A Method, System, Device and Medium for Generating a Personalized Privacy Policy

By matching user privacy preference data with preset privacy policy templates, and combining natural language processing and dynamic compliance inspections, the multi-dimensional complexity of user privacy preferences and insufficient supervision of privacy policy implementation are solved, and efficient generation of personalized privacy policies and the security improvement of privacy protection is achieved.

CN118966181BActive Publication Date: 2025-06-03GUANGZHOU SANQI DREAM NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410986938.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-23
Publication Date
2025-06-03
Estimated Expiration
2044-07-23

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively solve the problems of multi-dimensional complexity of user privacy preferences and insufficient supervision of privacy policies, resulting in discounted results in poor user experience.

Method used

By matching user privacy preference data with preset privacy policy templates, a draft of privacy policy is generated, and a privacy settings interactive interface is established through natural language processing and dynamic compliance inspections to improve the security of user experience and privacy protection.

Benefits of technology

It has achieved efficient generation and dynamic compliance inspection of personalized privacy policies, improved the security and user experience of privacy protection, and enhanced the supervision of the implementation of privacy policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118966181B_ABST
    Figure CN118966181B_ABST
Patent Text Reader

Abstract

This application is applicable to the field of information security technology, and provides a method for generating a personalized privacy policy, including: matching user privacy preference data with a preset privacy policy template to generate a draft privacy policy; scoring each clause in the draft privacy policy to obtain a privacy policy text; based on a regulation database, using natural language processing methods to convert the regulation database into a rule engine, and dynamically checking the compliance of the privacy policy text according to the rule engine to generate a compliance evaluation report; based on user privacy preference data, privacy policy text, and compliance evaluation report, establishing a privacy setting interaction interface. The present invention can dynamically generate a personalized privacy policy text according to privacy policy regulations and user privacy preferences, greatly improving the efficiency of privacy policy formulation and implementation, and having a good user experience at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security technology, and particularly relates to a method, system device and medium for generating personalized privacy policies. Background Art

[0002] In the modern digital age, privacy protection has become a focus of common concern for users and enterprises. In the prior art, regulatory frameworks and standards such as GDPR and CCPA have been established, providing basic guidance for privacy protection. The widespread application of these regulations covers multiple aspects, including but not limited to in-depth analysis of privacy policy texts, strict inspection of enterprise compliance, and permission control for user data access and processing, thus comprehensively strengthening the protection of personal privacy.

[0003] However, the personalized manifestations of users' privacy preferences are multi-dimensional and complex. For example, a financial service user may have extremely high requirements for the confidentiality of transaction data, while a social media user may be more concerned about the non-abuse of personal information. In addition, different industries such as finance and e-commerce have different legal requirements for the processing of user data, and there are also significant differences in the resource investment of large enterprises and small and medium-sized enterprises in data processing and privacy protection. In terms of effects, privacy policies are often textually complex, making it difficult for users to fully understand their meanings, resulting in a discount in the actual effects of privacy protection measures. In terms of user experience, users often need to read long privacy policies, resulting in a poor user experience. In terms of security, the execution supervision of privacy policies is insufficient, which may lead to data leakage or abuse. Summary of the Invention

[0004] Embodiments of this application provide a method, system device and medium for generating personalized privacy policies, which can solve at least one of the above-mentioned prior art problems.

[0005] In a first aspect, embodiments of this application provide a method for generating a personalized privacy policy, including:

[0006] Matching user privacy preference data with a preset privacy policy template to generate a draft privacy policy;

[0007] Scoring each clause in the draft privacy policy to obtain a privacy policy text;

[0008] Based on a regulation database, using natural language processing methods, converting the regulation database into a rule engine, and performing dynamic compliance checks on the privacy policy text according to the rule engine to generate a compliance assessment report;

[0009] Based on the user privacy preference data, privacy policy text, and compliance assessment report, a privacy setting interaction interface is established. The privacy setting interaction interface is used to graphically display options for various data permissions related to privacy settings and provide feedback information related to privacy settings.

[0010] Further, the matching of the user privacy preference data with a preset privacy policy template to generate a draft privacy policy includes:

[0011] Obtain the user's privacy preference data. By analyzing the privacy preference data, obtain the privacy preference portrait corresponding to the user;

[0012] Establish a privacy policy generation model. The privacy policy generation model is used to generate a preset privacy policy template according to the privacy preference portrait;

[0013] Adopt natural language processing technology to perform semantic analysis and keyword extraction on the privacy preference data to obtain the privacy requirement keywords of the user;

[0014] Match the privacy requirement keywords with the preset privacy policy template to generate a draft privacy policy.

[0015] Further, the establishment of the privacy policy generation model includes:

[0016] Obtain the sensitivity scores of different users for various data permissions to obtain a privacy data source;

[0017] Preprocess the privacy data source to obtain the privacy information of different users and establish privacy preference portraits for different user groups;

[0018] Obtain the existing privacy policy text, preprocess the existing privacy policy text to obtain a training dataset;

[0019] Based on the Transformer architecture, construct a pre-trained model. Adopt the fine-tuning technology, input the training dataset into the pre-trained model for training, and generate a privacy policy generation model;

[0020] Input the privacy preference portraits of different user groups into the privacy policy generation model for distributed training to generate multiple privacy policy templates.

[0021] Further, the scoring of each clause in the draft privacy policy to obtain a privacy policy text includes:

[0022] Adopt a deep learning algorithm to optimize the draft privacy policy to obtain a first draft of the privacy policy;

[0023] Retrieve the privacy regulation database using a graph traversal algorithm, and mark the regulation clauses in the privacy regulation database related to the initial draft of the privacy policy;

[0024] Adopt the expert analysis method, and score each clause of the initial draft of the privacy policy based on the marked regulation clauses to obtain the privacy policy text.

[0025] Furthermore, based on the regulation database, use the natural language processing method to convert the regulation database into a rule engine, and perform dynamic compliance checking on the privacy policy text according to the rule engine to generate a compliance evaluation report, including:

[0026] Dynamically obtain the regulation text in the regulation database, preprocess the regulation text through natural language technology to obtain a key database, and the key database is the privacy regulation database;

[0027] Adopt a keyword extraction algorithm to identify the privacy regulation terms in the key database;

[0028] Adopt a semantic analysis tool to analyze the specific context and relevance of the privacy regulation terms in the key database to obtain the semantic understanding rules of the privacy regulation terms;

[0029] Based on the semantic understanding rules, construct logical reasoning rules, and design a rule engine based on the logical reasoning rules;

[0030] Based on the rule engine, perform compliance checking on the privacy policy text to generate a compliance evaluation report.

[0031] Furthermore, based on the user privacy preference data, privacy policy text and compliance evaluation report, establish a privacy setting interaction interface, and the privacy setting interaction interface is used to graphically display the options of various data permissions related to privacy settings and provide feedback information related to privacy settings, including:

[0032] Adopt visual elements to intuitively display the options of various data permissions related to privacy settings;

[0033] Obtain the user's privacy setting information, and provide timely feedback information according to the privacy setting information, and the feedback information is used to explain the impacts and risks brought by the current privacy setting.

[0034] Furthermore, the above method for generating a personalized privacy policy further includes:

[0035] Adopt an unsupervised learning algorithm to establish a normal data access pattern;

[0036] Monitor the user's data access behavior in real time, detect abnormal behaviors that deviate from the normal data access pattern, intercept unauthorized abnormal behaviors, perform multi-dimensional risk scoring on the abnormal behaviors, and obtain a risk report;

[0037] Based on the risk report, prompt the user whether to update the privacy settings;

[0038] Obtain the user's updated privacy settings, and regenerate the privacy policy text according to the updated settings.

[0039] In a second aspect, an embodiment of the present application provides a personalized privacy policy generation system, including:

[0040] A privacy policy draft generation model: used to match the user's privacy preference data with a preset privacy policy template to generate a privacy policy draft;

[0041] A privacy policy text generation module: used to score each clause in the privacy policy draft to obtain a privacy policy text;

[0042] A dynamic compliance check module: used to convert the regulation database into a rule engine based on a regulation database by using natural language processing methods, and perform dynamic compliance checks on the privacy policy text according to the rule engine to generate a compliance evaluation report;

[0043] An interaction interface setting module: used to establish a privacy setting interaction interface based on the user's privacy preference data, privacy policy text, and compliance evaluation report, and the privacy setting interaction interface is used to graphically display options for various data permissions related to privacy settings and provide feedback information related to privacy settings.

[0044] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned personalized privacy policy generation method is implemented.

[0045] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, including a computer program stored in the computer-readable storage medium. When the computer program is executed by a processor, the above-mentioned personalized privacy policy generation method is implemented.

[0046] The beneficial effects of the embodiments of the present application compared with the prior art are:

[0047] In this application, by associating the user's privacy preferences with privacy regulations, the privacy policy text is automatically generated, greatly improving the efficiency of privacy policy formulation and implementation. At the same time, through the dynamic compliance check of the privacy policy text, the privacy policy text can respond in real time to the updates of relevant privacy policies and be dynamically updated according to the changes in the user's privacy preferences. The intelligent risk assessment and compliance check can timely detect and handle privacy risks, enhancing the security of privacy protection. In addition, by setting up a privacy setting interaction interface, the user experience is improved, making it easier for users to understand and control their privacy preferences. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] To more clearly illustrate the technical solutions in the embodiments of this application, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0049] Figure 1 It is a flowchart showing a method for generating a personalized privacy policy provided by an embodiment of the present invention;

[0050] Figure 2 It is a schematic structural diagram of a personalized privacy policy generation system provided by an embodiment of the present invention;

[0051] Figure 3 It is a schematic structural diagram of a terminal device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system structures and technologies are presented in order to thoroughly understand the embodiments of this application. However, those skilled in the art should clearly understand that this application can also be implemented in other embodiments without these specific details. In other cases, the detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of this application.

[0053] It should be understood that when used in the specification of this application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0054] It should also be understood that the term " / and" as used in the specification of this application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0055] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when", or "once", or "in response to determining", or "in response to detecting". Similarly, the phrases "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, to mean "once determined", or "in response to determining", or "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0056] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are used only for distinguishing descriptions and shall not be construed as indicating or implying relative importance.

[0057] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0058] Please refer to Figure 1 As shown, the present invention is a method for generating a personalized privacy policy, including the following steps:

[0059] S100. Matching the user privacy preference data with a preset privacy policy template to generate a draft privacy policy;

[0060] In this embodiment, the user privacy preference data is obtained, and then it is matched through the preset privacy policy template to generate a draft privacy policy. Among them, the preset privacy policy template contains basic clauses that meet the requirements of general laws and regulations, covering aspects such as data collection, use, storage, and sharing. In addition, automatically matching with the preset privacy policy template to generate a draft privacy policy reduces the risk of human errors and omissions, ensures that enterprises can quickly respond to the changing requirements of laws and regulations, and reduces legal risks.

[0061] In some of these embodiments, the above step S100 includes:

[0062] Obtaining the user's privacy preference data, and by analyzing the privacy preference data, obtaining a privacy preference portrait corresponding to the user;

[0063] Build a privacy policy generation model, which is used to generate a preset privacy policy template according to the privacy preference profile;

[0064] Use natural language processing technology to perform semantic analysis and keyword extraction on the privacy preference data to obtain the privacy requirement keywords of the user;

[0065] Match the privacy requirement keywords with the preset privacy policy template to generate a draft privacy policy.

[0066] In this embodiment, a privacy policy template library is generated through a privacy policy generation model, and the privacy policy template library includes multiple privacy policy templates.

[0067] In this embodiment, the privacy preference data of the user is obtained according to the interaction data generated between the user and the personalized privacy policy generation system. The sensitivity and focus of the user on privacy protection are analyzed through the privacy preference data, and then the user is assigned to the corresponding privacy preference profile. Specifically, through the privacy setting interaction module, the user selects the options of various data permissions related to privacy settings, and uses data collection and preprocessing technology to obtain the preference settings, selection behaviors, feedback information, etc. of the various data permissions selected by the user, and generates the original privacy preference data of the user. By summarizing and organizing the original privacy preference data, the structured user privacy preference data is obtained. Through feature extraction and quantitative analysis of the user privacy preference data, and using a privacy concern recognition algorithm, the degree of attention of the user to various privacy attributes is obtained. By sorting the degree of attention from high to low, the key attention areas and sensitive preferences of the user in terms of privacy protection are determined, and then the privacy preference features are generated. Using a portrait matching algorithm, the privacy preference features of the user are matched with the privacy preference portraits. Through feature similarity calculation, the matching degree of the privacy preference features of the user with different privacy preference portraits is obtained, and according to the level of the matching degree, the corresponding privacy preference portrait of the user is determined. Through this privacy preference portrait, the user can obtain personalized privacy preference setting suggestions.

[0068] For example, in a game platform, if a player's privacy preference is to be willing to share their game achievements, location data, and game activity records, then they can be classified as a user group with a specific privacy sharing tendency in the user privacy preference portrait. Then, according to the player's privacy preference portrait, a corresponding privacy policy template is generated. This privacy policy template clearly states that relevant game activity data and location information of the player will be obtained. At the same time, after generating the privacy policy text according to this privacy policy template, personalized privacy preference setting suggestions will be generated according to the corresponding privacy preference portrait, prompting the user to change the corresponding privacy preference settings.

[0069] In this embodiment, according to the privacy preference data provided by the user, natural language processing technology is used to perform semantic analysis on the feedback information in the privacy preference data and the preference settings of various data permissions selected by the user. Through processing such as word segmentation, part-of-speech tagging, and named entity recognition, keywords, phrases, and sentence components in the feedback information are obtained, and the privacy requirement keywords of the user's privacy preferences are obtained. The TF-IDF algorithm is used to calculate the weights of the privacy preference keywords. Specifically, by analyzing the occurrence frequency of the privacy requirement keywords in the privacy preference data and the option selections in each data permission, the importance of each privacy requirement keyword is obtained, and the privacy requirement keywords are sorted by weight.

[0070] Specifically, obtain the selection situations of the user for each data permission, including the authorization situations of privacy data such as location information, address book, photos, etc., to obtain the original data of the user's privacy preferences. By preprocessing the original privacy preference data, the data is converted into a format suitable for analysis. For example, the text data is converted into digital codes to determine the occurrence positions and frequencies of the privacy requirement keywords in the data. Using natural language processing technology, word segmentation and part-of-speech tagging are performed on the preprocessed privacy preference data to obtain keywords related to privacy requirements, such as "location", "address book", "photo", etc., and the occurrence frequency of each keyword is counted. According to the option selection situations of the user in each data permission, different weights are assigned to each option. For example, "allow" is assigned a higher weight, and "deny" is assigned a lower weight to obtain the privacy importance score of each data permission. By calculating the product of the occurrence frequency of the privacy requirement keyword and the importance score of the corresponding data permission, the weight of each privacy requirement keyword is obtained. The higher the weight, the more important the privacy requirement corresponding to the keyword. According to the weight sorting of the privacy requirement keywords, a keyword list of the user's privacy requirements is obtained. Keywords with higher weights represent privacy requirements that the user attaches more importance to, such as location privacy, social privacy, etc. When generating the privacy policy text, visualization technology is used to present the terms related to the user's privacy requirement keywords in an intuitive manner. For example, for keywords with higher weights, the font is larger, and the corresponding terms are marked with distinct colors for easy user reference and to improve the user experience.

[0071] In this embodiment, the privacy preference portrait corresponding to the user is input into the privacy policy model to dynamically generate a privacy policy template, obtaining a keyword list of the user's privacy requirements and the content of the privacy policy template. The privacy policy template is analyzed using natural language processing technology to obtain the paragraphs and sentences in the privacy policy template related to the keyword list. By matching the privacy requirement keywords with the relevant paragraphs and sentences in the privacy policy template, preliminary privacy policy content is obtained. According to the preliminary privacy policy content obtained by the matching, semantic analysis technology is used to optimize and supplement the content to ensure the integrity and accuracy of the privacy policy content. By formatting the optimized privacy policy content, a privacy policy draft that meets the standard format requirements is obtained.

[0072] In some of these embodiments, establishing the privacy policy generation model includes:

[0073] Obtain the sensitivity scores of different users for various data permissions to obtain a privacy data source;

[0074] Preprocess the privacy data source to obtain the privacy information of different users and establish privacy preference portraits for different user groups;

[0075] Obtain the existing privacy policy texts, preprocess the existing privacy policy texts to obtain a training data set;

[0076] Based on the Transformer architecture, construct a pre-trained model, and use the fine-tuning technology to input the training data set into the pre-trained model for training to generate a privacy policy generation model;

[0077] Input the privacy preference portraits of different user groups into the privacy policy generation model for distributed training to generate multiple privacy policy templates.

[0078] In this embodiment, a privacy preference questionnaire is designed to cover various data permissions such as location information, contacts, health, and biometrics, ensuring concise and clear expression; the questionnaire is published through an online platform, and digital recognition technology is used to ensure the uniqueness of the questionnaire data of each user to avoid duplicate filling; by obtaining the privacy preference questionnaires filled in by different users, the sensitivity scores of different users for various data permissions are obtained, and then a privacy data source is obtained.

[0079] In this embodiment, through the collaborative filtering algorithm, based on the privacy data source, cluster analysis is performed on similar user groups to obtain privacy information, and then a privacy preference profile is established. This profile contains the specific privacy requirements and preference settings of users, helping the system better perform personalized adjustment of services. Specifically, according to the privacy data source, data preprocessing techniques are used to clean, deduplicate, and normalize the original data to obtain a high-quality privacy dataset. Through feature engineering on the privacy dataset, key features of user privacy preferences, such as privacy settings and privacy concerns, are extracted to obtain feature vectors for collaborative filtering. The user-based collaborative filtering algorithm is used to calculate the similarity between users. According to the specific privacy requirements and preference settings of users, measurement methods such as cosine similarity or Pearson correlation coefficient are used to obtain a user similarity matrix. According to the user similarity matrix, a clustering algorithm is used to group similar users. Algorithms such as K-means and hierarchical clustering can be used. By setting appropriate clustering parameters, users with similar privacy preference features are classified to obtain the common features of different user groups, and based on these common features, the privacy preference category to which each user belongs is determined. According to the user characteristics of different privacy preference categories, the typical attributes of each privacy preference category in terms of privacy protection requirements, concerns, sensitivity levels, etc. are obtained. Through attribute combination, a privacy preference profile generation algorithm is used to obtain the corresponding privacy preference profile. According to the user privacy profile, a personalized recommendation algorithm is used to generate personalized privacy preference setting suggestions for each user. Through collaborative filtering and content-based recommendation techniques, combined with the user's historical privacy settings and group privacy profile, the user's personalized privacy preference profile is obtained. The personalized privacy preference profile is applied to the privacy protection and service personalized adjustment of the system. According to the user's privacy preferences, the privacy policy and service parameters of the system are dynamically adjusted to achieve precise protection of user privacy and optimization of personalized services, enhancing the user's sense of privacy security and usage experience. Continuously collect the user's privacy feedback and behavior data, and through incremental learning and online update mechanisms, the privacy preference profile is adjusted and optimized in real time. According to the changes in the user's privacy preferences and new privacy requirements, the group privacy profile and personalized recommendation model are dynamically updated to ensure the continuous improvement of privacy protection and service personalization.

[0080] In this embodiment, a large number of privacy policy texts are collected from sources such as the Internet, app stores, and enterprise websites. Among them, the privacy policy texts include privacy policies and relevant legal documents such as GDPR and CCPA. Then, the privacy policy texts are classified, scored, and key information is extracted, and the corresponding data is labeled. For example, the privacy policy texts can be labeled as "complete", "partially complete", or "incomplete", or key information such as data processing methods and data sharing objects is extracted. Then, the privacy policy texts are preprocessed. For example, noise data such as HTML tags and special characters are removed, and then duplicate data and abnormal data are processed. The abnormal data includes privacy policy texts labeled as partially complete and incomplete, ensuring the diversity and coverage of the data to improve the generalization ability of the model.

[0081] In this embodiment, the Transformer architecture is used as the basic framework, and a preliminary pre-trained model for privacy policy generation is constructed based on the training dataset. Then, the fine-tuning technology is used to obtain a pre-trained language model as the basic model, and by fine-tuning on specific domain data, a model suitable for the privacy policy generation task is obtained. Specifically, according to the business attributes of the privacy policy, the training dataset is further input into the pre-trained model, and the fine-tuning technology is used to perform fine-tuning training on the pre-trained model. Through multiple rounds of iterative optimization, the pre-trained model gradually adapts to the privacy policy generation task, and an initial version of the privacy policy generation model is obtained.

[0082] More specifically, data augmentation techniques are used. By expanding and transforming the training dataset, such as synonym replacement and sentence pattern rewriting, more diverse training samples are obtained, improving the generalization ability and robustness of the model. The training dataset expanded and transformed by the data augmentation technique is re-input into the privacy policy generation model, and in a continuous learning manner, by continuously fine-tuning the model, it better adapts to the characteristics and requirements of the privacy policy field, and a privacy policy generation model with excellent performance is obtained.

[0083] Even more specifically, methods of model evaluation and testing are used. By evaluating indicators such as the generation quality, content relevance, and readability of the model on an independent test set, it is judged whether the privacy policy generation model meets the expected performance requirements. According to the evaluation results, strategies of model optimization and adjustment are adopted. By adjusting model hyperparameters, optimizing training strategies, etc., the privacy policy generation model is further improved, and a high-quality privacy policy generation model that meets business requirements is obtained.

[0084] In this embodiment, according to different privacy preference portraits, the privacy information of different users is divided into multiple training sets and test sets, and a distributed training framework is used to train the privacy policy generation model, that is, different training sets and test sets are generated for different privacy preference portraits, and the privacy policy model is trained in a distributed parallel manner. The privacy policy model is divided into multiple node models according to the privacy preference portrait. Each node model independently updates the corresponding privacy policy model without directly exchanging data, and then the main model is updated and optimized by aggregating the data of all node models to obtain the privacy policy model. Specifically, on each node model, the node model is trained using the training data set corresponding to the node model, and the parameters of the node model are updated through the backpropagation algorithm to obtain an optimized node privacy policy model. Each node model is independently trained and updated without directly exchanging data to protect user privacy, and a trained node privacy policy model is obtained. Through a secure multi-party computing protocol, the parameter information of all node models is encrypted and aggregated to obtain the aggregated global privacy policy model parameters. The main privacy policy model is updated using the global model parameters, and it is judged whether the model meets the expected performance indicators by evaluating on the full test set. If the expected performance is not achieved, continue to iterate and optimize; if the requirements are met, the trained main privacy policy model is deployed online to generate a privacy policy template according to the user's privacy preferences.

[0085] S200. Score each clause in the privacy policy draft to obtain a privacy policy text;

[0086] In this embodiment, each clause in the privacy policy draft is scored by experts according to the relevant regulatory clauses in the privacy regulation database, so that the generated privacy policy text meets the requirements of laws and regulations and the needs of user privacy protection.

[0087] In some embodiments, the above step S200 includes:

[0088] Optimize the privacy policy draft using a deep learning algorithm to obtain a preliminary privacy policy;

[0089] Use a graph traversal algorithm to retrieve the privacy regulation database and mark the regulatory clauses in the privacy regulation database related to the preliminary privacy policy;

[0090] Use the expert analysis method to score each clause of the preliminary privacy policy based on the marked regulatory clauses to obtain a privacy policy text.

[0091] In this embodiment, according to the content of the privacy policy draft, natural language processing techniques are used to perform preprocessing on the privacy policy draft, such as word segmentation, part-of-speech tagging, named entity recognition, etc., to obtain the semantic features of the text. Through a corpus in the privacy policy field, word embedding algorithms such as Word2Vec are used to train a word vector model specific to privacy policies, obtaining a low-dimensional dense vector representation for each word. Algorithms such as TextRank and LDA are used to extract keywords and topic models from the privacy policy draft, obtaining the main content points and topic distributions of the privacy policy draft. According to the business attributes and characteristics of the privacy policy, deep learning models such as LSTM and Transformer are used to perform semantic understanding and representation learning on the privacy policy text, obtaining the deep semantic features of the privacy policy draft. Through the knowledge and experience of privacy policy field experts, a rule base and a case base for privacy policy quality assessment are constructed, obtaining the goals and constraints for privacy policy optimization. A reinforcement learning algorithm is used, taking the semantic features of the privacy policy draft as the state and the modification operations of the privacy policy draft as the actions. Through imitation learning and policy iteration, a policy network for optimizing the privacy policy draft is obtained. According to the policy network for optimizing the privacy policy, the privacy policy draft is iteratively modified. Through repeated evaluation and adjustment, the quality and readability of the privacy policy are continuously improved, and finally a relatively optimal initial draft of the privacy policy is obtained.

[0092] In this embodiment, according to the content of the initial draft of the privacy policy, the keywords involved therein, such as personal information collection, use, sharing, protection, etc., are obtained as the basis for retrieving the privacy regulation database. By representing the privacy regulation database as a graph structure, where the regulation clauses are nodes and the citation relationships between different regulation clauses are edges, a privacy regulation graph database is constructed. The breadth-first search algorithm is used to start from the keywords in the initial draft of the privacy policy and traverse the privacy regulation graph database to obtain the regulation clause nodes related to the keywords. By analyzing the content of the regulation clause nodes, their relevance to each part of the initial draft of the privacy policy is judged, obtaining a relevance metric value. According to the relevance metric value, a threshold filtering method is used to obtain a set of regulation clause nodes highly relevant to the initial draft of the privacy policy. For the selected highly relevant regulation clause nodes, they are marked by adding label attributes in the privacy regulation graph database, obtaining the relevant regulation clauses corresponding to the initial draft of the privacy policy. The marked relevant regulation clauses are matched with the initial draft of the privacy policy to obtain the parts that need to be modified and improved in the initial draft of the privacy policy, forming privacy policy revision suggestions. According to the privacy policy revision suggestions, the initial draft of the privacy policy is iteratively optimized to ensure that it meets the requirements of the latest privacy protection regulations, and finally a complete privacy policy text is generated.

[0093] In this embodiment, according to the content of the initial draft of the privacy policy, the expert analysis method is adopted to comprehensively evaluate the compliance, readability, integrity, etc. of each clause, and obtain the scoring results of the experts for each clause. By summarizing and analyzing the expert scoring results, the average score of each clause is obtained as a quantitative indicator of the quality of the clause. Using the tagged regulatory clauses as the reference standard, the similarity between each clause of the initial draft of the privacy policy and the standard clauses is obtained to determine the compliance degree of each clause. According to the two indicators of the average score of the expert scoring and the compliance degree, through the weighted average method, the comprehensive score of each clause is obtained as the final evaluation result of the clause. For the clauses with a comprehensive score lower than the preset threshold, judge the main problems existing in them and give modification suggestions to improve the overall quality of the privacy policy. According to the above evaluation results and modification suggestions, optimize and improve the initial draft of the privacy policy to obtain a privacy policy text that meets the regulatory requirements and is easy for users to understand.

[0094] S300. Based on the regulatory database, adopt the natural language processing method to convert the regulatory database into a rule engine, and perform dynamic compliance inspection on the privacy policy text according to the rule engine to generate a compliance evaluation report;

[0095] In this embodiment, the existing laws and regulations are assembled to form a regulatory database, the regulatory database is converted into a rule engine, and the privacy policy text is dynamically updated according to the update of the regulatory clauses related to privacy in the regulatory database, so that the generated privacy policy text can always meet the requirements of the latest laws and regulations and the user privacy protection needs.

[0096] In some of the embodiments, the above step S300 includes:

[0097] Dynamically obtain the regulatory text in the regulatory database, preprocess the regulatory text through natural language technology to obtain a key database, and the key database is a privacy regulatory database;

[0098] Adopt a keyword extraction algorithm to identify the privacy regulatory terms in the key database;

[0099] Adopt a semantic analysis tool to analyze the specific context and relevance of the privacy regulatory terms in the key database to obtain the semantic understanding rules of the privacy regulatory terms;

[0100] Based on the semantic understanding rules, construct logical reasoning rules, and based on the logical reasoning rules, design a rule engine;

[0101] Based on the rule engine, perform compliance inspection on the privacy policy text to generate a compliance evaluation report.

[0102] In this embodiment, according to business requirements, the scope of the regulatory database to be acquired is determined. Specifically, the fields involved in the business are analyzed, and it is found that they mainly involve environmental protection, work safety, labor employment, etc. Therefore, key attention is paid to the regulations issued by ministries and commissions such as the Ministry of Ecology and Environment, the Ministry of Emergency Management, and the Ministry of Human Resources and Social Security, as well as the local regulations issued by their subordinate local departments. The web crawler technology is used to collect data from the official websites of the above-mentioned ministries and commissions. By analyzing the URL rules, page structures, etc. of the websites, a crawler program is written to automatically capture regulatory data regularly. Again, the collected data is cleaned and structured. Using natural language processing technology, operations such as word segmentation, part-of-speech tagging, and named entity recognition are performed on the regulatory text to establish a regulatory database covering the fields required by the business.

[0103] In this embodiment, data collection technology is used to dynamically obtain the regulatory text in the regulatory database to obtain the original regulatory text dataset. Through natural language processing technology, preprocessing is performed on the obtained original regulatory text dataset, including operations such as word segmentation, stop word removal, and part-of-speech tagging, to obtain the preprocessed regulatory text dataset. According to the preprocessed regulatory text dataset, keyword extraction algorithms such as TF-IDF and TextRank are used to extract keywords in the regulatory text to obtain a set of regulatory keywords. By performing word frequency statistics and weight calculation on the set of regulatory keywords, the importance and relevance of the keywords are determined to obtain the filtered set of keywords. According to the filtered set of keywords, a keyword matching algorithm is used to match the regulatory text fragments containing the keywords of privacy regulation terms in the preprocessed regulatory text dataset to obtain a set of regulatory text fragments related to the keywords. By performing semantic analysis and relevance calculation on the set of regulatory text fragments, the logical relationship and context connection between the regulatory text fragments are judged to obtain a set of semantically related regulatory text fragments. According to the set of semantically related regulatory text fragments, data storage technology such as relational databases and non-relational databases is used to store the regulatory text fragments in the critical database to obtain a structured privacy regulation database. By performing data management and maintenance on the privacy regulation database, such as data update and data backup, the accuracy, integrity, and availability of the privacy regulation database are ensured, providing data support for subsequent privacy compliance analysis and risk assessment.

[0104] In this embodiment, a word segmentation algorithm is used to segment the regulations in the privacy regulation database to obtain a list of words in the privacy regulation database. By constructing a privacy regulation term library, keywords related to privacy regulations are obtained. A keyword extraction algorithm is used to match the word list with the privacy regulation term library to obtain the privacy regulation terms appearing in the privacy regulation database, and determine the privacy regulation attributes involved in the privacy regulation database. Natural language processing technology is used to perform semantic analysis on the critical database to obtain the context information and correlation measure of the privacy regulation terms in the critical database, and obtain the semantic feature vector of the privacy regulation terms. By constructing a semantic understanding rule knowledge base, the semantic feature vector of the privacy regulation terms is matched with the existing rules in the knowledge base to obtain a set of candidate semantic understanding rules related to the semantics of the privacy regulation terms. A sorting algorithm based on similarity calculation is used to score the relevance between the rules in the set of candidate semantic understanding rules and the privacy regulation terms, and the candidate rules are sorted according to the scoring results to obtain the semantic understanding rule with the highest confidence as the optimal semantic understanding rule of the privacy regulation terms. The optimal semantic understanding rule is applied to the critical database to parse and extract the semantic information of the privacy regulation terms in a specific context, and obtain the accurate semantic representation and association relationship of the privacy regulation terms in the critical database. According to the obtained semantic representation of the privacy regulation terms, a rule engine based on logical inference rules is used, combined with domain expert knowledge, to judge the compliance of the privacy regulation terms in the critical text, and determine whether the use of the terms meets the requirements of relevant laws and regulations on privacy protection. By generating a privacy compliance analysis report, the semantic understanding results of the privacy regulation terms, the compliance judgment conclusions, and information such as legal and regulatory clauses are integrated to form a complete privacy compliance analysis result, providing a basis for subsequent privacy compliance rectification.

[0105] In this embodiment, when the regulation text in the regulation database is updated, the privacy regulation terms and logical inference rules are updated synchronously, and then a compliance assessment report is regenerated. According to the regenerated privacy compliance assessment report, a report release process and a notification mechanism are adopted to notify the relevant stakeholders of the updated compliance assessment results. Through report distribution and explanation, it is ensured that all parties understand and comply with the latest privacy regulation requirements, and at the same time, it is also convenient for users to fully understand the corresponding privacy terms and improve the user experience.

[0106] S400. Based on the user's privacy preference data, privacy policy text, and compliance assessment report, a privacy setting interaction interface is established. The privacy setting interaction interface is used to graphically display the options of various data permissions related to privacy settings and provide feedback information related to privacy settings.

[0107] In this embodiment, through the privacy setting interaction interface, personalized privacy policies can be clearly displayed, and users can learn about the uses of their privacy preference data in this personalized privacy policy generation system, improving the transparency of the data processing process, helping to establish and maintain users' trust in this personalized privacy policy generation system. At the same time, it also facilitates users to more intuitively and clearly understand the privacy policy text generated by this personalized privacy policy generation method, improving the comprehensibility of this privacy policy text.

[0108] In some of these embodiments, the above step S400 includes:

[0109] Adopt visual elements to intuitively display options for various data permissions related to privacy settings;

[0110] Obtain the user's privacy setting information and provide timely feedback information according to the privacy setting information, where the feedback information is used to explain the impacts and risks brought by the current privacy settings.

[0111] In this embodiment, by setting visual elements in the privacy setting interaction interface, users can directly participate in the customization process of the privacy policy through options for various data permissions related to privacy settings, making the privacy policy more in line with the actual needs of users, thereby enhancing users' sense of trust and satisfaction in privacy protection.

[0112] In this embodiment, according to the user's operation behavior in the privacy setting interaction interface, the user's privacy setting information is obtained. Among them, the privacy setting information includes privacy preference data such as the user's degree of disclosure of personal information and the scope of data sharing. By analyzing the obtained user privacy setting information, the risk level of the user in terms of privacy protection is judged. The risk level can be divided into three levels: high, medium, and low, and different risk levels correspond to different possibilities of privacy leakage. According to the determined user privacy risk level, a personalized feedback method is adopted to provide the user with an impact description and risk prompt for privacy settings. The prompt content includes risks of data leakage that may be caused by the current privacy settings, problems such as an overly large scope of information sharing, etc., facilitating users to understand privacy-related terms and improving the user experience. Obtain the acceptance degree and understanding situation of the user for the feedback information, and guide the user to adjust and optimize the privacy settings in an interactive manner to help the user find a balance between privacy protection and usability. According to the user's adjusted privacy settings, re-evaluate the user's privacy protection level, determine whether the privacy risk has decreased, generate comparison data before and after the privacy setting optimization, and intuitively display the optimization effect. Adopt a method of regular reminder and update to continuously track the user's privacy settings, obtain the latest changes in the user's privacy protection status, and when it is found that the privacy risk increases, promptly send a reminder to the user to maintain the user's privacy security.

[0113] In some of these embodiments, the above-mentioned method for generating a personalized privacy policy further includes:

[0114] Using an unsupervised learning algorithm to establish a normal data access pattern;

[0115] Real-time monitoring of the user's data access behavior, detecting abnormal behaviors that deviate from the normal data access pattern, intercepting unauthorized abnormal behaviors, performing multi-dimensional risk scoring on the abnormal behaviors, and obtaining a risk report;

[0116] Based on the risk report, prompting the user whether to update the privacy settings;

[0117] Obtaining the user's updated privacy settings and regenerating the privacy policy text according to the updated settings.

[0118] In this embodiment, according to the server log data, data preprocessing technology is used to obtain key attributes such as the user's IP, access time, and requested resources. Through data cleaning and transformation, a normalized user access behavior dataset is obtained. The clustering analysis method in the unsupervised learning algorithm is used to group the obtained user access behavior data. By setting appropriate clustering parameters and similarity measurement methods, a clustering result reflecting different user access patterns is obtained. According to the clustering result, the access behavior characteristics of users within each cluster are analyzed, and statistical information such as access frequency, access time distribution, and requested resource type is obtained. Using machine learning algorithms such as support vector machines or random forests, based on the statistical information within each cluster, a normal data access pattern of the user is trained to obtain a user behavior portrait model.

[0119] In this embodiment, the user's real-time data access behavior is obtained. Through behavior data preprocessing, key features such as access time, access frequency, and access data volume are extracted to obtain the user's current access behavior feature vector. The user's current access behavior feature vector is input into the user behavior portrait model. Through model prediction, it is judged whether the current access behavior deviates from the normal access pattern to obtain an abnormal behavior detection result. According to the abnormal behavior detection result, an expert knowledge base is used to evaluate the risk of the abnormal behavior and determine the risk level of the abnormal behavior. According to the risk level of the abnormal behavior, access control strategies such as user authentication and access permission control are used to intercept high-risk abnormal behaviors and prevent unauthorized data access.

[0120] In this embodiment, for the user operations determined to be abnormal behaviors, a multi-dimensional risk assessment model is adopted to comprehensively consider various attributes of the behaviors, such as operation sensitivity, operation risk level, user identity trust level, etc., and calculate the risk score of the abnormal behaviors. According to the risk score of the abnormal behaviors and the degree of business impact, a risk report is generated, which details information such as the type of abnormal behaviors, occurrence time, risk level, etc., providing a basis for subsequent security decision-making and response. Continuously monitor the user's behavior data, regularly update the user behavior pattern, and through the online learning and incremental learning capabilities of machine learning algorithms, continuously optimize the accuracy and real-time performance of abnormal behavior detection and risk assessment, and improve the security protection level of the system.

[0121] In addition, based on the privacy risk assessment results, determine whether there is a risk of leaking personal sensitive information in the user's current privacy settings. If there is a relatively high risk, trigger the generation of a personalized privacy risk report. According to the user's privacy risk level and specific risk items, use natural language generation technology to automatically generate easy-to-understand privacy risk prompt content, reminding the user which information has a risk of leakage and the possible negative impacts. Obtain various existing privacy setting options on the platform, and through the risk items prompted in the risk report, intelligently recommend relevant privacy settings to guide the user to protect privacy. Use visualization technology to design a vivid and intuitive privacy setting wizard interface, present the recommended privacy setting options to the user, and provide convenient privacy setting methods such as one-key update to improve the user's willingness to update privacy settings. Obtain the user's feedback on the recommended privacy settings. If the user accepts the suggestion and updates the privacy settings, determine that this privacy risk prompt is effective; if the user ignores the risk prompt, judge that the prompting method may be insufficient and needs to be further optimized in the future. By continuously tracking the user's privacy setting situation and the changes in platform data, regularly update the privacy risk report and privacy setting recommendations for the user, and dynamically adjust the risk judgment and prompting strategy according to the user's feedback, continuously improve the intelligent level of privacy protection, and enhance the user's sense of gain.

[0122] This application provides an embodiment applicable to the game industry. Specifically, before entering the game interface, players need to create characters and set personal profiles. At this time, through this personalized privacy policy generation method, the privacy settings interface will prompt players to input their privacy preferences. Players can select corresponding privacy setting options according to their own privacy preferences. For example, when making privacy preference selections, players can choose whether they are willing to share their game achievements, whether they are willing to share location data or game activity records, etc. By selecting the relevant privacy preference settings of the players, the privacy preference data of the users is determined. Based on the privacy preference data, the corresponding privacy preference portrait of the players is determined. The privacy preference portrait is input into the privacy policy generation model to obtain a preset privacy policy template. Based on the privacy policy template and the privacy preference data of the users, a personalized privacy policy text is generated, clearly stating which player data will be collected during the game, how it will be used, and the conditions for sharing. For example, if a player is not willing to share location information, the privacy policy will clearly state this and ensure that this information will not be collected or shared. In addition, the data usage of players is monitored in real time. For example, it is monitored in real time and ensured that the location information of players is not illegally collected or shared. If the system detects potential violations, such as unauthorized data access, it will report immediately. If potential privacy risks are detected, such as a third party attempting to access unauthorized player data, the system will evaluate the severity of this behavior and take corresponding preventive or remedial measures. In addition, all data access records in the game are automatically audited to ensure that all data processing activities comply with the privacy preferences of the players and the regulations in the privacy policy text. At the same time, a visual interface is provided in the game platform, allowing players to view feedback on how privacy preference data is used. If there are any changes to the privacy policy or abnormalities in data usage, players will be actively notified to ensure transparency and trust. Through this personalized privacy policy generation method, not only the efficiency of formulating and implementing the privacy policy is improved, but also the trust of players in the game platform is enhanced, and the overall user experience is improved.

[0123] Please refer to Figure 2 As shown, the present invention also provides a personalized privacy policy generation system, which includes:

[0124] A privacy policy draft generation model 201: used to match user privacy preference data with a preset privacy policy template to generate a privacy policy draft;

[0125] A privacy policy text generation module 202: used to score each clause in the privacy policy draft to obtain a privacy policy text;

[0126] Dynamic compliance check module 203: It is used to convert the regulation database into a rule engine based on the regulation database by using natural language processing methods, and perform dynamic compliance checks on the privacy policy text according to the rule engine to generate a compliance evaluation report;

[0127] Interactive interface setting module 204: It is used to establish a privacy setting interactive interface based on user privacy preference data, privacy policy text, and compliance evaluation report. The privacy setting interactive interface is used to graphically display options for various data permissions related to privacy settings and provide feedback information related to privacy settings.

[0128] It can be understood that the content in the embodiment of the personalized privacy policy generation method as Figure 1 shown is applicable to the embodiment of this personalized privacy policy generation system. The functions specifically implemented in the embodiment of this personalized privacy policy generation system are the same as those in the embodiment of the personalized privacy policy generation method as Figure 1 shown, and the beneficial effects achieved are also the same as those achieved in the embodiment of the personalized privacy policy generation method as Figure 1 shown.

[0129] It should be noted that for the information interaction, execution process, etc. between the above systems, since they are based on the same concept as the method embodiment of the present invention, their specific functions and the technical effects brought can be specifically referred to in the method embodiment part, and will not be elaborated here.

[0130] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the system is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiment, and will not be elaborated here.

[0131] Please refer to Figure 3As shown in the figure, an embodiment of the present invention further provides a computer device 3, including: a memory 302, a processor 301, and a computer program 303 stored on the memory 302. When the computer program 303 is executed on the processor 301, it implements the personalized privacy policy generation method described in any one of the above methods.

[0132] The computer device 3 may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art can understand that Figure 3 This is only an example of the computer device 3 and does not constitute a limitation on the computer device 3. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0133] The so-called processor 301 may be a central processing unit (CPU). The processor 301 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0134] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as the hard disk or memory of the computer device 3. In other embodiments, the memory 302 may also be an external storage device of the computer device 3, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 3. Further, the memory 302 may also include both the internal storage unit and the external storage device of the computer device 3. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store data that has been output or will be output.

[0135] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the personalized privacy policy generation method described in any one of the above methods is implemented.

[0136] In this embodiment, if the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above embodiment methods of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0137] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A method for generating a personalized privacy policy, characterized in that: include: Match user privacy preference data with the preset privacy policy template to generate a privacy policy draft; Score each clause in the draft privacy policy to obtain the privacy policy text; Based on the regulatory database, a natural language processing method is used to convert the regulatory database into a rule engine, and a dynamic compliance check is performed on the privacy policy text according to the rule engine to generate a compliance assessment report; Based on the user's privacy preference data, the privacy policy text and the compliance assessment report, a privacy setting interactive interface is established, wherein the privacy setting interactive interface is used to graphically display the options of various data permissions related to the privacy setting and provide feedback information related to the privacy setting; The matching of the user privacy preference data with the preset privacy policy template to generate a privacy policy draft includes: Obtaining the user's privacy preference data, and obtaining a privacy preference profile corresponding to the user by analyzing the privacy preference data; Establishing a privacy policy generation model, wherein the privacy policy generation model is used to generate a preset privacy policy template according to the privacy preference profile; Using natural language processing technology to perform semantic analysis and keyword extraction on the privacy preference data to obtain the user's privacy demand keywords; The privacy requirement keywords are matched with the preset privacy policy template to generate a privacy policy draft.

2. The method according to claim 1, characterized in that The step of establishing a privacy policy generation model includes: Obtain different users' sensitivity scores for various data permissions and obtain privacy data sources; Preprocessing the privacy data source to obtain privacy information of different users and establish privacy preference profiles of different user groups; Obtaining an existing privacy policy text, preprocessing the existing privacy policy text, and obtaining a training data set; Based on the Transformer architecture, a pre-trained model is constructed, and fine-tuning technology is used to input the training data set into the pre-trained model for training to generate a privacy policy generation model; The privacy preference profiles of different user groups are input into the privacy policy generation model for distributed training to generate multiple privacy policy templates.

3. The method according to claim 1, characterized in that The step of scoring each clause in the draft privacy policy to obtain the privacy policy text includes: Use deep learning algorithms to optimize the privacy policy draft and obtain the first draft of the privacy policy; Using a graph traversal algorithm to search a privacy regulation database, marking regulatory clauses in the privacy regulation database that are related to the first draft of the privacy policy; An expert analysis method is used to score each clause of the draft privacy policy based on the marked regulatory clauses to obtain the privacy policy text.

4. The method according to claim 1, characterized in that Based on the regulatory database, a natural language processing method is used to convert the regulatory database into a rule engine, and a dynamic compliance check is performed on the privacy policy text according to the rule engine to generate a compliance assessment report, including: Dynamically obtain regulatory texts in a regulatory database, pre-process the regulatory texts through natural language technology, and obtain a key database, wherein the key database is a privacy regulatory database; Using a keyword extraction algorithm to identify privacy regulatory terms in the key database; Using semantic analysis tools to analyze the specific context and relevance of the privacy regulatory terms in the key database to obtain semantic understanding rules of the privacy regulatory terms; Based on the semantic understanding rules, construct logical reasoning rules, and based on the logical reasoning rules, design a rule engine; Based on the rule engine, the privacy policy text is checked for compliance and a compliance assessment report is generated.

5. The method according to claim 1, characterized in that The privacy setting interactive interface is established based on the user privacy preference data, the privacy policy text and the compliance assessment report. The privacy setting interactive interface is used to graphically display the options of various data permissions related to the privacy setting and provide feedback information related to the privacy setting, including: Use visual elements to intuitively display the options of various data permissions related to privacy settings; Obtain the user's privacy setting information, and provide timely feedback information based on the privacy setting information, wherein the feedback information is used to explain the impact and risks brought about by the current privacy setting information.

6. The method according to claim 1, characterized in that The method further comprises: Use unsupervised learning algorithms to establish normal data access patterns; Monitor users' data access behaviors in real time, detect abnormal behaviors that deviate from the normal data access patterns, intercept unauthorized abnormal behaviors, perform multi-dimensional risk scoring on the abnormal behaviors, and obtain risk reports; Prompting the user whether to update privacy settings through the risk report; Obtain the user's updated settings for privacy settings, and regenerate the privacy policy text according to the updated settings.

7. A personalized privacy policy generation system, characterized in that: include: Privacy policy draft generation model: used to match user privacy preference data with the preset privacy policy template to generate a privacy policy draft; Privacy policy text generation module: used to score each clause in the privacy policy draft to obtain the privacy policy text; Dynamic compliance check module: used to convert the regulatory database into a rule engine based on the regulatory database by using natural language processing methods, and to perform dynamic compliance check on the privacy policy text according to the rule engine to generate a compliance assessment report; Interactive interface setting module: used to establish a privacy setting interactive interface based on user privacy preference data, privacy policy text and compliance assessment report, wherein the privacy setting interactive interface is used to graphically display the options of various data permissions related to privacy settings and provide feedback information related to privacy settings; The matching of the user privacy preference data with the preset privacy policy template to generate a privacy policy draft includes: Obtaining the user's privacy preference data, and obtaining a privacy preference profile corresponding to the user by analyzing the privacy preference data; Establishing a privacy policy generation model, wherein the privacy policy generation model is used to generate a preset privacy policy template according to the privacy preference profile; Using natural language processing technology to perform semantic analysis and keyword extraction on the privacy preference data to obtain the user's privacy demand keywords; The privacy requirement keywords are matched with the preset privacy policy template to generate a privacy policy draft.

8. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Method and system for generating privacy policy text according to APK package

    CN113254923A

  • Compliance risk management and control method and system, electronic equipment and storage medium

    CN116205496A