Privacy compliance processing systems, methods, devices, storage media, and program product

By working together with the server-side and privacy compliance components, enterprise customers can edit privacy agreements and solidify authorization information, solving the problem of self-verification of privacy compliance, improving processing efficiency and accuracy, and enhancing customer experience.

CN114580020BActive Publication Date: 2026-02-03YOUMENG TONGXIN BEIJING TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210209839.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-04
Publication Date
2026-02-03
Estimated Expiration
2042-03-04

AI Technical Summary

Technical Problem

Enterprise clients often find it difficult to prove their privacy compliance. Existing privacy compliance testing methods are cumbersome and provide a poor customer experience, making it impossible to effectively demonstrate compliance with privacy requirements.

Method used

A privacy compliance processing system is provided, including a server and a privacy compliance component. The server provides a privacy agreement editing page to obtain privacy agreement information input by the application provider. The user terminal generates authorization information through the privacy compliance component and sends it to the server. The server verifies the authorization information, realizing professional and simple privacy agreement configuration and authorization verification.

Benefits of technology

It improved the efficiency and accuracy of privacy compliance processing, enhanced the compliance attributes of enterprise customers, simplified operating procedures, and improved customer experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114580020B_ABST
    Figure CN114580020B_ABST
Patent Text Reader

Abstract

The application provides a privacy compliance processing system, method, device, storage medium and program product, comprising a server and a privacy compliance component: the server is used for providing a privacy agreement editing page, obtaining privacy agreement information input by a provider of an application program on the privacy agreement editing page, the application program is built-in with the privacy compliance component, and a user terminal installed with the application program is used for obtaining and displaying the privacy agreement information through the privacy compliance component, and generating corresponding authorization information according to an authorization operation of the user on at least part of the privacy agreement information and sending the authorization information to the server; the server is also used for fixing the authorization information of the user, so that the server can provide the provider, such as an enterprise customer, with professional privacy agreement information configuration and authorization fixing capabilities, help the enterprise customer prove that the application program meets the privacy compliance requirements and effectively implement privacy agreement editing, authorization information fixing and other operations, and improve the processing efficiency and accuracy of privacy compliance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data compliance technology, and in particular to a privacy compliance processing system, method, device, storage medium and program product. Background Technology

[0002] The rapid development of the internet has led to increasingly serious exposure of user information, prompting relevant departments to strengthen requirements for applications to comply with privacy regulations when acquiring user privacy information.

[0003] In some technologies, applications on a device can pass privacy compliance checks and be successfully listed on app stores through processes such as application testing, problem identification, and application rectification. However, this method still carries the risk of failing to prove compliance with privacy requirements, and it is cumbersome and offers a poor user experience. Summary of the Invention

[0004] The main objective of this application is to provide a privacy compliance processing system, method, device, storage medium, and program product to solve the problem that enterprise customers have difficulty proving their privacy compliance, improve the efficiency and accuracy of privacy compliance processing, and enhance the experience of enterprise customers.

[0005] In a first aspect, embodiments of this application provide a privacy compliance processing system, including a server and a privacy compliance component:

[0006] The server is used to: provide a privacy agreement editing page, and obtain the privacy agreement information entered by the application provider on the privacy agreement editing page. The privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties.

[0007] The application has a built-in privacy compliance component. The user terminal with the application installed is used to: obtain and display the privacy agreement information through the privacy compliance component, and generate corresponding authorization information and send it to the server based on the user's authorization operation for at least part of the privacy agreement information.

[0008] The server is also used to: secure the user's authorization information.

[0009] Secondly, embodiments of this application provide a privacy compliance processing method, which is applied to a server and includes:

[0010] Obtain the privacy agreement information entered by the application provider on the provided privacy agreement editing page; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0011] The system receives authorization information sent by a user terminal with an application installed through a privacy compliance component; the authorization information is generated by the privacy compliance component based on the user's authorization operation regarding certain privacy agreement information; the privacy compliance component is set within the application; the privacy agreement information is obtained from the server through the privacy compliance component and displayed.

[0012] The user's authorization information is verified.

[0013] Thirdly, embodiments of this application provide a privacy compliance processing method, wherein the method is applied to a privacy compliance component, the privacy compliance component is set within an application, and the application is installed on a user terminal, and the method includes:

[0014] The privacy agreement information is obtained and displayed; the privacy agreement information is entered by the application provider on the privacy agreement editing page provided by the server; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0015] Based on the user's authorization actions regarding at least some privacy agreement information, corresponding authorization information is generated and sent to the server so that the server can verify the user's authorization information.

[0016] Fourthly, embodiments of this application provide an electronic device, including:

[0017] At least one processor; and

[0018] A memory that is communicatively connected to the at least one processor;

[0019] The memory stores instructions that can be executed by the at least one processor to cause the electronic device to perform the method described in any of the above aspects.

[0020] Fifthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described in any of the above aspects.

[0021] Sixthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method described in any of the above aspects.

[0022] The privacy compliance processing system, method, device, storage medium, and program products provided in this application include a server and a privacy compliance component. The server provides a privacy agreement editing page and obtains privacy agreement information entered by the application provider on the privacy agreement editing page. The privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect and a list of personal information that it expects to share with third parties. The application has a built-in privacy compliance component. A user terminal with the application installed is used to: obtain and display the privacy agreement information through the privacy compliance component; generate corresponding authorization information and send it to the server based on the user's authorization operations for at least some of the privacy agreement information; and the server is also used to: verify the user's authorization information. This provides application providers, such as enterprise customers, with professional, simple, and unified privacy agreement information configuration and authorization verification capabilities. It not only helps enterprise customers prove that their applications comply with privacy compliance requirements and enhance their compliance attributes, but also helps them quickly, smoothly, and effectively perform a series of operations such as privacy agreement editing and authorization information verification, improving the efficiency and accuracy of privacy compliance processing and enhancing the user experience. Attached Figure Description

[0023] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0024] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;

[0025] Figure 2 This is a schematic diagram of the structure of a privacy compliance processing system provided in an embodiment of this application;

[0026] Figure 3 A schematic diagram of device interaction provided in an embodiment of this application;

[0027] Figure 4 A schematic diagram illustrating a privacy compliance processing framework provided in this application embodiment;

[0028] Figure 5 An interactive diagram illustrating the management, authorization, and authentication of a privacy protocol provided in an embodiment of this application;

[0029] Figure 6 A schematic diagram illustrating a process for generating a privacy authorization string, provided as an embodiment of this application;

[0030] Figure 7 A schematic diagram of a privacy agreement editing page provided for an embodiment of this application;

[0031] Figure 8This is a schematic diagram of a personal information list editing page provided in an embodiment of this application;

[0032] Figure 9A A schematic diagram of a third-party shared personal information list editing page provided in an embodiment of this application;

[0033] Figure 9B A schematic diagram of an editing page for a shared list of related parties provided in an embodiment of this application;

[0034] Figure 9C A schematic diagram of an SDK shared manifest editing page provided for an embodiment of this application;

[0035] Figure 9D A schematic diagram of an editing page for a shared list of partners provided in an embodiment of this application;

[0036] Figure 10 A schematic diagram of an authorization pop-up editing page provided for an embodiment of this application;

[0037] Figure 11 A schematic diagram of a pop-up button editing page provided in an embodiment of this application;

[0038] Figure 12 A schematic diagram illustrating a package licensing model provided for an embodiment of this application;

[0039] Figure 13 A schematic diagram illustrating a per-item individual licensing mode provided for an embodiment of this application;

[0040] Figure 14 A flowchart illustrating a privacy compliance processing method provided in an embodiment of this application;

[0041] Figure 15 A flowchart illustrating another privacy compliance processing method provided in this application embodiment;

[0042] Figure 16 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0043] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0044] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0045] First, let me explain the terms used in this application:

[0046] CMP: Consent Manage Platform, a data compliance and evidence management platform.

[0047] CMPSDK: The SDK (Software Development Kit) provided by CMP for application developers among enterprise customers to access, serves as the implementation vehicle for this solution.

[0048] Third-party SDKs: Third-party SDKs integrated into an application may collect system or user information during application runtime.

[0049] RCString: A special string generated according to a certain algorithm, which records information such as user authorization operations in a specific format. In this article, it is referred to as "privacy authorization string".

[0050] Abstract: A message of arbitrary length can be generated by calculating a digest algorithm (e.g., a one-way hash encryption function); by comparing the digest corresponding to the received message with the original digest, it can be determined whether the message has been changed.

[0051] Credentials: Uploading a summary to the blockchain can be considered a blockchain transaction. Each transaction generates a unique blockchain transaction number, which serves as the credential. Information about the blockchain transaction can be obtained through the credential.

[0052] The application scenarios and inventive concepts of this application will be explained below.

[0053] With increasing emphasis on user privacy across industries and the enactment of relevant laws, ensuring that applications comply with privacy regulations has become a crucial legal requirement for businesses. Relevant departments have repeatedly inspected and penalized applications on the market, even removing them from app stores. The main issues involved include: obtaining user information without authorization; obtaining user information beyond the scope of business operations; and failing to specify the purpose and purpose of third-party SDKs obtaining user information in their privacy policies. Relevant legal provisions also stipulate that "if the processing of personal information infringes upon the rights and interests of personal information and causes damage, the personal information processor shall bear tort liability such as compensation for damages unless it can prove that it was not at fault." Therefore, all companies need to ensure they "prove their innocence" in terms of privacy compliance and security.

[0054] In view of this, this application provides a technical solution for realizing privacy agreement disclosure, compliant data collection, and compliant use, providing a service server and a privacy compliance component. The service server can be deployed within the domain of the application provider or in the cloud, enabling professional and simplified privacy agreement configuration. The privacy compliance component can be deployed on the user terminal, providing various data compliance and evidence-gathering capabilities to meet the relevant purposes and requirements for personal information protection, helping the provider to "prove its innocence" in terms of privacy compliance and privacy security, and enhancing its own compliance attributes.

[0055] In this application embodiment, the provider can be any customer capable of providing the application, for example, it can be an enterprise customer (such as a software development company), an individual customer (a single developer), a team customer (a team of multiple developers), etc.

[0056] Optionally, when the provider is an enterprise client or a team client, the specific personnel interacting with the server can be any person within the enterprise client or team client. For example, when a software development company is the provider, the application can be written or released by developers within the company, and operations and maintenance personnel can input privacy policies or view authorization information, etc.

[0057] For ease of description, this application embodiment uses an enterprise customer as an example for illustration.

[0058] Figure 1 This is an application scenario diagram provided for an embodiment of this application. For example... Figure 1As shown, this application provides a service server and a privacy compliance component. This component can be in the form of an SDK, namely a privacy compliance SDK. Enterprise customers can edit or save privacy agreement information through the server. In addition, the privacy compliance SDK can be built into the APP developed by the enterprise customer. Each user terminal with the APP installed can obtain privacy agreement information from the server through the privacy compliance SDK. The privacy agreement information can reveal two lists, including a list of personal information that the APP expects to collect and a list of personal information that it expects to share with third parties, for users to authorize personal information. The privacy compliance SDK can feed back the authorization information to the server, and the server can solidify the privacy agreement information and the corresponding authorization result of the user.

[0059] During app usage, if the app or a third-party SDK needs to collect users' personal information, it can first obtain the corresponding authorization result from the privacy compliance SDK and collect personal information only after confirming that the user has given their consent. If any user questions the app's collection behavior or files a lawsuit, the user's authorization can be confirmed through the server-side evidence.

[0060] Optionally, the technical solution provided in this application can be applied to any scenario that requires disclosure of privacy agreements and authorization of personal information.

[0061] For example, in the live streaming field, users can watch video content through live streaming software. This software can incorporate a third-party SDK, which can be a payment application, enabling users to purchase goods from the live streaming platform. When watching video content, the software can collect the user's location and voice information; when purchasing goods, the third-party SDK can collect the user's billing and location information. Here, the third-party SDK is a software development kit provided by a third-party vendor to implement a specific function of the software product.

[0062] Optionally, the server can provide a privacy agreement editing page to enterprise users who provide the live streaming software, and obtain the privacy agreement information entered by the enterprise customer on the privacy agreement editing page. The privacy agreement information includes at least one of the following: a list of personal information that the live streaming software provided by the enterprise customer expects to collect, and a list of personal information that it expects to share with third parties. The application has a built-in privacy compliance SDK, and the user terminal with the live streaming software installed is used to: obtain and display the privacy agreement information through the privacy compliance SDK, and generate corresponding authorization information and send it to the server based on the user's authorization operations for at least some of the privacy agreement information. The server is also used to: verify the user's authorization information.

[0063] Specifically, the live streaming software may include a live streaming service program for implementing the live streaming business, as well as a privacy compliance SDK and third-party SDKs such as a payment SDK, which can be used to communicate with the server.

[0064] The server can be used to provide a privacy agreement editing page to obtain privacy agreement information. This privacy agreement information, also known as a privacy policy, may include two lists: one list contains personal information that the live streaming service program expects to collect, such as image information, audio information, and contact information; the other list contains personal information that it expects to share with third parties, such as billing information and location information.

[0065] Users can authorize the dual lists, allowing live streaming applications and third-party SDKs to collect at least some of their personal information, or disallowing the collection of any personal information. The privacy compliance SDK can record and upload user authorization information, allowing live streaming applications and third-party SDKs to query the authorization information before collecting personal information.

[0066] The above solution provides enterprise clients in the live streaming industry with a professional and simplified process for configuring privacy agreement information and verifying authorization. Enterprise clients do not need to perform cumbersome development work through professional personnel. It not only helps enterprise clients smoothly complete a series of operations such as editing privacy agreements and verifying authorization information to prove that the application complies with privacy compliance requirements, but also simplifies customer operations and improves the user experience.

[0067] Furthermore, the embodiments of this application can also be applied to other fields. For example, in the film and television industry, users can watch programs through video and TV show software. Third-party SDKs can be set up in these software programs, and these SDKs can also be payment software, enabling users to purchase memberships or other goods through them. When watching programs using video and TV show software, the live streaming software can collect users' contact information, location information, and voice information, etc.; when purchasing goods, the third-party SDK can collect users' billing information, etc.

[0068] The following detailed description of some embodiments of this application is provided in conjunction with the accompanying drawings. Where there is no conflict between the embodiments, the following embodiments and features can be combined with each other. Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0069] Figure 2 This is a schematic diagram illustrating the structure of a privacy compliance processing system provided in an embodiment of this application. The privacy compliance processing system provided in this embodiment includes: a server and a privacy compliance component.

[0070] The server is used to: provide a privacy agreement editing page, and obtain the privacy agreement information entered by the application provider on the privacy agreement editing page. The privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties.

[0071] The application has a built-in privacy compliance component. The user terminal with the application installed is used to: obtain and display the privacy agreement information through the privacy compliance component, and generate corresponding authorization information and send it to the server based on the user's authorization operation for at least part of the privacy agreement information.

[0072] The server is also used to: secure the user's authorization information.

[0073] Optionally, the server can be software, hardware, or a combination of both. The server can perform authentication in a manner that meets credibility requirements, for example, through blockchain. The server can directly display the privacy agreement editing page to the provider, or it can send the privacy agreement editing page to the enterprise terminal for display to the provider.

[0074] Optionally, the server-side component can be a Privacy Compliance Management Platform (CMP), which provides an editor that allows providers to edit privacy agreements. Providers can operate this interface through their enterprise terminals. The personal information list includes personal information that the application expects to collect during runtime. The third-party shared personal information list includes personal information that the application shares with third-party services. This can be achieved by collecting and sending the information to the third-party service through a third-party SDK set within the application, or by the application's server directly sending it to the third-party service.

[0075] For example, in the live streaming field, live streaming software collects users' personal information based on a personal information list, and payment software set up in the live streaming software collects personal information based on a personal information list shared by a third party.

[0076] In this embodiment, the server can display a privacy agreement editing page to the provider, allowing the provider to edit privacy agreement information, such as editing a personal information list or a list of personal information that they wish to share with third parties, to obtain and save the privacy agreement information on the server. Optionally, the server can display the privacy agreement editing page to the provider upon receiving a privacy agreement editing request from the provider. For example, the server might display the privacy agreement editing page to the provider when it detects that the provider has clicked on a preset website.

[0077] For user terminals, an application is installed on the terminal, and this application includes a built-in privacy compliance component. For example, a privacy compliance component (CMPSDK) can be set up in live streaming software. The application needs to obtain the user's authorization information before collecting user information. Specifically, when preset conditions are met, the privacy compliance component can retrieve and display the privacy agreement information corresponding to the application from the server online.

[0078] In addition to the above-mentioned method of obtaining privacy agreement information from the server online through the privacy compliance component, the privacy agreement information corresponding to the application can also be pre-built in the privacy compliance component. This allows for quick display when user authorization information needs to be obtained, improving display efficiency.

[0079] After the privacy agreement information is displayed, users can authorize at least some of the privacy agreement details. The server can generate corresponding authorization information and send it to the client. Once the server receives the authorization information uploaded by the privacy compliance component, it can upload the authorization information to the blockchain to solidify the authorization information.

[0080] Optionally, the authorization information can be used to indicate whether the user authorizes the collection of personal information in the privacy policy. For example, the authorization information could indicate that the user authorizes the collection of all personal information mentioned in the privacy policy, or that the user refuses to have all personal information collected, or that the user authorizes the collection of some personal information.

[0081] In addition, the authorization information may also include other information such as the user authorization time. For example, the authorization information may include four elements: the user's temporary identity identifier, the time of occurrence, the authorization result, and the identifier of the corresponding privacy agreement information. Specifically, the identifier of the corresponding privacy agreement information can be the credential used to authenticate the privacy agreement information on the blockchain.

[0082] Optionally, when facing related lawsuits from users, the provider can use information obtained from the blockchain as evidence to prove that the collection of users' personal information was carried out in accordance with the users' authorization, thus proving the company's innocence.

[0083] In summary, the privacy compliance processing system provided in this embodiment includes a server and a privacy compliance component. The server provides a privacy agreement editing page and obtains the privacy agreement information entered by the provider on the privacy agreement editing page. The privacy agreement information includes at least one of the following: a list of personal information that the application provided by the provider expects to collect, and a list of personal information that it expects to share with third parties. The application has a built-in privacy compliance component. The user terminal with the application installed is used to: obtain and display the privacy agreement information through the privacy compliance component; generate corresponding authorization information and send it to the server based on the user's authorization operations for at least some of the privacy agreement information; and the server is also used to: verify the user's authorization information. This provides application providers, such as enterprise customers, with professional, simple, and unified privacy agreement information configuration and authorization verification capabilities. It not only helps enterprise customers prove that their applications comply with privacy compliance requirements and enhance their compliance attributes, but also helps them quickly, smoothly, and effectively perform a series of operations such as privacy agreement editing and authorization information verification, improving the efficiency and accuracy of privacy compliance processing and enhancing the user experience.

[0084] Figure 3 This is a schematic diagram of device interaction provided for an embodiment of this application. Figure 3 As shown, optionally, the privacy compliance process may involve interactions between devices such as the server, user terminal, enterprise terminal, and blockchain. The main process is as follows: When generating privacy agreement information, the server displays a privacy agreement editing page to the enterprise terminal and obtains the privacy agreement information sent by the enterprise terminal. When obtaining user authorization information, the server displays the privacy agreement information on the user terminal and receives the authorization information uploaded by the user terminal. When validating the authorization information, the server sends the authorization information to the blockchain and obtains the credential from the blockchain when verification is required. The server can be deployed in the enterprise customer's data center or provided as a shared server in a SaaS (Software-as-a-Service) manner.

[0085] During the interaction between the server and the enterprise terminal, after an enterprise customer generates and publishes privacy agreement information based on the privacy editing page, they can also update the privacy agreement information. When an enterprise customer needs to update the generated privacy agreement information, the operation process is the same as the initial generation process; simply update the version of the generated privacy agreement information. When the server stores privacy agreement information edited by different enterprise customers, it can obtain the enterprise customer's identification information to distinguish between them and store the identification information and the privacy agreement information accordingly. For example, the identification information can be an application identifier.

[0086] During the interaction between the server and the user terminal, the privacy compliance component in the application displays privacy agreement information to the user when preset conditions are met. For example, the preset conditions could be scenarios requiring the acquisition of user authorization information. These scenarios could include: the user opening the application for the first time; or the privacy agreement information being updated; or the current time being a preset duration since the last acquisition of authorization information. The preset conditions can be set according to the needs of enterprise customers.

[0087] In practical applications, when a user opens the application for the first time, the privacy compliance SDK can determine the user ID and obtain the latest privacy agreement information corresponding to the application from the server, and display it to the user in the form of a pop-up window.

[0088] After the privacy agreement is displayed, users can authorize at least some parts of the privacy agreement, allowing them to check boxes to consent to the collection of personal information by the application. This application does not restrict the application platform; the application can cover various application terminals, such as Android, iOS, mini-programs, and web.

[0089] Regarding the interaction between the server and the blockchain, after receiving authorization information, the server can process it and send it to the blockchain. When verification of the authorization information is required, a certificate can be obtained from the blockchain, and based on the certificate, it can be determined whether the user has authorized the collection of certain personal information. When facing related lawsuits from users, enterprises can use the certificates obtained from the blockchain as evidence to prove that the collection of users' personal information was carried out in accordance with the users' authorization, thus proving the enterprise's innocence.

[0090] In one or more embodiments of this application, optionally, the server is specifically configured to generate a corresponding digest based on the user's authorization information, send it to the blockchain for storage, and obtain a credential corresponding to the digest returned by the blockchain; wherein the digest and credential are used for the provider, the user, or a judicial institution to verify the user's authorization information.

[0091] Optionally, when generating the corresponding digest based on the user's authorization information, it can be generated using an anonymization process performed by a message digest algorithm. Optionally, one authorization information corresponds to one digest. The message digest algorithm can be a one-way hash encryption function, which is used to process the authorization message and generate the digest.

[0092] In addition to securing authorization information, privacy agreement information can also be secured. The process of securing privacy agreement information is the same as that of securing authorization information, that is, the privacy agreement information is processed through a message digest algorithm to obtain the corresponding digest, the obtained digest is sent to the blockchain for storage, and the credential returned by the blockchain is received.

[0093] The system can store privacy agreement information, authorization information, and their corresponding digests and credentials on the server side. When a user needs verification, the system checks whether the digests and credentials stored on the server side are consistent with those stored on the blockchain. If they are consistent, it indicates that the authorization information corresponding to the digests stored on the server side has not been tampered with. The user can be the application provider, a user, or a judicial institution.

[0094] Optionally, authorization information and privacy agreement information can be linked and verified. For example, a privacy policy credential can be added to the authorization information to identify the privacy policy information pointed to by the authorization information.

[0095] The above solution enables the storage of digests and credentials on both the server and the blockchain. The comparison of digests and credentials between the two ends facilitates the verification of authorization information and ensures the authenticity and credibility of authorization events.

[0096] In one or more embodiments of this application, optionally, the application has a built-in third-party SDK; the application is used to: query whether the user has authorized the application to collect the personal information before collecting any personal information through a privacy compliance component; if authorized, then call the personal information collection interface to collect the personal information.

[0097] The third-party SDK is used to: query whether the user has authorized sharing the personal information with a third party through a privacy compliance component before collecting any personal information; if authorized, then call the personal information collection interface to collect the personal information.

[0098] Figure 4 This application provides a schematic diagram of a privacy compliance processing framework, as shown in the embodiments of the present application. Figure 4As shown, the privacy compliance component can send user authorization information to the server via a privacy compliance string. After user authorization, personal information can be collected. The personal information collected by the application can be sent to the application service for processing. Specifically, this can be done by the application's business processing module, such as the live streaming business processing module in live streaming software. Personal information collected by a third-party SDK can be sent to a third-party service for processing. The personal information sent to the application service can be user-authorized information collected by the application, while the personal information sent to the third-party service can be user-authorized information shared with a third party. The application service and third-party service are equivalent to the application's server and the server providing third-party functionality, respectively, and can be deployed on a server or in the cloud.

[0099] For example, when a user is watching a live stream, the live streaming software may want to collect the user's personal information, such as location information, in order to recommend nearby live streams to the user. If the application directly collects the user's location information, there may be issues with non-compliance in information collection. Therefore, before collecting any personal information, the application should first determine whether the user has authorized the collection of that personal information.

[0100] Specifically, applications can query the server to see if personal information has been authorized by calling the relevant interfaces of privacy compliance components. When authorization is confirmed, the application collects the personal information by calling the personal information collection interface, thereby enabling the application service. For example, after collecting a user's location information, it can recommend nearby live streams to the user.

[0101] For example, the query process can be as follows: An application or third-party SDK sends a query request to a privacy compliance component. This request includes the user ID and the personal information to be collected. The privacy compliance component then sends the query request to the server. The server obtains the corresponding list of authorized personal information using the user ID and queries this list to determine if the requested personal information exists. If it does, the server sends a preset string to the privacy compliance component. The privacy compliance component then sends the authorized or unauthorized information to the application and performs the appropriate action based on the authorization status.

[0102] Alternatively, the query process could be as follows: Obtain complete authorization information, such as a privacy authorization string, from the server through the privacy compliance component; obtain a list of authorized personal information using the privacy agreement information and the privacy authorization string; then determine if the personal information to be collected exists in the list of authorized personal information; obtain the query result; and send the query result to the application. Alternatively, the privacy compliance component could cache complete authorization information, allowing for direct querying based on the cached information.

[0103] When a third-party SDK needs to collect personal information, it also needs to call the privacy compliance component to query whether the user has authorized sharing that personal information with the third party. The implementation process is similar to that of the applications mentioned above when collecting personal information, and will not be elaborated upon here.

[0104] It should be noted that when the privacy compliance component determines that the sender of the query request is a third-party SDK, the server obtains the corresponding list of authorized third-party shared personal information through the queryer and user ID, and then performs the query.

[0105] In practical applications, the above query process can be executed every time information is collected during the operation of an application or third-party SDK.

[0106] The above solution allows applications and third-party SDKs to verify that users have authorized the collection of their personal information when collecting data, ensuring that each collection of personal information is a compliant operation, meeting information compliance requirements, and improving user experience.

[0107] The following section details how the privacy compliance component obtains privacy agreement information from the server and generates authorization information based on the user's authorized actions.

[0108] In one or more embodiments of this application, the privacy compliance component may optionally include a renderer and a tracker.

[0109] The renderer is used to: after receiving a request to open a privacy compliance page or pop-up, obtain the latest privacy agreement information from the server, and render and generate a privacy compliance page or pop-up based on the obtained privacy agreement information; and determine the personal information that the user has checked to agree to authorize in the privacy compliance page or pop-up.

[0110] The tracker is used to: generate a corresponding privacy authorization string based on the personal information that the user agrees to authorize, and send it to the server so that the server can verify the privacy authorization string; and / or, record the exposure events of the privacy compliance page or pop-up on the user's terminal and the user's selection behavior and send them to the server so that the server can perform statistical analysis on the exposure events and selection behavior corresponding to the application.

[0111] Figure 5 This is an interactive diagram illustrating the management, authorization, and authentication of a privacy protocol, provided as an embodiment of this application. (See diagram below.) Figure 5 As shown, the renderer and tracker can be set up within the privacy compliance component, while the editor can be set up on the server side. The numbers in the diagram represent the steps involved in managing, authorizing, and securing privacy agreements.

[0112] The process of generating privacy agreement information is as follows (corresponding to) Figure 5 Steps 1 to 3): Enterprise customers edit the privacy agreement information online using the editor provided by the server. After editing, the privacy agreement information can be published to the server. Upon publication, the privacy compliance component can retrieve the privacy agreement information from the server. To facilitate modifications to the privacy agreement information by enterprise customers, in addition to publication, the privacy agreement information can also be saved on the server. After retrieving the privacy agreement information, the server can secure it.

[0113] The process of displaying privacy agreement information to users is (corresponding to) Figure 5 Steps 4 to 7): The user sends a request to the renderer to open the privacy compliance page or pop-up. The trigger condition for this request is a scenario requiring the user's authorization information, such as the first time the application is opened, as detailed above. Upon receiving the request, the renderer records the pop-up exposure event in the tracker. This pop-up exposure event facilitates statistical analysis by the server, allowing enterprise clients to understand user consent and rejection of the privacy agreement information. Simultaneously, the renderer also sends a request to the server to retrieve the latest privacy agreement information. Optionally, when retrieving the latest privacy agreement information, version information can be compared, and the highest version of the privacy agreement information can be determined as the latest. The server sends the latest privacy agreement information to the renderer, which then renders the page to display the privacy agreement information to the user.

[0114] When the renderer retrieves the latest privacy agreement information from the server, TypeScript can be used to represent the format in which the privacy agreement content is distributed. Optionally, the privacy compliance page or pop-up can be displayed using the following fields: the `raw` field represents the text content of the privacy agreement pop-up; the `blocks` field represents a two-dimensional array, where the two dimensions represent paragraph and style divisions, with each block representing a segment of content; the `blocks.text` field represents the text content of the current element or position; the `blocks.styles` field represents the text styles of the current element; and the `blocks.entities` field represents the entity content of the current element, which can be in the form of hyperlinks, expanding the text content to include images, videos, audio, etc. The text content and entity content together form rich text; the `settings` field represents the global style of the current rich text pop-up, which can include the title content, color, and button content, color, etc.

[0115] The process of handling user authorization operations is as follows (corresponding to) Figure 5 Steps 8 to 10): Users can check the privacy agreement details on the page, selecting personal information they agree to have their information collected by the application from a list. Upon receiving the selected privacy agreement information, the renderer determines the personal information the user has agreed to authorize. This selection is also recorded in the tracker, which generates a privacy authorization string upon receiving the user's selected personal information. This privacy authorization string is then sent to the server for verification.

[0116] Figure 6 This is a schematic diagram illustrating a process for generating a privacy authorization string, provided as an embodiment of this application. Figure 6 As shown, privacy agreement information can be stored in a tree structure. When generating a privacy compliance string, the configuration content of the tree structure can be read, the tree structure nodes can be traversed, and the node selection status can be recorded if it can be selected. After traversing all nodes, structured data can be generated and converted into an intermediate state string in binary format. The binary string is then segmented, converted into decimal format, and then converted into base64 encoded characters to assemble the RCstring (privacy compliance string). In this way, the SDK can convert and encode user authorization information to obtain a string in a specific format, improving the efficiency and accuracy of data transmission.

[0117] Furthermore, to help enterprise clients understand user consent and rejection regarding privacy policy information, trackers can record exposure events of privacy compliance pages or pop-ups on user devices; that is, recording is triggered sequentially every time a user sees the privacy policy. The tracker can also send the recorded user check-in behavior to the server. After receiving the exposure events and check-in behaviors, the server can perform statistical analysis. Specifically, it can count the number of exposure events and the number of user check-in behaviors within a certain period, and obtain the percentage of users who consented to the collection of personal information during that time period. Further, it can analyze the authorization status of specific personal information items, thereby improving the efficiency and experience of enterprise clients' setup.

[0118] In summary, by setting up a renderer in the privacy compliance component, the latest privacy agreement information can be obtained from the server, improving the real-time nature and accuracy of users obtaining privacy agreement information; by generating privacy authorization strings through the tracker, the server can easily perform evidence-based operations; and by statistically analyzing exposure events and check-in events, enterprise customers can easily analyze the operations of all users, improving the efficiency and experience of statistical analysis.

[0119] In one or more embodiments of this application, optionally, the tracker is further configured to:

[0120] When the renderer obtains the user's personal information indicating consent, and no query request is received from the application or third-party SDK, the user is notified to the application or third-party SDK of the user's consent to the personal information; wherein the query request is sent when the application or third-party SDK needs to collect the user's personal information.

[0121] Both the application and the privacy compliance component need to be initialized, but the initialization process may not be sequential. This can lead to the application collecting user information after it has completed initialization. When collecting personal information, the application or third-party SDK sends a query request to the privacy compliance component to confirm user authorization. However, if the privacy compliance component takes a long time to initialize, it may miss the query requests sent by the application or third-party SDK.

[0122] To address the aforementioned issues, the tracker within the privacy compliance component immediately notifies the application or third-party SDK upon confirming user authorization. Specifically, the tracker confirms user authorization when it receives the user's checked consent information from the renderer. If user authorization is confirmed but no query request is received from the application or third-party SDK, the tracker can then notify the application or third-party SDK of the agreed-upon personal information. This avoids situations where the application or third-party SDK remains in a waiting state while the privacy compliance component fails to send authorization information, resulting in untimely collection of personal information. The above process corresponds to... Figure 5 Step 11 in the process.

[0123] The above process avoids the application being unable to collect personal information due to excessively long initialization time of privacy compliance components, thus improving the stability of the application when collecting personal information.

[0124] Finally, after obtaining the user's selection behavior, the server verifies the selection behavior and, optionally, generates a corresponding digest based on the authorization information and sends it to the blockchain. The above process corresponds to... Figure 5 Step 12 in the process.

[0125] When generating privacy agreement information based on the privacy agreement editing page, text boxes, buttons, and links can be set on the privacy agreement editing page to facilitate enterprise customers in entering privacy agreement information.

[0126] In one or more embodiments of this application, optionally, when the server provides a privacy agreement editing page and obtains the privacy agreement information entered by the application provider on the privacy agreement editing page, it is specifically used for:

[0127] The privacy agreement editing page is displayed to the provider via the provider's terminal; wherein the privacy agreement information further includes: agreement content; the privacy agreement editing page includes: a text box for entering agreement content, a button for adding personal information lists, and a link to an example of a personal information list.

[0128] In response to the user clicking the button on the privacy agreement editing page, the corresponding personal information list editing page is displayed; the personal information list editing page includes at least one of the following: personal information list name, description, and personal information form.

[0129] Based on the content entered by the user on the privacy agreement editing page and the personal information list editing page, the corresponding privacy agreement information is generated.

[0130] The provider terminal can be a terminal device used by the provider. For example, when the provider is an enterprise customer, the provider terminal can be a terminal device used by the enterprise customer.

[0131] Figure 7 This is a schematic diagram of a privacy agreement editing page provided in an embodiment of this application. Figure 7 As shown, when an enterprise customer requests to edit privacy agreement information, the server can display the following on the enterprise terminal (the enterprise customer's terminal device): Figure 7 The privacy agreement editing page shown allows users to edit privacy agreement information. This privacy agreement information includes not only the two lists but also the privacy agreement content itself. The privacy agreement content can be information or guidance for users, such as informing them how personal information is collected and how they can authorize actions.

[0132] The privacy agreement editing page includes a text box for enterprise customers to input their privacy agreement content. Furthermore, the page also features buttons for customizing the font used in the privacy agreement, such as font style, size, color, line height, and character spacing. These buttons allow users to easily configure the font settings.

[0133] In addition, a button for adding personal information to a list can be set up. When an enterprise customer clicks this button, the server will respond to the button click operation and display the personal information list editing page, enabling the editing of the personal information collected in different scenarios.

[0134] Furthermore, to improve the efficiency of enterprise customers in editing personal information lists, a link to a sample personal information list can be set on the privacy agreement editing page. By clicking the link, a sample personal information list can be displayed, and customers can quickly generate a personal information list by referring to the sample.

[0135] Figure 8 This is a schematic diagram of a personal information list editing page provided in an embodiment of this application. Figure 8 As shown, the personal information list editing page includes the personal information list name, description, and personal information form. The personal information list name is the name of the privacy agreement information stored on the server, such as Version 1, Version 2, etc., for easy viewing by enterprise customers.

[0136] The personal information form includes the scenario / business function, the type of personal information, and the purpose of collection. The scenario / business function refers to the context in which personal information is collected. In payment software, the scenario / business function is user payment, transfer, etc., and the corresponding personal information type is billing information, with the purpose of facilitating user bill viewing. Similarly, in live streaming software, when the scenario / business function is to view nearby users, the corresponding personal information type is location information, with the purpose of accurately recommending nearby users. A button can be added to "Add Scenario / Business Function" to configure the personal information collected for different scenarios / business functions. Each scenario / business function can correspond to at least one type of personal information and its purpose; an option to add additional information can also be included on the page.

[0137] Additionally, the privacy agreement editing page can also include a button to add a list of personal information shared by third parties. When an enterprise customer clicks this button, the server will respond to the click operation and display the editing page for the list of personal information shared by third parties, allowing users to edit the content of personal information that different third parties need to collect.

[0138] Figure 9A This is a schematic diagram of a third-party shared personal information list editing page provided as an embodiment of this application. Figure 9A As shown, this also includes the list name, description, and personal information form. The list name and description are similar to those on the personal information list editing page mentioned above, and will not be repeated here. The personal information form here may include third-party names, function types, operators, link addresses, personal information, and purposes.

[0139] In one or more embodiments of this application, optionally, the list of personal information that the application expects to collect, and / or the list of personal information that it expects to share with third parties, can be more finely categorized according to relevant legal and regulatory requirements and the actual needs of the customer.

[0140] For example, the list of personal information that is expected to be shared with third parties may include at least one of the following types of lists: affiliate shared list (also known as affiliate app list), SDK shared list (also known as embedded SDK list), and partner shared list (also known as partner third-party list). See Table 1 for details.

[0141] Table 1 Example of a Third-Party Shared List

[0142]

[0143] Optionally, when displaying the privacy agreement editing page to enterprise customers, examples can be provided for each type of personal information list, allowing enterprise customers to edit them separately for each type. Correspondingly, in Figure 7 The page shown provides sample links for each type of list, as well as buttons for adding each type of list.

[0144] Figure 9B This is a schematic diagram of an editing page for a shared list of related parties, provided as an embodiment of this application. Figure 9C This is a schematic diagram of an editing page for an SDK shared manifest provided in an embodiment of this application. Figure 9D This is a schematic diagram of an editing page for a shared list of partners, provided as an embodiment of this application.

[0145] like Figure 9B to Figure 9D As shown, on the editing page for each type of list, enterprise customers are allowed to enter the list name, the company name of each third party (affiliate, SDK, or partner), a privacy agreement link, the scope of information sharing (which personal information the app is allowed to share with the third party), and the intended use, etc.

[0146] After users enter or select information on the above editing pages, privacy agreement information can be generated based on the input or selection.

[0147] By configuring the privacy agreement editing page and the personal information list editing page, we can provide enterprise clients with a visual interface to facilitate the input of privacy agreement information. At the same time, we offer professional templates to meet client needs.

[0148] To improve the user experience for enterprise customers, the display interface for privacy authorization pop-ups can also be customized.

[0149] In one or more embodiments of this application, optionally, the server is further configured to:

[0150] The authorization pop-up editing page is displayed to the provider of the application through the provider's terminal; wherein, the authorization pop-up editing page is used by the provider to edit the privacy compliance page or pop-up displayed on the user terminal; the authorization pop-up editing page includes: the title and content of the privacy compliance page or pop-up, a link for inserting privacy agreement information in the content, and an editing page for the buttons in the privacy compliance page or pop-up.

[0151] The privacy compliance component is also used to: after receiving a request to open a privacy compliance page or pop-up, obtain the information entered by the provider on the authorization pop-up editing page from the server, and render and generate a privacy compliance page or pop-up based on the obtained information.

[0152] Figure 10 This is a schematic diagram of an authorization pop-up editing page provided in an embodiment of this application. Figure 10 As shown, when the server receives a request from an enterprise customer to edit the authorization pop-up, the server responds by displaying the authorization pop-up editing page to the enterprise customer through the enterprise terminal. The authorization pop-up editing page is a visual editing page that allows the enterprise customer to customize the pop-up's style. For example, the pop-up title can be a title displayed at the top of the pop-up or in another location, such as "Privacy Policy"; the pop-up content can be the specific content displayed to the user within the pop-up. This content can be set by the enterprise user according to their actual needs. For example, the pop-up content may include the specific content of the privacy agreement, or it may include content guiding the user to authorize the process, or it may include a link to the privacy agreement information inserted within the content, so that clicking the link displays the specific privacy agreement information.

[0153] Furthermore, the style of the buttons in the pop-up window can be customized. Figure 11 This is a schematic diagram of a pop-up button editing page provided in an embodiment of this application. Figure 11 As shown, an "agree" button and a "disagree" button can be set on the user's terminal page or pop-up window. The arrangement of the two buttons can be selected, either horizontally or vertically. For each button, information such as fill color, border color, text color, and content can be set.

[0154] Once the enterprise customer has set the display interface for the pop-up, the privacy compliance component can obtain the information entered by the enterprise customer on the authorization pop-up editing page from the server after receiving a user's request to open the privacy compliance page or pop-up. Then, it can render and generate the privacy compliance page or pop-up based on the obtained information, and display the privacy compliance page or pop-up on the user's terminal.

[0155] By configuring the authorization pop-up editing page, enterprise customers can be provided with a visual interface, making it easy for them to customize the display interface of privacy compliance pages or pop-ups, improving the efficiency of page or pop-up settings, and meeting the customization needs of different enterprise customers.

[0156] Furthermore, considering that users may not want the application to collect all the required personal information in some scenarios, we offer both an item-by-item authorization mode and a package mode for users to choose from.

[0157] In one or more embodiments of this application, optionally, the privacy compliance page or pop-up includes an agree button, a disagree button, and an item-by-item authorization button; when the privacy compliance component determines that a user has checked the personal information they agree to authorize in the privacy compliance page or pop-up, it is specifically used for:

[0158] In response to the user selecting the individual authorization button, the application displays a list of personal information that it expects to collect and / or a list of personal information that it expects to share with third parties; determines that the user has checked the personal information they agree to authorize in the list of personal information that the application expects to collect and / or the list of personal information that it expects to share with third parties; and / or, in response to the user selecting the agree button or the disagree button, determines that the user agrees to authorize the collection of all personal information or disagrees to authorize the collection of personal information.

[0159] Figure 12 This is a schematic diagram illustrating a package licensing model provided in an embodiment of this application. Figure 13 This is a schematic diagram illustrating a per-item individual licensing model provided for an embodiment of this application. Figure 12 The privacy compliance page or pop-up includes "Agree," "Disagree," and "Authorize Individually" buttons for users to choose from. When a user does not wish for the application to collect all requested personal information, they can click the "Authorize Individually" button to display... Figure 13 The diagram shown is as follows. Figure 13 As shown, the diagram displays a list of personal information that the application expects to collect and / or shares with third parties. Agreement Information 1, Agreement Information 2, etc., in the diagram can represent various types of personal information, allowing users to select buttons corresponding to specific personal information that the application can collect. Furthermore, when a user authorizes the application using a comprehensive authorization model, they can choose... Figure 12 The "Agree" or "Disagree" button indicates whether the user agrees to the application collecting all their personal information or disagrees with the collection of all their personal information.

[0160] In practice, when a live streaming software wants to collect a user's location information, voice information, and contact information, if the user does not want the live streaming software to collect contact information, they can use the individual authorization mode for each item. Select the buttons corresponding to location information and voice information, and click the button to agree to the selected items to confirm that the application can collect these two personal information items.

[0161] In addition, this application also supports the modification of authorized content after the user confirms the authorization information. That is, a corresponding button is set on the user terminal. After clicking the button, the authorized content can be modified and submitted, which makes it convenient for users to modify the authorization information.

[0162] By offering two authorization modes, users can choose according to their needs, which improves the user experience when authorizing, meets users' personalized needs, and also increases the likelihood that users will agree to the application collecting certain personal information, thus facilitating the promotion and application of the application.

[0163] This application also provides several API interfaces for application developers to call. For example, `sdk.init(opts)` is an interface for initializing the privacy compliance component; `sdk.setConcentUserId(id)` is an interface for recording user IDs. During initialization, the application calls this interface to allow the privacy compliance component to obtain the user ID, which can be a temporary user identifier. `sdk.showDialog` is an interface for controlling the pop-up authorization window. When this interface is called, a privacy compliance page or pop-up will be displayed on the user's terminal. `sdk.getConsent(consentItemId)` is an interface for retrieving the authorization status of a specific piece of personal information. This can be called by applications or third-party SDKs during the query phase to obtain the authorization status of a specific piece of personal information and determine whether to collect the corresponding personal privacy information based on the result. `sdk.setConsent(consentItemId, isAgree)` is an interface for setting whether a user has agreed to a certain authorization. When a user checks the personal information item for which they agree to authorization, calling this interface will cause the privacy compliance component to modify the corresponding status data, but it will not submit the changes until the user clicks "confirm." sdk.submit is an interface for the provider to submit authorization results in the case of self-rendering. Optionally, the application can render the privacy compliance page or pop-up on its own without calling the privacy compliance component and obtain the user's authorization information. In this case, the application can call this interface to submit the authorization information to the server for evidence preservation.

[0164] Figure 14 This is a flowchart illustrating a privacy compliance processing method provided in an embodiment of this application. The method is applied to the server side. Figure 14 As shown, the method includes:

[0165] Step 1401: Obtain the privacy agreement information entered by the application provider on the privacy agreement editing page; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0166] Step 1402: Receive authorization information sent by a user terminal with the application installed through the privacy compliance component; the authorization information is generated by the privacy compliance component based on the user's authorization operation regarding certain privacy agreement information; the privacy compliance component is set within the application; the privacy agreement information is obtained from the server through the privacy compliance component and displayed.

[0167] Step 1403: Validate the user's authorization information.

[0168] The implementation principle and technical effects of the privacy compliance processing method provided in this embodiment can be found in the foregoing embodiments, and will not be repeated here.

[0169] Figure 15 This is a flowchart illustrating another privacy compliance processing method provided in an embodiment of this application. The method is applied to a privacy compliance component, which is set within an application, and the application is installed on the user's terminal. Figure 15 As shown, the method includes:

[0170] Step 1501: Obtain and display the privacy agreement information; the privacy agreement information is entered by the application provider on the privacy agreement editing page provided by the server; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0171] Step 1502: Based on the user's authorization operation regarding at least part of the privacy agreement information, generate corresponding authorization information and send it to the server so that the server can verify the user's authorization information.

[0172] The implementation principle and technical effects of the privacy compliance processing method provided in this embodiment can be found in the foregoing embodiments, and will not be repeated here.

[0173] Corresponding to the above method, this application embodiment also provides a privacy compliance processing device, applied on a server side, the device comprising:

[0174] The first acquisition module is used to acquire privacy agreement information entered by the application provider on the privacy agreement editing page; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0175] The receiving module is used to receive authorization information sent by a user terminal with the application installed through a privacy compliance component; the authorization information is generated by the privacy compliance component based on the user's authorization operation regarding certain privacy agreement information; the privacy compliance component is set within the application; the privacy agreement information is obtained from the server through the privacy compliance component and displayed.

[0176] The authentication module is used to authenticate the user's authorization information.

[0177] This application embodiment also provides a privacy compliance processing device applied to a privacy compliance component, wherein the privacy compliance component is set within an application, and the application is installed on a user terminal; the device includes:

[0178] The second acquisition module is used to acquire and display the privacy agreement information; the privacy agreement information is entered by the provider on the privacy agreement editing page provided by the server; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties;

[0179] The processing module is used to generate corresponding authorization information based on the user's authorization operation for at least part of the privacy agreement information and send it to the server so that the server can verify the user's authorization information.

[0180] The specific implementation principles and technical effects of the various devices provided in the embodiments of this application can be found in the foregoing embodiments, and will not be repeated here.

[0181] Figure 16 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 16 As shown, the electronic device in this embodiment may include:

[0182] At least one processor 1601; and

[0183] Memory 1602 is communicatively connected to the at least one processor 1601;

[0184] The memory 1602 stores instructions that can be executed by the at least one processor 1601 to cause the electronic device to perform the method as described in any of the above embodiments.

[0185] Alternatively, the memory 1602 can be either standalone or integrated with the processor 1601.

[0186] The implementation principle and technical effects of the electronic device provided in this embodiment can be found in the foregoing embodiments, and will not be repeated here.

[0187] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described in any of the foregoing embodiments.

[0188] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods described in any of the foregoing embodiments.

[0189] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed.

[0190] The integrated modules implemented as software functional modules described above can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application.

[0191] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor. The memory may include high-speed RAM, and may also include non-volatile memory (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk, or optical disc, etc.

[0192] The aforementioned storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.

[0193] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. Both the processor and the storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic device or host device.

[0194] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0195] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0196] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0197] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A privacy compliance processing system, characterized in that, This includes server-side and privacy compliance components; The server is used to: provide a privacy agreement editing page, obtain the privacy agreement information entered by the application provider on the privacy agreement editing page, and save the privacy agreement information, wherein the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties; The application has a built-in privacy compliance component. The user terminal with the application installed is used to: obtain and display the privacy agreement information from the server through the privacy compliance component, and generate corresponding authorization information and send it to the server based on the user's authorization operation for at least part of the privacy agreement information. The server is also used to: receive the user's authorization information and send it to the blockchain for storage, so as to obtain credentials from the blockchain when verification is required; The application has a built-in third-party SDK; The application is used to: query the server whether the user has authorized the application to collect the personal information before collecting any personal information by calling the relevant interface of the privacy compliance component; if authorized, call the personal information collection interface to collect the personal information; The third-party SDK is used to: query whether the user has authorized sharing the personal information with a third party through a privacy compliance component before collecting any personal information; if authorized, call the personal information collection interface to collect the personal information; The privacy compliance components include a renderer and a tracker; The renderer is used to: after receiving a request to open a privacy compliance page or pop-up, obtain the latest privacy agreement information from the server, and render and generate a privacy compliance page or pop-up based on the obtained privacy agreement information; determine the personal information that the user has checked to agree to authorize in the privacy compliance page or pop-up. The tracker is used to: generate a corresponding privacy authorization string based on the personal information that the user agrees to authorize, and send it to the server so that the server can verify the privacy authorization string; and / or, record the exposure events of privacy compliance pages or pop-ups on the user's terminal and the user's selection behavior and send them to the server so that the server can perform statistical analysis on the exposure events and selection behavior corresponding to the application. The tracker is also used for: When the renderer obtains the user's personal information that indicates consent to authorization, and no query request is received from the application or third-party SDK, the application or third-party SDK is notified of the user's consent to authorization of the personal information. The query request is sent when the application and third-party SDK need to collect the user's personal information.

2. The system according to claim 1, characterized in that, The server is specifically used to generate a corresponding digest based on the user's authorization information, send it to the blockchain for storage, and obtain the credential corresponding to the digest returned by the blockchain. The summary and credentials are used by the provider, the user, or a judicial authority to verify the user's authorization information.

3. The system according to claim 1 or 2, characterized in that, When the server provides a privacy agreement editing page and obtains the privacy agreement information entered by the application provider on the privacy agreement editing page, it is specifically used for: The privacy agreement editing page is displayed to the application provider via an enterprise terminal; wherein the privacy agreement information further includes: agreement content; the privacy agreement editing page includes: a text box for entering agreement content, a button for adding personal information lists, and a link to an example of a personal information list; In response to the user clicking the button on the privacy agreement editing page, a corresponding personal information list editing page is displayed; the personal information list editing page includes at least one of the following: personal information list name, description, and personal information form; Based on the content entered by the user on the privacy agreement editing page and the personal information list editing page, the corresponding privacy agreement information is generated.

4. The system according to claim 1 or 2, characterized in that, The server is also used for: The authorization pop-up editing page is displayed to the provider of the application through the provider's terminal; wherein, the authorization pop-up editing page is used by the provider to edit the privacy compliance page or pop-up displayed on the user terminal; the authorization pop-up editing page includes: the title of the privacy compliance page or pop-up, the content, a link for inserting privacy agreement information in the content, and an editing page for the buttons in the privacy compliance page or pop-up; The privacy compliance component is also used to: after receiving a request to open a privacy compliance page or pop-up, obtain the information entered by the provider on the authorization pop-up editing page from the server, and render and generate a privacy compliance page or pop-up based on the obtained information.

5. The system according to claim 1, characterized in that, The privacy compliance page or pop-up includes an "Agree" button, a "Disagree" button, and an item-by-item authorization button; when the privacy compliance component determines that a user has checked the boxes to authorize personal information in the privacy compliance page or pop-up, it is specifically used for: In response to the user's selection of the individual authorization button, display a list of personal information that the application expects to collect and / or a list of personal information that it expects to share with third parties; determine the personal information that the user agrees to authorize in the list of personal information that the application expects to collect and / or the list of personal information that it expects to share with third parties; And / or, In response to the user's selection of the "agree" or "disagree" button, determine whether the user agrees to authorize the collection of all personal information or disagrees with authorizing the collection of personal information.

6. A privacy compliance processing method, characterized in that, The method is applied to the server side, and the method includes: Obtain the privacy agreement information entered by the application provider on the privacy agreement editing page, and save the privacy agreement information; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties; The system receives authorization information sent by a user terminal with an application installed through a privacy compliance component; the authorization information is generated by the privacy compliance component based on the user's authorization operation regarding certain privacy agreement information; the privacy compliance component is set within the application; the privacy agreement information is obtained from the server through the privacy compliance component and displayed. The authorization information is sent to the blockchain for storage, so that credentials can be retrieved from the blockchain when verification is required; The method further includes: receiving a query request sent by the privacy compliance component, and, upon determining that authorization has been granted, sending information indicating authorization to the privacy compliance component, wherein the query request is used to query whether the user has authorized the application to collect the personal information or whether the user has authorized the sharing of the personal information with a third party before collecting any personal information; The privacy compliance components include a renderer and a tracker; The renderer is used to: after receiving a request to open a privacy compliance page or pop-up, obtain the latest privacy agreement information from the server, and render and generate a privacy compliance page or pop-up based on the obtained privacy agreement information; determine the personal information that the user has checked to agree to authorize in the privacy compliance page or pop-up. The tracker is used to: generate a corresponding privacy authorization string based on the personal information that the user agrees to authorize, and send it to the server so that the server can verify the privacy authorization string; and / or, record the exposure events of privacy compliance pages or pop-ups on the user's terminal and the user's selection behavior and send them to the server so that the server can perform statistical analysis on the exposure events and selection behavior corresponding to the application. The tracker is also used for: When the renderer obtains the user's personal information that indicates consent to authorization, and no query request is received from the application or third-party SDK, the application or third-party SDK is notified of the user's consent to authorization of the personal information. The query request is sent when the application and third-party SDK need to collect the user's personal information.

7. A privacy compliance processing method, characterized in that, The method is applied to a privacy compliance component, which is set within an application and the application is installed on a user terminal. The method includes: The application obtains and displays privacy agreement information from the server; the privacy agreement information is entered by the application provider on the privacy agreement editing page provided by the server; the privacy agreement information includes at least one of the following: a list of personal information that the application expects to collect, and a list of personal information that it expects to share with third parties; Based on the user's authorization actions regarding at least some privacy agreement information, corresponding authorization information is generated and sent to the server, so that the server sends the authorization information to the blockchain for storage, so that the credentials can be obtained from the blockchain when verification is required; The method further includes: The application receives a query request from a third-party SDK built into it and forwards the query request to the server to query whether the user has authorized the application to collect the personal information or whether the user has authorized the application to share the personal information with a third party. Receive the information sent by the server indicating authorization, and forward it to the third-party SDK; The method further includes: Upon receiving a request to open a privacy compliance page or pop-up, the renderer of the privacy compliance component obtains the latest privacy agreement information from the server and renders and generates the privacy compliance page or pop-up based on the obtained privacy agreement information; it then determines whether the user has checked the personal information they agree to authorize in the privacy compliance page or pop-up. The tracker of the privacy compliance component generates a corresponding privacy authorization string based on the personal information that the user selects to agree to authorize and sends it to the server so that the server can verify the privacy authorization string; and / or, records the exposure events of the privacy compliance page or pop-up on the user's terminal and the user's selection behavior and sends them to the server so that the server can perform statistical analysis on the exposure events and selection behavior corresponding to the application. When the tracker of the privacy compliance component obtains the personal information that the user has checked to agree to authorize from the renderer, it notifies the application or the third-party SDK of the personal information that the user has agreed to authorize without obtaining a query request from the application or the third-party SDK. The query request is sent when the application and the third-party SDK need to collect the user's personal information.

8. An electronic device, characterized in that, include: At least one processor; as well as A memory that is communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor to cause the electronic device to perform the method of claim 6 or 7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the method as described in claim 6 or 7.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method as described in claim 6 or 7.

Citation Information

Patent Citations

  • Protocol data management method, device and system, and storage medium

    CN110245144A

  • Privacy protection method and device

    CN111274598A

  • Permission control method, device and equipment and storage medium

    CN112131556A