A system that enables the monitoring of personal data breaches.
Patent Information
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS
- Filing Date
- 2024-04-19
- Publication Date
- 2026-06-22
Smart Images

Figure 00000012_0000
Abstract
Description
1 TARIFF A system that enables the monitoring of personal data breaches. SYSTEM Technical Area 5 This invention applies to data collected from corporate systems or systems that will collect data. a system that enables monitoring of personal data breaches on application interfaces It is related to the system. Previous Technique Today, with the enactment of the Personal Data Protection Law (KVKK), personal data... in the processing of the data, the fundamental rights of individuals, especially the privacy of private life, to protect their freedoms and the rights of natural and legal persons who process personal data 15 The issue of regulating their obligations and the procedures and principles they must comply with has entered our lives. It has entered [the system]. The adoption of the Personal Data Protection Law (KVKK) has had a major impact on the systems. This In accordance with the law, institutions and organizations have regulations regarding the storage, processing, and destruction of personal data. They have made the necessary adjustments by analyzing the impact on them. The law... Since its adoption, the legislation has undergone changes over time. 20 in accordance with the law. Identifying personal data that is not protected, processed or destroyed It is of utmost importance that this be done. For this reason, data collected from the systems of corporate companies or data that will be collected A 25 that enables the monitoring of personal data breaches on the interfaces of applications. It is understood that the system is needed. 2 United States number US11853452B2, which is included in the known state of the art. The states, in their patent documents, regulate databases containing personal data. It refers to a system structured to keep things in order. The invention, data by detecting the presence of sensitive data in databases in accordance with protection regulations And it's about protecting this data by transferring it to appropriate geographies. A 5 containing information. A request intended for the transaction is received, and the request is processed in a local database. The aim is to process the demand information using a model. The model... As a result of determining that the information relates to sensitive data, the request is for sensitive data. Transfer to a remote database associated with a geography that meets the requirement is being done and the request is being fulfilled. 10 Brief Description of the Invention The purpose of this invention is to analyze data collected from corporate systems or data Checking for personal data breaches on the interfaces of applications that will collect data. 15 It is about implementing a system developed to provide this. Another purpose of this invention is to periodically review the KVKK (Personal Data Protection Law) legislation and the existing regulations. If there is a difference, the difference should be analyzed, and the impact of this difference should be determined. 20 actions that need to be taken under the KVKK (Personal Data Protection Law) as a result of the changes and their detection. to ensure that actions are identified and warnings are issued regarding these matters It is about implementing a developed system. Another purpose of this invention is to control the personal data collected in systems. 25 It is about implementing a developed system. 3 Another purpose of this invention is to determine whether form pages collect personal data. to provide a mechanism that performs front-facing dimension control for inspection purposes It is about implementing a developed system. Another purpose of this invention is to obtain the relevant explicit consent when personal data is collected. to provide a mechanism that will automatically develop the text / information text The goal is to implement a system developed for this purpose. Another purpose of this invention is to periodically review the GDPR legislation and 10 Check when there is a change and provide the necessary information. It is about implementing a system developed to provide this. Another purpose of this invention is to collect and display the outputs of the scan data on demand. a system developed to provide an interface through which it can be displayed to accomplish. 15 Another purpose of this invention is to detect the use of personal data as a result of scanning. in order to provide a mechanism to inform the relevant developers in this situation It is about implementing a developed system. Detailed Description of the Invention The “Personal Data Breach Control” system was developed to achieve the purpose of this invention. A system enabling this is shown in the attached figure; Figure 1 shows a schematic view of the system that is the subject of the invention. 4 The parts shown in the figure are individually numbered, and the corresponding numbers correspond to these numbers. It is given below. 1. System 2. Application 5 3. Server Data collected from corporate systems or data that will be collected To ensure that personal data breaches are checked on the interfaces of applications. The system that is the subject of the invention developed for this purpose (1); 10 - through an interface, authorized users can access various reports and actions to be taken. at least one application (2) designed to enable them to access the recommendations and - collecting data from various sources, recording the collected data in a database. to maintain, periodically review personal data regulations and adapt to changes. Providing relevant users with information when personal data is collected 15 scanning the database regarding this matter, and when a situation that constitutes a violation is detected, the relevant configured to inform users and update the privacy policy. It contains at least one server (3). The application (2) in the system (1) which is the subject of the invention, can use any communication protocol 20 The application (2) is configured to communicate with the server (3) using. to ensure that the results of the analysis are presented to the relevant users It is structured. The application (2) tells the relevant users what kind of systems they can use. to ensure that the necessary changes are communicated It is structured. The application (2) is kept open on the database for the relevant users. Data encryption or the Privacy Policy (KVKK) text on the webpage. to provide feedback in the form of suggestions for texts like this It is being structured. The server (3) in the system (1) which is the subject of the invention, uses any communication protocol The server (3) is configured to communicate with the application (2) using. using any communication protocol various personal data protection laws It is configured to receive (KVKK) data. Server (3) receives KVKK data 5 It is structured to model data by performing analysis on it. Server (3) converts the modeled GDPR data to an application programming interface (API) It is configured to transmit. The server (3) is modeled with the help of the API and To enable the interpreted data to be displayed on a configuration screen. It is configured in such a way. The server (3) allows authorized users to access the application (2) via 10 They should intervene in the created models and prevent data inconsistencies from occurring. It is structured to provide the server (3), the text of the legislation, artificial intelligence. to enable the extraction of rule sets through algorithms is configured. Server (3), Naive Bayes Classification or Logistic Regression Algorithms that generate rule sets from text in the form of 15 and the extraction of rule sets It is configured to provide the following. The server (3) is configured to provide the extracted rule sets. to prepare validation brackets and algorithms is configured. Server (3), prepared validations or algorithms, t=0 While guidance is provided through immediate administrative support, the application's learning process progresses in the later stages. It is structured to enable its own derivation with its ability. Server (3), 20 without waiting for an intervention in case of a change or new addition to the legislation It is configured to enable scanning with current data. Server (3), particles that can run on the implementation (2) of validations or algorithms They are configured to ensure that they are. The server (3) uses Regex for a topic. Data collected from available sources using Rule (Regular Expression Rule) 25 by comparing it with the currently collected data on the subject in question. The server (3) is configured to check whether any data has been collected. By pointing to an application to be checked, if the place to be checked is data... 6 The set is the dataset on the x and y axes, created by the algorithm, and It is configured to scan with validations. Server (3), performance From the perspective of determining which rule should run on the data, starting from the initial data... It is configured to enable progress by converging. Server (3), By pointing to an application to be checked, if the place to be checked is a web 5 The page is an element on the DOM (Document Object Model). and using attributes, to determine what kind of data has been collected. is being configured. Server (3), with or without changes It is configured to receive the configurations. Server (3) is accessible. Scanning the interfaces of applications and determining what is missing in the interface in accordance with the GDPR. 10 to decide what is and what needs to be regulated and through implementation (2) It is configured to share with the relevant user. The server (3) processes the data. to generate analyses and record them in the database It is configured. The server (3) generates a report as a result of the analyses and 15 to ensure that it is transmitted to authorized users via application (2) It is being structured. Industrial Applicability Thanks to the system (1) which is the subject of the invention, 20 collected from the systems of corporate companies personal data breach on the interfaces of the data or applications that will collect the data This ensures that it is monitored. Around these fundamental concepts, the subject of the invention is "Controlling Personal Data Breach". It is possible to develop a wide variety of applications related to "A System Providing (1)" 25 and the invention cannot be limited to the examples described here, but mainly to the claims as stated.
Claims
7 REQUESTS 1. Data collected from the systems of corporate companies or those that will collect data. Checking for personal data breaches on application interfaces providing; 5 - through an interface, authorized users can access various reports and required information. at least one structured to enable them to access action recommendations application (2) includes and - collecting data from various sources, recording the collected data in a database. to keep it under control, periodically check personal data regulations and 10 To inform relevant users when changes occur, personal Scanning the database regarding data collection constitutes a breach. When detected, inform the relevant users and provide an information text. a server characterized by having at least one server (3) configured to update system (1). 15 2. Communicate with the server (3) using any communication protocol. The application structured as in Claim 1 is characterized by (2). system (1).
3. To ensure that the results of the analysis are presented to the relevant users. a structured application (2) characterized by a Claim 1 or 2 such as system (1).
4. Informing the relevant users about what kind of changes they need to make to their systems. 25 application (2) structured to enable the transmission of information a system like any of the above characterized demands (1). 8 5. Encrypting data kept open on the database for relevant users or Texts such as the Privacy Policy and Personal Data Protection Law text on the webpage structured to provide feedback in the form of suggestions any of the above claims characterized by application (2) such a system (1). 5 6. Communicate with the application (2) using any communication protocol. from the above requests characterized by the server (3) configured for a system like any other (1).
7. Protection of various personal data using any communication protocol. server (3) configured to receive data in accordance with the law (KVKK) a system like any of the above characterized demands (1).
8. To model data by performing analysis on KVKK (Personal Data Protection Law) data. 15 any of the above requests characterized by the configured server (3) a system like one of them (1).
9. Modeling the GDPR data into an application programming interface (API) The above 20 is characterized by the server (3) configured to transmit. a system like any of the requests (1).
10. A configuration of data modeled and interpreted using an API. the server (3) configured to ensure that it is displayed on the screen A system like any of the above-mentioned demands characterized (1). 25 11. Authorized users can interfere with models created via application (2). structured to enable them to prevent data inconsistencies from occurring. as in any of the above requests characterized by the server (3) a system (1). 30 9 12. Rule sets of the legislative text thanks to artificial intelligence algorithms. characterized by the server (3) configured to enable extraction a system like any of the above requests (1).
13. Rule from text in the form of Naive Bayes Classification or Logistic Regression. to enable the extraction of rule sets using algorithms that create the set any of the above requests characterized by the configured server (3) a system like one of them (1).
14. Validation brackets and derived rule sets. Characterized by the server (3) configured to prepare the algorithms a system like any of the above requests (1).
15. The prepared validations or algorithms are directed to the administrator with support at time t=0. as it is given, the learning ability of the application and itself in the subsequent process characterized by the server (3) configured to enable its derivation a system like any of the above requests (1).
16. An intervention in a change or new addition to the legislation 20 To enable scanning with up-to-date data without delay. any of the above requests characterized by the configured server (3) a system like one of them (1).
17. Validations or algorithms that can run on the application (2) 25 characterized by the server (3) which is configured to make them particles a system like any of the above-mentioned requests (1).
18. A topic can be accessed using a Regex Rule. 30 based on data collected from sources and existing collected data. by making a comparison, whether or not data has been collected on the subject in question. The above is characterized by the server (3) configured to control it. a system like any of the requests (1).
19. Pointing to an application to be checked, if the place to be checked is a 5 The dataset is represented on the x and y axes by the generated algorithm, and server (3) configured to perform scan with verifications a system like any of the above characterized demands (1).
20. Which rule should be run on the data in terms of performance? (Starting point 10) structured to enable progress by converging on the data as in any of the above requests characterized by the server (3) a system (1).
21. By pointing to an application to be inspected, if the place to be inspected is a 15 The web page uses the DOM (Document Object Model). What kind of data can be obtained using the elements and attributes on it? Characterized by the server (3) configured to extract the collected data. a system like any of the above requests (1).
22. To receive the configurations that have been changed or not changed. any of the above requests characterized by the configured server (3) a system like one of them (1).
23. Scanning the interfaces of accessible applications and verifying compliance with the KVKK (Personal Data Protection Law) requirements on the interface. to decide what is missing and what needs to be improved and configured to share with the relevant user via application (2) as in any of the above requests characterized by the server (3) a system (1). 11 24. Generating analyses for processed data and recording them in the database. from the above requests characterized by the server (3) configured for a system like any other (1).
25. To create a report as a result of the analyses and to authorize 5 people through the application (2). server (3) configured to ensure that it is delivered to users a system like any of the above characterized demands (1).