Method for setting the data protection for data collected by a vehicle

The method addresses inefficiencies in data protection for vehicle-collected data by creating and associating data protection tokens with data sets, ensuring transparent and compliant usage, and enabling efficient secondary use of the data.

WO2025119517A1PCT designated stage expired Publication Date: 2025-06-12BAYERISCHE MOTOREN WERKE AG
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/078084
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-07
Filing Date
2024-10-07
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing methods for managing data protection for vehicle-collected data are inefficient and lack transparency, particularly in ensuring user consent and compliance with data protection regulations.

Method used

A method that involves detecting user-set data protection settings, structuring data into records, and creating data protection tokens that contain user consent information. These tokens are associated with data sets before or during transfer to an external data receiving point, ensuring transparent and compliant data usage.

Benefits of technology

The method enables secure, transparent, and compliant utilization of vehicle-collected data, allowing for efficient secondary use while ensuring that data protection settings are permanently assigned to data sets, preventing unauthorized use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024078084_12062025_PF_FP_ABST
    Figure EP2024078084_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for setting the data protection for data collected by a vehicle, said vehicle being configured to collect data by means of sensors. The vehicle provides an interface, by means of which a user of the vehicle can set the data protection for data collected by the vehicle. The method has the following steps: a) by means of the vehicle, detecting the data protection set by the user of the vehicle for data collected by the vehicle; b) by means of the vehicle, detecting data and structuring the data in the form of data sets; c) transferring at least one data set to an external data receiving location; and d) automatically generating at least one data protection token for each data set to be transferred and associating the data protection token generated for each data set with the respective data set before, while, or after the data set is transferred from the vehicle to the external data receiving location, wherein the data protection token contains information regarding whether the user of the vehicle has approved of a specific use of the data set associated with the data protection token.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Procedure for setting data protection for data collected by a vehicle

[0002] Description

[0003] The present invention relates to a method for setting data protection for data collected by a vehicle.

[0004] Today's vehicles typically incorporate a multitude of sensors that collect data. It's common practice to transfer such data from a vehicle to a so-called backend server, where the collected data can be further processed independently or with data from other vehicles. Such data is typically subject to applicable data protection regulations, and processors require the vehicle user's permission to further process this data.

[0005] The published patent application DE 10 2021 207604 A1 describes a method for managing personal data associated with a vehicle. Sensors of a vehicle can receive a combination of personal and non-personal data. The method determines a label for the sensor data, which includes the respective identification of personal and non-personal data.

[0006] DE 102022 110 918 A1 describes the use of self-managed data with embedded metadata to ensure data protection, for example for data collected by vehicle sensors.

[0007] EP 3 968603 A1 describes a method for controlling communication between a vehicle and a backend device in a vehicle-to-cloud system, wherein data protection levels of certain data types and current data protection settings of the vehicle are checked when requests from mobile online services to connect to the backend device are made.

[0008] WO 2015 / 150534 A2 describes a human-machine interface in conjunction with a vehicle, with which access authorizations and identification authorizations for data collected by the vehicle can be configured. The object of the invention is to facilitate and improve data protection for data collected by vehicles.

[0009] The object of the invention is achieved by a method having the features of patent claim 1.

[0010] Such a method is provided for setting the data protection for data collected by a vehicle, wherein the vehicle is configured to collect data by means of sensors and wherein the vehicle provides an interface with which a user of the vehicle can make data protection settings for the data collected by the vehicle, the method comprising the following steps: a) detecting, by the vehicle, data protection settings made by the user of the vehicle for data collected by the vehicle; b) detecting data and structuring the data in the form of data records by the vehicle; c) transferring at least one data record to an external data receiving point;d) Automatically creating at least one data protection token for each data set to be transferred and associating the data protection token created for the respective data set with the respective data set before, during or after the data set is transferred from the vehicle to the external data receiving point, wherein the data protection token contains information as to whether the user of the vehicle has consented to a specific use of the data set associated with the data protection token;

[0011] Such a process enables the data or data sets to be used in compliance with data protection regulations and thus provides new data-based functions for the vehicle user, particularly in real time. Secondary use, i.e., the use of data collected or recorded once for a specific purpose directly related to the operation of the vehicle, for example by external service providers for further (second) purposes, is particularly more efficient because data collected once can be used multiple times. By associating data sets with data protection tokens, complete transparency can be created regarding the data protection principles that apply to a specific data set. Each data protection token represents a specific consent for use. Therefore, multiple data protection tokens can be associated with a data set, each representing different consents for use.Data protection tokens represent abstractions for the data protection law principles governing the usability of collected data and the associated disclosure to potential secondary users and the user. A data protection token is understood as a concrete literal with defined semantics. Compliance with data protection law regarding the use and processing of data is ensured, in particular, by a central system, namely the external data receiving point, only forwarding data to secondary systems or applications that meet the relevant data protection law requirements. These data protection law requirements include, in particular, the user's consent to the use of the data.The data protection requirements can be created in the form of logical expressions by the external data receiving point based on the data protection tokens and checked at the time of forwarding to the secondary systems or applications.

[0012] In an advantageous embodiment of the invention, the data protection token, in particular the information contained in the data protection token, is or are unchangeable after automated creation and / or the data protection token is unchangeably linked to the associated data set after association.

[0013] In this way, the data protection settings applicable to a specific data set can be permanently assigned to that data set. The data protection settings can therefore no longer be changed or tampered with at a later date. It can also prevent the data protection token from being separated from the data set as a whole and a new, potentially tampered with data protection token from being assigned to the data set. This increases the data security of the data set.

[0014] A further advantageous embodiment of the invention comprises that the data protection token contains information as to whether the user of the vehicle has or had consented to a specific use of the data set associated with the data protection token at the time the data set was captured by the vehicle or at the time the data set was transferred from the vehicle to the external data receiving point. If the user's consent has already been given at the time the data is captured by the vehicle, the data sets can already be provided with their applicable data protection settings at this time and are then equipped with these settings before they are transferred. If the consent is only given after the data has been captured, it can also be associated with the data retrospectively within the vehicle.

[0015] Furthermore, it may be advantageous if the data protection token contains information as to whether the data set associated with the data protection token is subject to a legal obligation to store this data set and / or to make it available to the user, in particular upon request.

[0016] Data sets equipped in this way can be checked for compliance with applicable data protection regulations both at the external data receiving point and on the systems or applications of secondary users. The data sets are thus consistently auditable.

[0017] Furthermore, it may be advantageous if the method additionally comprises the following steps: e) receipt by the external data receiving entity of a request from a further processing entity requesting one or more data records for further processing from the external data receiving entity; f) verification by the external data receiving entity of the data protection token(s) of data records eligible for fulfilling the request; and

[0018] Determining whether the information contained in the data protection token(s) permits or disallows further processing of the associated data record(s) by the further processing entity; g) Forwarding of the transferred data record(s) to a further processing entity by the external data receiving entity if it has been determined that the information contained in the data protection token(s) permits further processing of the associated data record(s) by the further processing entity. The further processing entity can be a system or application of a secondary user. Checking the data protection token allows the external data receiving entity to easily determine whether specific data records may be forwarded or not. This prevents data records for which the data protection settings do not permit secondary use from being forwarded by the external data receiving entity.

[0019] Alternatively or additionally, it may be advantageous if the method comprises the following steps: h) receiving a request from the external data receiving point by the vehicle, with which one or more data sets are requested from the vehicle for transfer to the external data receiving point; i) checking the data protection token(s) of data sets eligible for fulfilling the request by the vehicle; and j) determining whether the information contained in the data protection token(s) permits or does not permit the transfer of the associated data set(s) to the external data receiving point; j1) transferring the associated data set(s) to the external data receiving point if it is determined,that the information contained in the data protection token(s) permits the transfer of the associated data set(s) to the external data receiving point; or j2) not carrying out the transfer of the associated data set(s) to the external data receiving point if it is determined that the information contained in the data protection token(s) does not permit the transfer of the associated data set(s) to the external data receiving point and transferring information to the external data receiving point that the transfer of the requested data set(s) was not carried out and / or that the transfer of the requested data set(s) was not permitted. In this way, it is possible to determine within the vehicle whether certain data sets may be transferred from the vehicle to an external data receiving point. The user is thereby given the ability toto prevent the transfer of certain data to external data receiving points. At the same time, if the requested data set is not transferred, information is sent to the external data receiving point stating that the transfer was not carried out or could not be carried out, in order to clarify that the failure to carry out the transfer was not due to a transmission or communication error.

[0020] Furthermore, it is advantageous if the data protection token is written into or linked to the data set associated with the data protection token in the form of a set of metadata before or during the data set is transferred.

[0021] In this way, the data set contains the data protection regulations or settings applicable to it at the time of data collection or transfer before it is made available for further use. This can prevent unauthorized use of the data set.

[0022] In addition, it may be advantageous if the data protection token is associated with the data set at the time or immediately before the time of transfer of the data set to the external data receiving point.

[0023] In this way, it is possible to leave the data set changeable after the data has been collected, i.e. it is possible to discard or not save certain data and to only provide certain data relevant at the time of transfer with a data protection token and then transfer this data.

[0024] Additionally, it may be advantageous if the data protection token is inextricably embedded in the data set associated with the data protection token or is inextricably linked to it. In particular, it is advantageous if the data protection token and the data set are cryptographically linked.

[0025] This prevents the data protection settings for a data record from being subsequently changed or manipulated.

[0026] In a further advantageous embodiment of the method, the data record(s) can be transferred from the vehicle to the external data receiving point using a defined transfer protocol, wherein the data protection settings made by the user are communicated as a parameter of the transfer protocol from the vehicle to the external data receiving point, wherein the external data receiving point carries out the automated creation of a data protection token for each transferred data record depending on the data protection settings made and associates the data protection token created for the respective data record with the respective data record after the respective data record has been transferred.

[0027] Such an implementation is particularly advantageous, for example, when full consent has been given for all uses of the collected data. In this case, the same data protection settings apply to all data sets, so that creation and linking can only take place at the external data receiving point, thus saving computing resources, especially on the vehicle.

[0028] The object of the invention is also achieved by a computer program product with program code means which causes one or more electronic computing devices to carry out a method according to the invention when the program code means are processed by the electronic computing device(s).

[0029] The task is also fulfilled by a computer-readable storage medium containing such a computer program product.

[0030] Furthermore, the object of the invention is achieved by a system which comprises a vehicle and at least one or more external data receiving points for carrying out the method according to the invention.

[0031] Advantageous embodiments and further developments according to the invention emerge from the respective dependent patent claims and also from the following description.

[0032] The invention will be further explained below using exemplary embodiments with reference to the drawings. They show a schematic representation:

[0033] FIG 1 shows a basic communication structure for the execution of a method in an exemplary embodiment of the invention;

[0034] FIGS 2a and 2b show exemplary time sequences of a method in an embodiment of the invention;

[0035] FIG 1 illustrates a basic communication structure with a vehicle, for example, a motor vehicle, capable of collecting data using on-board sensors. A vehicle can also be coupled to a mobile communication device, for example, a smartphone or a navigation device, and thus be enabled to collect or record data using the mobile communication device or sensors of the mobile communication device.

[0036] The vehicle is therefore equipped with sensors that can record and transmit various sensor data. For example, such sensor data can include the vehicle's position data, operating data such as engine running time and performance data, engine consumption data, or the charge level of a vehicle's battery, or even vehicle-independent data such as ambient temperature or similar. Possible sensors include cameras, radar, ultrasonic, or infrared sensors.

[0037] The vehicle can be connected to an external data receiving point, a so-called backend server, via a wireless connection, in particular a network connection. It is also conceivable to connect the vehicle to the external data receiving point via a cable, for example, in the event of a repair. The backend server can be designed, in particular, to send, receive, and permanently store data.

[0038] In general, data from the vehicle can be collected continuously or at discrete times. For example, a specific sensor can continuously emit a sensor signal that can be received and processed by an evaluation unit.

[0039] Likewise, a sensor can continuously emit a sensor signal, which is then processed by the sensor itself or a sensor unit connected to it into a discrete sensor signal, which is then received and processed by the evaluation unit. Furthermore, a specific sensor can emit a sensor signal at specific intervals, which can also be received and processed by an evaluation unit.

[0040] The evaluation unit can be connected to or integrated into a vehicle's control unit to make the collected data usable for controlling or regulating the vehicle. Furthermore, the evaluation unit can be designed as a computer and / or storage unit.

[0041] The evaluation unit processes the sensor signals into data, which can be conveniently stored in data sets Di,...,D n structured and summarized and in the form of these data sets Di,... ,D n can be stored and communicated. A simple example data set Di,...,D n includes a numerical value and a unit, such as an SI unit, for a measured quantity recorded by a sensor, as well as so-called metadata, such as the time at which the numerical value was logged and an identifier for the sensor or sensor unit with which the measured quantity was recorded.

[0042] The communication of such data or data sets, known as telematics data, can be carried out via a permanently installed SIM card on board the vehicle to the backend server. The backend server stores and manages the data sets Di,...,D transferred from the vehicle. n .

[0043] In addition, the backend server must communicate with various data processors 1, 2, 3. These data processors 1, 2, 3 can process data or data sets Di,...,D n from the backend server in order to use or evaluate them for a specific purpose and the backend server can use corresponding data or data records Di,... ,D n to the data processors 1, 2, 3. For this purpose, the backend server is able to check whether the requested data or data records Di,... ,D n meet the necessary data protection requirements and in particular whether the user to whom the data or data sets are transferred Di,... ,D nhave agreed to further processing and thus to use by one or more of the data processors 1, 2, 3.

[0044] Data that contains direct or indirect identification features related to a person, such as a customer number with customer data, a chassis number, or a vehicle registration number, is referred to as personal data. At least within the European legal system, any linking of personal data for third-party purposes requires consent if the legal rights of the parties involved are not to be restricted. Agreements between the parties involved are possible for this purpose, thus documenting the express consent of the parties involved.

[0045] To enable the user of a vehicle to consent to the linking of personal or related data collected by the vehicle, the vehicle has an interface with which the driver or another affected user of the vehicle can configure data protection settings for the data collected by the vehicle. In particular, the driver or user can configure which additional services of the vehicle or for the operation of the vehicle should be permitted, which is accompanied by the approval of the use of the collected data by these services. If such approval is granted, the backend server is permitted to use those data records Di,...,D nto one or more of the data users 1, 2, 3, who, for example, use the data to offer a specific service. Data users can be, for example, providers of traffic information services, providers of repair or maintenance services or a rental car company that operates the vehicle within its rental car fleet. In order to be able to make the data collected or recorded with the vehicle available to a data user 1, 2, 3, the respective user of the vehicle must declare their consent to the use or evaluation. For this purpose, the vehicle provides options for declaring consent in full or only for specific data or data sets. The interface also enables the user to view and change the data protection settings they have set at any time.To prevent users from driving with the privacy settings of previous users, driver profiles are stored in the vehicle or can be created. Drivers have the option to change their driver profile. Driver profiles can also be linked to the vehicle key used. This means that a user can only operate a vehicle with their individual driver profile and the associated individual key, but not with the driver profile of another user. The privacy settings are linked to the respective driver profile. Once the driver profile is changed, the driver's privacy settings are used when linking tokens to collected data sets.If, as described above, data protection settings are set in the protocol for a connection to the backend server and tokens are only linked to the data records in the backend in order to save vehicle and connection resources, then the data protection settings set for the connection must be adjusted or the connection must be re-established when the driver profile changes or the data protection settings in the vehicle are changed.

[0046] For example, the driver or user can authorize the "Intelligent Maintenance" service to use data collected by the vehicle via the interface. In this example, personally identifiable data on driving behavior, such as driving speeds, tire pressure, and distances traveled, can be transmitted from the vehicle to the backend server, and the backend server can transmit this data upon request or without request to one or more data processors, who can use the data to determine the wear status of the vehicle's tires and alert the driver or user at an appropriate time when the tires are worn to the point where they need to be replaced.

[0047] In another example, the driver or user can specify that certain personal data be made available to their motor vehicle insurance company to enable a vehicle-related insurance contract to be tailored precisely and in real time to the actual vehicle parameters, such as the vehicle's annual mileage. To indicate whether a particular data set is Di,...,D n If the data set has been authorized by the driver or user for a specific third-party use, the data set is associated or linked with a specific data protection token. The data protection token can be created automatically for each data set and automatically associated with it. For example, the evaluation unit or a computing unit separate from the evaluation unit can create such a data protection token and associate or link it with the data set.

[0048] The data protection token can contain information indicating whether the vehicle user has consented or not consented to a specific use or analysis of the associated data set. Alternatively or additionally, a data protection token can include a literal, i.e., a character string that represents consent to a specific use of the data set. If such a data protection token (or literal) is associated with or attached to a specific data set, consent to the use is granted. If the data protection token is missing, consent for this specific data set is denied. A data set can be associated with multiple data protection tokens. The data protection token is readable by the backend server, but cannot be modified by or via the backend server. The respective information readable by the backend server is thus contained in the data protection tokens Si,..., S nstored with the respective associated data sets Di,... , D n are associated.

[0049] The data protection tokens Si,... , S n are, after their association or linking, inseparable and unchangeable from the respective associated data set Di,... , D n Likewise, the data sets Di,... , D n after their association with a data protection token Si,... , S n can no longer be changed.

[0050] Figs. 2a and 2b show possible time sequences for the creation of data protection tokens according to the invention.

[0051] In Fig. 2a, the vehicle's usage is recorded at time t0. At time t1, a specific sensor begins recording the measured value M. For example, the vehicle door may be unlocked at time t0, and the start of a journey may be detected at time t1, so that an odometer detects vehicle movement and measures the distance traveled. In the simple example of the odometer, recording the measured value M would correspond to recording the vehicle's mileage, which is usually accurate to the meter.

[0052] At a time t2, which can be during the journey, after the journey, or exactly at the end of the journey, the current measured value M at time t2 is logged, i.e., saved. At a later time tE, the user changes the data protection settings set at the start of the journey to such that the measured value M, or the data set in which the measured value M is stored, is released for a specific use. A corresponding data protection token is then created for the data set in which the measured value M is stored and associated or linked with the data set. At a time t3, the data set is transferred to the backend server with the data protection token.

[0053] This is advantageous because after the measured value M is stored at time t2, the measured value M is not immediately linked to a data protection token, so if the use of the measured value M is not permitted, this measured value is not necessarily “lost”.

[0054] In Fig. 2b, however, consent to the use of a measured value M already exists at time t0, i.e., before the recording of the measured value M begins. In this case, simultaneously with the storage or "logging" of the measured value M, a data protection token is created for the data set, in which the measured value M is stored and associated with the data set. In this way, the data set with the measured value M is inextricably linked to the data protection token even for the period between storage t2 and transfer tE.

[0055] It can also be advantageous, regardless of when a data protection setting was made, to only associate a data record with a data protection token when the data record has been requested from the backend server or when the data record is to be transferred to the backend server. This way, it is not necessary to assign data protection tokens to those measured values ​​or data records that are discarded before being transferred to the backend server.

[0056] In addition, the data protection settings for a specific data set or measured value can be changed even after it has been recorded, so that the data protection settings valid at the time of transfer can take effect.

[0057] In conjunction with the embodiments according to Fig. 2a and 2b, the possibility of generating a data protection token with a data set not at the time of measurement, but at a later point in time is demonstrated. In terms of data protection, however, it is generally more advantageous if the data protection settings at the time of measurement are decisive. The token mechanism should not open up the possibility of only using the data protection settings at the time of transmission to the backend in the event of non-consent at the time of measurement, because consent may then have been given. This would represent an opportunity for manipulation of the data protection settings, which is fundamentally to be avoided. Data sets must be provided with tokens immediately after measurement and stored inseparably in the vehicle until transmission to the backend takes place.The positive case in which measured values ​​are not lost due to the tokens is when consent was given at the time of measurement, but no longer at the time of transfer to the backend.

[0058] Alternatively, it may also be possible to transmit one or more specific data protection settings to the backend server as a session property defined by a transfer protocol, separately from the data records to which the data protection settings apply. This mechanism is intended to avoid redundancy of tokens in data records transmitted over a mobile radio link. This redundancy exists for data records that are measured while the mobile radio connection between the vehicle and the backend server is established and that are transmitted immediately. In this case, all of these data records carry the same data protection tokens. By setting the tokens as a connection property and by associating the tokens with the data records only in the backend, the result for these data records is ultimately the same as if this optimization had not taken place.Data records that were already tokenized in the vehicle before the connection was established and are transmitted when the connection is established may then need to be excluded from this optimization. This is particularly advantageous if, for example, full consent has been given to all uses of the collected data. Since a data protection token is only associated with consent to the use, and no token is associated with refusal, more consent also means more data protection tokens and thus more redundancy. In such a case, the same data protection settings apply to all data records, so setting the data protection settings as a session property enables significantly reduced transmission and resource overhead on the backend server.

Claims

Patent claims 1. A method for setting data protection for data collected by a vehicle, wherein the vehicle is configured to collect data by means of sensors and wherein the vehicle provides an interface with which a user of the vehicle can make data protection settings for the data collected by the vehicle, the method comprising the following steps: a) detecting, by the vehicle, data protection settings made by the user of the vehicle for data collected by the vehicle; b) detecting data and structuring the data in the form of data records by the vehicle; c) transferring at least one data record to an external data receiving point;d) Automatically creating at least one data protection token for each data set to be transferred and associating the data protection token created for the respective data set with the respective data set before, during or after the data set is transferred from the vehicle to the external data receiving point, wherein the data protection token contains information as to whether the user of the vehicle has consented to a specific use of the data set associated with the data protection token; 2. Method according to claim 1, characterized in that the data protection token, in particular the information contained in the data protection token, is or are unchangeable after the automated creation and / or that the data protection token is unchangeably linked to the associated data record after the association.

3. Method according to one of the preceding claims, characterized in that the data protection token contains information as to whether the user of the vehicle consents to a specific use of the data set associated with the data protection token at the time the data set is captured by the vehicle or at the time has or had consented to the transfer of the data set from the vehicle to the external data receiving point.

4. Method according to one of the preceding claims, characterized in that the data protection token contains information as to whether the data set associated with the data protection token is subject to a legal obligation to store this data set and / or to make it available to the user, in particular upon request.

5. Method according to one of the preceding claims, comprising the following steps: e) receiving a request from a further processing entity by the external data receiving entity, with which one or more data records are requested for further processing from the external data receiving entity; f) checking the data protection token(s) of data records eligible for fulfilling the request by the external data receiving entity; and Determine whether the information contained in the data protection token(s) permits or does not permit further processing of the associated data record(s) by the further processing entity; g) Forward the transferred data record(s) to a further processing entity by the external data receiving entity if it has been determined that the information contained in the data protection token(s) permits further processing of the associated data record(s) by the further processing entity.

6. A method according to any one of the preceding claims, comprising the following steps: h) receiving a request from the external data receiving point by the vehicle requesting one or more data sets from the vehicle for transfer to the external data receiving point; i) checking the data protection token(s) of data sets eligible for fulfilling the request by the vehicle; and j) determining whether the information contained in the data protection token(s) permits or does not permit the transfer of the associated data set(s) to the external data receiving entity; j1) transferring the associated data set(s) to the external data receiving entity if it is determined that the information contained in the data protection token(s) permits the transfer of the associated data set(s) to the external data receiving entity;or j2) not carrying out the transfer of the related data record(s) to the external data receiving entity if it is determined that the information contained in the data protection token(s) does not allow the transfer of the related data record(s) to the external data receiving entity and transferring information to the external data receiving entity that the transfer of the requested data record(s) has not been carried out and / or that the transfer of the requested data record(s) has not been permitted.; 7. Method according to one of the preceding claims, characterized in that the data protection token is written in the form of a set of metadata into the data record associated with the data protection token or is linked to it before or during the data record is transferred.

8. The method according to claim 7, characterized in that the data protection token is inseparably written into the data set associated with the data protection token or is inseparably linked to it, in particular wherein the data protection token and the data set are linked to one another in a cryptographically secured manner.

9. Method according to one of the preceding claims, characterized in that the data protection token is associated with the data set at the time or immediately before the time of transfer of the data set to the external data receiving point.

10. Method according to one of the preceding claims, characterized in that the data record(s) are transferred from the Vehicle to the external data receiving point, wherein the data protection settings made by the user are communicated as a parameter of the transfer protocol from the vehicle to the external data receiving point, wherein the external data receiving point carries out the automated creation of a data protection token for each transferred data set depending on the data protection settings made and associates the data protection token created for the respective data set with the respective data set after the respective data set has been transferred.

11. A computer program product comprising program code means which causes one or more electronic computing devices to carry out a method according to one of claims 1 to 10 when the program code means are processed by the electronic computing device(s).

12. A computer-readable storage medium comprising at least one computer program product according to claim 11.

13. System comprising a vehicle and at least one or more external data receiving points for carrying out the method according to one of claims 1 to 12.

Citation Information

Patent Citations

  • DATA PROTECTION SYSTEM

    DE102021207604A1

  • Embedded metadata for data protection compliance

    DE102022110918A1

  • Controlling privacy settings of a communication between a vehicle and a backend cloud device

    EP3968603A1

  • Autonomous vehicle system

    DE112020001663T5

  • Systems and methods for preserving the privacy of collected vehicular data

    US20200175193A1