Information management device

The information management device on a vehicle manages privacy information through jurisdiction-specific modules, ensuring compliance with varying laws and protecting privacy effectively.

JP2025125853AActive Publication Date: 2025-08-28TOYOTA JIDOSHA KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024022078
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-16
Publication Date
2025-08-28
Estimated Expiration
2044-02-16

AI Technical Summary

Technical Problem

Privacy laws vary across jurisdictions, posing a risk that privacy information may not be appropriately protected when moved to a jurisdiction with different privacy laws.

Method used

An information management device on a vehicle that includes data processing hardware with modules to manage user consent, correction, and deletion of privacy information based on the vehicle's location, adjusting operations according to varying jurisdictional requirements.

Benefits of technology

Ensures appropriate protection of privacy information by activating or deactivating modules based on jurisdictional laws, reducing user inconvenience and ensuring compliance with repeated queries or location changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025125853000001_ABST
    Figure 2025125853000001_ABST
Patent Text Reader

Abstract

To appropriately protect privacy information, according to privacy regulations different for each jurisdiction.SOLUTION: An information management device 10 mounted on a vehicle 100 includes a data processing hardware 20, a storage 30, and a user interface 40. A switching module 24 determines whether to operate a user consent acquisition module 21, a correction module 22 and a deletion module 23, according to jurisdiction where the vehicle 100 is positioned. The user consent acquisition module 21 stores privacy setting in the storage 30 in association with the jurisdiction where the vehicle 100 is positioned. The correction module 22 corrects one stored privacy information term according to a correction request. The deletion module 23 deletes the one stored privacy information term according to a deletion request.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information management device mounted on a vehicle. [Background technology]

[0002] Patent Document 1 discloses an information management device mounted on a vehicle. The information management device queries the vehicle user as to whether or not to allow the user's private information to be stored in a persistent storage device. Here, the private information includes, for example, the user's name, credit card number, user location information, and vehicle speed.

[0003] If the user permits the storage of the privacy information in the persistent storage device, the information management device stores the user's privacy information in the persistent storage device. If the user refuses the storage of the privacy information in the persistent storage device, the information management device loads the user's privacy information into volatile memory and uses it. In such a case, the user's privacy information is not stored in the persistent storage device. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2021-170016 Summary of the Invention [Problem to be solved by the invention]

[0005] Privacy laws applicable in one jurisdiction, such as a country, state, or territory, may differ from those applicable in another jurisdiction, for example, some jurisdictions may require user consent to store privacy information items in persistent storage, while others may not.

[0006] Therefore, differences in privacy laws in each jurisdiction may result in differences in the functions required for the appropriate protection of privacy information, and as a result, there is a risk that privacy information may not be appropriately protected when moved to a jurisdiction with different privacy laws. [Means for solving the problem]

[0007] The means for solving the above problems and their effects will be described below. According to one aspect of the present disclosure, there is provided an information management device mounted on a vehicle, the information management device comprising: data processing hardware; a storage configured to communicate with the data processing hardware; and a user interface configured to communicate with the data processing hardware, wherein the data processing hardware includes a user consent acquisition module configured to display on the user interface a display for accepting from a user a privacy setting indicating whether or not to allow one or more privacy information items to be stored in the storage, receive the privacy setting from the user interface, and store the privacy setting in the storage in association with a jurisdiction in which the vehicle is located; and a user consent acquisition module configured to display on the user interface a display for accepting a correction request to correct one of the one or more privacy information items that has already been stored in the storage. a correction module configured to display on the user interface a display for accepting a deletion request to delete one of the one or more privacy information items stored in the storage, receive the deletion request from the user interface, and delete the one stored privacy information item in accordance with the deletion request; and a switching module configured to determine whether to operate the user consent acquisition module, the correction module, and the deletion module, respectively, according to the jurisdiction in which the vehicle is located at the time the vehicle's drive system is turned on. [Effects of the Invention]

[0008] According to the above configuration, privacy information can be appropriately protected in accordance with privacy laws that differ from jurisdiction to jurisdiction. [Brief explanation of the drawings]

[0009] [Figure 1]FIG. 1 is a diagram showing an information management device according to an embodiment mounted on a vehicle. [Figure 2] FIG. 2 is a diagram showing an example of a screen display in the user interface. [Figure 3] FIG. 3 is a flowchart showing the process executed by the information management device shown in FIG. [Figure 4] FIG. 4 is a flowchart showing the module operation determination process shown in FIG. [Figure 5] FIG. 5 is a flow chart illustrating a process for complying with privacy laws in jurisdictions that require users to be repeatedly queried for privacy settings. [Figure 6] FIG. 6 is a flow chart illustrating a process for obtaining privacy settings for jurisdictions adjacent to the jurisdiction in which the vehicle is currently located. DETAILED DESCRIPTION OF THE INVENTION

[0010] An information management device according to an embodiment will be described below with reference to the drawings. <Configuration of Information Management Device 100> 1, the configuration of an information management device 10 mounted on a vehicle 100 will be described. The information management device 10 includes data processing hardware 20, a storage 30, and a user interface 40. Each of the storage 30 and the user interface 40 is configured to communicate with the data processing hardware 20.

[0011] An ignition switch 31 is provided in the vehicle 100. The data processing hardware 20 includes a drive system module 28. When a user presses the ignition switch 31, the drive system module 28 turns on the drive system 50 of the vehicle 100. This turns on the switching module 24, the current jurisdiction determination module 25, the storage module 26, and the control module 27. These modules provided in the data processing hardware 20 will be described in detail below.

[0012] A GPS (Global Positioning System) sensor 32 is provided on the vehicle 100. A current jurisdiction determination module 25 determines the jurisdiction in which the vehicle 100 is located based on the location information of the vehicle 100 acquired via the GPS sensor 32. The current jurisdiction determination module 25 provides information indicating the jurisdiction in which the vehicle 100 is located to the switching module 24. A jurisdiction is, for example, a country, a state, or a territory. Multiple countries may constitute one jurisdiction.

[0013] The switching module 24 determines whether to activate the privacy protection modules according to the jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on. Here, the privacy protection modules include a user consent acquisition module 21, a correction module 22, and a deletion module 23. The privacy protection modules will be described later. The process of determining whether to activate the privacy protection modules is step S314 of FIG. 3 and the module operation determination process shown in FIG. 4. As will be described later with reference to step S310 of FIG. 3, the switching module 24 also executes the module operation determination process immediately after switching from the restricted mode to the normal mode. The restricted mode is a mode that is set when the position of the vehicle 100 cannot be acquired, as will be described later with reference to step S316 of FIG. 3. The normal mode is a mode that is set when the position of the vehicle 100 can be acquired, as will be described later with reference to step S302 of FIG. 3. As will be described later with reference to step S312 of FIG. 3, the switching module 24 also performs the module operation determination process when the jurisdiction in which the vehicle 100 is currently located is different from the jurisdiction in which the vehicle 100 was previously determined to be located.

[0014] A DCM (Data Communication Module) 33 is provided in the vehicle 100. The DCM 33 can communicate with devices external to the vehicle 100. As described above, the switching module 24 executes a module operation determination process according to the jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on. The module operation determination process executed by the switching module 24 can be changed via the DCM 33. For example, for a certain jurisdiction, it is possible to change from a mode in which only the user consent acquisition module 21 is activated to a mode in which all of the privacy protection modules are activated. An update tool 34 may be provided in the vehicle 100. The module operation determination process can be changed by connecting the update tool 34 to the vehicle 100 via a wired connection.

[0015] A user interface 40 is provided on the vehicle 100. The user interface 40 is, for example, a touch display that accepts input from a user. The privacy protection modules included in the data processing hardware 20 will now be described in detail.

[0016] The user consent acquisition module 21 displays a display on the user interface 40 to accept a privacy setting from the user. The privacy setting indicates whether or not one or more privacy information items are permitted to be stored in the storage 30. The user consent acquisition module 21 receives the privacy setting from the user interface 40. The user consent acquisition module 21 stores the privacy setting in the storage 30 in association with the jurisdiction in which the vehicle 100 is located. The storage of the privacy setting in the storage 30 is performed via the storage module 26.

[0017] The correction module 22 displays a message on the user interface 40 to accept a correction request. The correction request is a request to correct one privacy information item stored in the storage 30 among one or more privacy information items. The correction module 22 receives the correction request from the user interface 40. The correction module 22 corrects the stored privacy information item in accordance with the correction request. The correction of the stored privacy information item is performed via the storage module 26.

[0018] The deletion module 23 displays a message on the user interface 40 to accept a deletion request. The deletion request is a request to delete one privacy information item stored in the storage 30 from one or more privacy information items. The deletion module 23 receives the deletion request from the user interface 40. The deletion module 23 deletes the stored privacy information item in accordance with the deletion request. The deletion of the stored privacy information item is performed via the storage module 26.

[0019] As mentioned above, the data processing hardware 20 includes a control module 27. The control module 27 requests the storage module 26 to store privacy information items in the storage 30 in accordance with the privacy settings.

[0020] <Example of screen display 200 in user interface 40> Referring to Figure 2, an example of a screen display 200 in the user interface 40 is described. The screen display 200 in the user interface 40 includes four privacy information items. These four privacy information items are surrounded by a dashed line 202 in Figure 2. The four privacy information items are name, credit card number, location information of the vehicle 100, and the speed of the vehicle 100. One or more of the privacy information items displayed in the user interface 40 may differ from jurisdiction to jurisdiction.

[0021] The screen display 200 in the user interface 40 indicates whether or not the user has consented to each of four privacy information items. The indication of whether or not the user has consented is surrounded by a dashed line 204 in FIG. 2. In the example shown in FIG. 2, the user has consented to storing the name, credit card number, and speed of the vehicle 100 in the storage 30. The user has not consented to storing the location information of the vehicle 100 in the storage 30. Note that in the example shown in FIG. 2, whether or not the user has consented to each of the four privacy information items is indicated. Alternatively, whether or not the user has consented to all of the privacy information items may be indicated together.

[0022] In the example shown in FIG. 2, the user consent acquisition module 21 is running. Depending on the jurisdiction, the user consent acquisition module 21 may not be running. In other words, whether or not to run the user consent acquisition module 21 is determined for each jurisdiction. When the user consent acquisition module 21 is running, it is determined for each jurisdiction which one or more privacy information items the user will be asked for permission to collect.

[0023] In the example shown in FIG. 2, the deletion module 23 is not activated. One or more privacy information items may be non-deletable or may be automatically deleted. For example, one or more privacy information items associated with a first jurisdiction may be automatically deleted when the vehicle 100 moves from a first jurisdiction to a second jurisdiction. Unlike the example shown in FIG. 2, when the deletion module 23 is activated, one to four deletion buttons may be displayed in the area surrounded by the dashed-dotted line 206 in FIG. 2. In other words, whether or not to activate the deletion module 23 is determined for each jurisdiction. When the deletion module 23 is activated, it is determined which of the one or more privacy information items the user is allowed to delete.

[0024] In the example shown in FIG. 2, the correction module 22 is activated. In the example shown in FIG. 2, the name and credit card number can be corrected. In contrast, the location information of the vehicle 100 and the speed of the vehicle 100 cannot be corrected. In the area surrounded by the dashed dotted line 208 in FIG. 2, a correction button for correcting the name and a correction button for correcting the credit card number are displayed. In the example shown in FIG. 2, only privacy information items manually entered by the user can be corrected, while automatically entered privacy information items cannot be corrected. Depending on the jurisdiction, correction may be possible for all privacy information items. That is, depending on the jurisdiction, correction is possible regardless of whether the user entered the information. Depending on the jurisdiction, the correction module 22 may not be activated. In this way, whether the correction module 22 is activated is determined for each jurisdiction. When the correction module 22 is activated, it is determined which of one or more privacy information items the user can correct.

[0025] <Outline of Processing Executed by Information Management Device 10> An overview of the processing executed by the information management device 10 will be described with reference to FIG. The information management device 10 repeatedly executes the process shown in FIG. 3 at predetermined intervals while the drive system 50 is operating. The information management device 10 attempts to acquire the position of the vehicle 100 in step S300. Next, the information management device 10 proceeds to step S302. In step S302, the information management device 10 determines whether or not the position of the vehicle 100 has been acquired. If the determination in step S302 is negative (S302: NO), the information management device 10 proceeds to step S316. In step S316, the information management device 10 sets the restricted mode. That is, if the switching module 24 cannot acquire the position of the vehicle 100, it transitions to the restricted mode. The restricted mode is a mode in which the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 is stopped regardless of the jurisdiction. For example, in the restricted mode, the information management device 10 of this embodiment stops the operation of the user consent acquisition module 21, the correction module 22, and the deletion module 23, regardless of the jurisdiction.

[0026] If the information management device 10 makes a positive determination in step S302 (S302: YES), the process proceeds to step S304. In step S304, the information management device 10 sets the normal mode. The normal mode is a mode in which no restricted mode is imposed. The information management device 10 then proceeds to step S306.

[0027] In step S306, the information management device 10 determines the jurisdiction in which the vehicle 100 is currently located based on the position of the vehicle 100. The information management device 10 then proceeds to step S308. In step S308, the information management device 10 determines whether or not the ignition switch 31 has just been turned on. If the information management device 10 makes a positive determination in step S308 (S308: YES), the information management device 10 proceeds to step S314. If the information management device 10 makes a negative determination in step S308 (S308: NO), the information management device 10 proceeds to step S310. In step S310, the information management device 10 determines whether or not the switching module 24 has just switched from the restricted mode to the normal mode. If the information management device 10 makes a positive determination in step S310 (S310: YES), the information management device 10 proceeds to step S314. If the information management device 10 makes a negative determination in step S310 (S310: NO), the information management device 10 proceeds to step S312. In step S312, the information management device 10 determines whether the jurisdiction in which the vehicle 100 is currently located is different from the jurisdiction in which the vehicle 100 was previously determined to be located. If the information management device 10 makes a positive determination in step S312 (S312: YES), the information management device 10 proceeds to step S314.

[0028] In step S314, the information management device 10 executes a module operation determination process, which will be described later with reference to FIG. If the information management device 10 makes a negative determination in step S312 (S312: NO), it ends the processing shown in Fig. 3. The information management device 10 also ends the processing shown in Fig. 3 when it has completed step S314 or step S316.

[0029] <Module operation determination process> The module operation determination process in step S314 of FIG. 3 will be described with reference to FIG. 4. As shown in step S306 of FIG. 3, the information management device 10 knows the jurisdiction in which the vehicle 100 is currently located. In step S400, the information management device 10 determines whether module operation information related to the jurisdiction in which the vehicle 100 is currently located has been stored in the storage 30. The module operation information is information indicating whether or not a privacy protection module group is to be operated. If the information management device 10 makes a negative determination in step S400 (S400: NO), the information management device 10 proceeds to step S424. In step S424, the information management device 10 attempts to acquire module operation information related to the jurisdiction in which the vehicle 100 is currently located. For example, the information management device 10 requests module operation information from a data center installed in the jurisdiction in which the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S426. In step S426, the information management device 10 determines whether or not module operation information related to the jurisdiction in which the vehicle 100 is currently located has been acquired. If the information management device 10 makes a positive determination in step S426 (S426: YES), the process proceeds to step S402. If the information management device 10 makes a negative determination in step S426 (S426: NO), the process proceeds to step S428. In step S428, the information management device 10 prohibits the operation of the user consent acquisition module 21, the correction module 22, and the deletion module 23.

[0030] If the information management device 10 makes a positive determination in step S400 (S400: YES), the process proceeds to step S402. The module operation information related to the jurisdiction in which the vehicle 100 is currently located indicates whether or not the user consent acquisition module 21 is to be operated in the jurisdiction in which the vehicle 100 is currently located. In step S402, the information management device 10 determines whether or not to operate the user consent acquisition module 21. If the information management device 10 makes a positive determination in step S402 (S402: YES), the process proceeds to step S404. In step S404, the information management device 10 operates the user consent acquisition module 21. The information management device 10 then proceeds to step S406. In step S406, the information management device 10 determines whether or not the privacy settings related to the jurisdiction in which the vehicle 100 is currently located have been stored in the storage 30. If the information management device 10 makes a positive determination in step S406 (S406: YES), the process proceeds to step S412. If the information management device 10 makes a negative determination in step S406 (S406: NO), the process proceeds to step S408. In step S408, the information management device 10 acquires the privacy settings by inquiring of the user.

[0031] If the information management device 10 makes a negative determination in step S402 (S402: NO), the process proceeds to step S410. In step S410, the information management device 10 prohibits operation of the user consent acquisition module 21. The information management device 10 also proceeds to step S412 when step S408 or step S410 is completed.

[0032] The module operation information related to the jurisdiction in which the vehicle 100 is currently located indicates whether or not to operate the correction module 22 in the jurisdiction in which the vehicle 100 is currently located. In step S412, the information management device 10 determines whether or not to operate the correction module 22. If the determination in step S412 is affirmative (S412: YES), the information management device 10 proceeds to step S414. In step S414, the information management device 10 operates the correction module 22.

[0033] If the information management device 10 makes a negative determination in step S412 (S412: NO), the process proceeds to step S416. In step S416, the information management device 10 prohibits operation of the correction module 22. If the correction module 22 is operating, the information management device 10 prohibits operation and stops the operation of the correction module 22.

[0034] When the information management device 10 completes step S414 or step S416, the process proceeds to step S418. The module operation information related to the jurisdiction in which the vehicle 100 is currently located indicates whether or not to operate the deletion module 23 in the jurisdiction in which the vehicle 100 is currently located. In step S418, the information management device 10 determines whether or not to operate the deletion module 23. If the determination in step S418 is affirmative (S418: YES), the information management device 10 proceeds to step S420. In step S420, the information management device 10 operates the correction module 22.

[0035] If the information management device 10 makes a negative determination in step S418 (S418: NO), the process proceeds to step S422. In step S422, the information management device 10 prohibits operation of the deletion module 23. If the deletion module 23 is operating, the information management device 10 prohibits operation and stops the operation of the deletion module 23.

[0036] When the information management device 10 completes step S420, step S422, or step S428, the flow of FIG. 4 ends. <Process of repeatedly asking the user about privacy settings> A process for complying with privacy laws in jurisdictions that require repeatedly querying the user for privacy settings will be described with reference to Figure 5. The process shown in Figure 5 is repeatedly performed when the process shown in Figure 4 has not been performed and normal mode is set.

[0037] In step S500, the information management device 10 determines whether or not the jurisdiction in which the vehicle 100 is currently located requires the user to be periodically queried about the privacy settings. That is, the information management device 10 determines whether or not the laws and regulations of the jurisdiction in which the vehicle 100 is currently located require the user to periodically check the privacy settings. For example, the module operation information includes information indicating whether or not the user needs to be periodically queried about the privacy settings.

[0038] If the information management device 10 makes a positive determination in step S500 (S500: YES), the process proceeds to step S502. In step S502, the information management device 10 determines whether a predetermined period has elapsed since the previous inquiry. If the information management device 10 makes a positive determination in step S502 (S502: YES), the process proceeds to step S504.

[0039] In step S504, the information management device 10 acquires the privacy settings by inquiring of the user. When the information management device 10 completes step S504, it ends the flow of Fig. 5. When the information management device 10 makes a negative determination in step S500 (S500: NO), it also ends the flow of Fig. 5. When the information management device 10 makes a negative determination in step S502 (S502: NO), it also ends the flow of Fig. 5.

[0040] Privacy Settings for Jurisdictions Adjacent to the Jurisdiction Where the Vehicle 100 is Currently Located A process for acquiring privacy settings for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located will be described with reference to Fig. 6. The information management device 10 repeatedly executes the process of Fig. 6 when the normal mode is set.

[0041] In step S600, the information management device 10 determines whether the vehicle 100 is within a predetermined distance from the border of a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located. If the determination in step S600 is negative (S600: NO), the information management device 10 repeats step S600. If the determination in step S600 is positive (S600: YES), the information management device 10 proceeds to step S602.

[0042] In step S602, the information management device 10 determines whether module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located has already been stored in the storage 30. If the information management device 10 makes a positive determination in step S602 (S602: YES), the process proceeds to step S608. If the information management device 10 makes a negative determination in step S602 (S602: NO), the process proceeds to step S604. In step S604, the information management device 10 attempts to acquire module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S606. In step S606, the information management device 10 determines whether module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located has been acquired. If the information management device 10 makes a positive determination in step S606 (S606: YES), the process proceeds to step S608. If the determination in step S606 is negative (S606: NO), the information management device 10 ends the flow of FIG.

[0043] The module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located includes information indicating whether or not the user consent acquisition module 21 is to be operated in the adjacent jurisdiction. In step S608, the information management device 10 determines whether or not the user consent acquisition module 21 is to be operated in the jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located. If the determination in step S608 is negative (S608: NO), the information management device 10 ends the flow of FIG. 6. If the determination in step S608 is positive (S608: YES), the information management device 10 proceeds to step S610. In step S610, the information management device 10 determines whether or not privacy settings related to the jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located have been stored in the storage 30. If the determination in step S610 is positive (S610: YES), the information management device 10 ends the flow of FIG. 6. If the information management device 10 makes a negative determination in step S610 (S610: NO), the information management device 10 proceeds to step S612. In step S612, the information management device 10 acquires the privacy settings related to the jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located by inquiring of the user. When the information management device 10 completes step S612, it ends the flow of FIG. 6.

[0044] <Operation of this embodiment> According to step S306 in FIG. 3, the information management device 10 repeatedly determines the jurisdiction in which the vehicle 100 is currently located while the drive system 50 is on. The module operation information of the jurisdiction in which the vehicle 100 is currently located is information indicating whether or not to operate the privacy protection module group. The privacy protection module group includes a user consent acquisition module 21, a correction module 22, and a deletion module 23. If a positive determination is made in step S308, step S310, or step S312, a module operation determination process shown in step S314 and FIG. 4 is executed. This process, particularly according to steps S308 and S314, is performed according to the jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on. In the module operation determination process, as shown in steps S402 to S422, it is determined whether or not to operate the privacy protection module group.

[0045] 3, the following can be said: When the switching module 24 is able to acquire the location of the vehicle 100, the switching module 24 performs the following process: The switching module 24 determines whether to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the jurisdiction in which the vehicle 100 is located.

[0046] 3, the following can be said: The switching module 24 may detect whether the vehicle 100 moves from the first jurisdiction to the second jurisdiction while the drive system 50 of the vehicle 100 is in operation. In such a case, the switching module 24 determines whether to operate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the second jurisdiction.

[0047] According to steps S402 to S406, the following can be said: When the vehicle 100 is located in a jurisdiction where the user consent acquisition module 21 is operated, the information management device 10 operates the user consent acquisition module 21. When the privacy settings associated with the jurisdiction are stored in the storage 30, the user consent acquisition module 21 does not inquire about the privacy settings from the user. In other words, the user consent acquisition module 21 does not display on the user interface 40 to accept the privacy settings from the user.

[0048] 5, the following can be said: The laws and regulations of the jurisdiction in which the vehicle 100 is currently located may require the user to periodically confirm whether or not to allow privacy information items to be stored in the storage 30. In such a case, even if the privacy settings associated with the jurisdiction are stored in the storage 30, the user consent acquisition module 21 periodically queries the user about the privacy settings. That is, the user consent acquisition module 21 displays a message on the user interface 40 to accept the privacy settings from the user.

[0049] <Effects of this embodiment> (1) The information management device 10 mounted on the vehicle 100 includes data processing hardware 20. The information management device 10 includes a storage 30 configured to communicate with the data processing hardware 20. The information management device 10 includes a user interface 40 configured to communicate with the data processing hardware 20. The data processing hardware 20 includes a user consent acquisition module 21. The user consent acquisition module 21 displays a display on the user interface 40 to accept a privacy setting from a user indicating whether or not to allow one or more privacy information items to be stored in the storage 30. The user consent acquisition module 21 receives the privacy setting from the user interface 40. The user consent acquisition module 21 stores the privacy setting in the storage 30 in association with the jurisdiction in which the vehicle 100 is located. The data processing hardware 20 includes a correction module 22. The correction module 22 displays a display on the user interface 40 to accept a correction request to correct one privacy information item stored in the storage 30 out of the one or more privacy information items. The correction module 22 receives a correction request from the user interface 40. The correction module 22 corrects one stored privacy information item in accordance with the correction request. The data processing hardware 20 includes a deletion module 23. The deletion module 23 displays a display on the user interface 40 to accept a deletion request to delete one privacy information item stored in the storage 30 from among the one or more privacy information items. The deletion module 23 receives the deletion request from the user interface 40. The deletion module 23 deletes the one stored privacy information item in accordance with the deletion request. The data processing hardware 20 includes a switching module 24. The switching module 24 determines whether to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively. This determination is made according to the jurisdiction in which the vehicle 100 is located at the time the drive system 50 of the vehicle 100 is turned on.

[0050] According to the above configuration, the switching module 24 determines whether to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, depending on the jurisdiction. Therefore, it is possible to activate the necessary modules in accordance with the privacy laws that differ from jurisdiction to jurisdiction. Therefore, according to the above configuration, it is possible to appropriately protect privacy information in accordance with the privacy laws that differ from jurisdiction to jurisdiction.

[0051] (2) There may be a case where the vehicle 100 is located in a first jurisdiction where the user consent acquisition module 21 is operating. Even in such a case, if the privacy settings associated with the first jurisdiction are stored in the storage 30, the privacy settings are not queried. In other words, the user consent acquisition module 21 does not display on the user interface 40 a message for accepting the privacy settings from the user.

[0052] According to the above configuration, when the privacy settings associated with the first jurisdiction have been stored, the user consent acquisition module 21 does not inquire about the privacy settings of the user. This reduces the user's inconvenience caused by inquiries about the privacy settings.

[0053] (3) The laws and regulations of the first jurisdiction may require the user to periodically confirm whether or not to allow privacy information items to be stored in the storage 30. In such a case, the privacy settings associated with the first jurisdiction are queried even if they are stored in the storage 30. That is, the user consent acquisition module 21 periodically displays a message on the user interface 40 to accept the privacy settings from the user.

[0054] According to the above configuration, privacy information can be appropriately protected in accordance with privacy laws in jurisdictions that require users to be repeatedly queried for privacy settings.

[0055] (4) There are cases where the location of the vehicle 100 cannot be obtained. In such cases, the switching module 24 transitions to a restricted mode in which one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 are stopped from operating, regardless of the jurisdiction. When the location of the vehicle 100 can be obtained, the switching module 24 transitions to a normal mode. When the switching module 24 transitions to the normal mode, it makes the following determination. That is, the switching module 24 determines whether to operate each of the user consent acquisition module 21, the correction module 22, and the deletion module 23 according to the jurisdiction in which the vehicle 100 is located.

[0056] In a situation where the location of vehicle 100 cannot be obtained, operation of one or more of user consent acquisition module 21, correction module 22, and deletion module 23 is stopped. Then, when the location of vehicle 100 can be obtained, it is determined whether or not to operate each module according to the jurisdiction in which vehicle 100 is located. Therefore, when the location of vehicle 100 can be obtained, it is possible to return to a state in which processing related to privacy information can be performed in accordance with the privacy laws of the jurisdiction in which vehicle 100 is located.

[0057] (5) There is a case where the vehicle 100 moves from the first jurisdiction to the second jurisdiction while the drive system 50 of the vehicle 100 is in operation. In such a case, the switching module 24 determines whether to operate the user consent acquisition module 21, the correction module 22, and the deletion module 23 according to the second jurisdiction.

[0058] There may be a case where the vehicle 100 moves from a first jurisdiction to a second jurisdiction that has different privacy laws from those of the first jurisdiction while the drive system 50 of the vehicle 100 is in operation. With the above configuration, privacy information can be appropriately protected in accordance with the privacy laws of the second jurisdiction.

[0059] <Example of change> This embodiment can be modified as follows: This embodiment and the following modifications can be combined and implemented within the scope of technical compatibility.

[0060] In the above embodiment, the privacy settings are stored in the storage 30 via the storage module 26. The correction of one stored privacy information item is performed via the storage module 26. The deletion of one stored privacy information item is performed via the storage module 26. However, these storage, correction, and deletion may be performed without the intervention of the storage module 26.

[0061] At least one of step S310 and step S312 in FIG. 3 may be omitted. In the above embodiment, the restricted mode is a mode in which the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 is stopped. However, this is merely an example. The restricted mode may be a mode in which it is determined whether to operate the privacy protection modules based on module operation information of the jurisdiction in which the vehicle 100 is located immediately before entering the restricted mode.

[0062] In the above embodiment, in step S428, the information management device 10 prohibits the operation of all of the user consent acquisition module 21, the correction module 22, and the deletion module 23. However, this is merely an example. For example, the information management device 10 may prohibit the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23.

[0063] In the above embodiment, in step S400, the information management device 10 determines whether module operation information related to the jurisdiction in which the vehicle 100 is currently located has been stored. For example, it is also possible for module operation information related to all jurisdictions to be pre-stored in the storage 30. In such a case, steps S400, S424, S426, and S428 may be omitted.

[0064] The process in Figure 5 can be omitted. The process in Figure 6 can be omitted. [Explanation of symbols]

[0065] 10...information management device, 20...data processing hardware, 21...user consent acquisition module, 22...correction module, 23...deletion module, 24...switching module, 30...storage, 40...user interface, 50...drive system, 100...vehicle

Claims

1. An information management device mounted on a vehicle, data processing hardware; storage configured to communicate with the data processing hardware; a user interface configured to communicate with the data processing hardware; The data processing hardware includes: a user consent acquisition module configured to display on the user interface to receive from the user a privacy setting indicating whether to allow one or more privacy information items to be stored in the storage, receive the privacy setting from the user interface, and store the privacy setting in the storage in association with a jurisdiction in which the vehicle is located; and a correction module configured to display on the user interface a display for receiving a correction request to correct one privacy information item stored in the storage among the one or more privacy information items, receive the correction request from the user interface, and correct the one stored privacy information item according to the correction request; a deletion module configured to display on the user interface a display for receiving a deletion request to delete one privacy information item stored in the storage among the one or more privacy information items, receive the deletion request from the user interface, and delete the one stored privacy information item according to the deletion request; a switching module configured to determine whether to activate the user consent acquisition module, the correction module, and the deletion module, respectively, according to a jurisdiction in which the vehicle is located at the time the drive system of the vehicle is turned on; Information management device.

2. Even when the vehicle is located in a first jurisdiction in which the user consent acquisition module is operated, if the privacy setting associated with the first jurisdiction is stored in the storage, the user consent acquisition module does not display the display for accepting the privacy setting from the user on the user interface. The information management device according to claim 1 .

3. If the laws and regulations of the first jurisdiction stipulate that the user be periodically prompted as to whether or not to allow the privacy information items to be stored in the storage, the user consent acquisition module periodically displays the indication on the user interface for accepting the privacy settings from the user, even if the privacy settings associated with the first jurisdiction are stored in the storage. The information management device according to claim 2 .

4. The switching module is configured to transition to a restricted mode in which one or more of the user consent acquisition module, the correction module, and the deletion module are stopped from operating when the vehicle location cannot be obtained, regardless of the jurisdiction, and to determine whether to operate each of the user consent acquisition module, the correction module, and the deletion module according to the jurisdiction in which the vehicle is located when the vehicle location can be obtained. The information management device according to claim 1 .

5. The switching module is configured to, when the vehicle moves from a first jurisdiction to a second jurisdiction while the drive system of the vehicle is in operation, determine whether to operate the user consent acquisition module, the correction module, and the deletion module according to the second jurisdiction. The information management device according to claim 1 .

Citation Information

Patent Citations

  • Information processing apparatus, image forming apparatus, information processing method, and program

    JP2020014174A

  • Control device, vehicle, program and control method

    JP2021103408A

  • Information management device, information management method, and information management program

    JP2024115196A

  • Information management device, information management method, and information management program

    JP2024115197A

  • Personally identifiable information removal based on private area logic

    US20220382903A1