Information management device

JP7916929B2Active Publication Date: 2026-09-08TOYOTA JIDOSHA KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024022078
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-02-16
Publication Date
2026-09-08
Estimated Expiration
2044-02-16

AI Technical Summary

Benefits of technology

【0008】 上記構成によれば、法域毎に異なるプライバシー法規に合わせて、プライバシー情報の保護を適切に行うことができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007916929000001
    Figure 0007916929000001
  • Figure 0007916929000002
    Figure 0007916929000002
  • Figure 0007916929000003
    Figure 0007916929000003
Patent Text Reader

Abstract

To appropriately protect privacy information, according to privacy regulations different for each jurisdiction.SOLUTION: An information management device 10 mounted on a vehicle 100 includes a data processing hardware 20, a storage 30, and a user interface 40. A switching module 24 determines whether to operate a user consent acquisition module 21, a correction module 22 and a deletion module 23, according to jurisdiction where the vehicle 100 is positioned. The user consent acquisition module 21 stores privacy setting in the storage 30 in association with the jurisdiction where the vehicle 100 is positioned. The correction module 22 corrects one stored privacy information term according to a correction request. The deletion module 23 deletes the one stored privacy information term according to a deletion request.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information management device mounted on a vehicle. [Background Art]

[0002] Patent Document 1 discloses an information management device mounted on a vehicle. The information management device inquires of a user of the vehicle whether the user permits storage of the user's privacy information in a persistent storage device. Here, the privacy information is, for example, the user's name, credit card number, user's location information, and vehicle speed.

[0003] When the user permits storage of the privacy information in the persistent storage device, the information management device stores the user's privacy information in the persistent storage device. When the user refuses to store the privacy information in the persistent storage device, the information management device loads and uses the user's privacy information on a volatile memory. In such a case, the user's privacy information is not stored in the persistent storage device. [Prior Art Documents] [Patent Documents]

[0004] [Patent Document 1] Japanese Unexamined Patent Publication No. 2021-170016 [Summary of the Invention] [Problem to be Solved by the Invention]

[0005] Privacy regulations applied in one jurisdiction may differ from privacy regulations applied in another jurisdiction. Here, the jurisdiction is, for example, a country, a state, or a territory. For example, there are jurisdictions where user consent is required for storing privacy information items in a persistent storage device, and there are also jurisdictions where such consent is not required.

[0006] Therefore, differences in privacy laws across jurisdictions can lead to variations in the functions necessary for the proper protection of private information. As a result, there is a risk that private information may not be adequately protected when privacy laws are transferred to a different jurisdiction. [Means for solving the problem]

[0007] The following describes the means and effects of solving the above problems. According to one aspect of the present disclosure, an information management device mounted on a vehicle comprises: data processing hardware; storage configured to communicate with the data processing hardware; and a user interface configured to communicate with the data processing hardware, wherein the data processing hardware is configured to display a user interface for receiving a privacy setting from a user indicating whether or not to allow one or more privacy information items to be stored in the storage; receive the privacy setting from the user interface; and store the privacy setting in the storage in association with the jurisdiction in which the vehicle is located; and to display a user consent acquisition module for receiving a correction request to correct one of the one or more privacy information items already stored in the storage. An information management device is provided, comprising: a correction module configured to make a correction request to the user interface, receive the correction request from the user interface, and correct one of the stored privacy information items in accordance with the correction request; a deletion module configured to display to the user interface a notification for accepting a deletion request to delete one of the one or more privacy information items stored in the storage, receive the deletion request from the user interface, and delete the stored privacy information item in accordance with the deletion request; and a switching module configured to determine whether or not to activate the user consent acquisition module, the correction module, and the deletion module, respectively, according to the jurisdiction where the vehicle is located when the vehicle's drive system is turned on. [Effects of the Invention]

[0008] According to the above configuration, privacy information can be appropriately protected in accordance with the different privacy laws in each jurisdiction. [Brief explanation of the drawing]

[0009] [Figure 1]Figure 1 shows an information management device according to one embodiment, mounted on a vehicle. [Figure 2] Figure 2 shows an example of a screen display in a user interface. [Figure 3] Figure 3 is a flowchart showing the processes performed by the information management device shown in Figure 1. [Figure 4] Figure 4 is a flowchart showing the module operation determination process shown in Figure 3. [Figure 5] Figure 5 is a flowchart illustrating the process for complying with privacy laws in jurisdictions that require repeated inquiries to users regarding their privacy settings. [Figure 6] Figure 6 is a flowchart showing the process for obtaining privacy settings related to jurisdictions adjacent to the jurisdiction where the vehicle is currently located. [Modes for carrying out the invention]

[0010] Hereinafter, an information management device according to one embodiment will be described with reference to the drawings. <Configuration of Information Management Device 100> Referring to Figure 1, the configuration of the information management device 10 installed in the vehicle 100 will be described. The information management device 10 comprises data processing hardware 20, storage 30, and a user interface 40. Both the storage 30 and the user interface 40 are configured to communicate with the data processing hardware 20.

[0011] An ignition switch 31 is provided in the vehicle 100. The data processing hardware 20 includes a drive system module 28. When the user presses the ignition switch 31, the drive system module 28 turns on the drive system 50 of the vehicle 100. This turns on the switching module 24, the current law area determination module 25, the memory module 26, and the control module 27. Details of these modules provided in the data processing hardware 20 will be described later.

[0012] A GPS (Global Positioning System) sensor 32 is installed on the vehicle 100. The current jurisdiction determination module 25 determines the jurisdiction where the vehicle 100 is located based on the location information of the vehicle 100 obtained via the GPS sensor 32. The current jurisdiction determination module 25 provides the switching module 24 with information indicating the jurisdiction where the vehicle 100 is located. A jurisdiction is, for example, a country, a state, or a territory. Multiple countries may constitute a single jurisdiction.

[0013] The switching module 24 determines whether or not to activate the privacy protection module group according to the jurisdiction in which the vehicle 100 is located when the vehicle 100's drive system 50 is turned on. Here, the privacy protection module group includes a user consent acquisition module 21, a correction module 22, and a deletion module 23. The privacy protection module group will be described later. The process of determining whether or not to activate the privacy protection module group is the module activation determination process shown in step S314 of Figure 3 and Figure 4. As will be described later with reference to step S310 of Figure 3, the switching module 24 also executes the module activation determination process immediately after switching from restricted mode to normal mode. Restricted mode is a mode set when the location of the vehicle 100 cannot be obtained, as will be described later with reference to step S316 of Figure 3. Normal mode is a mode set when the location of the vehicle 100 can be obtained, as will be described later with reference to step S302 of Figure 3. As will be described later with reference to step S312 in Figure 3, the switching module 24 also performs the module operation determination process when the legal area where the vehicle 100 is currently located is different from the legal area where the vehicle 100 was previously determined to be located.

[0014] A Data Communication Module (DCM) 33 is provided in the vehicle 100. The DCM 33 can communicate with devices located outside the vehicle 100. As described above, the switching module 24 performs a module operation determination process according to the jurisdiction in which the vehicle 100 is located when the vehicle's drive system 50 is turned on. The module operation determination process performed by the switching module 24 can be changed via the DCM 33. For example, for a given jurisdiction, the mode can be changed from one in which only the user consent acquisition module 21 is operated to one in which all of the privacy protection modules are operated. An update tool 34 may also be provided in the vehicle 100. The module operation determination process can be changed by connecting the update tool 34 to the vehicle 100 via a wired connection.

[0015] A user interface 40 is provided in the vehicle 100. The user interface 40 is, for example, a touch display that accepts input from the user. The following describes the privacy protection modules included in the data processing hardware 20.

[0016] The user consent acquisition module 21 displays a message on the user interface 40 to receive privacy settings from the user. The privacy settings indicate whether or not to allow one or more privacy information items to be stored in the storage 30. The user consent acquisition module 21 receives the privacy settings from the user interface 40. The user consent acquisition module 21 stores the privacy settings in the storage 30, associating them with the jurisdiction in which the vehicle 100 is located. The storage of privacy settings in the storage 30 is performed via the storage module 26.

[0017] The correction module 22 causes the user interface 40 to display a display for accepting a correction request. The correction request is a request to correct one privacy information item stored in the storage 30 among one or more privacy information items. The correction module 22 receives the correction request from the user interface 40. The correction module 22 corrects the one stored privacy information item in accordance with the correction request. The correction of the one stored privacy information item is performed via the storage module 26.

[0018] The deletion module 23 causes the user interface 40 to display a display for accepting a deletion request. The deletion request is a request to delete one privacy information item stored in the storage 30 among one or more privacy information items. The deletion module 23 receives the deletion request from the user interface 40. The deletion module 23 deletes the one stored privacy information item in accordance with the deletion request. The deletion of the one stored privacy information item is performed via the storage module 26.

[0019] As described above, the data processing hardware 20 includes the control module 27. The control module 27 requests the storage module 26 to store the privacy information item in the storage 30 in accordance with privacy settings.

[0020] <Example of screen display 200 on user interface 40> With reference to FIG. 2, an example of screen display 200 on the user interface 40 will be described. The screen display 200 on the user interface 40 includes four privacy information items. These four privacy information items are surrounded by an alternate long and short dash line 202 in FIG. 2. The four privacy information items are a full name, a credit card number, position information of the vehicle 100, and a speed of the vehicle 100. The one or more privacy information items displayed on the user interface 40 may be different for each jurisdiction.

[0021] The screen display 200 in the user interface 40 indicates whether consent has been given for each of the four privacy information items. The indication of consent is enclosed by a dashed line 204 in Figure 2. In the example shown in Figure 2, the user has consented to the storage 30 storing their name, credit card number, and the speed of vehicle 100. The user has not consented to the storage 30 storing the location information of vehicle 100. Note that in the example shown in Figure 2, the consent status is shown for each of the four privacy information items. Alternatively, the consent status for all privacy information items may be shown collectively.

[0022] In the example shown in Figure 2, the user consent acquisition module 21 is operational. In some jurisdictions, the user consent acquisition module 21 does not need to be operational. In other words, whether or not the user consent acquisition module 21 is operational is determined for each jurisdiction. If the user consent acquisition module 21 is operational, the one or more privacy information items for which the user's permission to collect is requested is determined for each jurisdiction.

[0023] In the example shown in Figure 2, the deletion module 23 is not active. One or more privacy information items may be non-deletable or automatically deleted. For example, when vehicle 100 moves from the first jurisdiction to the second jurisdiction, one or more privacy information items associated with the first jurisdiction may be automatically deleted. Unlike the example shown in Figure 2, when the deletion module 23 is active, one to four delete buttons may be displayed in the area enclosed by the dashed line 206 in Figure 2. In other words, it is determined whether or not the deletion module 23 is active for each jurisdiction. When the deletion module 23 is active, it is determined whether or not the user can delete any of the one or more privacy information items.

[0024] In the example shown in Figure 2, the correction module 22 is operational. In the example shown in Figure 2, the name and credit card number can be corrected. In contrast, the location information and speed of the vehicle 100 cannot be corrected. In the area enclosed by the dashed line 208 in Figure 2, correction buttons for correcting the name and correction buttons for correcting the credit card number are displayed. In the example shown in Figure 2, only privacy information items manually entered by the user can be corrected, while privacy information items automatically entered cannot be corrected. In some jurisdictions, all privacy information items may be correctable. That is, in some jurisdictions, correction is possible regardless of whether the user entered them or not. In some jurisdictions, the correction module 22 does not need to be operational. Thus, whether or not the correction module 22 is operational is determined for each jurisdiction. When the correction module 22 is operational, it is determined whether or not the user can correct one or more of the privacy information items.

[0025] <Overview of the processes executed by the information management device 10> Referring to Figure 3, an overview of the processes performed by the information management device 10 will be described. The information management device 10 repeatedly executes the process shown in Figure 3 at a predetermined interval while the drive system 50 is in operation. In step S300, the information management device 10 attempts to acquire the position of the vehicle 100. Next, the information management device 10 proceeds to step S302. In step S302, the information management device 10 determines whether or not it was able to acquire the position of the vehicle 100. If the information management device 10 determines in step S302 that it was not possible (S302: NO), it proceeds to step S316. In step S316, the information management device 10 sets itself to restricted mode. In other words, if the switching module 24 cannot acquire the position of the vehicle 100, it transitions to restricted mode. Restricted mode is a mode in which the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 is stopped, regardless of the jurisdiction. For example, in the restricted mode, the information management device 10 of this embodiment shuts down the user consent acquisition module 21, the correction module 22, and the deletion module 23, regardless of the jurisdiction.

[0026] If the information management device 10 determines that step S302 is positive (S302: YES), it proceeds to step S304. In step S304, the information management device 10 sets to normal mode. Normal mode is a mode in which no restriction mode is imposed. The information management device 10 then proceeds to step S306.

[0027] In step S306, the information management device 10 determines the legal area in which the vehicle 100 is currently located based on the position of the vehicle 100. The information management device 10 then proceeds to step S308. In step S308, the information management device 10 determines whether or not the ignition switch 31 has just been turned on. If the information management device 10 determines that the ignition switch 31 has just been turned on, it proceeds to step S314. If the information management device 10 determines that the ignition switch 31 has just been turned on, it proceeds to step S310. In step S310, the information management device 10 determines whether or not the switching module 24 has just been switched from restricted mode to normal mode. If the information management device 10 determines that the ignorance switch 24 has just been switched from restricted mode to normal mode, it proceeds to step S314. If the information management device 10 determines that step S310 is negative (S310: NO), it proceeds to step S312. In step S312, the information management device 10 determines whether the jurisdiction in which the vehicle 100 is currently located is different from the jurisdiction in which the vehicle 100 was previously determined to be located. If the information management device 10 determines that step S312 is positive (S312: YES), it proceeds to step S314.

[0028] In step S314, the information management device 10 executes a module operation determination process, which will be described later, with reference to Figure 4. If the information management device 10 determines that the result is negative in step S312 (S312: NO), it terminates the process shown in Figure 3. The information management device 10 also terminates the process shown in Figure 3 if it completes step S314 or step S316.

[0029] <Module operation determination process> Referring to Figure 4, the module operation determination process in step S314 of Figure 3 will be explained. As shown in step S306 of Figure 3, the information management device 10 knows the jurisdiction in which the vehicle 100 is currently located. In step S400, the information management device 10 determines whether or not module operation information related to the jurisdiction in which the vehicle 100 is currently located is stored in the storage 30. Module operation information is information indicating whether or not to activate the privacy protection module group. If the information management device 10 determines in step S400 that it is not OK (S400: NO), it proceeds to step S424. In step S424, the information management device 10 attempts to obtain module operation information related to the jurisdiction in which the vehicle 100 is currently located. For example, the information management device 10 requests module operation information from a data center located in the jurisdiction in which the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S426. In step S426, the information management device 10 determines whether it was able to obtain module operation information related to the jurisdiction in which the vehicle 100 is currently located. If the information management device 10 determines that it was able to obtain module operation information related to the jurisdiction in step S426 (S426: YES), it proceeds to step S402. If the information management device 10 determines that it was not able to obtain module operation information related to the jurisdiction in step S426 (S426: NO), it proceeds to step S428. In step S428, the information management device 10 disables the operation of the user consent acquisition module 21, the correction module 22, and the deletion module 23.

[0030] If the information management device 10 determines in step S400 that it is correct (S400:YES), it proceeds to step S402. The module operation information pertaining to the jurisdiction where the vehicle 100 is currently located indicates whether or not to operate the user consent acquisition module 21 in the jurisdiction where the vehicle 100 is currently located. In step S402, the information management device 10 determines whether or not to operate the user consent acquisition module 21. If the information management device 10 determines in step S402 that it is correct (S402:YES), it proceeds to step S404. In step S404, the information management device 10 operates the user consent acquisition module 21. Next, the information management device 10 proceeds to step S406. In step S406, the information management device 10 determines whether or not the privacy settings pertaining to the jurisdiction where the vehicle 100 is currently located are stored in the storage 30. If the information management device 10 determines in step S406 that it is correct (S406:YES), it proceeds to step S412. If the information management device 10 determines that the result is negative in step S406 (S406: NO), it proceeds to step S408. In step S408, the information management device 10 obtains the privacy settings by querying the user.

[0031] If the information management device 10 determines that the result is negative in step S402 (S402: NO), it proceeds to step S410. In step S410, the information management device 10 prohibits the operation of the user consent acquisition module 21. If the information management device 10 completes step S408 or step S410, it proceeds to step S412.

[0032] The module operation information pertaining to the jurisdiction where vehicle 100 is currently located indicates whether or not to activate the correction module 22 in the jurisdiction where vehicle 100 is currently located. In step S412, the information management device 10 determines whether or not to activate the correction module 22. If the information management device 10 determines affirmatively in step S412 (S412: YES), it proceeds to step S414. In step S414, the information management device 10 activates the correction module 22.

[0033] If the information management device 10 determines that the result is negative in step S412 (S412: NO), it proceeds to step S416. In step S416, the information management device 10 prohibits the operation of the correction module 22. If the correction module 22 is operating, the information management device 10 prohibits its operation and stops the operation of the correction module 22.

[0034] If the information management device 10 completes step S414 or step S416, it proceeds to step S418. The module operation information pertaining to the jurisdiction where vehicle 100 is currently located indicates whether or not to activate the deletion module 23 in the jurisdiction where vehicle 100 is currently located. In step S418, the information management device 10 determines whether or not to activate the deletion module 23. If the information management device 10 makes an affirmative determination in step S418 (S418: YES), it proceeds to step S420. In step S420, the information management device 10 activates the correction module 22.

[0035] If the information management device 10 determines that the condition is negative in step S418 (S418: NO), it proceeds to step S422. In step S422, the information management device 10 prohibits the operation of the deletion module 23. If the deletion module 23 is operating, the information management device 10 prohibits its operation and stops the operation of the deletion module 23.

[0036] The information management device 10 terminates the flow shown in Figure 4 when it has completed step S420, step S422, or step S428. <Process to repeatedly prompt the user for privacy settings> Refer to Figure 5 to explain the process for complying with privacy laws in jurisdictions that require repeated prompting of the user for privacy settings. The process shown in Figure 5 is repeatedly executed when the process shown in Figure 4 has not been performed and normal mode is set.

[0037] In step S500, the information management device 10 determines whether it is necessary to periodically inquire about the user's privacy settings in the jurisdiction where the vehicle 100 is currently located. That is, the information management device 10 determines whether the regulations in the jurisdiction where the vehicle 100 is currently located stipulate that the user be periodically confirmed with their privacy settings. For example, the module operation information includes information indicating whether it is necessary to periodically inquire about the user's privacy settings.

[0038] If the information management device 10 determines that it is correct in step S500 (S500: YES), it proceeds to step S502. In step S502, the information management device 10 determines whether a predetermined period of time has elapsed since the previous inquiry. If the information management device 10 determines that it is correct in step S502 (S502: YES), it proceeds to step S504.

[0039] In step S504, the information management device 10 obtains the privacy settings by inquiring with the user. If the information management device 10 completes step S504, it terminates the flow shown in Figure 5. The information management device 10 also terminates the flow shown in Figure 5 if it makes a negative determination in step S500 (S500: NO). The information management device 10 also terminates the flow shown in Figure 5 if it makes a negative determination in step S502 (S502: NO).

[0040] <Privacy settings related to jurisdictions adjacent to the jurisdiction where vehicle 100 is currently located> Referring to Figure 6, the process for obtaining privacy settings related to jurisdictions adjacent to the jurisdiction where vehicle 100 is currently located will be explained. When normal mode is set, the information management device 10 repeatedly executes the process shown in Figure 6.

[0041] In step S600, the information management device 10 determines whether the vehicle 100 is within a predetermined distance from the boundary of a legal area adjacent to the legal area in which the vehicle 100 is currently located. If the information management device 10 determines in step S600 that the vehicle 100 is not within a predetermined distance (S600: NO), it repeats step S600. If the information management device 10 determines in step S600 that the vehicle 10 is not within a predetermined distance (S600: YES), it proceeds to step S602.

[0042] In step S602, the information management device 10 determines whether module operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located is stored in the storage 30. If the information management device 10 determines that the operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located is positive (S602:YES), it proceeds to step S608. If the information management device 10 determines that the operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located is negative (S602:NO), it proceeds to step S604. In step S604, the information management device 10 attempts to acquire module operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S606. In step S606, the information management device 10 determines whether it was able to acquire module operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located. If the information management device 10 determines that the operation information for a jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located is positive (S606:YES), it proceeds to step S608. If the information management device 10 determines that the result is negative in step S606 (S606: NO), it terminates the flow shown in Figure 6.

[0043] The module operation information for jurisdictions adjacent to the jurisdiction where vehicle 100 is currently located includes information indicating whether or not to operate the user consent acquisition module 21 in the adjacent jurisdiction. In step S608, the information management device 10 determines whether or not to operate the user consent acquisition module 21 in the jurisdiction adjacent to the jurisdiction where vehicle 100 is currently located. If the information management device 10 determines in step S608 that it is not the case (S608: NO), it terminates the flow shown in Figure 6. If the information management device 10 determines in step S608 that it is the case (S608: YES), it proceeds to step S610. In step S610, the information management device 10 determines whether or not the privacy settings for the jurisdiction adjacent to the jurisdiction where vehicle 100 is currently located are stored in the storage 30. If the information management device 10 determines in step S610 that it is the case (S610: YES), it terminates the flow shown in Figure 6. If the information management device 10 determines that step S610 is negative (S610: NO), it proceeds to step S612. In step S612, the information management device 10 obtains the privacy settings related to the jurisdiction adjacent to the jurisdiction where the vehicle 100 is currently located by querying the user. If the information management device 10 completes step S612, it terminates the flow shown in Figure 6.

[0044] <Operation of this embodiment> According to step S306 in Figure 3, the information management device 10 repeatedly determines the jurisdiction in which the vehicle 100 is currently located while the drive system 50 is on. The module operation information for the jurisdiction in which the vehicle 100 is currently located is information indicating whether or not to activate the privacy protection module group. The privacy protection module group includes a user consent acquisition module 21, a correction module 22, and a deletion module 23. If a positive determination is made in step S308, step S310, or step S312, the module operation determination process shown in step S314 and Figure 4 is executed. In particular, according to steps S308 and S314, this process is performed according to the jurisdiction in which the vehicle 100 is located when the vehicle 100's drive system 50 is turned on. In the module operation determination process, as shown in steps S402 to S422, it is determined whether or not to activate the privacy protection module group.

[0045] According to steps S310 and S314 in Figure 3, the following can be said: When the switching module 24 is able to acquire the position of the vehicle 100, it performs the following processing: The switching module 24 determines whether or not to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the jurisdiction in which the vehicle 100 is located.

[0046] According to steps S312 and S314 in Figure 3, the following can be said: The switching module 24 may determine whether to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the second jurisdiction, while the vehicle 100's drive system 50 is in operation.

[0047] According to steps S402 to S406, the following can be said: If the vehicle 100 is located in a jurisdiction where the user consent acquisition module 21 is activated, the information management device 10 activates the user consent acquisition module 21. When the privacy settings associated with that jurisdiction are stored in the storage 30, the user consent acquisition module 21 does not prompt the user for the privacy settings. That is, the user consent acquisition module 21 does not display any indication on the user interface 40 for accepting privacy settings from the user.

[0048] According to Figure 5, the following can be said: The regulations in the jurisdiction where the vehicle 100 is currently located may require the user to periodically confirm whether or not to allow the storage of privacy information items in the storage 30. In such cases, even if the privacy settings associated with that jurisdiction are stored in the storage 30, the user consent acquisition module 21 periodically prompts the user for the privacy settings. That is, the user consent acquisition module 21 displays a message on the user interface 40 to accept the privacy settings from the user.

[0049] <Effects of this embodiment> (1) The information management device 10 mounted on the vehicle 100 includes data processing hardware 20. The information management device 10 includes storage 30 configured to communicate with the data processing hardware 20. The information management device 10 includes a user interface 40 configured to communicate with the data processing hardware 20. The data processing hardware 20 includes a user consent acquisition module 21. The user consent acquisition module 21 displays a message to the user interface 40 to receive a privacy setting from the user indicating whether or not to allow one or more privacy information items to be stored in the storage 30. The user consent acquisition module 21 receives the privacy setting from the user interface 40. The user consent acquisition module 21 stores the privacy setting in the storage 30 in association with the jurisdiction in which the vehicle 100 is located. The data processing hardware 20 includes a correction module 22. The correction module 22 displays a message to the user interface 40 to receive a correction request to correct one of the one or more privacy information items that is already stored in the storage 30. The correction module 22 receives a correction request from the user interface 40. The correction module 22 corrects one stored privacy information item in accordance with the correction request. The data processing hardware 20 includes a deletion module 23. The deletion module 23 displays a notification to the user interface 40 to accept a deletion request for one of one or more privacy information items stored in the storage 30. The deletion module 23 receives a deletion request from the user interface 40. The deletion module 23 deletes one stored privacy information item in accordance with the deletion request. The data processing hardware 20 includes a switching module 24. The switching module 24 determines whether to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively. This determination is made according to the jurisdiction in which the vehicle 100 is located when the vehicle 100's drive system 50 is turned on.

[0050] According to the above configuration, the switching module 24 determines whether or not to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the jurisdiction. Therefore, the necessary modules can be activated in accordance with the different privacy laws of each jurisdiction. Accordingly, according to the above configuration, privacy information can be appropriately protected in accordance with the different privacy laws of each jurisdiction.

[0051] (2) The vehicle 100 may be located in the first jurisdiction where the user consent acquisition module 21 is operating. Even in such a case, if the privacy settings associated with the first jurisdiction are stored in the storage 30, the user consent acquisition module 21 will not prompt the user for a privacy setting. In other words, the user consent acquisition module 21 will not display any information on the user interface 40 to accept privacy settings from the user.

[0052] According to the above configuration, when the privacy settings associated with the first jurisdiction are already stored, the user consent acquisition module 21 does not prompt the user for information about the privacy settings. This reduces the burden on the user of being asked about their privacy settings.

[0053] (3) In some cases, the regulations in the first jurisdiction may require the user to periodically confirm whether or not to allow the storage of privacy information items in the storage 30. In such cases, even if the privacy settings associated with the first jurisdiction are stored in the storage 30, a query for privacy settings will be made. That is, the user consent acquisition module 21 periodically displays a message on the user interface 40 to accept privacy settings from the user.

[0054] According to the above configuration, privacy information can be appropriately protected in accordance with the privacy laws of jurisdictions that require repeated inquiries to users regarding their privacy settings.

[0055] (4) There are cases where the location of vehicle 100 cannot be obtained. In such cases, the switching module 24 transitions to a restricted mode in which it stops the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23, regardless of the jurisdiction. When the switching module 24 becomes able to obtain the location of vehicle 100, it transitions to normal mode. When the switching module 24 transitions to normal mode, it makes the following determination. That is, the switching module 24 determines whether or not to operate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the jurisdiction in which vehicle 100 is located.

[0056] If the location of vehicle 100 cannot be obtained, one or more of the user consent acquisition module 21, correction module 22, and deletion module 23 are deactivated. When the location of vehicle 100 becomes available, a decision is made on whether or not to activate each module according to the jurisdiction in which vehicle 100 is located. Therefore, when the location of vehicle 100 becomes available, the system can return to a state in which it can process privacy information in accordance with the privacy laws of the jurisdiction in which vehicle 100 is located.

[0057] (5) While the drive system 50 of the vehicle 100 is in operation, the vehicle 100 may move from the first jurisdiction to the second jurisdiction. In such cases, the switching module 24 determines whether or not to activate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, according to the second jurisdiction.

[0058] While the drive system 50 of vehicle 100 is in operation, vehicle 100 may move from the first jurisdiction to the second jurisdiction, where privacy laws differ from those of the first jurisdiction. With the above configuration, privacy information can be appropriately protected in accordance with the privacy laws of the second jurisdiction.

[0059] <Example of changes> This embodiment can be implemented with the following modifications. This embodiment and the following modifications can be combined with each other to the extent that they do not contradict each other technically.

[0060] In the above embodiment, the storage of privacy settings in the storage 30 is performed via the storage module 26. Correction of a stored privacy information item is performed via the storage module 26. Deletion of a stored privacy information item is performed via the storage module 26. However, these storage, correction, and deletion may be performed without going through the storage module 26.

[0061] At least one of steps S310 and S312 in Figure 3 may be omitted. In the above embodiment, the restricted mode is a mode in which the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 is stopped. However, this is merely an example. The restricted mode may also be a mode in which the privacy protection module group is determined based on the module operation information of the jurisdiction in which the vehicle 100 is located immediately before entering the restricted mode.

[0062] In the above embodiment, the information management device 10 disables the operation of the user consent acquisition module 21, the correction module 22, and the deletion module 23 in step S428. However, this is merely an example. For example, the information management device 10 may disable the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23.

[0063] In the above embodiment, the information management device 10 determines in step S400 whether or not module operation information relating to the jurisdiction in which the vehicle 100 is currently located has been stored. For example, it is also possible that module operation information relating to all jurisdictions has been stored in the storage 30 in advance. In this case, steps S400, S424, S426, and S428 may be omitted.

[0064] The process shown in Figure 5 is optional. The process shown in Figure 6 is optional. [Explanation of symbols]

[0065] 10... Information management device, 20... Data processing hardware, 21... User consent acquisition module, 22... Correction module, 23... Deletion module, 24... Switching module, 30... Storage, 40... User interface, 50... Drive system, 100... Vehicle

Claims

1. An information management device installed in a vehicle, Data processing hardware and A storage device configured to communicate with the aforementioned data processing hardware, The system includes a user interface configured to communicate with the aforementioned data processing hardware, The aforementioned data processing hardware is A user consent acquisition module is configured to display a privacy setting on the user interface indicating whether or not to allow the storage of one or more privacy information items, to receive the privacy setting from the user interface, and to store the privacy setting in the storage in association with the jurisdiction in which the vehicle is located. A correction module is configured to display a correction request on the user interface for correcting one of the one or more privacy information items stored in the storage, receive the correction request from the user interface, and correct the stored privacy information item in accordance with the correction request. A deletion module is configured to display a notification on the user interface for accepting a deletion request to delete one of the one or more privacy information items stored in the storage, to receive the deletion request from the user interface, and to delete the stored privacy information item in accordance with the deletion request. The vehicle includes a switching module configured to determine whether or not to activate the user consent acquisition module, the correction module, and the deletion module, respectively, according to the jurisdiction in which the vehicle is located when the vehicle's drive system is turned on. Information management device.

2. Even if the vehicle is located in the first jurisdiction where the user consent acquisition module is operating, if the privacy settings associated with the first jurisdiction are stored in the storage, the user consent acquisition module will not display the information on the user interface for receiving the privacy settings from the user. The information management device according to claim 1.

3. If the regulations in the first jurisdiction stipulate that the user be periodically asked whether or not to allow the storage of the privacy information items, then even if the privacy settings associated with the first jurisdiction are stored in the storage, the user consent acquisition module shall periodically display the notification to the user interface for accepting the privacy settings from the user. The information management device according to claim 2.

4. The switching module is configured to transition to a restricted mode in which, if the vehicle's location cannot be obtained, it stops the operation of one or more of the user consent acquisition module, the correction module, and the deletion module, regardless of the jurisdiction. When the vehicle's location becomes obtainable, it is configured to determine whether or not to operate the user consent acquisition module, the correction module, and the deletion module, respectively, according to the jurisdiction in which the vehicle is located. The information management device according to claim 1.

5. The switching module is configured to determine whether or not to activate the user consent acquisition module, the correction module, and the deletion module, respectively, when the vehicle moves from the first jurisdiction to the second jurisdiction while the vehicle's drive system is in operation, according to the second jurisdiction. The information management device according to claim 1.

Citation Information

Patent Citations

  • Information processing apparatus, image forming apparatus, information processing method, and program

    JP2020014174A

  • Control device, vehicle, program and control method

    JP2021103408A

  • Design for user privacy protection on autonomous driving vehicle

    JP2021170016A

  • Information management device, information management method, and information management program

    JP2024115196A

  • Information management device, information management method, and information management program

    JP2024115197A