a privacy notice; and updating the user consent. Thus, the consent management system can be enabled to notify the user of updates from multiple services that may require the user's attention or input.

[0024] In an embodiment, the system may further include a data storage unit adapted to store the user consent information associated with the user. Thus, the consent management system can be enabled to access the user consent information and synchronize the information between the system and the registered services.

[0025] In an embodiment, in registering the multiple services for the user, the consent management unit may be adapted to: entrust the consent management unit to manage the user consent; generate a token; and use the token to register the multiple services for the user. The token may be unique for the user. This can enable the consent management system to generate the information required for the process of registering only once. Thus, the consent management system can be implemented as an effective method for registering multiple services for the user.

[0026] For example, in an embodiment, the token may include at least one of the following: a consent management system network address; a service network address; the user request; a timestamp; the validity period of the user consent; and a digital signature. In this way, the generated token can contain all the information required to register the user for multiple services. The token can be used more than once, thus reducing the need for the consent management system to repeatedly generate information when needed.

[0027] In an embodiment, the system may further include a user interface unit adapted to display one or more of the following: a list of the multiple services; notifications from the multiple services; a list of consent entries; and a list of user permissions. Thus, the unified interface provided by the consent management system may be the user interface unit. This can provide the user with access to a summary of information related to services and user consent, thereby improving the efficiency of communication information.

[0028] In an embodiment, the system may be a blockchain-based consent management system adapted to record one or more of the following: the user consent information; privacy notifications from the multiple services; the user request; and the service request. Thus, the data used by the consent management system may be decentralized, and changes to the data may require consensus from the network corresponding to the blockchain-based consent management system. This can reduce the risk of retroactive changes to the data.

[0029] In an embodiment, the consent management unit may also be adapted to receive the user consent information.

[0030] According to an example of an aspect of the present invention, there is provided a computer program product for managing user consent for multiple services, the computer program product including a computer-readable storage medium having program instructions embodied therewith, the program instructions executable by a processing unit to cause the processing unit to perform a method including: registering the user for multiple services; obtaining user consent information associated with the user; and controlling consent operations for the multiple services registered for the user based on the user consent information associated with the user.

[0031] According to an example of an aspect of the present invention, there is provided a method for managing user consent for multiple services, the method including: registering the user for multiple services; obtaining user consent information associated with the user; and controlling consent operations for the multiple services registered for the user based on the user consent information associated with the user.

[0032] These and other aspects of the invention will become apparent with reference to the embodiments described hereinafter and will be elucidated with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] For a better understanding of the present invention and to more clearly show how it may be implemented, reference will now be made, by way of example only, to the accompanying drawings, in which:

[0034] Figure 1 is a simplified block diagram of a system for managing user consent for multiple services according to an embodiment;

[0035] Figure 2 is a flowchart of a method for managing user consent for multiple services according to an embodiment;

[0036] Figure 3 illustrates a method for registering multiple services for a user according to an embodiment;

[0037] Figure 4 illustrates a method for synchronizing user consent information between a consent management system and multiple services according to an embodiment;

[0038] Figure 5 illustrates a method for updating a privacy notice; and

[0039] Figure 6 illustrates an example of a computer for implementing a controller or a processor according to an embodiment. DETAILED DESCRIPTION

[0040] The present invention will be described with reference to the accompanying drawings.

[0041] It should be understood that the detailed description and specific examples, while indicating exemplary embodiments of the apparatus, systems and methods, are intended for purposes of illustration only and are not intended to limit the scope of the invention. These and other features, aspects and advantages of the apparatus, systems and methods of the present invention will be better understood from the following description, claims and drawings. It should be understood that the drawings are merely schematic and are not drawn to scale. It should also be understood that the same reference numerals are used throughout the drawings to indicate the same or similar components.

[0042] The present invention provides a consent management system for managing user consent for multiple services. The system includes a consent management unit adapted to register multiple services for a user and obtain user consent information associated with the user. The consent management unit is further adapted to control consent operations of the multiple services registered for the user based on the user consent information associated with the user.

[0043] Figure 1A system 10 for managing user consent for multiple services 15 is shown.

[0044] System 10 acts as a unified interface between multiple services 15 and user 11. System 10 communicates directly with multiple services 15 and enables user 11 to access consent-related services. Thus, an indirect communication path is implemented between user 11 and multiple services 15 via system 10. The indirect communication path is indicated by a dashed arrow in Figure 1 . The direct communication path is indicated by a solid arrow in Figure 1 .

[0045] System 10 includes a consent management unit 12, a user interface unit 13, and a data storage unit 14.

[0046] Consent management unit 12 is adapted to register multiple services 15 for user 11 and obtain user consent information associated with the user. Consent management unit 12 then is adapted to control the consent operations of the multiple services 15 registered for user 11 based on the user consent information associated with user 11.

[0047] The consent operations include operations that adopt data privacy preference information associated with user 11. These operations also include responding to a user request from user 11, responding to a service request from multiple services 15, and / or determining whether the user consent information associated with user 11 is consistent with the data access requirements of service 15.

[0048] When responding to a user request from user 11, consent management unit 12 is also adapted to receive a user request from user 11 and request multiple services 15 to complete the user request. Consent management unit 12 is also adapted to synchronize user consent information between consent management system 12 and multiple services 15.

[0049] User requests include, but are not limited to, updating user consent, revoking user consent, correcting user consent information, and / or deleting user consent information.

[0050] When responding to a service request, consent management unit 12 is also adapted to receive a service request from multiple services 15, notify user 11 of the update, and receive a user response. Consent management unit 12 is also adapted to respond to multiple services 15 based on the user response.

[0051] Service requests include, but are not limited to, updating privacy notices and / or updating user consent.

[0052] When registering multiple services 15 for user 11, consent management unit 12 is adapted to entrust consent management unit 12 to manage user consent, generate a token, and then use the token to register multiple services 15 for user 11.

[0053] The token includes but is not limited to the consent management system network address, service network address, user request, timestamp; the validity period of the user consent and / or digital signature.

[0054] In addition, the consent management unit 12 is also adapted to receive user consent information associated with the user 11. The consent management unit 12 is configured to communicate directly with a plurality of services 15. For example, the consent management unit 12 communicates directly with the consent manager of the service 15.

[0055] The user interface unit 13 is adapted to display a list of a plurality of services 15, notifications from a plurality of services 15, a list of consent entries; and / or a list of user permissions.

[0056] The user interface unit 13 communicates directly with the consent management unit 12. For example, the user interface unit 13 is a web portal, website or application interface.

[0057] The data storage unit 14 is adapted to store user consent information associated with the user 11.

[0058] The data storage unit 14 communicates directly with the consent management unit 12.

[0059] Figure 2 A method 20 for managing user consent for a plurality of services 15 is shown.

[0060] The method 20 starts in step 21, where a plurality of services 15 are registered for the user 11.

[0061] In step 22, user consent information associated with the user 11 is obtained.

[0062] In step 23, the consent operations of the plurality of services 15 registered for the user 11 are controlled based on the user consent information associated with the user 11.

[0063] Figure 3 A method 30 for registering a plurality of services 15 for the user 11 as described in step 21 is shown.

[0064] In step 31, the user 11 entrusts the system 10 to manage user consent and the corresponding user consent information at the service 15.

[0065] In step 32, a token is then generated by means of the consent management unit 12.

[0066] The token includes at least one of a consent management system network address, a service network address, a user request, a timestamp, a validity period of user consent, and a digital signature. For example, the network addresses of the consent management system 10 and the service 15 are their respective uniform resource locators (URLs). The user request is a request to register for the service 15 by the user 11. The user request also records information about the user request. The timestamp provides an indication of the time when the token is generated and / or updated. The validity period of user consent provides the date range during which the token is valid. If the token is no longer valid, the consent management unit 12 generates an updated token. The digital signature is provided by the user 11 and provides confirmation that the user 11 has acknowledged the token.

[0067] In step 33, the token is returned to the user 11 for the user to acknowledge the token.

[0068] In step 34, once the consent management unit 12 confirms and receives the user's acknowledgment, the token is registered for the service 15 by means of the consent management unit 12.

[0069] In step 35, the consent management unit 12 then provides a request containing the token to the service 15 to request management of user consent.

[0070] In step 36, the consent management unit 12 receives a response corresponding to the registration request from the service 15.

[0071] The consent operation in step 33 includes an operation of adopting data privacy preference information associated with the user 11. The operation of adopting data privacy preference information also includes: responding to a user request from the user 11, responding to service requests from multiple services 15, and / or determining whether the user consent information associated with the user 11 is consistent with the data access requirements of the service 15.

[0072] In responding to a user request from the user 11, the consent management unit 12 receives the user request from the user 11 and requests multiple services 15 to complete the user request. The consent management unit 12 then synchronizes the user consent information between the consent management system 10 and the multiple services 15.

[0073] Figure 4 A method 40 for synchronizing user consent information between the consent management system 10 and multiple services 15 is shown.

[0074] In step 41, the process is triggered by a user request to update user consent. The process is also triggered when the user consent and / or user consent information is updated or modified.

[0075] In step 42, the consent management unit 12 receives the updated user consent and updates the user consent stored in the data storage unit 14 based on the received updated user consent.

[0076] In step 43, the consent management unit 12 then provides the updated user consent to the plurality of services 15, for example, using an authentication process. For example, the consent management unit 12 provides the updated user consent to the database of the service 15.

[0077] In step 44, the user requests at the plurality of services 15 are then synchronized with respect to the updated user consent. For example, the updated user consent at the service management unit of the service 15 is synchronized with the updated user consent at the consent management unit 12. Additionally, the service 15 internally synchronizes the updated user consent between the service management unit and the database of the service 15.

[0078] In step 45, when the consent management unit 12 receives a response confirming the synchronization status from the plurality of services 15, the process is completed. For example, the consent management unit 12 receives a response from the service management unit.

[0079] The consent management unit 12 provides the user 11 with an option to directly contact the plurality of services or a specific service, for example, via the user interface unit 13 using their request.

[0080] The operation of adopting data privacy preference information also includes responding to service requests from the service 15. The service requests include, but are not limited to, updating the privacy notice and / or updating the user consent.

[0081] Figure 5 A method 50 for updating the privacy notice is shown.

[0082] In step 51, the consent management unit 12 receives a privacy notice update request from the plurality of services 15.

[0083] In step 52, the consent management unit 12 notifies the user 11 of the privacy notice update, for example, by providing a notice.

[0084] In step 53, the user 11 provides a response to the consent management unit 12. The response includes the updated user consent corresponding to the privacy notice update.

[0085] In step 54, the consent management unit 12 generates a backup of the updated user consent and stores it in the data storage unit 14.

[0086] In step 55, the consent management unit 12 provides a response to the plurality of services 15. For example, the response can be provided to the service management unit. When the consent management unit 12 receives a response from the plurality of services 15 confirming the status of the privacy notice update, the process is completed. The consent management unit 12 can receive a response from the service management unit, for example.

[0087] It should be appreciated from the above description that the proposed system may employ a controller or a processor for processing data.

[0088] Figure 6 An example of a computer 60 for implementing the controller or processor described above is illustrated.

[0089] The computer 60 includes, but is not limited to, a PC, a workstation, a laptop computer, a PDA, a handheld device, a server, a storage device, etc. Generally speaking, in terms of the hardware architecture, the computer 60 may include one or more processors 61, a memory 62, and one or more I / O devices 63 that are communicatively coupled via a local interface (not shown). The local interface can be, for example, but not limited to, one or more buses or other wired connections or wireless connections, as known in the art. The local interface may have additional elements for implementing communication, such as, for example, controllers, buffers (caches), drivers, transponders, and receivers. In addition, the local interface may include address connections, control connections, and / or data connections to enable proper communication among the above components.

[0090] The processor 61 is a hardware device for executing software that can be stored in the memory 62. The processor 61 can substantially be any custom or commercially available processor, a central processing unit (CPU), a digital signal processor (DSP), or a secondary processor among several processors associated with the computer 60, and the processor 61 can be a semiconductor-based microprocessor (in the form of a microchip) or a microprocessor.

[0091] The memory 62 can include any one or a combination of volatile memory elements (e.g., random access memory (RAM) such as dynamic random access memory (DRAM), static random access memory (SRAM), etc.) and non-volatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic tape, compact disc read-only memory (CD-ROM), magnetic disk, floppy disk, cassette tape, cartridge tape, etc.). In addition, the memory 62 can include electrical, magnetic, optical, and / or other types of storage media. Note that the memory 62 can have a distributed architecture, where multiple components are located far from each other but can be accessed by the processor 61.

[0092] The software in the memory 62 can include one or more separate programs, each of which includes an ordered list of executable instructions for implementing a logical function. The software in the memory 62 includes a suitable operating system (O / S) 64, a compiler 65, source code 66, and one or more applications 67 according to the exemplary embodiments.

[0093] Application 67 includes a number of functional components such as computing units, logic, functional units, processes, operations, virtual entities, and / or modules.

[0094] Operating system 64 controls the execution of computer programs and provides scheduling, input-output control, file and data management, memory management, and communication control and related services.

[0095] Application 67 can be a source program, an executable program (object code), a script, or any other entity that contains a set of instructions to be executed. When it is a source program, the program is typically translated via a compiler (e.g., compiler 65), assembler, interpreter, etc., which may or may not be included in memory 62, in order to operate properly in conjunction with operating system 64. Additionally, application 67 can be written in an object-oriented programming language (with classes of data and methods), or a procedural programming language (with routines, subroutines, and / or functions), such as but not limited to C, C++, C#, Pascal, BASIC, API calls, HTML, XHTML, XML, ASP scripts, JavaScript, FORTRAN, COBOL, Perl, Java, ADA,.NET, etc.

[0096] I / O device 63 can include input devices such as but not limited to a mouse, keyboard, scanner, microphone, camera, etc. Additionally, I / O device 63 can also include output devices such as but not limited to a printer, display, etc. Finally, I / O device 63 can also include devices that communicate with both input and output, such as but not limited to, a network interface controller (NIC) or a modem / demodulator (for accessing remote devices, other files, devices, systems, or networks), a radio frequency (RF) or other transceiver, a telephone interface, a bridge, a router, etc. I / O device 63 also includes components for communicating over a variety of networks (e.g., the Internet or an intranet).

[0097] When computer 60 is in operation, processor 61 is configured to execute software stored in memory 62, transfer data to and from memory 62, and generally control the operation of computer 60 in accordance with the software. Application 67 and operating system 64 are read in whole or in part by processor 61, perhaps cached within processor 61, and then executed.

[0098] When application 67 is implemented in software, it should be noted that application 67 can be substantially stored in any computer-readable medium for use by or in conjunction with any computer-related system or method. In the context of this document, a computer-readable medium can be an electronic, magnetic, optical, or other physical device or component that contains or stores a computer program for use by or in conjunction with a computer-related system or method.

[0099] Those skilled in the art can understand and implement other variations of the disclosed embodiments when studying the drawings, the specification, and the claims during the practice of the claimed invention. In the claims, the word "comprising" does not exclude other elements or steps, and the words "a" or "an" do not exclude a plurality. Although certain measures are recited in mutually different dependent claims, this does not indicate that the combination of these measures cannot be used advantageously. Any reference signs in the claims should not be construed as limiting the scope.

[0100] System 10 may be a blockchain-based consent management system. The blockchain-based system may be adapted to record user consent information, privacy notices from multiple services 15, user requests, and / or service requests.

[0101] In an embodiment, the user request may be a request to revoke user consent. To revoke user consent, user 12 may, for example, use user interface unit 13 to access consent management system 10. Then, user 11 may request to revoke the user's consent for multiple services 15 or a specific service 15. Consent management unit 12 may then provide the request to multiple services 15 or the specific service 15.

[0102] In another embodiment, the user request may be a request to correct user consent information. To correct user consent information, user 12 may, for example, use user interface unit 13 to access consent management system 10. Then, user 11 may request to correct the user's consent information for multiple services 15 or a specific service 15. Consent management unit 12 may then provide the request to multiple services 15 or the specific service 15. For example, system 10 serves as an audit platform for correcting user consent information.

[0103] In another embodiment, the user request may be a request to delete user consent information. To delete user consent information, user 12 may, for example, use user interface unit 13 to access consent management system 10. Then, user 11 may request to delete the user's consent information for multiple services 15 or a specific service 15. Consent management unit 12 may then provide the request to multiple services 15 or the specific service 15.

[0104] Those skilled in the art can understand and implement variations of the disclosed embodiments when studying the accompanying drawings, the description, and the claims in practicing the claimed invention. In the claims, the word "comprising" does not exclude other elements or steps, and the words "a" or "an" do not exclude a plurality. A single processor or other unit may implement the functions of several items recited in the claims. Although certain measures are recited in mutually different dependent claims, this does not indicate that the combination of these measures cannot be used advantageously. If a computer program is as discussed above, it may be stored / distributed on a suitable medium, such as an optical storage medium or a solid-state medium supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems. If the term "adapted to" is used in the claims or the description, it should be noted that the term "adapted to" is intended to be equivalent to the term "configured to". Any reference signs in the claims should not be construed as limiting the scope.

Claims

1. A consent management system (10) for managing user consent for multiple services (15), the system comprises: A consent management unit (12) adapted to: Register multiple services for a user (11); Obtain user consent information associated with the user (11); and Control consent operations for the multiple services (15) registered for the user (11) based on the user consent information associated with the user (11), wherein the consent operations include operations that employ data privacy preference information associated with the user (11), and wherein the operations that employ data privacy preference information include responding to a service request from one of the multiple services (15), and wherein, in responding to the service request, the consent management unit (12) is adapted to: Receive the service request from a specific service among the multiple services (15); Notify the user (11) of updates from the multiple services (15) in response to the service request from the specific service; Receive a user response; and Respond to the multiple services (15) according to the user response.

2. The system according to claim 1, wherein, The operations that employ data privacy preference information include at least one of the following: Respond to a user request from the user (11); and Determine whether the user consent information associated with the user (11) is consistent with the data access requirements of the service (15).

3. The system according to claim 2, wherein, In responding to a user request from the user (11), the consent management unit (12) is adapted to: Receive the user request from the user (11); Request the multiple services (15) to complete the user request; and Synchronize the user consent information between the consent management system (10) and the multiple services (15).

4. The system according to claim 2 or 3, wherein, The user request includes one or more of the following: Update the user consent; Revoke the user consent; Correct the user consent information; and Delete the user consent information.

5. The system according to claim 2 or 3, wherein, The service request includes one or more of the following: Update the privacy notice; and Update the user consent.

6. The system according to any one of claims 1 to 3, wherein, The system (10) further includes a data storage unit (14) adapted to store the user consent information associated with the user (11).

7. The system according to any one of claims 1 to 3, wherein, In registering the multiple services (15) for the user (11), the consent management unit (12) is adapted to: Entrust the consent management unit (12) to manage the user consent; Generate a token; and Use the token to register the multiple services (15) for the user (11).

8. The system according to claim 7, wherein, The token includes at least one of the following: Consent management system network address; Service network address; User request; Timestamp; The validity period agreed by the user; and Digital signature.

9. The system according to any one of claims 1 to 3, wherein, the system (10) further includes a user interface unit (13), and the user interface unit is adapted to display one or more of the following: a list of the plurality of services (15); notifications from the plurality of services (15); a list of consent items; and a list of user permissions.

10. The system according to claim 9, wherein, the system (10) is a blockchain-based consent management system, and the blockchain-based consent management system is adapted to record one or more of the following: the user consent information; privacy notifications from the plurality of services (15); user requests; and service requests.

11. The system according to any one of claims 1 to 3, wherein, the consent management unit (12) is further adapted to receive the user consent information.

12. A computer program product for managing user consent for a plurality of services, the computer program product includes a computer-readable storage medium having program instructions embodied therewith, and the program instructions can be run by a processing unit to cause the processing unit to execute a method, the method includes: registering a plurality of services for the user; obtaining user consent information associated with the user; and controlling consent operations of the plurality of services registered for the user based on the user consent information associated with the user, wherein the consent operations include operations of adopting data privacy preference information associated with the user (11), and the operations of adopting data privacy preference information include operations of responding to a service request from one of the plurality of services (15), and in the process of responding to the service request, the following steps are executed: receiving the service request from a specific service among the plurality of services (15); notifying the user (11) of updates from the plurality of services (15) in response to the service request from the specific service; receiving a user response; and responding to the plurality of services (15) according to the user response.

13. A method (20) for managing user consent for a plurality of services, the method includes: registering (21) a plurality of services for the user; obtaining (22) user consent information associated with the user; and controlling (23) consent operations of the plurality of services registered for the user based on the user consent information associated with the user, wherein the consent operations include operations of adopting data privacy preference information associated with the user (11), and the operations of adopting data privacy preference information include operations of responding to a service request from one of the plurality of services (15), and in the process of responding to the service request, the following steps are executed: receiving the service request from a specific service among the plurality of services (15); Notify the user (11) of updates from the plurality of services (15) in response to the service request from the specific service; Receive a user response; and Respond to the plurality of services (15) according to the user response.

Citation Information

Patent Citations

  • Apparatuses, methods and systems for a mobile healthcare manager-based video prescription provider

    US20110119290A1

  • System and method for controlling communication of private information over a network

    US20120331567A1