Selective disclosure data transmission method

The selective two-step data disclosure method simplifies and secures personal data transactions by ensuring only authorized entities access the appropriate data, reducing complexity and cost in multi-entity data exchanges.

FR3159247A1Pending Publication Date: 2025-08-15M ITRUST
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2024001458
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-14
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Existing methods for transmitting personal data involve multiple entities, leading to complex, costly, and inefficient transactions, especially when intermediary entities require only partial access to user data, resulting in duplicate data transmission and increased processing time.

Method used

A method for selective disclosure of personal data involving two-step data transmission: first disclosing 'main' data to an intermediary entity and 'additional' data to a final recipient, with encryption and user consent, ensuring only authorized entities access the appropriate data.

Benefits of technology

Simplifies data transactions by reducing duplicate data transmission and processing time, while ensuring data security and compliance with access rights, allowing entities to manage their part of the transaction independently.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for transmitting personal data with selective disclosure, implemented by computer and comprising the following steps: - for each user of a set (3) of users, obtaining main personal data (2) and complementary personal data (6) of this user from one or more data providers (7), - main disclosure, to an entity (4) authorized to access the main data, of the main data (2) of the users of the set (3) of users, - complementary disclosure, to an entity (8) authorized to access the complementary data, of the complementary data (6) of the users of a subset (5) of users among the set (3) of users, the subset (5) not comprising all the users of the set (3). Figure for abstract: figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for transmitting data with selective disclosure

[0001] The invention relates to the transmission of personal data of a user.

[0002] When a provider of any service, for example a bank, requests the sending of personal data to a user, in particular to justify a personal situation of this user, it is common for the user to obtain this data online through another service provider with which the requested data is stored. For example, this involves the user obtaining proof of address stored with an electricity supplier, the latter supplier then playing the role of data provider, and sending this proof to the bank. This work of searching for and obtaining personal data by the user from various online data providers, repeated moreover from time to time for several recipient service providers, is tedious.The work of processing and checking the transmitted documents by the service provider receiving the documents generates a certain cost and a long delay. In addition, by providing these raw documents which include a lot of personal data, the user transmits, in addition to the data required by the receiving service provider, additional personal data not required, for example here information relating to his electricity bills, which is inconvenient for him.

[0003] To overcome these problems, a method for securely transmitting a user's personal data is known in the prior art, according to document FR3091797 in the name of the applicant, in which the user's personal data is accessed from a data provider, this data is minimized by selecting the relevant data, and then the relevant data is transmitted to an online service provider with which the user interacts. Thus, the user's data relevant to the online service provider, and only this relevant data, is selected from the data provider and transmitted directly to the online service provider, without user intervention other than consent, which guarantees the reliability of the data, the speed of the process and the user's control over his or her personal data.

[0004] However, it may happen that a transaction of a user's personal data must be carried out in several stages, in particular via the transmission of some of the user's data in a first step, then the transmission of other data of the same user in a second step and possibly only in the event of selection of this user. It also happens that an intermediary entity, distinct from the final service provider, intervenes in the transaction and is interested in obtaining certain data but is not intended to take cognizance of other user data intended for the service provider.

[0005] For example, when a real estate broker is looking for a rental candidate as an agent for a lessor, he obtains data from a large number of candidates, in particular their respective declarations concerning their respective personal situations, and he also obtains the supporting documents for these declarations, such as the respective tax notices of all these candidates. However, he is only intended to study the declarations of the candidates, in order to select a small number of candidates on this basis and to transmit their data to the lessor. In a second step, the lessor is intended to study the evidence, and this only for the candidates selected by the broker on the basis of their declarations.Thus, it is costly and unnecessary for the lessor to settle a transaction of evidence concerning all the candidates when it is not intended to take cognizance of those of the candidates not selected by the broker, just as it is costly and unnecessary for the broker to settle a transaction concerning the evidence of all the candidates when it is not intended to study them, but only to study their respective declarations. In certain contexts, the intermediary entity and the final recipient entity do not even have, by regulation, the same access rights to a user's data.

[0006] Generally speaking, there are therefore transactions of personal user data involving a data provider, a recipient service provider and an intermediary entity, in which neither the intermediary entity nor the service provider has to know all of the data obtained for all of the users from the data provider, each of these entities being only interested, or even authorized, in obtaining certain data and / or for certain users only.

[0007] One solution to this type of transaction is to perform two separate transactions, one targeting the intermediary entity, and then another transaction, only for certain users and certain data, targeting the actual final service provider. However, this solution is complex to implement and uncomfortable for each party. It notably involves the validation of two transactions for certain users while they consider themselves to be experiencing a single process. In some cases, this solution also involves the duplicate transmission of data, once to one entity, a second time to a second entity, which is costly.

[0008] The invention aims in particular to simplify transactions of personal data of users, from a data provider to a service provider involving an intermediary entity and to provide adjusted possibilities of settlement of these transactions for each of the interested parties.

[0009] To this end, the invention relates to a method for transmitting personal data with selective disclosure, implemented by computer and comprising the following steps:

[0010] - for each user of a set of users, obtaining personal data primary and additional personal data of this user from one or more data providers,

[0011] - main disclosure, to an entity authorized to access the main data, of the main user data of the user set,

[0012] - additional disclosure, to an entity authorized to access the additional data additional data of users of a subset of users from the set of users, the subset not including all users of the set.

[0013] “Personal data” means data of a personal nature, i.e. any information relating to a natural person and which is intended to remain under their control. This may include, for example, data relating to their income, their home address, their identity, their family, their profession, etc.

[0014] The user's "main data" is personal data of that user that is intended to be disclosed first and for all users in the user group. This includes data that asserts the users' personal situations without demonstrating them. It thus allows an entity, in particular the entity authorized to access the main data, to make a selection between all these users as part of a selection process with at least two stages, for example in the context of selecting a candidate for a property rental. The "additional data" is personal data of the user that is intended to be disclosed at a later stage, and only for a subset of users, in particular for users selected after the disclosure of the main data.This includes data that can be used to further explore the personal circumstances of these users, in particular to substantiate the claims made in the primary data. It is on the basis of this data, or the set of primary data and additional data of the user subset, that one or more users can be selected or move on to the next stage of the selection process.

[0015] The choice of personal data as belonging to the “main data” or to the “additional data” is made by the user and / or by a third party entity, for example by an entity in charge of implementing the method of the invention, depending on the type of data concerned. In particular, for the same document from a data provider, data can be deduced therefrom main and additional data. For example, for proof of address from an electricity supplier, the main data is the home address alone, the additional data is the proof itself allowing the source of this address to be authenticated.

[0016] Instead of "main data" and "supplementary data", we could speak of "intermediate data" and respectively of "final data", or more generally of "first data" and respectively of "second data". Corollarily, instead of "main disclosure and "supplementary disclosure", we could speak of "intermediate disclosure" and "final disclosure" or of "first disclosure" and "second disclosure".

[0017] By "data provider" is meant an entity making personal data of the user available to the user. These include service providers, such as an electricity supplier, a bank, a government site such as the tax service, which make documents available to the user, such as an electricity bill, a bank statement or a tax notice, containing personal data of this user in connection with the services that these service providers offer. By making these documents accessible to the user, they form data providers within the meaning of the invention. The data are made available, with the consent of the user, to the method of the invention.

[0018] By "entity authorized to access the main data" is meant any entity, in particular any natural or legal person, authorized by regulation and / or by the user to take cognizance of the main data of this user. These include, for example, brokers. In the context of the method of the invention, one could also speak of "intermediate entity" or more generally of "first entity".

[0019] By "entity authorized to access the additional data" is meant any entity, in particular any natural or legal person, authorized by regulation and / or by the user to take cognizance of the additional data of this user. This includes in particular service providers requiring the personal data of a limited number of users previously selected by the intermediary entity. In the context of the method of the invention, one could also speak of "final entity", "service provider", "recipient service provider" or more generally of "second entity".

[0020] Thus, each user of a set of users is only concerned by a single transaction of all of their data. However, this transmission method comprises two separate data disclosure steps, which makes it possible to disclose some of the data first and other data later. only some of the users, in a second step. An intermediary entity can therefore sort between users after the first disclosure, while a receiving service provider can access the additional data after the second disclosure, and only for the users selected by the intermediary entity. Transactions involving an intermediary entity are therefore simplified and offer new possibilities for controlling access to personal data. In particular, each entity can settle the part of the transaction that concerns it independently of all the data transmitted by the data provider.

[0021] Other optional features, taken alone or in combination, follow.

[0022] Preferably, the main disclosure is made during a first time period, and the complementary disclosure is made during a second period subsequent to the first time period.

[0023] Thus, for each user, not all of their data are disclosed at the same time. This two-step division makes it possible, for example, to first disclose all of the main data for all of the users in the set, to select a subset of the users in the set on the basis of this main data, and then, in the second step, to disclose the complementary data of the users in this subset. This process necessarily involves two distinct time periods associated respectively with the main and complementary disclosures.

[0024] Advantageously, at least one additional data item of a user comprises proof of an assertion made by at least one main data item of this user.

[0025] Thus, if the main data is a value declared by the user, the additional data is for example an official document or one from a company recognized as reliable, repeating this value, demonstrating the correctness of the main data.

[0026] Preferably, the entity authorized to access the main data and the entity authorized to access the complementary data are two separate entities.

[0027] Thus, the first is for example a broker, the second for example a lessor whose purpose is only to take cognizance of the personal data of the candidates selected by the broker.

[0028] Advantageously, the entity authorized to access the main data is not authorized to access the additional data, and / or the entity authorized to access the additional data is not authorized to access the main data.

[0029] Thus, these authorization constraints may come from the user and / or be of a regulatory nature. For example, the user may not want to make his documents evidence accessible only to a lessor and not to a real estate broker. These constraints allow for enhanced data minimization, by only disclosing data to interested entities and not to any other entity. This implies in particular that an entity collecting data can only access it if authorized.

[0030] Alternatively, the entity authorized to access the main data and the entity authorized to access the additional data are one and the same entity.

[0031] Thus, for example, it is a service provider who first studies the main data of all the candidates to select a subset, before studying the supporting documents, i.e. the additional data, only of the candidates in the selected subset.

[0032] Preferably, to achieve the disclosure of the additional personal data of a user to the entity authorized to access the additional data, the following steps are implemented:

[0033] - asks the user for consent to the disclosure of his personal data additional data to the entity authorized to access the additional data;

[0034] - obtaining user consent.

[0035] Thus, before the additional disclosure step, the user's consent for this additional disclosure is requested and obtained. The user can thus freely decide whether or not he agrees to disclose his additional data.

[0036] Preferably, the method comprises, before requesting consent, a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent, a step of obtaining the user's consent for some or all of the entities on the list.

[0037] Thus, the user provides his consent only for certain previously identified entities. This identification can be carried out by the entity authorized to access the main data.

[0038] Advantageously, at least one of the disclosure steps among the main and complementary disclosures, preferably both the main and complementary disclosure steps, are carried out in return for remuneration granted directly or indirectly to an organizing entity making the method available to users, to the entity authorized to access the main data and to the entity authorized to access the complementary data, the organizing entity being for example a data transmission platform.

[0039] Thus, the organizer of the process is remunerated by the actors of the process according to the data disclosed to each of the entities. This remuneration can for example be carried out directly by the main or complementary entities concerned by the data disclosures.

[0040] Preferably, the method comprises, after the step of obtaining the main data and the complementary data of the users, for each user of the set of users, a step of forming a digital token of authenticity of the user, the digital token of authenticity of the user comprising the main personal data of this user and the complementary personal data of this user, this token of the user certifying the authenticity of these main data and these complementary data of this user, and in which the main disclosure is carried out by providing, to the entity authorized to access the main data, access to the main data of the tokens of the users of the set of users, and the complementary disclosure is carried out by providing, to the entity authorized to access the complementary data,access to additional data from the tokens of users in the user subset.

[0041] Thus, this token is the digital equivalent of a paper certificate including the data, certifying the authenticity of the data and the user's consent to the sharing of this data. This token ensures the integrity of the data and allows their framed disclosure to authorized entities in a simple and efficient manner.

[0042] Advantageously, the method comprises the following steps:

[0043] - for each user of the set of users, after the step of obtaining the data :

[0044] **encryption of the user's additional personal data, such that the user's authenticity token includes the user's main personal data in clear text and the user's additional data in encrypted form;

[0045] **when the main disclosure of the main data of this user to the entity authorized to access the main data, disclosure of the main data in clear and of the additional encrypted data;

[0046] - for each of the users of the subset of users for which the data additional data are disclosed, to disclose this additional data to the entity authorized to access the additional data, decryption of this additional data.

[0047] Thus, the token includes all the data, and the entity authorized to access the main data can access the content of this token, but the additional data is encrypted, so that only the entity authorized to access the additional data can read it.

[0048] Preferably, the digital authenticity token is a token meeting the standard called “JSON Web Token”.

[0049] Thus, this standard allows the secure exchange of tokens, called "tokens", between several parties, here between the data provider and the entities. This security of the exchange results in the verification of the integrity and authenticity of the data.

[0050] Advantageously, the entity authorized to access the main data is of at least one of the following types:

[0051] **a mortgage or insurance broker;

[0052] **a real estate agent;

[0053] ** a car advisor in a dealership

[0054] and the entity authorized to access the additional data is of at least one of the following types:

[0055] ** a lessor;

[0056] ** an insurance agent;

[0057] ** a bank.

[0058] The invention also provides a computer program comprising: instructions which, when the program is executed by a computer, cause the latter to implement the steps of the method described above.

[0059] Also provided according to the invention is a computer-readable recording medium comprising instructions which, when executed by a computer, cause the latter to implement the steps of the method described above.

[0060] According to the invention, a data transmission platform is also provided, comprising:

[0061] - a module for obtaining main personal data and personal data complementary user profiles of a set of users from one or more data providers,

[0062] - a main disclosure module, to an entity authorized to access the data main, main data of users of the user set,

[0063] - an additional disclosure module, to an entity authorized to access the additional data, additional data of users of a subset of users from the set of users, the subset not including all users of the set.

[0064] By "personal data transmission platform" is meant a digital platform, therefore implemented by computer means, serving as a trusted third party between users, providers of personal data of these users, and entities authorized to access some or all of this personal data. It is made up of computer modules responsible for specific tasks such as obtaining data from data providers and disclosing it to entities. It possibly includes one or more interfaces accessible online, allowing for example a user to provide his consent on the transmission of its data. Brief description of the figures

[0065] The invention will be better understood on reading the following description given solely by way of example and with reference to the appended drawings in which:

[0066] [Fig-1] is a diagram of a data transmission system according to a mode of realization of the invention;

[0067] [Fig.2] is a diagram of a data transmission method according to an embodiment of the invention. Detailed description

[0068] [Fig.l] shows a selective disclosure data transmission system 1 according to an embodiment of the invention. The system 1 aims to obtain and transmit, in a first step, main data 2 of a set 3 of users to a real estate broker 4, which forms an entity authorized, by the users of the set 3, to access this main data 2. This main data 2 is formed of information relating in particular to the income of the users of this set 3 of users. The system 1 aims to transmit, in a second step and for a subset 5 of these users, smaller than the set 3, that is to say not including all the users of the set 3, additional data 6 of the users of this subset 5, to a real estate lessor 8, which forms an entity authorized to access the additional data 6, after selection of the subset 5 by the broker 4.These additional data are notably formed by the tax notices of the users of subset 5, which form the proof of the income indicated in the main data 2. In other words, the additional data 6 of the users include the proof of the assertions made by the respective main data of these users. The broker 4 and the lessor 8 form two separate entities.

[0069] Alternatively, additional data 6 may carry information other than evidence of the main data 2. This may involve, for example, providing details about the user, details not provided by the main data.

[0070] The system 1 comprises providers 7 of personal data of the users of the set 3. Each of these data providers is associated with a respective database 9. Although the providers share the same numerical reference 7 and the associated databases respectively share the same numerical reference 9, each of the providers are distinct from each other and the databases are distinct from each other. As examples, these providers 7 are an electricity supplier, a website of the tax department, a website of a primary health insurance fund, a website of a mutual health. In this example, we will focus on the tax department, each of which has online spaces specific to its users. Each of the providers provides the data of a user from set 3. Alternatively, a provider provides the data of several, or even all, users in set 3. For example, the tax department provides the tax notices of each of the users in set 3.

[0071] The system 1 comprises a selective disclosure data transmission platform 11.

[0072] The platform 11 comprises computer means 15 for implementing various computer modules described below. These means include in particular a processor 12 and a memory 13 conventional for those skilled in the art. The memory is formed of a computer-readable recording medium 13. This recording medium comprises a computer program 14 comprising instructions which, when the program is executed by a computer, here by the processor 12, lead the latter to implement the steps of the method 100 described below. In other words, considering the computer-readable recording medium 13 or any other medium on which the program 14 is written, this medium 13 comprises instructions which, when executed by a computer, here by the processor 12, lead the latter to implement the steps of the method 100.

[0073] The computer modules described below make it possible to implement the method 100 described below.

[0074] The platform 11 comprises a module 16 for obtaining the main personal data 2 and the additional personal data 6 of the users of the subset 3 from the suppliers 7, that is to say in particular from the tax department on the online spaces of each of the users. The module 16 is configured to obtain the amount of a reference income of each user of the set 3 and to consider it as a main data item 2 of each of these users. This module 16 is also configured to classify the tax notice itself as an additional data item 6 forming the proof of the main data item 2 for each of these users. Other forms of main data are possible.For example, alternatively, the main data is a statement of the type "the reference income of this user is greater than X euros", X being a threshold configurable by a third party, the module obtaining this information from the tax notice. Similarly, alternatively, the additional data is not the tax notice itself but another proof document certifying that the income exceeds a reference threshold. Finally, naturally, for each user, other types of main and additional data, associated for example with their address, can be obtained if necessary.

[0075] The platform 11 comprises a data encryption module 18 for encrypting the complementary data 6 of the users of the set 3 of users.

[0076] The platform 11 comprises a module 20 for forming respective authenticity tokens 22 of each user of the set 3 of users, the digital authenticity token 22 of a user comprising the main personal data of this user and the additional personal data in encrypted form of this user, this token 22 of the user certifying the authenticity of these main data and these additional data of this user. Each token therefore comprises the main data 2 and additional data 6 of a single user of the set 3 of users. In addition, each token comprises a means of contacting the user, for example an email address or a telephone number of the user.

[0077] The platform 11 comprises a main disclosure module 24, to an entity authorized to access the main data 2, therefore here to the real estate broker 4, of the main data 2 of the users of the set 3 of users.

[0078] The platform 11 comprises a module 26 for selecting a subset 5 of users from the set 3 of users. This module 26 provides in particular an interface available to an entity authorized to carry out the selection, in particular for the broker 4 or generally for the entity authorized to access the main data of the users, the interface allowing this entity to carry out this selection.

[0079] The platform 11 comprises a module 28 for additional disclosure, to an entity authorized to access the additional data, therefore here to the lessor 8, of the additional data 6 of the users of the subset 5 of users among the set 3 of users.

[0080] We will now describe the method 100 for transmitting personal data with selective disclosure, implemented by the platform 11.

[0081] Step 101 is, for each user of the set 3 of users, obtaining the main personal data 2 and the complementary personal data 6 of this user from one or more data providers 7, in our example in particular from the personal spaces of the users within their online spaces with the tax department. This step 101 is implemented by the module 16 for obtaining this data, which assigns the “main” or “complementary” character to the data obtained depending on their content. Alternatively, this choice is made by the user or by a third-party entity, for example an entity in charge of the platform 11.

[0082] Step 102 is, for each user of the set 3 of users, a step of encryption of the additional personal data 6 of the user. This step is implemented by the encryption module 18.

[0083] Step 103 is, for each user of the set 3 of users, a step of forming the digital authenticity token 22 of the user. This digital authenticity token 22 is a token meeting the standard called “JSON Web Token”. This authenticity token 22 of the user includes the main personal data 2 of the user in clear text and the additional data 6 of the user in encrypted form. This step also includes the integration of a means of contact, for example an email address or a telephone number, of the user. This step is implemented by the formation module 20 of the token 22.

[0084] Step 104 is the main disclosure, to the broker 4, and generally to an entity authorized to access the main data, of the main data 2 of the users of the set 3 of users. This main disclosure is carried out by providing, to the entity authorized to access the main data, access to the data of the tokens 22 of the users of the set 3 of users. The main data 2 are disclosed in clear text and the complementary data 6 are disclosed in encrypted form, so that the entity authorized to access the main data cannot become aware of the complementary data 6 in clear text. This main disclosure is carried out during a first period of time.It is carried out in return for remuneration granted to the platform 11, and more particularly to the organizing entity making the platform 11 and therefore the process 100 available to the users of the set 3, the broker 4 and the lessor 8. Thus, the broker 4 remunerates the platform 11, by regulation when the data is disclosed, by a non-illustrated interface of the platform. This remuneration can be carried out by other means and at other times.

[0085] Step 105 is the selection, by the broker 4, of a subset 5 of users not including all the users of the subset 3. This step is carried out by the broker 4 itself, through an interface of the selection module 26. Alternatively, this step could be carried out by other means.

[0086] Step 106 is, for each user of subset 5 of selected users, the request from the user for consent for the disclosure of his additional personal data 6, to the lessor 8 and generally to an entity authorized to access the additional data.

[0087] Step 107 is obtaining the user's consent for this additional disclosure.

[0088] These steps 106 and 107 are implemented through a non-illustrated interface of the platform 11. In particular, the user has a personal account on the platform 11, which allows him to confirm or not his consent. Alternatively, these steps are implemented by other means, for example by SMS or by email. The request for consent is sent to the user's contact means. integrated into its token.

[0089] Step 108 is the additional disclosure, to the lessor 8, that is to say to an entity authorized to access the additional data 6, of the additional data 6 of the users of the subset 5 of users among all the users. This step is implemented by the additional disclosure module 28. To do this, for each of the users of the subset 5 of users for whom the additional data 6 are disclosed, the module 28 performs the decryption of these additional data 6 for the lessor 8 and for the lessor 8 only when only the lessor 8 is the entity authorized to access the additional data 6. The decrypted additional data 6 are therefore made accessible to the lessor 8 only via an interface of the additional disclosure module, the broker 4 not having access to these additional data 6 in clear.This disclosure is made during a second period subsequent to the first time period. This disclosure is also made in return for remuneration granted to the platform 11. This remuneration is made by the lessor 8. Alternatively, it is made by another entity, for example by the broker 4, who then re-invoices the amount invoiced to the lessor 8.

[0090] Alternatively, one or both of the compensation steps may not take place.

[0091] The invention is not limited to the embodiments presented and other embodiments will become apparent to those skilled in the art.

[0092] In particular, certain steps described in the embodiment presented are not implemented in all the embodiments envisaged. The request for consent from the user and, consequently, the integration of a means of contacting the user in the token are, for example, advantageous optional steps in certain application cases, when the user wishes, for example, increased control over the disclosure of his data.

[0093] In a variant corresponding to a case potentially comprising several entities authorized to access the additional data, before step 106 of requesting consent, the method 100 comprises a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent in step 107, a step of obtaining the user's consent for some or all of the entities on the list. The identification step is carried out for example by the broker 4, who identifies several potential real estate agencies for candidates looking for rental, for example. In a sub-variant, if the list is not defined, all the real estate agencies registered on the platform 11 and authorized by default to access the additional data can access it.

[0094] Similarly, alternative steps to token formation and / or encryption of the additional data could be implemented in order to disclose the data to authorized entities. These steps are nevertheless advantageous in terms of the simplicity and security of data transmission.

[0095] Certain steps involve access configurations that could be different. In particular, in the embodiment presented, the entity authorized to access the main data is not authorized to access the complementary data, and the entity authorized to access the complementary data is not authorized to access the main data. However, as a variant, the entity authorized to access the main data is authorized to access the complementary data, and / or the entity authorized to access the complementary data is authorized to access the main data, all combinations being possible.

[0096] Furthermore, as a variant, the entity authorized to access the main data and the entity authorized to access the complementary data are one and the same entity. For example, the lessor 8 performs the selection itself instead of the broker 4. This process remains advantageous for the lessor 8 at least in economic terms because the lessor 8 only becomes aware of and pays for the complementary data of the users it has selected after the main disclosure.

[0097] Furthermore, alternatively, other disclosure steps are provided, possibly to other authorized entities, during other respective time periods.

[0098] Furthermore, although a real estate broker and a lessor have been taken as examples, any entity is conceivable. As other non-limiting examples, the entity authorized to access the main data may be an insurance broker or a real estate agent, while the entity authorized to access the additional data may be an insurance agent or a bank. Similarly, the entity authorized to access the main data may be a car advisor in a dealership, for example located in a small village. Indeed, although he collects a lot of personal data, he does not have to have access to certain data. Data providers can also be of any type.

[0099] Finally, it is noted that in the embodiment presented, all the users of the set 3 are the subject of the main disclosure step of their main data 2, and all the users of the subset 5 are the subject of the complementary disclosure step of their complementary data 6. However, as a variant, only a first subset of the set 3 is the subject of the main disclosure step of the main data, then a subset of users of this subset, that is to say a second subset of users, originating from the first subset of users and not comprising all the users of the first subset, is the subject of the complementary disclosure step. Reference List

[0100] 1: Data Transmission System 2: Main Personal Data

[0101]

[0102]

[0103]

[0104]

[0105]

[0106]

[0107]

[0108]

[0109]

[0110] [YES]

[0112]

[0113]

[0114]

[0115]

[0116]

[0117]

[0118]

[0119]

[0120] 3: User Set 4: Real Estate Broker / Entity Authorized to Access Main Data 5: User Subset 6: Additional Personal Data 7: Data Provider 8: Landlord / Entity Authorized to Access Additional Data 9: User Database 11: Data Transmission Platform 12: Processor 13: Computer Readable Storage Medium 14: Computer program 15: Computer means 16: Module for obtaining personal data 18: Encryption module 20: Module for forming digital authenticity tokens 22: Digital authenticity token 24: Main disclosure module 26: Selection module 28: Additional disclosure module100: Data transmission method

Claims

Claims

1. A method (100) for transmitting personal data with selective disclosure, implemented by computer and characterized in that it comprises the following steps: - for each user of a set (3) of users, obtaining (101) main personal data (2) and complementary personal data (6) of this user from one or more data providers (7), - main disclosure (104), to an entity (4) authorized to access the main data, of the main data (2) of the users of the set (3) of users, - complementary disclosure (108), to an entity (8) authorized to access the complementary data, of the complementary data (6) of the users of a subset (5) of users among the set (3) of users, the subset (5) not comprising all the users of the set (3).

2. Method (100) according to the preceding claim, wherein the main disclosure (104) is carried out during a first period of time, and the complementary disclosure (108) is carried out during a second period subsequent to the first period of time.

3. Method (100) according to one of the preceding claims, in which at least one complementary data item (6) of a user comprises proof of an assertion made by at least one main data item (2) of this user.

4. Method (100) according to any one of the preceding claims, wherein the entity (4) authorized to access the main data and the entity (8) authorized to access the complementary data are two separate entities.

5. Method (100) according to the preceding claim, in which the entity (4) authorized to access the main data is not authorized to access the complementary data (6), and / or the entity (8) authorized to access the complementary data is not authorized to access the main data (2).

6. Method (100) according to any one of claims 1 to 3, in which the entity authorized to access the main data and the entity authorized to access the complementary data are one and the same entity.

7. Method (100) according to any one of the preceding claims, in which, to carry out the disclosure (108) of the additional personal data of a user to the entity authorized to access the additional data, the following steps are implemented: - requesting (106) the user for consent for the disclosure of his additional personal data (6) to the entity (8) authorized to access the additional data; - obtaining (107) the user's consent.

8. Method (100) before the preceding claim, comprising, before requesting consent, a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent, a step of obtaining the user's consent for some or all of the entities on the list

9. Method (100) according to any one of the preceding claims, in which at least one of the disclosure steps (104, 108) among the main (104) and complementary (108) disclosures, preferably both the main and complementary disclosure steps, are carried out in return for remuneration granted directly or indirectly to an organizing entity making the method available to users, to the entity authorized to access the main data and to the entity authorized to access the complementary data, the organizing entity being for example a data transmission platform.

10. Method (100) according to any one of the preceding claims, comprising, after the step of obtaining (101) the main data (2) and the complementary data (6) of the users, for each user of the set (3) of users, a step of forming (103) a digital authenticity token (22) of the user, the digital authenticity token (22) of the user comprising the main personal data (2) of this user and the complementary personal data (6) of this user, this token (22) of the user certifying the authenticity of these main data and these complementary data of this user, and in which the main disclosure (104) is carried out by providing, to the entity (4) authorized to access the main data (2), access to the main data (2) of the tokens (22) of the users of the set (3) of users, and the additional disclosure (108) is achieved by providing, to the entity (8) authorized to access the additional data (6), access to the additional data (6) of the tokens (22) of the users of the subset (5) of users.

11. Method (100) according to the preceding claim, comprising the following steps: - for each user of the set (3) of users, after the step of obtaining (101) the data: **encryption (102) of the complementary personal data (6) of the user, such that the authenticity token (22) of the user comprises the main personal data (2) of the user in clear text and the complementary data (6) of the user in encrypted form; **during the main disclosure (104) of the main data (2) of this user to the entity (4) authorized to access the main data (2), disclosure of the main data in clear text and of the encrypted complementary data;- for each of the users of the subset (5) of users for which the additional data (6) are disclosed, to disclose this additional data (6) to the entity (8) authorized to access the additional data, decryption of this additional data (6).;

12. Method (100) according to claim 10 or 11, wherein the digital authenticity token (22) is a token meeting the standard called “JSON Web Token”.

13. Method (100) according to any one of the preceding claims, wherein: - the entity authorized to access the main data is of at least one of the following types: **a mortgage or insurance broker; **a real estate agent; **a car dealership advisor; - the entity authorized to access the additional data is of at least one of the following types: ** a lessor; ** an insurance agent; ** a bank.

14. A computer program (14) comprising instructions which, when the program is executed by a computer, causing the latter to implement the steps of the method (100) according to any one of the preceding claims.

15. A computer-readable recording medium (13) comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method (100) according to any one of claims 1 to 13.

16. Data transmission platform (11), characterized in that it comprises: - a module for obtaining (16) main personal data (2) and additional personal data (6) of users of a set (3) of users from one or more data providers (7), - a main disclosure module (24), to an entity (4) authorized to access the main data, the main data (2) of the users of the set (3) of users, - an additional disclosure module (28), to an entity (8) authorized to access the additional data, additional data (6) of the users of a subset (5) of users among the set (3) of users, the subset (5) not including all the users of the set (3).

Citation Information

Patent Citations

  • Advanced secure personal data transmission platform

    FR3091797A1

  • Method for automatically updating a user's data

    FR3116134A1

  • Systems and methods for managing tokens and filtering data to control data access

    US11379614B1