Method for setting a data protection for data collected by a vehicle

By detecting data protection settings in the vehicle and creating data protection tokens, the issues of data privacy and compliance during vehicle data transmission are resolved, achieving real-time compliance and transparency of data and improving data security.

CN122070544APending Publication Date: 2026-05-19BAYERISCHE MOTOREN WERKE AG
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BAYERISCHE MOTOREN WERKE AG
Filing Date
2024-10-07
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing technologies, the data collected by vehicles lacks effective data protection mechanisms during transmission and processing, making it difficult to guarantee data privacy and compliance.

Method used

By detecting user data protection settings in the vehicle, structured data records are generated, and data protection tokens containing user consent information are automatically created before and after data transfer to ensure data compliance and transparency.

Benefits of technology

It achieves real-time compliance and transparency of data, ensures that data is processed legally and compliantly in external systems, prevents unauthorized use, and improves data security and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122070544A_ABST
    Figure CN122070544A_ABST
Patent Text Reader

Abstract

The invention relates to a method for setting data protection for data collected by a vehicle, the vehicle being provided for collecting data by means of a sensor and the vehicle providing an interface by means of which a user of the vehicle can perform data protection setting for data collected by the vehicle, the method comprises the following steps: a) detecting, by the vehicle, a data protection setting made by a user of the vehicle for data collected by the vehicle; b) detecting data by means of the vehicle and constructing the data in the form of a data record; c) transferring the at least one data record to an external data receiving point; d) before, during or after the transfer of the data record from the vehicle to the external data reception point, automatically creating at least one data protection token for each data record to be transferred and associating the data protection token created for the respective data record with the respective data record, the data protection token contains information whether a user of the vehicle has agreed to the application of the determination of the data record associated with the data protection token.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for setting up data protection for data collected via vehicles. Background Technology

[0002] Modern vehicles typically include multiple sensors that collect data. This data is known to be transmitted from the vehicle to a so-called backend server, where it can be further processed, either alone or along with data from other vehicles. Such data is generally subject to current data protection regulations, and further processing requires authorization from the vehicle's user.

[0003] Publication DE 10 2021 207 604 A1 describes a method for managing personnel-related data connected to a vehicle. The vehicle's sensors can receive a combination of personnel-related and non-personnel-related data. In this method, labels are determined for the sensor data, including corresponding determinations for both personnel-related and non-personnel-related data.

[0004] DE 10 2022 110 918 A1 describes the application of self-managed data with embedded metadata for, for example, in cases where data is collected via vehicle sensors to comply with data protection.

[0005] EP 3 968 603 A1 describes a method for controlling communication between a vehicle and a backend device in a vehicle-to-cloud system, wherein, in the event of a mobile online service inquiry, the data protection level of the determined data type and the vehicle's current data protection settings are detected in order to connect to the backend device.

[0006] WO 2015 / 150534 A2 describes a human-machine interface connected to a vehicle, which allows setting access permissions and recognition permissions for data collected by the vehicle. Summary of the Invention

[0007] The purpose of this invention is to mitigate and improve data protection for data collected by vehicles.

[0008] The objective of this invention is achieved by a method having the features of claim 1.

[0009] This method is specified for setting data protection for data collected by a vehicle, wherein the vehicle is configured to collect data by means of sensors, and the vehicle provides an interface through which the vehicle's user can set data protection for the data collected by the vehicle. The method includes the following steps:

[0010] a) Data protection settings for data collected from vehicles and for users of vehicles through vehicle inspection;

[0011] b) Using vehicle inspection data and structuring the data in the form of data records;

[0012] c) Transfer at least one data record to an external data receiving point;

[0013] d) Before, during, or after the data record is transferred from the vehicle to an external data receiving point, at least one data protection token is automatically created for each data record to be transferred and the data protection token created for the corresponding data record is associated with the corresponding data record, wherein the data protection token contains information such as whether the user of the vehicle has consented to a specific application of the data record associated with the data protection token.

[0014] This method enables the data or data records to be used in compliance with data protection regulations and thus enables the provision of new data-based functions, particularly in real time, for vehicle users. Secondary use, i.e., using data collected or extracted once for a specific purpose directly related to vehicle operation—for example, through an external service provider for another (secondary) purpose—is particularly effective because the extracted data can be applied multiple times. The association of data records with data protection tokens establishes complete transparency regarding the legal basis for data protection applicable to specific data records. Each data protection token here maps to a specific application consent. Multiple data protection tokens can be associated with data records that map to different application consents. The data protection token here represents an abstract concept of the legal basis for the availability of extracted data and a disclosure of relevant information to potential secondary users and users. The data protection token should be understood here as a specific text with a defined semantics. The use and processing of data are consistent with data protection laws, particularly ensuring that the central system, i.e., the external data receiving point, merely forwards such data to secondary use systems or applications that meet the relevant data protection legal preconditions. The legal prerequisites for data protection specifically include user consent to the use of the data. These legal prerequisites can be created by the external data receiving point based on a data protection token in the form of a logical expression and are checked when forwarded to systems or applications that use the data for secondary purposes.

[0015] In an advantageous embodiment of the invention, the data protection token, and in particular the information contained in the data protection token, is immutable after its automated creation, and / or the data protection token is immutably coupled to the associated data record after association.

[0016] This method allows for the immutable attachment of data protection settings effective only for a specific data record. Therefore, the data protection settings cannot be changed or tampered with at subsequent times. It also prevents the data protection token from being separated from the data record as a whole and the assignment of new, and if necessary, modified data protection tokens to the data record. This enhances the data security of the data record.

[0017] Another advantageous embodiment of the invention includes: the data protection token containing information such as whether the vehicle user has agreed or consented to the identification of the data record associated with the data protection token at the time of data record detection by the vehicle or at the time of data record transfer from the vehicle to an external data receiving point.

[0018] If the user's consent statement already exists at the time the vehicle detects the data, then the data record can already be configured with effective data protection settings at that time, and these data protection settings are also configured before it is transferred. If the consent statement is provided after the detection, then the consent statement can also be associated with the data in the vehicle afterwards.

[0019] Furthermore, it is advantageous for the data protection token to include information such as whether the data record associated with the data protection token is the subject of a legal obligation to store the data record and / or to provide the data record, in particular, to the user upon request.

[0020] Such data records can be inspected not only at external data receiving points but also within the system or application by secondary users in accordance with effective data protection regulations. The data records are thus universally inspectable.

[0021] Furthermore, it is advantageous that the method additionally includes the following steps:

[0022] e) Receive a request for further processing from an external data receiving point, and use the request to request one or more data records from the external data receiving point for further processing;

[0023] f) Check one or more data protection tokens for the appropriate data record that meets the request through an external data receiving point;

[0024] And confirm whether the information contained in the one or more data protection tokens allows or disallows further processing of one or more associated data records through further processing points;

[0025] g) If it is confirmed that the information contained in the one or more data protection tokens allows for further processing of one or more associated data records by a further processing point, then the one or more transferred data records are forwarded to the further processing point by an external data receiving point.

[0026] Further processing points here could be the system or application of a secondary user. The checking of the data protection token allows the external data receiving point to easily confirm whether forwarding a specific data record is permitted. This prevents the external data receiving point from forwarding data records where data protection settings disallow secondary use.

[0027] Alternatively or additionally advantageously, the method may include the following steps:

[0028] h) Receive a request from an external data receiving point via the vehicle, and use the request to request one or more data records from the vehicle for transfer to the external data receiving point;

[0029] i) Checking the vehicle for one or more data protection tokens that meet the request for appropriate data records; and

[0030] j) Confirm: Whether the information contained in one or more data protection tokens allows or disallows the transfer of one or more associated data records to an external data receiving point;

[0031] j1) If it is determined that the information contained in one or more data protection tokens allows the transfer of the one or more associated data records to an external data receiving point, then the one or more associated data records are transferred to the external data receiving point; or

[0032] j2) If it is determined that the information contained in one or more data protection tokens does not allow the transfer of one or more associated data records to an external data receiving point, then the transfer of one or more associated data records to the external data receiving point is not carried out, and the following information is transferred to the external data receiving point: the requested transfer of the one or more data records is not carried out and / or the request transfer of the one or more data records is not allowed.

[0033] In this way, it is possible to determine within the vehicle whether the transfer of a specific data record from the vehicle to an external data receiving point is permitted. The user thus gains the ability to prevent the transfer of the requested data to the external data receiving point. Simultaneously, if the transfer of the requested data record is not implemented, the following information is transmitted to the external data receiving point: the transfer is not or cannot be implemented, to clarify that the non-implementation of the transfer is not due to a transmission or communication error.

[0034] Furthermore, it is advantageous to write the data protection token into or link it to the data record associated with the data protection token as a group of metadata before or during the transfer of the data record.

[0035] In this way, the data record contains data protection rules or settings that are effective at the time of data retrieval or transfer before it is made available for further use. This prevents unauthorized use of the data record.

[0036] Another advantage is that the data protection token can be associated with the data record at the moment it is transferred to the external data receiving point or immediately before that moment.

[0037] In this way, it is possible to variably retain data records after the detection data; that is, it is possible to discard or not store certain data and only the data that is relevant at the time of transfer is equipped with a data protection token and then the data is transferred.

[0038] Additionally, it is advantageous that the data protection token is inseparably written into or inseparably linked to the data record associated with the data protection token. Particularly advantageous is that the data protection token and the data record are cryptographically linked together.

[0039] This method prevents the subsequent alteration or tampering of data protection settings for data records.

[0040] In another advantageous embodiment of the method, the one or more data records can be transferred from the vehicle to an external data receiving point under a defined transfer protocol, wherein data protection settings made by the user are notified to the external data receiving point by the vehicle as parameters of the transfer protocol, and wherein, after the corresponding data records are transferred, the external data receiving point automatically creates a data protection token for each transferred data record according to the made data protection settings and associates the data protection token created for the corresponding data record with the corresponding data record.

[0041] Such an implementation is particularly advantageous, for example, when there is complete consent for all uses of the collected data. In this case, the same data protection settings apply to all data records, so creation and linking can be achieved at an external data receiving point, thereby saving computing resources, especially in vehicles.

[0042] The object of the present invention is further achieved by a computer program product comprising a program code segment that, when processed by one or more electronic computing devices, causes the one or more electronic computing devices to implement the method according to the present invention.

[0043] The objective is further achieved by a computer-readable storage medium, which includes a computer program product.

[0044] Furthermore, the objective is achieved by a system comprising a vehicle and at least one or more external data receiving points for implementing the method according to the invention.

[0045] Advantageous embodiments and further extensions of the invention arise from the corresponding dependent claims and the following description. Attached Figure Description

[0046] The invention is further illustrated below with reference to the accompanying drawings and embodiments. The schematic drawings show:

[0047] Figure 1 The basic communication structure for the process flow of the method is shown in an exemplary embodiment of the present invention;

[0048] Figure 2a and 2b An exemplary time flow is shown in one embodiment of the invention. Detailed Implementation

[0049] Figure 1 The diagram illustrates a basic communication architecture including a vehicle, such as a motor vehicle, capable of collecting data using its own sensors. The vehicle may also be coupled to a mobile communication device, such as a smartphone or navigation device, thus enabling it to collect or detect data using the mobile communication device or its sensors.

[0050] The vehicle thus incorporates sensing devices that can record and transmit various sensor data. Such sensor data may include, for example, vehicle location data, operational data such as motor operating duration and power data, motor consumption data, or vehicle battery state of charge, or vehicle-independent data such as ambient temperature, or the like. Examples of sensors considered include cameras, radar, ultrasonic sensors, or infrared sensors.

[0051] The vehicle can connect to or be connected to an external data receiving point, or so-called a back-end server, via wireless connection, particularly a network connection. It is also conceivable that the vehicle can be wired to an external data receiving point, for example, during maintenance. The back-end server can be specifically configured for sending, receiving, and persistently storing data.

[0052] Generally, data can be detected by the vehicle continuously or at discontinuous times. For example, a defined sensor can continuously output sensor signals, which can be received and processed by an analysis and processing unit. Similarly, a sensor can continuously output sensor signals, which have already been processed into discrete sensor signals by the sensor itself or a connected sensor unit, and these discrete sensor signals are then received and processed by the analysis and processing unit. Furthermore, a defined sensor can output sensor signals at defined intervals, which can also be received and processed by the analysis and processing unit.

[0053] The analysis and processing unit can be connected to or integrated into the vehicle's sensor units so that the detected data can be used for vehicle control or regulation. Furthermore, the analysis and processing unit can be configured as a computer unit and / or a memory unit.

[0054] The analysis and processing unit processes the sensor signals into data, which is then appropriately constructed and summarized in data records D1,...,D n And the data D1,...,D can be recorded in the above data. n The data is stored and communicated in the form of records D1,...,D. A simple example is a set of data records D1,...,D. n This includes the numerical value and unit of the measurement parameter detected by the sensor, such as SI units, as well as so-called metadata, such as the time when the value was recorded and the identifier of the sensor or sensor unit—which is used to detect one or more measurement parameters.

[0055] This type of communication, known as remote communication data or data record communication, can be achieved via a SIM card permanently installed in the vehicle to a backend server. The backend server stores and manages the data records D1,...,D transferred from the vehicle. n .

[0056] Furthermore, the backend server can communicate with different data users 1, 2, and 3. These data users 1, 2, and 3 can request data or data records D1,...,D from the backend server. n This is so that the data or data records can be used or analyzed for a specific purpose, and the backend server can then process the corresponding data or data records D1,...,D n The data is transferred to users 1, 2, and 3. For this purpose, the backend server can verify: the requested data or data records D1,...,D n Does the necessary data protection prerequisites meet, and in particular: the data or data records D1,...,D nWhether the users involved have consented to further exploitation and use by one or more of data users 1, 2, and 3.

[0057] Data that includes direct or indirect identifying characteristics of persons, such as customer numbers, vehicle identification numbers, or vehicle license plates, is referred to as data concerning persons. At least within the European legal system, each link to data concerning persons for a third party's purpose requires consent, provided that the legitimate claims of the participating parties are not restricted. Furthermore, agreements made between the participating parties and thus indicating their explicit consent are possible.

[0058] To enable vehicle users to consent to the connection of data collected by the vehicle, involving or potentially involving personnel, the vehicle has an interface through which the vehicle driver or other involved users can configure data protection settings for the data collected by the vehicle. Specifically, the driver or user can configure which additional services or services of the vehicle, or for the operation of the vehicle, are permitted, along with the permission to use the collected data through said services or services. With such permission, the backend server is allowed to record such data D1,...,D n The data is forwarded to one or more of data users 1, 2, and 3, who, for example, use the data to provide specific business or services. Data users may be, for example, a traffic information service provider, a repair or maintenance service provider, or a car rental company operating vehicles within its fleet.

[0059] To allow data collected or detected using the vehicle to be provided to data users 1, 2, and 3, the corresponding user of the vehicle must indicate their consent to the use or analysis. The vehicle provides the possibility of indicating consent, either fully or only for specific data or data records. The interface also allows users to view and change their set data protection settings at any time. To prevent users from driving with previous users' data protection settings, driver profiles are stored in the vehicle, or can be created. Drivers have the possibility to change their driver profiles. Furthermore, driver profiles can be coupled to the vehicle key used. Therefore, a user can operate the vehicle only with their individual driver profile and associated individual key, but not with other users' driver profiles. Data protection settings are linked to the corresponding driver profile. Upon changing a driver profile, its data protection settings are applied to the connection between the token and the collected data records. If, as described above, the data protection settings are set in the protocol used for connecting to the backend server and the token is only linked to the data records on the backend to save vehicle and connection resources, then in the event of a driver profile change or a change in data protection settings in the vehicle, the data protection settings for the connection settings must be matched or the connection must be re-established.

[0060] For example, a driver or user can authorize the "Smart Maintenance" service via an interface to use data detected by the vehicle. In this example, data concerning driving behavior, such as speed, tire pressure, and distance traveled, can be transmitted from the vehicle to a backend server, which then transmits the data, either queriedly or without query, to one or more data users. These users use the data to determine the wear condition of the vehicle's tires and, at an appropriate time, instruct the driver or user that the tires are worn to the point where they must be replaced.

[0061] In another example, a driver or user can determine that data of identified individuals can be made available to their motor vehicle insurance policies so that insurance contracts involving the vehicle can be accurately and in real-time matched to the vehicle's actual vehicle parameters, such as annual mileage.

[0062] To label: definite data records D1,...,D n Whether the data record has been released by the driver or user for use by a specific third party, the data record is associated or linked with a specific data protection token. A data protection token can be automatically created for each data record and automatically associated with that data record. For example, an analytics processing unit or a separate computing unit can create such a data protection token and associate it with the data record.

[0063] The data protection token may contain information indicating whether the vehicle user has consented to or disagreed with the specific use or analysis of the associated data record. Alternatively or additionally, the data protection token may include text, i.e., a string, representing consent to the specific use of the data record. If such a data protection token (or text) is associated with or linked to a specific data record, then consent to the use is granted. If a data protection token is missing, then consent to the specific data record is denied. A data record may be associated with multiple data protection tokens. The data protection tokens may be readable by the backend server, but cannot be modified by or through the backend server. The corresponding information readable by the backend server is thus stored in the data protection tokens S1,..., S... n In the process, the data protection token is associated with its respective data record D1,...,D n Related.

[0064] Data protection tokens S1,..., S n After its association or connection, it is inseparable from and immutable with the corresponding configured data records D1,...,D n Connection. Similarly, data records D1,...,D n In its relation to data protection tokens S1,..., S n Once associated, it can no longer be changed.

[0065] Figure 2a and 2b This document illustrates a possible timeline for creating a data protection token according to the present invention.

[0066] exist Figure 2a In this system, vehicle usage is recorded at time t0. At time t1, the sensors begin detecting a measurement value M. For example, the door can be unlocked at time t0, and the start of driving can be confirmed at time t1, allowing the odometer to sense the vehicle's movement and measure the distance traveled. In this simple example of the odometer, the detected measurement value M corresponds to the detected vehicle's distance in kilometers, typically accurate to meters.

[0067] At time t2—which can be during, after, or immediately after the journey—the measurement value M is recorded, i.e., stored at time t2. At subsequent times t... E The user changes the data protection settings set at the start of the journey (t0) to release the measured value M or the data record containing the measured value M for a given purpose. Subsequently, a corresponding data protection token is created for the data record containing the measured value M and associated or linked to the data record. At time t3, the data record along with the data protection token is transferred to the backend server.

[0068] This is advantageous because after storing the measurement value M at time t2, the connection between the measurement value M and the data protection token is not performed directly, and the measurement value is therefore not forcibly "lost" if its use is not permitted.

[0069] And in Figure 2b In this case, at time t0, that is, before the detection of measurement value M begins, consent to use measurement value M already exists. Simultaneously with storing or "recording" measurement value M, a data protection token is created for the data record—which holds measurement value M—and associated with it. In this way, the data record with measurement value M is also valid for storage at t2 and transfer at t... E The time period between them is inextricably linked to the data protection token.

[0070] Advantageously, data records can be associated with data protection tokens only when requested by a backend server or when data records should be transferred to a backend server, regardless of the timing of data protection settings. This avoids the need for measurement values ​​or data records that are discarded before being transferred to the backend server to be associated with data protection tokens. Furthermore, the data protection settings for a data record or measurement can be changed after it has been identified, allowing data protection settings effective at the time of transfer to be applied.

[0071] Combined with Figure 2a and 2b The implementation suggests the possibility that a data protection token with a data record might be generated not at the time of measurement, but at a subsequent time. However, in principle, it is more advantageous for the data protection setting to be decisive at the time of measurement. The token mechanism should not allow for the possibility that the data protection setting might be considered in the backend only at the time of transmission if there is disagreement at the time of measurement, since consent might be provided at that time. This would constitute a possibility for tampering with the data protection setting, which should be avoided in principle. The data record is assigned a token immediately after measurement and is stored inextricably in the vehicle until transmission to the backend is achieved. The positive scenario, based on the assumption that the token will not be lost, is that consent is provided at the time of measurement, but not at the time of transmission to the backend.

[0072] Alternatively, one or more specific data protection settings can be transmitted separately to the backend server as session attributes defined by the transfer protocol, along with the data records for which the data protection settings are valid. This mechanism should be used to avoid token redundancy on data records transmitted via a mobile radio link. This redundancy exists for data records where a mobile radio connection exists between the vehicle and the backend server, and the data records are measured during immediate transmission. In such cases, all these data records have the same data protection token. By setting the token as a connection feature and associating the token with the data record only in the backend, the same result ultimately occurs for these data records as if the optimization were not implemented. Data records for which tokens have been configured before the connection is established in the vehicle and transmitted upon connection establishment must therefore be excluded from the optimization if necessary. This is particularly advantageous when, for example, full consent to all uses of the collected data is explicitly stated. Because data protection tokens are associated only with consent to use, and not with consent to refusal, more consent means more data protection tokens and therefore more redundancy. In such a case, the same data protection settings apply to all data records, thus enabling significantly reduced transmission and resource costs on the backend server by setting data protection settings as session attributes.

Claims

1. A method for setting up data protection for data collected via vehicles, wherein, The vehicle is configured to collect data using sensors, and the vehicle provides an interface through which the vehicle's user can configure data protection settings for the data collected by the vehicle. The method includes the following steps: a) Data protection settings for users of vehicles that collect data from them, through vehicle inspection; b) Construct the data from vehicle inspection data and in the form of data records; c) Transfer at least one data record to an external data receiving point; d) Before, during, or after the data record is transferred from the vehicle to the external data receiving point, at least one data protection token is automatically created for each data record to be transferred and the data protection token created for the corresponding data record is associated with the corresponding data record, wherein the data protection token contains information such as whether the user of the vehicle has consented to a specific application of the data record associated with the data protection token.

2. The method according to claim 1, characterized in that, The data protection token, and in particular the information contained in the data protection token, is immutable after its automated creation, and / or the data protection token is immutably coupled to the associated data record after the association.

3. The method according to any one of the preceding claims, characterized in that, The data protection token contains information such as whether the vehicle user has consented to or previously consented to the specific application of the data record associated with the data protection token at the time the data record is detected by the vehicle or when the data record is transferred from the vehicle to an external data receiving point.

4. The method according to any one of the preceding claims, characterized in that, The data protection token includes information about whether the data record associated with the data protection token is the subject of a legal obligation to store the data record and / or provide the data record to the user, particularly if asked to be provided to the user.

5. The method according to any one of the preceding claims, the method comprising the following steps: e) Receive a request for a further processing point through the external data receiving point, and use the request to request one or more data records from the external data receiving point for further processing; f) Check one or more data protection tokens for the appropriate data record that meets the request through an external data receiving point; And confirm whether the information contained in the one or more data protection tokens allows or disallows further processing of one or more associated data records through the further processing point; g) If it is confirmed that the information contained in the one or more data protection tokens allows further processing of the one or more associated data records through the further processing point, then the transferred one or more data records are forwarded to the further processing point through the external data receiving point.

6. The method according to any one of the preceding claims, the method comprising the following steps: h) Receive a request from the external data receiving point via the vehicle to request one or more data records from the vehicle for transfer to the external data receiving point; i) Check the vehicle for one or more data protection tokens that meet the appropriate data record requirements; as well as j) Confirm whether the information contained in the one or more data protection tokens allows or disallows the transfer of one or more associated data records to the external data receiving point; j1) If it is determined that the information contained in the one or more data protection tokens allows the transfer of the one or more associated data records to the external data receiving point, then the one or more associated data records are transferred to the external data receiving point; or j2) If it is determined that the information contained in the one or more data protection tokens does not allow the transfer of the one or more associated data records to the external data receiving point, then the transfer of the one or more associated data records to the external data receiving point is not implemented, and the following information is transferred to the external data receiving point: the requested transfer of the one or more data records is not implemented and / or the requested transfer of the one or more data records is not allowed.

7. The method according to any one of the preceding claims, characterized in that, Before or during the transfer of data records, the data protection token is written into or linked to the data record associated with the data protection token as a group of metadata.

8. The method according to claim 7, characterized in that, The data protection token is inseparably written into or associated with the data record, and in particular, the data protection token and the data record are cryptographically linked together.

9. The method according to any one of the preceding claims, characterized in that, The data protection token is associated with the data record at the moment the data record is transferred to the external data receiving point or immediately before that moment.

10. The method according to any one of the preceding claims, characterized in that, The one or more data records are transferred from the vehicle to an external data receiving point under a defined transfer protocol, wherein the data protection settings made by the user are notified to the external data receiving point by the vehicle as parameters of the transfer protocol, and wherein, after the corresponding data records are transferred, the external data receiving point automatically creates a data protection token for each transferred data record according to the data protection settings made and associates the data protection token created for the corresponding data record with the corresponding data record.

11. A computer program product comprising a program code segment that, when processed by one or more electronic computing devices, causes the one or more electronic computing devices to perform the method according to any one of claims 1 to 10.

12. A computer-readable storage medium comprising at least one computer program product according to claim 11.

13. A system comprising a vehicle and at least one or more external data receiving points for implementing the method according to any one of claims 1 to 12.