Vehicle system for restricting access to personal data associated with vehicle

By storing personal data marked with user identity in the vehicle system and controlling access according to service type and geographical location, the problem of vehicle-related personal data access control is solved, and fine access and privacy protection of data is achieved.

CN119998809AInactive Publication Date: 2025-05-13NINGBO GEELY AUTOMOBILE RES & DEV CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380070767.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-10
Filing Date
2023-10-07
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is difficult to effectively limit access to personal data associated with a vehicle, especially when a vehicle is shared or served, which may result in unauthorized access to personal data.

Method used

Provided is a vehicle system that stores personal data marked with the identity of a user through processing circuits and sends request messages to approve access to certain personal data while restricting access to other personal data. The system can determine when access to personal data will be allowed based on conditions such as the type of vehicle service and geographical location.

Benefits of technology

A meticulous access control of the personal data associated with the vehicle is realized, allowing access to a portion of the personal data according to the request while maintaining the privacy of other parts, suitable for vehicle sharing and service scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119998809A_ABST
    Figure CN119998809A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a vehicle system (100) for restricting access to personal data associated with a vehicle (1). The system (100) comprises processing circuitry (102a, 102b, 102c) configured to: store at least a first set of personal data tagged with a user identity; storing at least a second set of personal data tagged with the user identity; sending a request message indicating a request to access the first set of personal data; receiving a response message indicating approval of access to the first set of personal data; and determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data. The disclosure also relates to a method and a computer program product (500) for restricting access to personal data associated with a vehicle (1).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to vehicle systems, methods, and computer program products for limiting access to personal data associated with a vehicle. Background Art

[0002] Today's vehicles generate a large amount of data associated with the person using the vehicle. This data can describe, for example, the geographic location of the person, the speed at which the person is driving at a specific geographic location, who else is present with the person in the vehicle, and so on.

[0003] Vehicles are often shared with others, such as with family members, within vehicle sharing communities, in vehicle rental services, and similar services.

[0004] Vehicles are also shared from time to time with vehicle attendants and vehicle service providers, etc., who are allowed access to the vehicle for limited times.

[0005] Whether it is an individual or in order to comply with the country's personal data protection laws and regulations, some data, namely personal data, is desired to be hidden from others (such as service personnel).

[0006] Nowadays, personal data may be accessed, for example, when a vehicle is in service. When a service person has the keys to a vehicle, in order to perform some service on the vehicle, a large amount of personal data may be accessed that is not necessary.

[0007] However, there may be times when it is desirable for service personnel to have access to some personal data in order to perform a particular service. Summary of the invention

[0008] An object of the present disclosure is to mitigate, alleviate or eliminate one or more of the above-mentioned deficiencies and disadvantages in the prior art, and to at least solve the above-mentioned problems.

[0009] According to a first aspect, a vehicle system for limiting access to personal data associated with a vehicle is provided. The system comprises a processing circuit configured to store at least a first set of personal data tagged with a user identity and to store at least a second set of personal data tagged with the user identity.

[0010] The configured processing circuit is also configured to be able to send a request message indicating a request to access a first set of personal data, receive a response message indicating approval of access to the first set of personal data, and determine when to allow access to the first set of personal data while restricting access to at least a second set of personal data.

[0011] An advantage of the first aspect is that access to personal data by others can be restricted, but access to a portion of the personal data can be allowed upon request while restricting access to other portions of the personal data which will remain hidden.

[0012] According to some embodiments, the processing circuit is further configured to detect a request for vehicle service, determine a type of vehicle service requested, and identify a first set of personal data desired for the determined type of vehicle service.

[0013] One advantage of this embodiment is that, depending on the type of vehicle service, certain data required for the service can be identified and access to the desired data can be requested and approved prior to the service.

[0014] According to some embodiments, the processing circuit is further configured to determine a first set of personal data to which access is authorized, and to determine at least a second set of personal data to which access is not authorized, to which access is to be restricted.

[0015] One advantage of this embodiment is that when determining when to allow access to a first set of personal data while restricting access to at least a second set of personal data, the first set of personal data that is approved for access can be determined, and the second set of personal data that is not approved for access can be determined so that the data is ready when the first set of personal data is to be accessed.

[0016] According to some embodiments, the processing circuit is further configured to determine a geographic location of the vehicle, determine whether the vehicle is at a predetermined location, and allow access to the first set of personal data when it is determined that the vehicle is at the predetermined location.

[0017] An advantage of this embodiment is that the geographic location of the vehicle is used when determining when to allow access to the first set of personal data.

[0018] According to some embodiments, the first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data was acquired.

[0019] An advantage of this embodiment is that the original source of the data or the sensor associated with the data when it was acquired can be used to classify the data at an early stage.

[0020] According to some embodiments, the processing circuit is also configured to: obtain personal data; obtain user preferences for how to store personal data; and determine through an artificial intelligence model such as a neural network whether the obtained personal data is stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

[0021] One advantage of this embodiment is that the user is able to indicate preferences for how data is stored and the artificial intelligence model supports the storage of the data accordingly.

[0022] According to some embodiments, personal data tagged with the user's identity is further tagged as GDPR data, and restriction of access to the personal data tagged as GDPR data is managed via a response message indicating approval of access to the first set of personal data.

[0023] An advantage of this embodiment is that a user can approve access to GDPR data by approving access to a first set of personal data while restricting access to at least a second set of personal data. Thus, the system can be used to support compliance with national regulations, such as the General Data Protection Regulation.

[0024] According to some embodiments the request message indicating a request to access the first set of personal data further comprises a request for user identification data and the response message indicating approval of access to the first set of personal data further comprises the user identification data.

[0025] An advantage of this embodiment is that, using the user identification data, it can be verified that the correct user is accessing the first set of personal data.

[0026] According to a second aspect, a method for limiting access to personal data associated with a vehicle is provided.

[0027] The method comprises the steps of storing at least a first set of personal data tagged with a user identity; storing at least a second set of personal data tagged with the user identity; sending a request message indicating a request to access the first set of personal data; receiving a response message indicating approval of access to the first set of personal data; and determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data.

[0028] One advantage of the first aspect is that access to personal data by others can be restricted, but upon request, access can be allowed to a portion of the personal data while restricting access to other portions of the personal data which will remain hidden.

[0029] According to some embodiments, the method further comprises the steps of detecting a request for vehicle service, determining a type of vehicle service requested, and identifying a first set of personal data desired for the determined type of vehicle service.

[0030] One advantage of this embodiment is that, depending on the type of vehicle service, certain data required for the service can be identified and access to the desired data can be requested and approved prior to the service.

[0031] According to some embodiments, the method further comprises the steps of determining a first set of personal data to which access is approved, and determining at least a second set of personal data to which access is not approved, to which access is to be restricted.

[0032] One advantage of this embodiment is that when determining when to allow access to a first set of personal data while restricting access to at least a second set of personal data, the first set of personal data that is approved for access can be determined, and the second set of personal data that is not approved for access can be determined so that the data is ready when the first set of personal data is to be accessed.

[0033] According to some embodiments, the method further includes the following steps: obtaining personal data; obtaining user preferences for how to store personal data; and determining through an artificial intelligence model such as a neural network whether the obtained personal data is stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

[0034] One advantage of this embodiment is that the user is able to indicate preferences for how data is stored, and the artificial intelligence model supports the storage of the data accordingly.

[0035] According to some embodiments, the first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data was acquired.

[0036] An advantage of this embodiment is that the original source of the data or the sensor associated with the data when it was acquired can be used to classify the data at an early stage.

[0037] According to some embodiments, the method further comprises the steps of determining a geographic location of the vehicle, determining whether the vehicle is at a predetermined location, and allowing access to the first set of personal data when the vehicle is determined to be at the predetermined location.

[0038] An advantage of this embodiment is that the geographic location of the vehicle is used when determining when to allow access to the first set of personal data.

[0039] According to a third aspect, there is provided a computer program product comprising a non-transitory computer-readable medium, on which is a computer program comprising program instructions, which can be loaded into a processing circuit and is configured to enable the method to be performed when the computer program is run by the processing circuit.

[0040] The effects and features of the second and third aspects are largely similar to those described above in connection with the first aspect. The embodiments mentioned in connection with the first aspect are widely compatible with the second and third aspects.

[0041] The present disclosure will become apparent from the detailed description given below. The detailed description and specific embodiments disclose preferred embodiments of the present disclosure only by way of illustration. According to the guidance in the detailed description, those skilled in the art will appreciate that changes and modifications can be made within the scope of the present disclosure.

[0042] Therefore, it should be understood that the disclosure disclosed herein is not limited to the specific components of the described device or the steps of the described method, because such devices and methods are changeable. It should also be understood that the terms used in this article are only for describing specific embodiments and are not intended to be limiting. It should be noted that when used in the specification and the appended claims, the articles "one", "an", "the" and "said" are intended to indicate the presence of one or more elements unless the context clearly stipulates otherwise. Therefore, for example, a reference to "a unit" or "the unit" may include several devices, etc. In addition, the words "comprise", "include", "contain" and similar words do not exclude other elements or steps. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The above and other objects, features, and advantages of the present disclosure will be more fully understood by referring to the following illustrative and non-limiting detailed description of exemplary embodiments of the present disclosure when taken in conjunction with the accompanying drawings.

[0044] Figure 1 An exemplary vehicle system for limiting access to personal data associated with a vehicle is shown according to an embodiment of the present disclosure.

[0045] Figure 2 A flow chart showing method steps according to the second aspect of the present disclosure is shown.

[0046] Figure 3 A computer program product according to a third aspect of the present disclosure is shown.

[0047] Figure 4a The acquisition and storage of different sets of data associated with a vehicle is shown.

[0048] Figure 4b Access to a first set of personal data is shown to be granted while access to at least a second set of personal data is restricted. DETAILED DESCRIPTION

[0049] The present disclosure will now be described with reference to the accompanying drawings, in which preferred exemplary embodiments of the present disclosure are shown. However, the present disclosure may be implemented in other forms and should not be construed as being limited to the embodiments disclosed herein. The disclosed embodiments are provided to fully convey the scope of the present disclosure to those skilled in the art.

[0050] Figure 1 An exemplary vehicle system for limiting access to personal data associated with a vehicle is shown according to an embodiment of the present disclosure.

[0051] A first aspect of the disclosure shows a vehicle system 100 for limiting access to personal data associated with a vehicle 1. The system 100 comprises processing circuits 102a, 102b, 102c.

[0052] According to some embodiments, Figure 1 As shown, processing circuit 102a is the processing circuit of an onboard vehicle computer.

[0053] According to some embodiments, Figure 1 As shown, the processing circuits 102 b , 102 c are included in electronic devices 200 , 300 that are connectable to the vehicle system 100 via a wireless communication network 50 .

[0054] According to some embodiments, the vehicle system 100 further comprises a memory 101a, 101b, 101c configured to store data.

[0055] According to some embodiments, Figure 1 As shown, the memory 101a is the memory of the onboard vehicle computer.

[0056] According to some embodiments, Figure 1 As shown, the memories 101 b , 101 c are included in electronic devices 200 , 300 that can be connected to the vehicle system 100 via the wireless communication network 50 .

[0057] According to some embodiments, Figure 1 The wireless communication network 50 shown is a standard wireless wide area network, such as Global System for Mobile communications GSM, extended GSM, General Radio Packet Service GPRS, Enhanced Data Rates for GSM Evolution EDGE, Wideband Code Division Multiple Access WCDMA, Long Term Evolution LTE, narrowband IoT, 5G, Worldwide Interoperability for Microwave Access WiMAX or Ultra Mobile Broadband UMB, or similar networks.

[0058] According to some embodiments, the wireless communication network 50 is a standardized wireless local area network, such as wireless local area network, WLAN, Bluetooth TM , ZigBee, Ultra-Wideband, Radio Frequency Identification, RFID or similar networks.

[0059] According to some embodiments, the wireless communication network 50 may also be a combination of a local area network and a wide area network. According to some embodiments, the wireless communication network 50 is defined by a public Internet protocol.

[0060] According to some embodiments, the processing circuits 102a, 102b, 102c are configured to acquire data. According to some embodiments, the data is acquired by sensors of the vehicle 1. In one example, the sensors are configured to acquire speed data of the vehicle.

[0061] According to some embodiments, the acquired data is personal data. According to some embodiments, personal data is data associated with a person. In one example, the speed data of a vehicle is associated with the person who is driving the vehicle. This person can be anyone. In one example, the video data of a camera in a vehicle cabin is associated with the people in the video. These people can be anyone.

[0062] According to some embodiments, the personal data is associated with the user's identity. In one example, the speed data of a vehicle is associated with the person driving the vehicle, and the identity of that person can be determined.

[0063] According to some embodiments, the personal data is tagged with the user identity.

[0064] According to some embodiments, personal data is tagged with a user identity, wherein the tagging is performed with information indicative of an association with a particular user.

[0065] According to some embodiments, the tag is to use the vehicle key identification information as information associated with a specific user. In one example, a user has a personal vehicle key for accessing a vehicle 1 associated with the user.

[0066] According to some embodiments, the tag is to use user account data information as information associated with a specific user. In one example, the user has a user account for accessing the vehicle 1.

[0067] According to some embodiments, tagging is the use of biometric data as information associated with a specific user. According to some embodiments, biometric data or a combination of different biometric data may be used to identify a user.

[0068] According to some embodiments, tagging is the use of facial recognition data as information associated with a particular user.

[0069] According to some embodiments, tagging is the use of fingerprint data as information associated with a particular user.

[0070] According to some embodiments, tagging is the use of speech recognition data as information associated with a particular user.

[0071] According to some embodiments, tagging is the use of personal identification number code data as information associated with a particular user.

[0072] According to some embodiments, tagging is the use of vehicle order information data as information associated with a particular user.

[0073] According to some embodiments, tagging is the use of vehicle rental information data as information associated with a specific user.

[0074] According to some embodiments, tagging is the use of video data as information associated with a specific user.

[0075] According to some embodiments, the processing circuits 102a, 102b, 102c are configured to acquire at least a first set of personal data tagged with a user identity. In one example, the first set of personal data tagged with a user identity is speed data of a vehicle associated with an identity of a person driving the vehicle.

[0076] According to some embodiments, the processing circuits 102a, 102b, 102c are configured to acquire at least a second set of personal data tagged with a user identity. In one example, the second set of personal data tagged with a user identity is video data from a camera in the vehicle cabin associated with the identity of the person driving the vehicle.

[0077] The processing circuits 102a, 102b, 102c are configured to be able to: store at least a first set of personal data tagged with a user identity, store at least a second set of personal data tagged with the user identity, send a request message indicating a request to access the first set of personal data, receive a response message indicating approval of access to the first set of personal data, and determine when to allow access to the first set of personal data while restricting access to at least the second set of personal data.

[0078] According to some embodiments, the first and second sets of personal data tagged with the user identity are generated by tagging the acquired data with the user identity when acquiring the data.

[0079] According to some embodiments, all acquired data is tagged with the user's identity and stored as personal data tagged with the user's identity.

[0080] According to some embodiments, all acquired data is tagged with the user identity and stored in the memory 101a, 101b, 101c as personal data tagged with the user identity.

[0081] like Figure 1As shown, according to some embodiments, personal data marked with user identity is stored in the memory of the onboard vehicle computer 101a or any one of the memories 101b, 101c, and the memories 101b, 101c are included in the electronic device 200, 300 that can be connected to the vehicle system 100 via the wireless communication network 50.

[0082] According to some embodiments, personal data tagged with the user's identity is only stored in the onboard vehicle computer 101a. In one example, the data is restricted to being stored in the onboard vehicle computer 101a so that the data always belongs to the owner of the vehicle 1.

[0083] According to some embodiments, personal data tagged with a user identity is stored in an onboard vehicle computer 101a and backed up in memories 101b, 101c included in electronic devices 200, 300 that can be connected to the vehicle system 100 via a wireless communication network 50.

[0084] According to some embodiments, personal data tagged with the user's identity is not stored in the onboard vehicle computer 101a but in a memory 101b, 101c contained in an electronic device 200, 300 that can be connected to the vehicle system 100 via the wireless communication network 50. In one example, for integrity and security, the data is stored in the electronic device 200, 300 at a remote location, making it impossible to hack into the memory of the onboard vehicle computer 101a.

[0085] One advantage of the first aspect is that access to personal data by others can be restricted, but upon request, access can be allowed to a portion of the personal data while restricting access to other portions of the personal data which will remain hidden.

[0086] In one example, a first set of personal data is data associated with identifying the geographic location of a vehicle during a specific time period, tagged with the user identity of the vehicle occupant who was driving the vehicle at the time, and a second set of personal data is associated with video data captured in the vehicle cabin during the same time period, tagged with the user identity of the vehicle occupant who was driving the vehicle at the time.

[0087] In one example, it is possible to grant access to a first set of personal data related to identifying the geographic location of a vehicle during a specific time period while restricting access to a second set of personal data related to video data captured in the vehicle cabin during the same time period.

[0088] According to some embodiments, a request message indicating a request to access the first set of personal data is configured to be received at the user terminal 200 , and a response message indicating approval of access to the first set of personal data is generated at the user terminal 200 .

[0089] In one example, refer to Figure 1 , the user 5 of the system 100 is able to receive the request message at the smart phone 200 of the user 5 and respond to the request message via the user interface 400b of the smart phone.

[0090] In one example, the first set of personal data is video data captured of the vehicle 1 surroundings, and the second set of personal data is video data captured in the cabin of the vehicle 1, and access to the video data captured of the vehicle 1 surroundings is granted while access to the video data captured in the cabin remains restricted.

[0091] According to some embodiments, a request message indicating a request to access the first set of personal data is configured to be processed at the system 100 , and a response message indicating approval of access to the first set of personal data is generated by the system 100 .

[0092] According to some embodiments, the processing circuits 102a, 102b, 102c are further configured to process the request message indicating a request to access the first set of personal data based on pre-configured access control settings. In one example, a user of the system 100 can input preferred access control settings via a user interface 400a, 400b of the system 100. In one example, the user can pre-configure the system 100 to never grant access to video data acquired in the vehicle cabin, while always granting access to geolocation data.

[0093] According to some embodiments, the processing circuits 102a, 102b, 102c are configured to initiate the sending of the request message based on a pre-configured vehicle service type. In one example, the request message is sent when it is determined that an over-the-air firmware update (FOTA) is to be performed.

[0094] According to some embodiments, the processing circuits 102a, 102b, 102c are configured to initiate the sending of the request message based on the sensor data. In one example, the request message is sent when a vehicle tilt is determined, such as when the vehicle 1 is being towed.

[0095] According to some embodiments, determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data is performed based on information contained in the request message.

[0096] According to some embodiments, the request message indicates immediate access to the first set of personal data. In one example, the vehicle is at a vehicle service center, and in order to perform certain services, immediate access to the first set of personal data is desired.

[0097] According to some embodiments, the request message indicates access to the first set of personal data at a later point in time. In one example, the vehicle is scheduled to be located at a vehicle service center at a certain point in time in the future, and in order to perform service at that time, it is desired to access the first set of personal data at that certain point in time in the future.

[0098] According to some embodiments, determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data is performed based on information contained in the response message.

[0099] According to some embodiments, the response message indicates immediate access to the first set of personal data. In one example, the vehicle is at a vehicle service center, and in order to perform certain services, immediate access to the first set of personal data is granted.

[0100] According to some embodiments, the response message indicates access to the first set of personal data at a later point in time. In one example, the vehicle is scheduled to be located at a vehicle service center at a certain point in the future, and access to the first set of personal data is granted at that certain point in the future in order to perform service at that time.

[0101] In one example, refer to Figure 1 , a user 5 of the system 100 may receive a request message indicating immediate access to the first set of personal data, but the user 5 responds with a response message indicating access to the first set of personal data at a later point in time.

[0102] According to some embodiments, a request message indicating a request to access a first set of personal data is sent to a user who is using vehicle 1 at a specific time when the requested first set of personal data is generated. In one example, vehicle 1 is involved in a collision at a certain point in time and further data is needed to investigate the collision.

[0103] According to some embodiments, the processing circuit 102a, 102b, 102c is further configured to be capable of receiving a response message indicating that access to at least any one of the first set of personal data and the second set of personal data is not approved.

[0104] According to some embodiments, the processing circuit 102a, 102b, 102c is further configured to be capable of receiving a response message indicating an instruction to delete at least any one of the first set of personal data and the second set of personal data.

[0105] According to some embodiments, the processing circuit 102a, 102b, 102c is further configured to be able to delete at least any one of the first set of personal data and the second set of personal data.

[0106] According to some embodiments, limiting access to at least the second set of personal data includes deleting at least the second set of personal data.

[0107] According to some embodiments, determining when to allow access to a first set of personal data while restricting access to at least a second set of personal data also includes: determining when at least any one of the first set of personal data and the second set of personal data can be deleted; and deleting at least any one of the first set of personal data and the second set of personal data accordingly.

[0108] According to some embodiments, the processing circuit 102a, 102b, 102c is further configured to be able to determine when the first set of personal data has been accessed.

[0109] According to some embodiments, after the first set of personal data is accessed, the at least either one of the first set of personal data and the second set of personal data is deleted.

[0110] According to some embodiments, the processing circuits 102a, 102b, 102c are further configured to detect a request for vehicle service, determine a type of vehicle service requested, and identify a first set of personal data desired for the determined type of vehicle service.

[0111] One advantage of this embodiment is that, depending on the type of vehicle service, certain data required for the service can be identified and access to the desired data can be requested and approved prior to the service.

[0112] In one example, a service is battery related and desires historical power consumption data including speed at a certain point in time. The user may then allow access to historical power consumption data including speed at a certain point in time, while data related to geographic location at that certain point in time remains hidden.

[0113] According to some embodiments, the processing circuits 102a, 102b, 102c are further configured to be able to determine a first set of personal data to which access is authorized, and determine at least a second set of personal data to which access is not authorized, to which access is to be restricted.

[0114] One advantage of this embodiment is that when determining when to allow access to a first set of personal data while restricting access to at least a second set of personal data, the first set of personal data that is approved for access can be determined, and the second set of personal data that is not approved for access can be determined so that the data is ready when the first set of personal data is to be accessed.

[0115] In one example, data files of a first set of personal data are managed and categorized to be separate from data files of a second set of personal data.

[0116] According to some embodiments, the processing circuits 102a, 102b, 102c are further configured to determine the geographic location of the vehicle 1, determine whether the vehicle 1 is at a predetermined location, and allow access to the first set of personal data when it is determined that the vehicle 1 is at the predetermined location.

[0117] An advantage of this embodiment is that the geographic location of the vehicle is used in determining when to allow access to the first set of personal data.

[0118] In one example, access to the first set of personal data is allowed only when the vehicle is at the geographic location of the vehicle service center, and access is not allowed when the vehicle is not at the geographic location of the vehicle service center. This ensures that it is most likely that employees of the vehicle service center are granted access to the first set of personal data, rather than people outside the vehicle service center.

[0119] According to some embodiments, the first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data is acquired.

[0120] An advantage of this embodiment is that the original source of the data or the sensor associated with the data when it was acquired can be used to classify the data at an early stage.

[0121] In one example, the original source is vehicle engine data, such as power consumption, revolutions per minute, engine temperature, etc., and is defined as a first set of personal data tagged with the user's identity, while data from a camera sensor in the vehicle cabin is defined as a second set of personal data tagged with the user's identity.

[0122] According to some embodiments, the sensor associated with the data when the data is acquired is an imaging sensor 20a.

[0123] According to some embodiments, the sensor associated with the data when the data is acquired is microphone 20b.

[0124] According to some embodiments, the sensor associated with the data when the data is acquired is the vehicle engine data sensor 20c.

[0125] According to some embodiments, the processing circuits 102a, 102b, 102c are also configured to be able to: obtain personal data; obtain user preferences for how to store the personal data; and determine through an artificial intelligence model such as a neural network whether the obtained personal data is stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

[0126] One advantage of this embodiment is that the user is able to indicate preferences for how data is stored, and the artificial intelligence model supports the storage of the data accordingly.

[0127] In one example, a user can indicate that any vehicle engine data acquired by the vehicle engine data sensor 20c, such as power consumption, revolutions per minute, and engine temperature, is to be stored as a first set of personal data tagged with the user's identity, while any image data acquired by the camera sensor 20a or voice data acquired by the microphone 20b is to be stored as a second set of personal data tagged with the user's identity.

[0128] According to some embodiments, personal data tagged with the user's identity is further tagged as GDPR data, and restriction of access to the personal data tagged as GDPR data is managed via a response message indicating approval of access to the first set of personal data.

[0129] An advantage of this embodiment is that a user can approve access to GDPR data by approving access to a first set of personal data while restricting access to at least a second set of personal data. Thus, the system can be used to support compliance with national regulations, such as the General Data Protection Regulation.

[0130] In one example, the response message indicates that access to the first set of personal data is permitted, and the response message is stored to support compliance with national regulations.

[0131] According to some embodiments, the request message indicating a request to access the first set of personal data 1 further comprises a request for user identification data, and the response message indicating approval of access to the first set of personal data further comprises the user identification data.

[0132] An advantage of this embodiment is that, using the user identification data, it can be verified that the correct user is accessing the first set of personal data.

[0133] A second aspect of the present disclosure illustrates a method for limiting access to personal data associated with a vehicle 1 . Figure 2 A flow chart showing method steps according to the second aspect of the present disclosure is shown.

[0134] The method comprises the following steps: S1a, storing at least a first set of personal data tagged with a user identity; S1b, storing at least a second set of personal data tagged with a user identity; S5, sending a request message indicating a request for access to the first set of personal data; S6, receiving a response message indicating approval of access to the first set of personal data; and, S8, determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data.

[0135] One advantage of the first aspect is that access to personal data by others can be restricted, but upon request, access can be allowed to a portion of the personal data while restricting access to other portions of the personal data which will remain hidden.

[0136] According to some embodiments, the method further comprises the steps of: S2, detecting a request for a vehicle service; S3, determining a type of vehicle service requested; and S4, identifying a first set of personal data desired for the determined type of vehicle service.

[0137] One advantage of this embodiment is that, depending on the type of vehicle service, certain data required for the service can be identified and access to the desired data can be requested and approved prior to the service.

[0138] According to some embodiments, the method further comprises: step S7, determining a first set of personal data to which access is approved, and determining at least a second set of personal data to which access is not approved and to which access is to be restricted.

[0139] One advantage of this embodiment is that when determining when to allow access to a first set of personal data while restricting access to at least a second set of personal data, the first set of personal data that is approved for access can be determined, and the second set of personal data that is not approved for access can be determined so that the data is ready when the first set of personal data is to be accessed.

[0140] According to some embodiments, the method further includes the following steps: obtaining personal data; obtaining user preferences for how to store the personal data; and determining through an artificial intelligence model such as a neural network whether the obtained personal data is stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

[0141] One advantage of this embodiment is that the user is able to indicate preferences for how data is stored, and the artificial intelligence model supports the storage of the data accordingly.

[0142] According to some embodiments, the first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data is acquired.

[0143] An advantage of this embodiment is that the original source of the data or the sensor associated with the data when it was acquired can be used to classify the data at an early stage.

[0144] According to some embodiments, the method further comprises the steps of determining a geographic location of the vehicle 1 , determining whether the vehicle 1 is at a predetermined location, and allowing access to the first set of personal data when it is determined that the vehicle 1 is at the predetermined location.

[0145] An advantage of this embodiment is that the geographic location of the vehicle is used in determining when to allow access to the first set of personal data.

[0146] Figure 3 A computer program product 500 according to a third aspect of the present disclosure is shown. According to a third aspect, there is provided a computer program product 500 comprising a non-transitory computer readable medium having a computer program comprising program instructions thereon, the computer program being loadable into a processing circuit 102a, 102b, 102c and being configured to cause the method to be performed when the computer program is run by the processing circuit 102a, 102b, 102c.

[0147] For illustrative purposes, Figure 4a shows the acquisition and storage of different sets of data associated with the vehicle 1, and Figure 4b Annotating access to a first set of personal data while restricting access to at least a second set of personal data is shown.

[0148] exist Figure 4a In the example illustration in , the memory 101a is visualized as a box surrounding the data set stored in the memory 101a. In the example illustration, the acquisition of data associated with the vehicle 1 is shown by arrows, and different acquired data is stored in the memory 101a depending on what type of data it is. Figure 4a The storage of at least a first set of personal data 1SPD tagged with a user identity and the storage of at least a second set of personal data 2SPD tagged with a user identity are shown.

[0149] exist Figure 4b In the example illustration of , a request message indicating a request to access a first set of personal data has been sent, and a response message indicating approval to access the first set of personal data has been received. Figure 4b Access to the first set of personal data 1SPD has been granted, and Figure 4b The arrows in show how access to a first set of personal data is allowed by a computer at an electronic device 700 (eg, a service center), while restricting access to at least a second set of personal data retained in the memory 101a.

[0150] Those skilled in the art will recognize that the present disclosure is not limited to the preferred embodiments described above. Those skilled in the art will also recognize that modifications and variations are possible within the scope of the appended claims.

[0151] Additionally, variations to the disclosed embodiments can be understood and effected by the skilled artisan practicing the claimed disclosure, from a study of the drawings, the disclosure, and the appended claims.

Claims

1. A vehicle system (100) for limiting access to personal data associated with a vehicle (1), the system (100) comprising: Processing circuitry (102a, 102b, 102c) configured to: - storing at least a first set of personal data tagged with the user's identity; - storing at least a second set of personal data tagged with the user's identity; - sending a request message indicating a request for access to said first set of personal data; - receiving a response message indicating approval of access to said first set of personal data; as well as - determining when to allow access to said first set of personal data while restricting access to at least said second set of personal data.

2. The system (100) according to claim 1, wherein: The processing circuit (102a, 102b, 102c) is further configured to: - Detecting requests for vehicle services; - determining the type of vehicle service requested; and - identifying said first set of personal data desired for the determined type of vehicle service.

3. The system (100) according to claim 1 or 2, wherein: The processing circuit (102a, 102b, 102c) is further configured to: The first set of personal data to which access is approved is determined, and at least a second set of personal data to which access is not approved is determined, to which access is to be restricted.

4. The system (100) according to any one of the preceding claims, wherein: The processing circuit (102a, 102b, 102c) is further configured to: - determining the geographical location of the vehicle (1); - determining whether the vehicle (1) is in a predetermined position; as well as - allowing access to the first set of personal data upon determining that the vehicle (1) is in the predetermined location.

5. The system (100) according to any one of the preceding claims, wherein: The first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data is acquired.

6. The system (100) according to any one of the preceding claims, wherein: The processing circuit (102a, 102b, 102c) is further configured to: - Access to personal data; - obtain user preferences for how personal data is stored; and - Determining, by an artificial intelligence model such as a neural network, whether the acquired personal data is to be stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

7. The system (100) according to any one of the preceding claims, wherein: The personal data tagged with the user's identity is further tagged as GDPR data, and restriction of access to the personal data tagged as GDPR data is managed by the response message indicating approval of access to the first set of personal data.

8. The system (100) according to any one of the preceding claims, wherein: The request message indicating a request for access to the first set of personal data further comprises a request for user identification data, and the response message indicating approval of access to the first set of personal data further comprises user identification data.

9. A method for limiting access to personal data associated with a vehicle (1), the method comprising: - (S1a) storing at least a first set of personal data tagged with a user's identity; - (S1b) storing at least a second set of personal data tagged with the user's identity; - (S5) sending a request message indicating a request to access the first set of personal data; -(S6) receiving a response message indicating approval of access to the first set of personal data; as well as - (S8) determining when to allow access to the first set of personal data while restricting access to at least the second set of personal data.

10. The method according to claim 9, further comprising: - (S2) detecting a request for vehicle service; -(S3) determining the type of vehicle service requested; as well as - (S4) identifying said first set of personal data desired for the determined type of vehicle service.

11. The method according to claim 9 or 10, further comprising: - (S7) determining the first set of personal data to which access is authorized, and determining at least a second set of personal data to which access is not authorized, to which access is to be restricted.

12. The method according to any one of claims 9 to 11, further comprising: - Access to personal data; - Obtain user preferences for how personal data is stored; as well as - Determining, by an artificial intelligence model such as a neural network, whether the acquired personal data is to be stored as a first set of personal data tagged with the user's identity or as a second set of personal data tagged with the user's identity.

13. The method according to any one of claims 9 to 11, wherein: The first set of personal data tagged with the user's identity and the second set of personal data tagged with the user's identity are defined by the original source of the data, or by a sensor associated with the data when the data is acquired.

14. The method according to any one of claims 9 to 13, further comprising: - determining the geographical location of the vehicle (1); - determining whether the vehicle (1) is in a predetermined position; as well as - allowing access to the first set of personal data upon determining that the vehicle (1) is in the predetermined location.

15. A computer program product (500) comprising a non-transitory computer readable medium having thereon a computer program comprising program instructions, the computer program being loadable into a processing circuit (102a, 102b, 102c) and being configured to enable execution of the method according to any one of claims 9 to 14 when the computer program is run by the processing circuit (102a, 102b, 102c).