Apparatus for managing level of interest in personal information and predicting inclusion of personal information and control method thereof

By analyzing user behavioral data during consent processes to calculate personal information interest, the device addresses challenges in determining user sensitivity and managing personal information, effectively reducing unnecessary collection and leaks.

WO2025121890A1PCT designated stage expired Publication Date: 2025-06-12O NE PEOPLE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/019772
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-12-02
Filing Date
2024-12-04
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Current technologies face challenges in objectively determining user sensitivity to personal information during consent processes, managing collected personal information effectively, and predicting the inclusion of personal information items, leading to unnecessary collection and potential leaks.

Method used

A device and method for managing and predicting user interest in personal information by analyzing behavioral data during consent processes, determining abnormal and normal behaviors, calculating personal information interest, and assigning grades based on this interest.

Benefits of technology

This approach enables customized management strategies to suppress unnecessary personal information collection, prevent leaks, and improve user comfort by objectively assessing user sensitivity and interest.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024019772_12062025_PF_FP_ABST
    Figure KR2024019772_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to an apparatus for managing the level of interest in personal information and predicting the inclusion of the personal information, and a control method thereof, and the purpose of the present disclosure is to: collect, through an input module, data regarding behavior of a user viewing a consent form; analyze the behavior data; determine abnormal and normal behaviors on the basis of the result of analyzing the behavior data; calculate the level of interest in personal information by processing the behavior data on the basis of the determined result; and assign a grade according to the calculated level of interest in personal information.
Need to check novelty before this filing date? Find Prior Art

Description

Device for managing and predicting the level of interest in personal information and its control method

[0001] The present disclosure relates to a device for managing and predicting personal information interest. More specifically, the device analyzes and manages a user's interest in personal information based on behavioral data during the personal information consent process, and predicts the likelihood of personal information inclusion in questions entered by the user. The device and its control method are intended to manage and predict personal information interest and inclusion.

[0002] With the recent advancements in IT technology, personal authentication and the collection of personal information are becoming essential procedures when using many IT devices. Pursuant to Article 16, Paragraph 1 of the Personal Information Protection Act, personal information processors must collect the minimum amount of personal information necessary for the purpose of collecting personal information. In this case, the burden of proof lies with the personal information processor, who has collected the minimum amount of personal information.

[0003] Currently, the purpose of personal information collection is often unclear, or unnecessary information is collected for that purpose. According to the 2015 Personal Information Protection Survey, approximately 64% of data subjects cited unnecessary and excessive collection of personal information as the primary cause of personal information leaks, and 72% of the public responded that personal information processors currently collect excessive amounts of personal information. However, the minimum necessary scope can vary depending on the industry of the personal information processor, the circumstances of collection, and the purpose of the data collection, making it practically difficult for individuals to determine this.

[0004] In the case of conventional technology, there was a problem in that users felt uncomfortable because it was impossible to objectively know the level of sensitivity of the user regarding personal information when the information subject consented to providing personal information.

[0005] Furthermore, with conventional technology, it was difficult to determine whether collected information contained personal information, making it difficult to manage the collected information. Furthermore, defining the appropriate purpose for collecting personal information was daunting and challenging. This raised the barrier to entry for personal information collection and management, resulting in user inconvenience.

[0006] The purpose of the embodiment disclosed in this disclosure is to provide a device and a control method for managing and predicting the inclusion of personal information by collecting user behavioral data during the personal information consent process, analyzing the user's interest in personal information, and establishing a customized management strategy for the same.

[0007] In addition, the embodiment disclosed in the present disclosure aims to provide a device and a control method for managing and predicting the level of interest in personal information by analyzing various patterns of user behavior and evaluating sensitivity when creating a personal information consent record.

[0008] In addition, the embodiment disclosed in the present disclosure aims to provide a device for managing interest in and predicting inclusion of personal information, which can predict the possibility of including personal information items by analyzing the processing of personal information based on items input by a user, and a control method thereof.

[0009] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0010] A personal information interest management device according to the present disclosure comprises: an input module for collecting data; a communication module for transmitting and receiving the data with an external device including a mobile device; a memory for storing at least one process for personal information interest management; and a processor for controlling an operation according to the process, wherein the processor collects user behavior data of viewing a consent form through the input module, analyzes the behavior data, determines abnormal and normal behavior based on the analysis result of the behavior data, processes the behavior data based on the determined result to calculate a personal information interest, and assigns a grade based on the calculated personal information interest.

[0011] In addition, a method for managing personal information interest, which analyzes and manages a user's personal information interest based on behavioral data in a personal information consent process performed by a processor of a device according to the present disclosure, includes the steps of: collecting behavioral data of a user viewing a consent form through the input module; analyzing the behavioral data; determining abnormal and normal behavior based on the analysis result of the behavioral data; calculating a personal information interest by processing the behavioral data based on the determined result; and assigning a grade based on the calculated personal information interest.

[0012] In addition, a computer program stored in a computer-readable recording medium may be further provided to execute a method for implementing the present disclosure.

[0013] In addition, a computer-readable recording medium recording a computer program for executing a method for implementing the present disclosure may be further provided.

[0014] According to the present invention, by collecting user behavioral data during the personal information consent process, the user's level of interest in personal information can be analyzed and a customized management strategy can be established, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0015] In addition, according to the present invention, when creating a personal information consent record, various patterns of user behavior can be analyzed and sensitivity can be evaluated and managed, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0016] In addition, according to the present invention, it is possible to predict the possibility of including personal information items by analyzing the processing of personal information based on items entered by the user, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0017] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0018] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0019] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0020] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0021] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0022] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0023] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0024] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0025] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0026] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0027] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0028] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0029] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0030] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0031] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0032] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0033] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0034] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0035] Figure 18 is a drawing showing the status of consignment companies according to the present disclosure.

[0036] Figure 19 is a diagram illustrating the status of personal information processing according to the present disclosure.

[0037] Figure 20 is a drawing showing the status of subcontracting companies according to the present disclosure.

[0038] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0039] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0040] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0041] Figure 24 is a diagram illustrating a configuration of a personal information interest management device according to the present disclosure.

[0042] Figure 25 is a diagram illustrating a flowchart of a personal information interest management method according to the present disclosure.

[0043] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0044] FIG. 27 is a diagram illustrating an embodiment of a personal information interest management method according to the present disclosure.

[0045] FIG. 28 is a diagram illustrating an example of customer sensitivity judgment according to the present disclosure.

[0046] Figure 29 is a diagram illustrating an example of user consent process behavior analysis according to the present disclosure.

[0047] Figure 30 is a diagram illustrating a flowchart of a prediction method including personal information according to the present disclosure.

[0048] Figure 31 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0049] FIG. 32 is a diagram illustrating a flowchart 1 of a prediction method including personal information according to the present disclosure.

[0050] FIG. 33 is a diagram illustrating a flowchart 2 of a prediction method including personal information according to the present disclosure.

[0051] Figure 34 is a diagram illustrating the structure of a legal decision system according to the present disclosure.

[0052] FIG. 35 is a diagram illustrating the structure of a proxy label method according to the present disclosure.

[0053] Figure 36 is a diagram illustrating an example of personal information classification according to the present disclosure.

[0054] Figure 37 is a diagram illustrating the structure of a personal information classification system according to the present disclosure.

[0055] Figure 38 is a diagram illustrating a personal information purpose search according to the present disclosure.

[0056] Throughout this disclosure, the same reference numerals denote the same components. This disclosure does not describe all elements of the embodiments, and any content that is common in the technical field to which this disclosure pertains or that overlaps between embodiments is omitted. The terms "part, module, element, block" used in the specification may be implemented in software or hardware, and depending on the embodiments, multiple "parts, modules, elements, blocks" may be implemented as a single component, or a single "part, module, element, block" may include multiple components.

[0057] Throughout the specification, when a part is said to be "connected" to another part, this includes not only direct connection but also indirect connection, and indirect connection includes connection via a wireless communication network.

[0058] Additionally, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.

[0059] Throughout the specification, when we say that an element is "on" another element, this includes not only cases where the element is in contact with the other element, but also cases where another element exists between the two elements.

[0060] The terms first, second, etc. are used to distinguish one component from another, and the components are not limited by the aforementioned terms.

[0061] Singular expressions include plural expressions unless the context clearly indicates otherwise.

[0062] The identification codes for each step are used for convenience of explanation and do not describe the order of each step. Each step may be performed in a different order than specified unless the context clearly indicates a specific order.

[0063] The operating principle and embodiments of the present disclosure are described below with reference to the attached drawings.

[0064] The present invention can be implemented not only in a server system but also in various devices capable of performing computational processing and providing results to a user. For example, the present invention can include a computer, a server device, and a mobile terminal, or can be implemented in any one of these forms.

[0065] Here, the computer may include, for example, a notebook, desktop, laptop, tablet PC, slate PC, etc. equipped with a web browser.

[0066] The above server device is a server that processes information by communicating with an external device, and may include an application server, a computing server, a database server, a file server, a game server, a mail server, a proxy server, and a web server.

[0067] The above portable terminal may include, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), WiBro (Wireless Broadband Internet) terminal, a smart phone, and a wearable device such as a watch, a ring, a bracelet, an anklet, a necklace, glasses, contact lenses, or a head-mounted device (HMD).

[0068] The artificial intelligence-related functions according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, one or more processors may be a general-purpose processor such as a CPU, an AP, a DSP (Digital Signal Processor), a graphics-only processor such as a GPU or a VPU (Vision Processing Unit), or an artificial intelligence-only processor such as an NPU. One or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if one or more processors are artificial intelligence-only processors, the artificial intelligence-only processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0069] The predefined operation rules or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that the basic artificial intelligence model is learned by a learning algorithm using a plurality of learning data, thereby creating a predefined operation rules or artificial intelligence model set to perform a desired characteristic (or purpose). This learning may be performed in the device itself on which the artificial intelligence according to the present disclosure is performed, or may be performed through a separate server and / or system. Examples of the learning algorithm include, but are not limited to, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning.

[0070] An artificial intelligence model may be composed of multiple neural network modules. Each of the multiple neural network modules has multiple weight values, and performs neural network operations through operations between the operation results of the previous module and the multiple weights. The multiple weights of the multiple neural network modules may be optimized based on the learning results of the artificial intelligence model. For example, the multiple weights may be updated so that the loss value or cost value obtained from the artificial intelligence model is reduced or minimized during the learning process. The artificial neural network may include a deep neural network (DNN), and examples thereof include, but are not limited to, a convolutional neural network (CNN), a deep neural network (DNN), a recurrent neural network (RNN), a restricted boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), or deep Q-networks.

[0071] The processor can create a neural network, train (or learn) a neural network, perform computations based on received input data, and generate information signals based on the results of the computations, or retrain the neural network.

[0072] Neural networks include CNN (Convolutional Neural Network), RNN (Recurrent Neural Network), perceptron, multilayer perceptron, FF (Feed Forward), RBF (Radial Basis Network), DFF (Deep Feed Forward), LSTM (Long Short Term Memory), GRU (Gated Recurrent Unit), AE (Auto Encoder), VAE (Variational Auto) Encoder), DAE (Denoising Auto Encoder), SAE (Sparse Auto Encoder), MC (Markov Chain), HN (Hopfield Network), BM (Boltzmann Machine), RBM (Restricted Boltzmann Machine), DBN (Depp Belief Network), DCN (Deep Convolutional Network), DN (Deconvolutional Network), DCIGN (Deep Convolutional Inverse Graphics Network), Generative Adversarial Network (GAN), Liquid State Machine (LSM), Extreme Learning Machine (ELM), It will be understood by those skilled in the art that any neural network may be included, including but not limited to ESN (Echo State Network), DRN (Deep Residual Network), DNC (Differentiable Neural Computer), NTM (Neural Turning Machine), CN (Capsule Network), KN (Kohonen Network), and AN (Attention Network).

[0073] According to an exemplary embodiment of the present disclosure, the processor may be configured to perform a process for generating a CNN (Convolution Neural Network) such as GoogleNet, AlexNet, VGG Network, Region with Convolution Neural Network (R-CNN), Region Proposal Network (RPN), Recurrent Neural Network (RNN), Stacking-based deep Neural Network (S-DNN), State-Space Dynamic Neural Network (S-SDNN), Deconvolution Network, Deep Belief Network (DBN), Restrcted Boltzman Machine (RBM), Fully Convolutional Network, Long Short-Term Memory (LSTM) Network, Classification Network, Generative Modeling, eXplainable AI, Continual AI, Representation Learning, AI for Material Design, BERT, SP-BERT, MRC / QA for natural language processing, Text Analysis, Dialog System, GPT-3, GPT-4, Visual Analytics for vision processing, Visual Understanding, Video Synthesis, ResNet for data intelligence, Anomaly Detection, Prediction, Time-Series Forecasting, Various artificial intelligence structures and algorithms, including optimization, recommendation, and data creation, can be utilized, but are not limited thereto. Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0074] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0075] Referring to Fig. 1(10), the configuration of the entire system is described.

[0076] The system (10) is briefly composed of part A (100), part B (200), part C (300), part D (400), part E (500), part F (600), and a processor (50).

[0077] Part A (100) may be referred to as the Compliance Collection and Registration Department.

[0078] Part B (200) may be named the Personal Information Collection and Use and Analysis Department.

[0079] Part C (300) may be named the Compliance and Security Risk Analysis Department.

[0080] Department D (400) may be called a service-specific personal information analysis department.

[0081] Part E (500) may be called a personal information destruction part.

[0082] Part F (600) may be called the authentication management department.

[0083] The processor (50) controls section A (100), section B (200), section C (300), section D (400), section E (500), and section F (600).

[0084] At least one detailed function among Part A (100), Part B (200), Part C (300), Part D (400), Part E (500), and Part F (600) can be stored in memory as software, and the processor (50) can execute the detailed function of each part by referring to the memory.

[0085] Define key terms of the present invention.

[0086] Compliance typically encompasses legal compliance, compliance monitoring, and internal control. A compliance program is a set of systems designed to ensure companies voluntarily comply with relevant laws and regulations during their business operations. Compliance also includes security regulations.

[0087] Regulations include laws, enforcement decrees, notices, guides, etc.

[0088] Inspection means construction, and investigation means the act of creating and configuring control items for investigation, that is, the act of establishing standards.

[0089] Control items refer to items that an organization must comply with to protect personal information.

[0090] A trigger is a condition for an occurrence.

[0091] Tags represent main keywords.

[0092] Internal compliance refers to internal rules.

[0093] Security requirements refer to the security standards and security rules requested by each organization (company) or service situation to protect information assets.

[0094] Common regulations are commonalities among national regulations, including national common regulations and industry-specific common regulations.

[0095] Common regulations by country refer to regulations that exist in common among the regulations that exist in each country selected by the institution or company.

[0096] Common regulations by industry refer to regulations that exist in common among the regulations required for the industry, industry, and scale selected by the organization or company.

[0097] Microregulations are regulations that differ among multiple regulations.

[0098] For example, micro-regulations may be regulations that institutions or companies choose to comply with individually, or may be regulations that are not specifically stipulated in the law or have no specific timing or method.

[0099] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0100] Referring to FIG. 2 (210), the compliance collection and registration unit (100) is described.

[0101] The Compliance Collection and Registration Department (100) is abbreviated as Department A (100).

[0102] The A1 module (110) may be named a compliance collection automation module, the A2 module (120) may be named a compliance inspection automation module, and the A3 module may be named a company-specific security requirements analysis automation module.

[0103] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0104] Referring to FIG. 3 (310), the compliance collection automation module (110) is described.

[0105] The compliance collection automation module (110) finds regulations related to personal information by country, classifies the regulatory provisions, and analyzes the ‘subject’, ‘object’, and ‘predicate’ appearing in the provisions by dividing them into main text and clauses.

[0106] The compliance collection automation module (110) sets keywords based on the analysis and creates tags using these.

[0107] The compliance collection automation module (110) includes a compliance collection module (111) and a compliance analysis-refinement ML module (112).

[0108] The compliance collection module (111) includes a Crawler, Scraper, and API.

[0109] The Compliance Analysis-Refinement ML module (112) sets keywords based on the analysis and converts them into tags. It includes Vision AI, NLP AI, and ETC.

[0110] The Compliance Analysis-Refinement ML module (112) performs the following:

[0111] First, determine your priorities.

[0112] 1) Determine whether it is the main text or a proviso, 2) the priority of regulations based on whether it is a general law or a special law, and 3) the priority of application of regulations based on the legal system.

[0113] Second, it performs subject, object, and verb judgment and tagging.

[0114] 1) Defining the ‘subject of law’ for each clause means judging what corresponds to the subject of a legal provision based on the citation relationship of the legal provision.

[0115] 2) Defining the ‘object of law’ for each clause means judging what corresponds to the object of a legal provision based on the citation relationship of the legal provision.

[0116] 3) Define ‘verb’.

[0117] Third, legal differences are judged and tagging is performed.

[0118] 1) Determine differences between countries regarding specific regulations (laws, enforcement decrees, enforcement rules, notices, instructions, rules, etc.).

[0119] Here, the regulations include:

[0120] An Act (or Law, or Statute) is a law enacted through the legislative process of the National Assembly. It is translated into English as "Act," "Law," or "Statute." For example, "Civil Act" can be translated as "Civil Law."

[0121] An Enforcement Decree is a presidential decree to specifically enforce a law, and is translated into English as "Enforcement Decree."

[0122] Enforcement Rule refers to a regulation of a ministry that provides more detailed regulations for enforcement ordinances, and is translated into English as "Enforcement Rule."

[0123] A public notice (notification) is issued to inform of specific matters and is translated as "Public Notice" or "Notification".

[0124] A directive (or instruction) is an administrative order that gives instructions from a higher authority to a lower authority, and is translated as "directive" or "instruction."

[0125] Regulations (Official Instructions) contain rules regarding procedures or work within an administrative agency and can be translated as "Regulation" or "Official Instruction."

[0126] The country-specific personal information laws (laws, enforcement decrees, rules, notices, instructions, and regulations) management module (not shown) processes personal information-related regulations by country to enable quick assessment.

[0127] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0128] Referring to FIG. 4 (410), the compliance inspection module (120) is described.

[0129] The compliance inspection module (120) builds and creates customized control items related to personal information protection that the organization must comply with.

[0130] The compliance inspection module (120) creates control items by considering 1) the ‘country compliance’ collected and refined in the A1 module (110) and 2) the security requirements.

[0131] The compliance inspection module (120) includes a country-specific compliance inspection trigger automation module (121) and an internal regulation generation module (122).

[0132] The country-specific compliance inspection trigger automation module (121) investigates personal information protection regulations (compliance) by country (the method is to attach an appropriate tag to each provision) and classifies the investigated regulatory tags as micro-regulations or common regulations.

[0133] The internal regulation generation module (122) selects micro-regulations in accordance with internal compliance and generates internal regulations based on the selected micro-regulations.

[0134] The internal regulation creation module (122) allows the internal security officer to review the values ​​from the primary module, select micro-regulations that fit the internal regulations, and create internal regulations using the selected regulations.

[0135] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0136] Referring to FIG. 5 (510), the in-house compliance inspection automation module (123) is described.

[0137] The in-house compliance inspection automation module (123) creates internal regulations as inspection automation modules (as inspection items) so that inspection can be turned on or off.

[0138] The in-house compliance inspection automation module (123) can be connected to the B2 module (220).

[0139] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0140] Referring to Figure 6 (610), the company-specific security requirements analysis automation module (130) is described.

[0141] The company-specific security requirements analysis automation module (130) includes a business security requirements analysis module (131). Here, the company also includes an institution.

[0142] The company-specific security requirements analysis automation module (130) obtains agency information and service information.

[0143] Obtain country information from the location, company name, size, company identification number, and service information.

[0144] The business security requirements analysis module (131) determines which regulation applies based on the acquired information.

[0145] Specifically, the business security requirements analysis module (131) determines which regulations will be applied based on the (obtained) organization / service information.

[0146] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0147] Referring to Figure 7 (710), the personal information collection and use and analysis unit (200) will be described.

[0148] The personal information collection and use and analysis department (200) corresponds to Department B (200).

[0149] Part B (200) includes a B1 module (210), a B2 module (220), a B3 module (230), a B4 module (240), and a B5 module (250).

[0150] The B1 module (210) may be named a collection form creation and response automation module, the B2 module (220) may be named a personal information collection detection automation module, the B3 module (230) may be named a collection and use consent form automatic creation module, the B4 module (240) may be named a personal information processing policy automatic creation module, and the B5 module (250) may be named a personal information subject token and consent history hash creation module.

[0151] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0152] Referring to FIG. 8 (810), the collection form creation and response automation module (210) is described.

[0153] The collection form creation and response automation module (210) allows the administrator to create an input form and collect personal information from the information subject.

[0154] The collection form creation and response automation module (210) includes a personal information collection form creation module (211), a personal information collection detection module (212), an in-house compliance establishment module (213), a processing basis creation module (214), and a personal information processing policy creation module (215).

[0155] The personal information collection form creation module (211) collects content (text, image, video), determines the response method (electronic signature, identity verification), and creates a list and type of information to be collected.

[0156] The personal information collection detection module (212) determines whether the personal information collected in the form for collecting personal information is actual personal information, and if the collected information corresponds to personal information, it transmits the information to the ‘Collection Behavior Management Department’ in charge of personal information collection detection.

[0157] The in-house compliance building module (213) investigates in-house compliance.

[0158] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts an investigation, it can be considered an inspection.

[0159] The processing basis generation module (214) automatically generates a personal information collection and use consent form.

[0160] The processing basis generation module (214) automatically generates personal information collection / provision and use consent forms, as well as processing basis forms. Because the consent forms are generated based on institutional and service information, they can be customized. The consent forms can be modified, such as by tailoring them based on the information of the data subject providing the personal information.

[0161] The grounds for processing are as follows:

[0162] 1. In case the consent of the information subject has been obtained.

[0163] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0164] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0165] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0166] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0167] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.

[0168] 7. In cases where it is for public safety and well-being, such as public health.

[0169] The personal information processing policy creation module (215) automatically creates a personal information processing policy.

[0170] The personal information processing policy creation module (215) automatically generates a personal information processing policy based on institutional and service information. It can also create a customized personal information processing policy based on the information of the data subject providing the personal information. The generated personal information processing policy is then transferred to the "Processing Policy Management Department" for management.

[0171] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0172] Figure 9 includes Figures 9(a), 9(b) and 9(c).

[0173] Figure 9(a)(910) is a drawing illustrating a personal information collection form creation module (211).

[0174] Figure 9(b)(920) is a diagram illustrating a personal information collection detection module (212), an in-house compliance establishment module (213), and a processing basis generation module (214).

[0175] Figure 9(c)(930) is a diagram illustrating a personal information processing policy creation module (215).

[0176] As shown in Fig. 9(a)(910), the personal information collection form generation module (211) generates a form for importing personal information, which can be selected by the in-house service manager based on organization information and service information, and automatically generates a personal information collection form (S1).

[0177] As shown in Fig. 9(b)(920), the personal information collection detection module (212) determines whether the information collected in the form for collecting personal information is personal information or not, and if the collected information corresponds to personal information, it transmits the information to the ‘collection behavior management department’ in charge of personal information collection detection (S2).

[0178] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts investigations, it conducts inspections (S3).

[0179] The processing basis generation module (214) automatically generates a consent form for the collection / provision of personal information or a basis for processing (S4). Because it generates a consent form based on institutional and service information, it can be customized. The consent form can be modified, such as by tailoring it based on the information of the data subject providing the personal information.

[0180] The grounds for processing are as follows:

[0181] 1. In case the consent of the information subject has been obtained.

[0182] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0183] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0184] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0185] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0186] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.

[0187] 7. For public safety and well-being, including public health.

[0188] As illustrated in Fig. 9(c)(930), the personal information processing policy creation module (215) automatically creates a personal information processing policy based on institutional information and service information, and manages it by transferring it to the ‘processing policy management department’ (S5).

[0189] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0190] Referring to FIG. 10 (1010), the personal information collection detection automation module (220) includes an AI inspection module (221) for detecting whether personal information collection is requested and an AI inspection module (222) for detecting whether personal information is submitted.

[0191] The personal information collection detection automation module (220) is linked with the personal information collection detection module (212) of the B1 module (210).

[0192] The personal information collection detection automation module (220) is linked with the in-house compliance inspection automation module (123).

[0193] The personal information collection detection automation module (220) detects whether a personal information collection request has occurred and manages the collected information by determining whether it corresponds to actual personal information. Personal information includes sensitive information, unique identification numbers, and resident registration numbers.

[0194] The AI ​​Inspect module (221) detects whether a request for personal information collection has been made and automatically classifies the type of information being collected (e.g., personal information, sensitive information, unique identification number, etc.) according to the type of personal information, and automatically applies the appropriate processing procedure for each type.

[0195] The AI ​​Inspect module (222) detects whether personal information has been submitted, and determines whether the information provided by the user is personal information through AI-based analysis (e.g. Vision AI, NLP AI, etc.) to prevent unwanted, unnecessary, and unintended collection of personal information, and detects whether it has been collected.

[0196] The AI ​​Inspect module (222) that detects whether personal information has been submitted analyzes the user's input data using various artificial intelligence technologies such as Vision AI and NLP AI, and determines in real time whether the input information corresponds to personal information.

[0197] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0198] Referring to FIG. 11 (1110), the automatic collection and use consent form generation module (230) is described.

[0199] The automatic collection and use consent form generation module (230) corresponds to the B3 module (230).

[0200] The automatic collection and use consent form automatic generation module (230) includes a processing guide, an automatic collection and use consent form generation module (231), an automatic consent form type template reflection module (232), and a personal information collection purpose analysis module (233).

[0201] The automatic collection and use consent form generation module (230) is a system that automatically generates and manages consent forms required during the collection and processing of personal information. It analyzes the type and purpose of personal information collection to automatically apply an appropriate consent form template. It also generates customized consent forms that reflect legal requirements, automating the process of obtaining consent from data subjects, thereby complying with personal information protection regulations.

[0202] The operational flow of the present invention is described.

[0203] First, the type of personal information consent form is selected according to the type of personal information classified by the B2 module (220).

[0204] Second, the information that should be included in the consent form is directly entered by the personal information processor.

[0205] 1. If the purpose of processing personal information falls under the conditions that do not require the creation of a consent form, a basis for consent is created.

[0206] 2. In the case of creating a consent form, the purpose of processing personal information in the consent form is proposed in the personal information collection purpose analysis module by referring to the value of the personal information collection form creation module.

[0207] 3. Create a consent form using the above information and the template selected by the personal information processor.

[0208] The automated processing guide, collection and use consent form generation module (231) automatically generates consent forms and processing guides related to personal information, sensitive information, and unique identification information. Consent forms and guides are categorized into the following formats.

[0209] 1) In the case of a consent form for collection and use of personal information, it is created when collecting general personal information (name, phone number, email, etc.) and includes the items collected, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0210] 2) In the case of consent to collection and use of sensitive information, it is used when collecting sensitive personal information such as health information and financial information, and includes notifications and requests for additional consent in accordance with relevant laws.

[0211] 3) In the case of a consent form for the collection and use of unique identification information, it is created when collecting unique identification numbers such as alien registration number, passport number, and driver's license number, and includes a request for notification and additional consent items in accordance with relevant laws.

[0212] 4) In the case of the Resident Registration Number Processing Guide, it is a guide provided when processing a unique identification number such as the Resident Registration Number, and the purpose of processing and legal basis are clearly stated.

[0213] 5) In the case of an optional consent form, it is created when personal information is collected selectively rather than for essential purposes such as advertising, and includes the collected items, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0214] The automated module for creating a processing guide, collection and use consent form (231) provides an intuitive interface so that the data subject can understand the consent form and easily choose whether to consent, and each item of the consent form is updated in accordance with relevant laws and regulations.

[0215] The automated consent form template reflection module (232) predefines various types of consent forms and processing guide templates and automatically reflects the appropriate template based on the user's selected personal information collection purpose and legal requirements. The main functions of this module are as follows:

[0216] First, consent form template management.

[0217] Different templates are provided depending on the type of personal information collected, and customized consent forms are created based on the service purpose. For example, different templates can be applied depending on the personal information required for online service registration and offline transactions.

[0218] Second, there are template reflection rules.

[0219] It operates based on rules that automatically select the appropriate template when a specific type of information is entered, as well as the preferences of the personal information handler. For example, when collecting health information, a sensitive information template is applied, while when collecting simple contact information, a personal information template is applied.

[0220] Third, it is an automatic reflection of legal regulations.

[0221] Consent form templates reflect country-specific and industry-specific legal regulations according to predefined rules. For example, consent forms are tailored to the application of the GDPR (European General Data Protection Regulation) and the CCPA (California Consumer Privacy Act).

[0222] The consent form type template reflection automation module (232) is continuously updated, and when new laws or regulations are announced, the corresponding contents can be immediately reflected in the template.

[0223] The personal information collection purpose analysis module (233) utilizes Vision AI, NLP AI, and other artificial intelligence technologies to analyze user-entered information and automatically classify and process the personal information collection purpose accordingly. Its main functions are as follows:

[0224] First, it is Vision AI-based image analysis.

[0225] If the personal information collection form includes an image, the subject matter within the text or image is extracted and analyzed to suggest an appropriate purpose. For example, if the subject matter of an event is extracted from an event poster image, a corresponding purpose is recommended.

[0226] Second, it is NLP AI-based text analysis.

[0227] We analyze text data entered by users to determine the purpose of collection. For example, we analyze information entered by users to create an online registration page and suggest that the purpose is to sign up for a service.

[0228] Third, it is recommended to provide consent forms for each purpose.

[0229] Based on the collected information, we analyze which legal requirements the information must meet and recommend a suitable purpose. For example, if a resident registration number is collected on a prize winner's personal information collection form, we recommend tax reporting purposes.

[0230] The personal information collection purpose analysis module (233) accurately analyzes the purpose of processing collected personal information and helps to notify and obtain consent from the data subject by applying an appropriate processing method in accordance with the Personal Information Protection Act.

[0231] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0232] Referring to Figure 12 (1210), the personal information processing policy automatic generation module (240) is described.

[0233] The personal information processing policy automatic generation module (240) corresponds to the B4 module (240).

[0234] The personal information processing policy automatic generation module (240) includes a service analysis module (241), a processing policy component generation module (242), and a processing policy template reflection automation module (243).

[0235] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It automates all processes, from service analysis to policy template implementation. This module meets legal requirements related to personal information processing and automatically generates policies tailored to the company's service characteristics and security requirements.

[0236] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It uses the service analysis module to identify service characteristics, automatically generates processing policy components, and incorporates these into a template to finalize the final processing policy. This system satisfies legal requirements arising during personal information processing and provides customized processing policies tailored to the characteristics of each service provider, effectively ensuring compliance with legal regulations related to personal information protection.

[0237] The personal information processing policy automatic generation module (240) consists of three modules, and each module efficiently performs the composition of the processing policy and automated management procedures.

[0238] Describes the flow of operations linked with other modules.

[0239] First, the status of the service is provided to the user and the requirements for processing policies related to the status, such as the relevant industry, are analyzed.

[0240] Second, the user is provided with the status of personal information processing and the requirements for processing policies related to that status are analyzed.

[0241] Third, a personal information processing policy is established based on the information provided.

[0242] Fourth, the personal information processing policy is printed by applying the template selected by the user.

[0243] The service analysis module (241) analyzes the service's size, industry, and security requirements to develop a personal information processing policy tailored to the characteristics of the company or service provider. Its main functions are as follows:

[0244] First, industry analysis.

[0245] By analyzing the industry to which the service belongs, the system automatically reflects the industry's regulatory and legal requirements. For example, financial services and healthcare services have different legal requirements, so processing policies tailored to each industry are automatically identified and generated.

[0246] Second, analysis of service scale.

[0247] The complexity and requirements of a privacy policy vary depending on the size of the business. This module analyzes the size of the service provider—large corporations, small and medium-sized enterprises, and startups—and selects an appropriate privacy policy. Large-scale services can apply complex data processing policies, while smaller services can adopt simplified policies.

[0248] Third, there is the analysis of other variables (ETC).

[0249] We analyze various factors, including the service provider's business model, customer base, and whether or not international data transfers are involved. For example, if you provide a global service, legal requirements for cross-border data transfers are reflected in your processing policy.

[0250] The processing policy component generation module (242) automatically generates key components of the processing policy based on data provided by the service analysis module. This module designs each item of the processing policy in detail and can be tailored to the company's operational policies. Its main functions are as follows:

[0251] First, it is the collection, use, and provision of personal information.

[0252] It defines the purpose of collecting personal information, the types of information collected, and whether or not consent is required from the data subject. This includes the scope of use of the personal information collected by the company and how it is provided to third parties, and is designed to ensure clear disclosure to the data subject.

[0253] Second, whether or not pseudonymized information is processed.

[0254] For companies using pseudonymized information, the scope of use and processing methods for pseudonymized personal information are automatically defined. This provision is tailored to the type of data requiring pseudonymization and its intended use, and legal justification is provided where necessary.

[0255] Third, there is the information retention and destruction policy.

[0256] Define how long collected personal information will be retained and how it will be destroyed when no longer needed. This section automatically generates information retention periods and destruction procedures, and includes data retention and destruction policies tailored to specific legal regulations (e.g., GDPR or CCPA).

[0257] Fourth, entrustment of personal information and provision to third parties.

[0258] When personal information is outsourced or provided to a third party, all necessary legal procedures and consent forms are managed. Clearly define the legal requirements for entrusting personal information, the method of data sharing with third parties, and notify the data subject and obtain their consent.

[0259] Fifth, overseas relocation and security personnel.

[0260] When personal information is transferred internationally, it reflects the security and legal requirements that arise during the process. Furthermore, it is designed to strengthen data protection by specifying the deployment of security personnel within the company and their roles.

[0261] The Processing Policy Template Reflection Automation Module (243) reflects the generated personal information processing policy components into templates and automates their implementation. This module automatically maps each component to a predefined template to complete the processing policy. Its main functions are as follows:

[0262] First, there is the management of processing policy templates.

[0263] We provide predefined templates for each item in our privacy policy, and we customize and optimize these templates to meet the needs of each service provider. For example, financial institutions may provide templates that incorporate more stringent security requirements, while smaller services may offer simpler policies.

[0264] Second, there is automatic template mapping.

[0265] Data generated by the service analysis module and processing policy component generation module is automatically mapped to templates. This process is performed without manual intervention, and processing policies tailored to the characteristics of each service are automatically generated.

[0266] Third, it reflects legal requirements.

[0267] Automated rules are set up within templates to ensure legal requirements are reflected. For example, if regulations such as GDPR or CCPA are included, applicable items are automatically added and information specifying the rights and responsibilities of data subjects is included.

[0268] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0269] Referring to FIG. 13 (1310), the personal information subject token and consent history hash generation module (250) is described.

[0270] The personal information subject token and consent history hash generation module (250) corresponds to the B5 module (250).

[0271] The personal information subject token and consent history hash generation module (250) includes a third-party DID module (251), a personal information subject token generation module (252), and a consent history hash generation module (253).

[0272] The Personal Information Subject Token and Consent History Hash Generation Module (250) is responsible for generating and managing the data subject's token and the consent history hash value in the personal information protection system. This module handles data subject authentication in various ways, securely stores data generated during the consent process, and maintains record integrity through hash values. Furthermore, it collaborates with third parties (DIDs) to provide various authentication methods and ensure information reliability.

[0273] The Personal Information Subject Token and Consent History Hash Generation Module (250) automates all procedures required for data subject token generation and consent history management. This module securely authenticates the data subject's identity, converts consent history into a hash value to ensure integrity, and thoroughly manages submitted personal information. This module effectively meets legal requirements related to personal information protection.

[0274] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0275] Referring to FIG. 14 (1410), the compliance and security risk analysis unit (300) is described.

[0276] The compliance and security risk analysis unit (300) includes a personal information risk scoring module (310).

[0277] The personal information risk scoring module (310) includes a personal information flow risk identification scoring module (311), a third-party (trustee) cooperation scoring module (312), a personal information destruction scoring module (313), a personal information consistency scoring module (314), a consent history management scoring module (315), a registration and processing policy maintenance scoring module (316), and an overall integrated scoring module (317).

[0278] The Compliance and Security Risk Analysis Department (300) automatically evaluates the risk of personal information within the system to meet personal information protection and compliance requirements, and performs a comprehensive risk assessment through various scoring methods.

[0279] The Compliance and Security Risk Analysis Department (300) evaluates security risks that may arise at all stages of personal information collection, processing, storage, and destruction, and supports the implementation of appropriate protective measures.

[0280] The Compliance and Security Risk Analysis Department (300) analyzes the risk of personal information through various scoring methods, and each scoring is performed based on the following criteria.

[0281] Describes the flow of operations linked with other modules.

[0282] First, each scoring function operates independently.

[0283] Second, the risk is analyzed based on the scoring results.

[0284] The Personal Information Flow Risk Identification Scoring Module (311) assesses potential risks that may arise during the process of personal information being collected and then transferred within the system. Its main functions include:

[0285] First, data movement path analysis.

[0286] Track and analyze where personal information moves within the system and how it is processed. Identify potential data leaks and unauthorized access that may occur during the information transfer process, and assess the risk.

[0287] Second, access rights analysis.

[0288] Analyze the level of user access to personal information to assess whether appropriate permissions have been granted. If permissions are unnecessarily broad or illegal access attempts are detected, the risk is assessed as high.

[0289] Third, data encryption status analysis.

[0290] Ensure that appropriate encryption is applied during data transfer. If encryption is not applied or the encryption level is low, the risk score increases.

[0291] The Third-Party (Trustee) Collaboration Scoring Module (312) assesses the risks associated with sharing personal information with external trustees or third parties. It analyzes potential security risks when personal information is processed by trustees. Its main functions include:

[0292] First, it is an evaluation of the trustee's security level.

[0293] Assess the security policies and management status of the trustee handling personal information. If the trustee is not implementing appropriate security measures or has not obtained security certification, the risk is assessed as high.

[0294] Second, data transmission security evaluation.

[0295] Analyze the security protocols used when personal information is transmitted to third parties. For example, assess whether data is transmitted encrypted and whether security certificates are valid to determine the level of risk.

[0296] Third, third-party access control analysis.

[0297] Analyze the permissions and access control methods of third parties who have access to personal information. Risk increases if unnecessary access is granted or management is poor.

[0298] The Personal Information Destruction Scoring Module (313) evaluates the process of appropriately destroying collected personal information when it is no longer needed or the legal retention period has expired. Its main functions include:

[0299] First, it is an evaluation of compliance with the destruction policy.

[0300] Evaluate whether your personal information destruction policy complies with relevant laws and regulations. For example, ensure that personal information is destroyed promptly according to legal requirements such as the GDPR and CCPA.

[0301] Second, the destruction method is evaluated.

[0302] Assess whether personal information has been completely deleted or recovered appropriately. If secure data deletion methods (e.g., digital shredding, overwriting, etc.) were not applied, the risk is assessed as high.

[0303] Third, the transparency of the destruction procedure is assessed.

[0304] Assess whether the destruction process is transparently managed and recorded. If the destruction process is unclear or records are incomplete, the risk increases.

[0305] The Personal Information Integrity Scoring Module (314) evaluates whether collected personal information is used for its intended purpose and whether the collected information is accurate. Its main functions are as follows:

[0306] First, it is an evaluation of whether it matches the purpose of collection.

[0307] We analyze whether personal information is being used for the originally agreed-upon purposes. If personal information is used for purposes other than those agreed upon, the risk is assessed as high.

[0308] Second, it is an assessment of the accuracy of personal information.

[0309] Assess the accuracy of collected personal information and whether any inaccurate information has been entered. Risks increase when inaccurate information is processed or errors occur.

[0310] Third, it is an evaluation of the protection of the rights of the information subject.

[0311] Assess whether the data subject can appropriately exercise their right to correct, delete, or suspend the use of their personal information. If the data subject's request is ignored or not processed, the risk is assessed as high.

[0312] The Consent History Management Scoring Module (315) evaluates whether appropriate consent was obtained from the data subject when personal information was collected and whether that consent was legally managed. Its main functions are as follows:

[0313] First, it is an evaluation of compliance with the consent procedure.

[0314] Assess whether clear consent has been obtained from the data subject for the collection and use of personal information. If personal information is collected or used without proper consent, the risk is assessed as high.

[0315] Second, it is an evaluation of the management status of consent records.

[0316] Assess whether consent records are securely stored and whether withdrawals are promptly reflected upon the data subject's request. Risks increase if consent records are damaged or withdrawal requests are not reflected.

[0317] The Registration and Processing Policy Maintenance Scoring Module (316) evaluates whether personal information processing policies are properly registered and maintained. Its main functions are as follows:

[0318] First, it is an evaluation of the latest processing policy.

[0319] Evaluate whether your privacy policy is continuously updated to reflect the latest legal requirements. If your privacy policy is not updated despite legal changes, the risk is assessed as high.

[0320] Second, it is an evaluation of the transparency of the processing policy.

[0321] Evaluate whether the processing policy is easily accessible to the data subject and whether it is clear and understandable. If the processing policy is unclear or difficult for the data subject to access, the risk increases.

[0322] The overall integrated scoring module (317) synthesizes the risks generated from each individual scoring module to calculate the overall integrated risk of the personal information processing process. The overall integrated scoring includes the following elements:

[0323] First, weighting is applied.

[0324] The overall risk is calculated by applying weights based on the importance of each scoring module. For example, if the personal information destruction scoring is weighted heavily, a flaw in the destruction process will significantly impact the overall risk.

[0325] Second, it is the calculation of comprehensive risk.

[0326] Based on the individual scoring results, a final overall risk assessment is calculated. The overall risk assessment indicates the overall security level of personal information processing and can be used to suggest additional security measures or management strategies.

[0327] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0328] Referring to Figure 15 (1510), the service-specific personal information analysis unit (400) is described.

[0329] The service-specific personal information analysis unit (400) includes a service-specific personal information analysis module (410).

[0330] The service-specific personal information analysis unit (400) is a system that analyzes personal information collected during service provision by pseudonymizing and anonymizing it, and based on this, classifies the answers provided by users into keywords and determines the meaning of positive or negative.

[0331] The service-specific personal information analysis unit (400) performs pseudonymization and anonymization processing for personal information protection, and analyzes personal information in various stages to support functions necessary for service provision. The service-specific personal information analysis unit (400) of the present invention primarily consists of the following processing steps.

[0332] Step 1 is the pseudonymization step.

[0333] Pseudonymization is the process of protecting personally identifiable information by pseudonymizing it. Pseudonymization is a key method for strengthening privacy protection while using personal information for data analysis and service optimization. Its key functions include:

[0334] First, the personal information identification elements are separated.

[0335] Personal information provided by users, such as name, resident registration number, and email address, is replaced with the minimum information necessary for data analysis. This ensures that data is processed in a way that does not identify specific individuals.

[0336] Second, the application of a pseudonymization algorithm.

[0337] Pseudonymization involves replacing personal information using algorithms such as randomization or hash functions. For example, a user's name is pseudonymized by replacing it with a randomly generated ID. This ID can identify the same individual, but cannot be directly traced back to the original data.

[0338] Third, pseudonymized data management for data analysis.

[0339] Pseudonymized personal information is managed for analysis purposes and stored separately from the original data. After analysis, the original data can be set to not be restored.

[0340] The second step is the anonymization step.

[0341] Anonymization is the process of removing all personally identifiable information from personal data, rendering it completely anonymous. Anonymization completely obscures an individual's identity and is primarily used in statistical analysis and large-scale data analysis. Its main functions are as follows:

[0342] First, the complete removal of personal identification factors.

[0343] All identifiable information, such as name, resident registration number, and address, is deleted or replaced from personal information so that specific individuals cannot be traced during data analysis.

[0344] Second, it is to strengthen statistical safety.

[0345] Anonymized data is used as aggregated data, not individual information. For example, only non-identifiable information, such as a user's age or gender, is retained for statistical analysis.

[0346] Third, there are measures to prevent re-identification.

[0347] Anonymized data is subject to additional security measures to prevent re-identification. Various security technologies are employed to prevent data recombining to restore the original data.

[0348] Step 3 is the question and multiple answer merge processing step.

[0349] The question and multiple answer merge process analyzes and merges multiple user-provided answers to derive a consistent answer. This process integrates multiple answers to generate final data, and based on that data, it provides results appropriate for the service. Key features include:

[0350] First, there is question analysis.

[0351] The content of user-entered questions and the resulting responses are analyzed. Natural language processing (NLP) technology is used to understand the meaning of the question and extract and process relevant responses.

[0352] Second, multiple answers are merged.

[0353] When multiple answers are provided for the same question, duplicate or ambiguous answers are merged to produce a consistent answer. This improves the quality of the response data and provides consistent results.

[0354] Third, response optimization.

[0355] We refine data by optimizing merged responses to provide optimal answers when providing services.

[0356] Step 4 is the response content analysis step.

[0357] The response content analysis step analyzes user-provided response data and determines the keywords and meaning of the response, whether positive or negative. This step utilizes natural language processing (NLP) technology to analyze the response, extract key keywords, and determine the sentiment of the response through sentiment analysis. Key features include:

[0358] First, keyword extraction.

[0359] This step extracts important keywords from user-provided responses. Frequently occurring or contextually significant words in the text data are identified and categorized as keywords. For example, keywords like "satisfied," "dissatisfied," "fast," and "slow" are extracted.

[0360] Second, there are positive and negative judgments.

[0361] Based on extracted keywords, responses are automatically classified as positive or negative. A sentiment analysis algorithm is used to determine whether keywords carry positive or negative connotations. For example, the keyword "satisfied" is classified as positive, while "dissatisfied" is classified as negative.

[0362] Third, keyword weighting.

[0363] Extracted keywords are weighted to determine their importance in providing services. Different weights are assigned based on importance, increasing the accuracy of analysis results.

[0364] Explains the keywords in the response content and the method of judging whether it is positive or negative.

[0365] First, NLP-based text preprocessing is performed.

[0366] The response data is input into a natural language processing model, where unnecessary words are removed and the data is converted into an analyzable form. This includes preprocessing tasks such as tokenization, stopword removal, and stemming.

[0367] Second, extract keywords.

[0368] Extract important keywords based on preprocessed data. Using techniques like TF-IDF and Word2Vec, we identify high-frequency, context-sensitive words.

[0369] Third, perform sentiment analysis.

[0370] Based on the extracted keywords, the sentiment of the responses is analyzed and classified as positive, negative, or neutral. The sentiment analysis algorithm uses a pre-trained dictionary of positive and negative words to evaluate the sentiment of each keyword.

[0371] Fourth, derive results.

[0372] Finally, the extracted keywords and sentiment analysis results are combined to derive the meaning of the answer and generate the information necessary for providing the service.

[0373] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0374] Referring to Figure 16 (1610), the personal information destruction unit (500) will be described.

[0375] The personal information destruction unit (500) includes a personal information destruction automation and hash generation module (510).

[0376] The personal information destruction automation and hash generation module (510) includes a destruction history hash generation module (511).

[0377] The personal information destruction unit (500) is a system that safely destroys personal information when the collection and storage period of the information ends, and creates a destruction history generated in the process as a hash value to ensure integrity.

[0378] The Personal Information Destruction Department (500) automates the personal information destruction process, ensuring compliance with legal requirements and transparently managing the data destruction process. The Personal Information Destruction Department (500) destroys personal information through the following key steps.

[0379] Step 1: Create a personal information destruction scheduler.

[0380] The Personal Information Destruction Scheduler creation step automatically creates and executes a destruction schedule when personal information no longer needs to be retained. This applies when the personal information retention period has expired or when immediate destruction is required at the data subject's request. Key features include:

[0381] First, review the holding period.

[0382] We review the retention period for each personal information item and determine whether the retention period established by legal or service requirements has been exceeded. Personal information is reviewed based on the preset retention period, and any data exceeding the retention period is designated for destruction.

[0383] Second, the destruction schedule is automatically set.

[0384] When personal information is designated for destruction, a destruction scheduler is automatically created and a destruction schedule is set. The destruction schedule can be adjusted to optimize time, taking into account legal requirements and system resources.

[0385] Third, immediate processing of the request for destruction.

[0386] If the data subject requests immediate destruction of personal information, the scheduler immediately sets a destruction schedule and quickly executes the data destruction process.

[0387] Step 2 is the personal information destruction step.

[0388] The personal information destruction stage is the process of actually destroying personal information according to a schedule set by the scheduler. This stage securely destroys data through physical or logical means, and the destroyed information is processed so that it cannot be recovered. Key features include:

[0389] First, it is a logical breakdown.

[0390] Destruction involves deleting personal information stored within the system. This removes the personal information from files or databases, rendering it inaccessible or retrievable. Logical destruction is performed by removing all indexes and references to the data within the system.

[0391] Second, there is physical destruction.

[0392] Completely destroy data by shredding or deleting disks or other storage media containing personal information stored on physical storage devices. This method physically destroys the disk or media, rendering the data unrecoverable.

[0393] Third, data overwriting.

[0394] To ensure that logically deleted data cannot be recovered, the space where the data was stored is repeatedly overwritten with random data to ensure its destruction. This process is a secure method for completely erasing digital data, preventing any possibility of recovery.

[0395] Step 3 is the destruction history hash generation step.

[0396] The destruction history hash generation step records the history of personal information destruction and generates a hash value to ensure integrity. This step records information about the destroyed personal information and the destruction process, and generates a hash value to prevent tampering with this information. Its main functions are as follows:

[0397] First, it is the collection of destruction history data.

[0398] After personal information is destroyed, all data generated during the destruction process is collected. This includes information such as the personal information subject token, authentication method, authentication date, collection form ID, consent ID, and processing policy ID. This data is crucial for ensuring the reliability of the destruction history.

[0399] Second, hash value generation.

[0400] A unique hash value is generated by applying a hash algorithm (such as SHA256) based on the collected destruction history data. This hash value ensures the integrity of the destruction history and protects the data from tampering during the subsequent verification process.

[0401] Third, storage and management of destruction history.

[0402] The generated hash values ​​are securely stored along with the history of destroyed personal information and are managed so that their integrity can be verified by certification authorities or audit processes. The logs and hash values ​​of destroyed data are protected from external access and can be referenced for data verification when necessary.

[0403] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0404] Referring to FIG. 17 (1710), the authentication management unit (600) is described.

[0405] The authentication management unit (600) includes a personal information protection authentication management module (610).

[0406] The certification management department (600) is a system that manages and maintains certifications related to personal information protection, and performs the role of obtaining and maintaining various international and domestic standard certifications based on compliance logs generated within the company.

[0407] The authentication management unit (600) safely processes data generated during the authentication acquisition process and is comprised of steps to verify compliance with authentication standards. The authentication management unit (600) of the present invention primarily manages authentication through the following steps.

[0408] Step 1 is to create an in-house compliance log.

[0409] The internal compliance log generation step involves recording all activities occurring within the system to ensure compliance with privacy and related legal regulations. These logs contain data related to personal information processing, access control, and security incident response, primarily collecting and storing the following information:

[0410] First, there is a record of personal information processing activities.

[0411] All activities, including the collection, storage, processing, and destruction of personal information, are recorded in internal compliance logs. Each record includes the time of the activity, the person responsible, and related information.

[0412] Second, there is an access control log.

[0413] Prevent illegal access or abuse of authority by recording the users who accessed personal information, their authority level, and the time of access.

[0414] Third, there is a record of security incident response.

[0415] If a security incident involving personal information occurs, we record the response to the incident. For example, this includes incident response records for hacking attempts or internal information leaks.

[0416] The logs collected at this stage will be used as data required for subsequent certification applications, and all personal information processing activities occurring within the company will be transparently recorded.

[0417] Step 2 is to create an in-house compliance log hash.

[0418] The in-house compliance log hash generation step generates a hash value to ensure the integrity of the collected compliance log data. The hash value plays a crucial role in protecting the data and verifying whether the log has been tampered with during subsequent authentication procedures. Its main functions are as follows:

[0419] First, the hash algorithm is applied.

[0420] A cryptographic hash algorithm, such as SHA256, is applied to the collected log data to generate a unique hash value. This proves that the log data has not been tampered with.

[0421] Second, log integrity is guaranteed.

[0422] The generated hash value ensures the integrity of the compliance log and provides credibility when the log is subsequently reviewed by a certification authority. This hash value can be provided to external certification authorities to help verify the log's authenticity.

[0423] Third, hash value storage.

[0424] The generated hash value is stored in a secure database and can be referenced during subsequent authentication procedures. The stored hash value serves as a crucial element in verifying that log data has not been tampered with.

[0425] Step 3 is the certification application and management stage.

[0426] The certification application and management stage involves applying for and maintaining international and domestic personal information protection-related certifications based on internally generated compliance logs and hash values. Key certifications are managed in accordance with ISO standards and domestic and international regulations. The process for obtaining these certifications is as follows.

[0427] First, ISO 27701.

[0428] ISO 27701, a Personal Information Management System (PIMS) certification, is an international standard for personal information protection. The certification management department reviews compliance with the ISO 27701 certification criteria and prepares the necessary documents and log data to apply for certification. ISO 27701 certification evaluates compliance with the standard for personal information protection policies, risk management, and personal information processing activities.

[0429] Second, ISO 27001.

[0430] ISO 27001, an Information Security Management System (ISMS) certification, is an international standard for information security. This standard assesses whether an organization has established the management systems necessary to maintain the confidentiality, integrity, and availability of information. The certification management department manages internal information security policies and procedures in accordance with ISO 27001 standards and generates essential log data to maintain certification.

[0431] Third, ISMS-P.

[0432] As a domestic personal information protection and information security management certification, ISMS-P assesses compliance with domestic legal requirements. This certification requires a management system that satisfies both information protection and personal information protection, and the certification management department collects and manages data to maintain ISMS-P certification.

[0433] Fourth, other certifications.

[0434] Other certifications related to privacy and information security (e.g., country-specific privacy certifications, industry-specific regulatory certifications, etc.) are also managed by the Certification Management Department. The department manages internal data in accordance with the requirements of each certification, prepares the necessary documents and materials, and applies for certification.

[0435] At this stage, the certification management department (600) manages all matters necessary for maintaining certification, starting from the application process, and continuously performs certification maintenance and renewal procedures in cooperation with the certification agency.

[0436] For example, FIG. 18 shows the status of a consignee according to the present disclosure (1810), FIG. 19 shows the status of personal information processing (1910), and FIG. 20 shows the status of a subcontractor (2010).

[0437] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0438] Referring to Figure 21 (2110), the inspection items of the inspection checklist are described.

[0439] Inspection items are categorized by order, area, category, inspection item, inspection item details, related evidence, and evaluation criteria.

[0440] The area includes administrative safeguards.

[0441] The division includes an internal management plan.

[0442] Inspection items include establishment and implementation of internal management plans.

[0443] Relevant evidence includes the full text of the internal management plan.

[0444] The evaluation criteria are as follows:

[0445] Y - Contains all essential elements of the internal management plan.

[0446] P - Some items in the internal management plan are missing.

[0447] N - Internal management plan not collected.

[0448] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners and individual organizations.

[0449] The details of the inspection items, related evidence, and evaluation criteria are as follows.

[0450] First, the details of the first inspection item, related evidence, and evaluation criteria.

[0451] Question) Are you including all of the following in your personal information protection documents (internal management plan and related regulations)?

[0452] 1. Matters concerning the composition and operation of the personal information protection organization.

[0453] 2. Matters concerning the qualifications and designation of the personal information protection manager

[0454] 3. Matters concerning the roles and responsibilities of the personal information protection officer and personal information handler.

[0455] 4. Matters concerning management, supervision, and education of personal information handlers

[0456] 5. Matters concerning management of access rights

[0457] 6. Matters concerning access control

[0458] 7. Matters concerning encryption of personal information

[0459] 8. Matters concerning storage and inspection of connection records

[0460] 9. Matters concerning the prevention of malicious programs, etc.

[0461] 10. Matters concerning vulnerability inspection to prevent personal information leakage or theft.

[0462] 11. Matters concerning physical safety measures

[0463] 12. Matters concerning the establishment and implementation of a plan to respond to personal information leaks.

[0464] 13. Matters concerning risk analysis and management

[0465] 14. Matters concerning the management and supervision of the trustee when entrusting personal information processing work.

[0466] 15. Matters concerning the establishment, amendment, and approval of the internal personal information management plan.

[0467] 16. Other matters necessary for personal information protection"

[0468] The relevant evidence is as follows.

[0469] 1. Full text of the Personal Information Protection Policy Document (Internal Management Plan and Personal Information Protection-Related Regulations)

[0470] The evaluation criteria are as follows:

[0471] Y - Contains all required elements within the policy document

[0472] P - Some details are missing from the policy document.

[0473] N - No policy document established

[0474] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners, individuals, and organizations.

[0475] Second, the details of the second inspection item, related evidence, and evaluation criteria.

[0476] Question) Are you obtaining approval from the CEO (or Chief Personal Information Officer) for the personal information protection policy document (internal management plan and personal information protection-related regulations) in accordance with internal personnel procedures?

[0477] - Specify approval records in groupware (deliberation) or internal management plan

[0478] Question) Is the personal information protection policy document (internal management plan and personal information protection-related regulations) published internally?

[0479] - Announcement through posting of internal management plan on groupware bulletin board

[0480] - Produce booklets, etc. and place them in accessible locations.

[0481] The relevant evidence is as follows.

[0482] 1. Approval record

[0483] 2. Publication evidence

[0484] The evaluation criteria are as follows:

[0485] Y - Approved and properly publicized

[0486] P - Approved but not published

[0487] N - Not Approved

[0488] Third, here are the details of the third inspection item.

[0489] Question) Are the personal information protection policy documents (internal management plan and personal information protection-related regulations) reviewed regularly (at least once a year)?

[0490] - Annual review history of personal information protection policy documents (internal management plan and personal information protection-related regulations)

[0491] - Details of approval and announcement of revisions

[0492] The relevant evidence is as follows.

[0493] 1. History of revisions to the Personal Information Protection Policy document (internal management plan and personal information protection-related regulations).

[0494] The evaluation criteria are as follows:

[0495] Y - Records the revision history of the privacy policy document.

[0496] N - Do not keep track of revisions to the Privacy Policy document.

[0497] Fourth, the details of the 4th inspection item.

[0498] Question) Are you inspecting and managing the implementation status of the personal information protection policy document (internal management plan and personal information protection-related regulations) at least once a year and implementing improvement measures for any deficiencies?

[0499] - The personal information protection officer shall conduct an inspection of the implementation status of the personal information protection policy document at least once a year.

[0500] - Review and approval of the inspection results by the personal information protection officer

[0501] - Required checklist when checking the status of implementation

[0502] 1. Access Rights Management

[0503] 2. Storage and inspection of connection records

[0504] 3. Encryption measures

[0505] The relevant evidence is as follows.

[0506] 1. Plan for Inspection of the Implementation Status of Personal Information Protection Policy

[0507] 2. Report on the Implementation Status of Personal Information Protection Policy

[0508] The evaluation criteria are as follows:

[0509] Y - We inspect the implementation of our privacy policy at least once a year.

[0510] P - We are checking the implementation status of the personal information protection policy, but there are some missing items among the required inspection items.

[0511] N - No verification of compliance with privacy policy

[0512] Fifth, the details of the fifth inspection item.

[0513] Question) Have you officially designated a Personal Information Protection Officer with appropriate qualifications?

[0514] - Specify the person responsible for personal information protection in the personal information protection policy, organizational chart, and personal information processing policy.

[0515] 1. Business owner or representative

[0516] 2. Executive (if there is no executive, the head of the department in charge of personal information processing)

[0517] ※ In the case of small business owners, the business owner or representative is deemed to have been designated as the personal information protection officer without separate designation.

[0518] The relevant evidence is as follows.

[0519] Official documents that confirm the appointment of a personal information protection officer, such as a personal information protection policy, organizational chart, personal information processing policy, and personnel appointments.

[0520] The evaluation criteria are as follows:

[0521] Y - Designate a personal information protection officer and meet the requirements for designating a personal information protection officer.

[0522] P - A personal information protection officer has been designated, but the requirements for designating a personal information protection officer are not met or the person has not been designated in an official document.

[0523] N - No data protection officer has been designated

[0524] Sixth, the details of the 6th inspection item.

[0525] Question) Are you collecting personal information handlers' security pledges for personal information protection?

[0526] ① Confirmation of whether a security pledge is required upon joining or leaving the company.

[0527] ② Regularly (once a year) check whether all personal information handlers are required to re-sign the security pledge.

[0528] ※ Security pledge composition

[0529] - The following content is designed to remind users of their responsibilities to prevent personal information from being leaked.

[0530] 1. Obligations of personal information handlers to protect personal information

[0531] 2. Disciplinary action in case of violation

[0532] 3. Examples of pledges: The following are relevant evidence, such as personal information security pledges and confidentiality pledges.

[0533] 1. Employee Security Pledge

[0534] 2. Security pledge for former employees

[0535] The evaluation criteria are as follows:

[0536] Y - We are regularly collecting security pledges without fail (at least once a year).

[0537] P - We are collecting security pledges, but there are missing people.

[0538] N - Not requesting a security pledge

[0539] Seventh, the details of the 7th inspection item.

[0540] Question) Do you provide personal information protection training to personal information protection officers and personal information handlers at least once a year?

[0541] - Develop a personal information protection education plan

[0542] ① Prepare an annual personal information protection education plan including the following:

[0543] 1. Educational Purpose and Target

[0544] 2. Training Content

[0545] 3. Training schedule and method

[0546] - Evidence of implementation of personal information protection job-specific training

[0547] ① Confirmation of implementation of personal information protection training for personal information handlers

[0548] ② Confirmation of training implementation evidence at least once a year

[0549] ③ Confirmation of management and supervision of those who have not completed training

[0550] ※ Personal information handler: A person who processes personal information under the direction and supervision of a personal information processor, such as an employee, dispatched worker, or part-time worker.

[0551] The relevant evidence is as follows.

[0552] 1. Personal Information Protection Education Plan

[0553] 2. Personal Information Protection Training Results

[0554] 3. Personal information protection training materials

[0555] 4. Personal information protection training completion certificate

[0556] 5. List of Personal Information Protection Training Attendees

[0557] 6. Other evidence that can confirm personal information protection education

[0558] The evaluation criteria are as follows:

[0559] Y - We have established a personal information protection education plan, provide regular education at least once a year, and supervise and manage those who have not completed the education.

[0560] P - Personal information protection training is conducted at least once a year, but no supervision is provided for those who have not completed the training.

[0561] N - Personal information protection training is not conducted at least once a year.

[0562] Eighth, the details of the 8th inspection item.

[0563] Question) Have you established response procedures and methods in case of loss, theft, or leakage of personal information?

[0564] - A personal information leak response plan must be established and implemented, including matters such as leak reporting and notification, damage report reception, and damage relief.

[0565] - Accidents must be reported to the consignor immediately.

[0566] The relevant evidence is as follows.

[0567] 1. Personal Information Leak Response Plan

[0568] The evaluation criteria are as follows:

[0569] Y - Establishing and implementing a personal information leak response plan.

[0570] N - No personal information leak response plan in place

[0571] Ninth, the details of the 9th inspection item.

[0572] Question) In principle, re-entrustment by the trustee without prior consultation is prohibited, but in cases where re-entrustment is unavoidable, is re-entrustment done according to standards?

[0573] - Re-entrustment must be done with the consent of the consignor.

[0574] - A subcontracting agreement must be prepared based on the consignor's consignment agreement.

[0575] - Personal information cannot be used or provided beyond the scope of work entrusted by the consignor.

[0576] The relevant evidence is as follows.

[0577] 1. Evidence of prior approval

[0578] 2. Contract regarding re-consignment

[0579] The evaluation criteria are as follows:

[0580] Y - Personal information is being re-entrusted according to the relevant standards.

[0581] N - Personal information is being re-entrusted without the entrustor's approval.

[0582] Tenth, here are the details of the 10th inspection item.

[0583] Question) When re-entrusting personal information, are you conducting periodic inspections and training?

[0584] The relevant evidence is as follows.

[0585] 1. Regular inspection and training plan for re-trustees

[0586] 2. Results of regular inspection and training of re-trustees

[0587] The evaluation criteria are as follows:

[0588] Y - We manage and supervise trustees through education and inspection.

[0589] N - Not managing and supervising the trustees through education and inspection.

[0590] N / A - Personal information is not re-entrusted

[0591] Eleventh, details of the 11th inspection item.

[0592] Question) Have you established a personal information processing policy that includes all of the required items below and made it publicly available in a way that is easily understandable to the data subject?

[0593] - Personal information processing policy information (Personal information processing policy drafting guidelines, Personal Information Protection Commission, April 2024)

[0594] 1. Title (required)

[0595] 2. Purpose of processing personal information (required)

[0596] 3. Items of personal information processed (required)

[0597] 4. Matters concerning the processing of personal information of children under the age of 14 (recommended when applicable)

[0598] 5. Personal information processing and retention period (required)

[0599] 6. Matters concerning the procedures and methods for destroying personal information (required)

[0600] 7. Matters regarding provision of personal information to third parties (required when applicable)

[0601] 8. Criteria for determining if additional use or provision continues (required when applicable)

[0602] 9. Matters concerning the entrustment of personal information processing (required when applicable)

[0603] 10. Matters concerning the overseas collection and transfer of personal information (required when applicable)

[0604] 11. Matters concerning measures to ensure the security of personal information (required)

[0605] 12. How to choose whether to disclose sensitive information and whether to keep it private (required if applicable)

[0606] 13. Matters concerning the processing of pseudonymized information (required when applicable)

[0607] 14. Matters concerning the installation and operation of automatic personal information collection devices and their refusal (required when applicable)

[0608] 15. Matters concerning the collection, use, and refusal of behavioral information collected by third parties through automatic personal information collection devices (recommended if applicable)

[0609] 16. Matters concerning the rights, obligations, and exercise methods of the data subject and legal representative (required)

[0610] 17. Name of the Personal Information Protection Officer, the department in charge of personal information management, and the department handling complaints (required)

[0611] 18. Matters concerning the designation of a domestic agent (required if applicable)

[0612] 19. Remedies for Infringement of the Rights of Data Subjects (Recommended)

[0613] 20. Matters concerning the operation and management of fixed-type video information processing equipment (required when applicable)

[0614] 21. Matters concerning the operation and management of mobile video information processing devices (required when applicable)

[0615] 22. Matters autonomously established by the personal information processor regarding personal information processing standards and protective measures in the personal information processing policy (recommended)

[0616] 23. Matters regarding changes to the personal information processing policy (required)

[0617] - Disclosure of personal information processing policy

[0618] ① The established or changed personal information processing policy shall be continuously posted on the operating Internet homepage so that the information subject can easily check it.

[0619] ② In cases where it cannot be posted on the Internet homepage, it can be made public through the following methods:

[0620] 1. Place it in a place where it can be easily seen, such as the personal information processor's workplace.

[0621] 2. Publication in publications, newsletters, promotional materials, or bills issued more than twice a year.

[0622] 3. “Specification in the contract with the information subject for the provision of goods or services, etc.”

[0623] The relevant evidence is as follows.

[0624] 1. Personal Information Processing Policy

[0625] 2. Disclosure of Personal Information Processing Policy"

[0626] The evaluation criteria are as follows:

[0627] Y - We have established and continuously disclose a privacy policy that includes all essential information.

[0628] P - Some of the essential provisions of the privacy policy are missing or not consistently posted.

[0629] N - No privacy policy established

[0630] N / A - Personal information will not be re-entrusted"

[0631] The twelfth, the 12th inspection item details.

[0632] Question) Do you have established and are operating access control procedures for physical storage locations where personal information is stored, such as computer rooms and archives?

[0633] - Office access control procedures

[0634] - Installation of additional control devices such as fingerprint recognition devices, card key devices, and number key devices"

[0635] The relevant evidence is as follows.

[0636] 1. Access Control Procedure Document

[0637] 2. Status of application of access control

[0638] 3. Evidence of access control operation (entrance / exit log, etc.)

[0639] The evaluation criteria are as follows:

[0640] Y - Establish and operate access control procedures for physical storage locations.

[0641] N - No access control procedures for physical storage locations are established.

[0642] The thirteenth, the 13th inspection item details.

[0643] Question) Are documents and auxiliary storage media containing personal information stored in a secure location with a lock or other locking device?

[0644] - Safely store documents and auxiliary storage media containing personal information.

[0645] The relevant evidence is as follows.

[0646] 1. Evidence materials such as documents or auxiliary storage media containing personal information are stored in a separate space with a locking device.

[0647] The evaluation criteria are as follows:

[0648] Y - Documents and auxiliary storage media containing personal information are stored in a safe place.

[0649] N - Documents and auxiliary storage media containing personal information are not stored in a secure location.

[0650] Fourteenth, the details of the 14th inspection item.

[0651] Question) Have you established and implemented a policy to control the import and export of auxiliary storage media?

[0652] - Establish procedures for bringing in / taking out auxiliary storage media within internal regulations.

[0653] ① Check if there is a procedure for bringing in / taking out auxiliary storage media.

[0654] ② Check whether there is a permit request and approval procedure for import / export

[0655] ③ Check the auxiliary storage media import / export management ledger when bringing in / out

[0656] The relevant evidence is as follows.

[0657] 1. Policy on controlling the import and export of auxiliary storage media

[0658] 2. Auxiliary storage media import / export management ledger

[0659] The evaluation criteria are as follows:

[0660] Y - Establishing standards for the import and export of auxiliary storage media and implementing control procedures.

[0661] P - The standards for exporting and importing auxiliary storage media are inadequate or there is no control over export and import.

[0662] N - There are no standards for the import and export of auxiliary storage media, and there is no control over import and export.

[0663] Fifteenth, the details of the 15th inspection item.

[0664] Question) Are you granting personal information handlers differential access to the personal information processing system to the minimum extent necessary for performing their duties?

[0665] - Issuance of accounts for each personal information handler

[0666] - No account sharing

[0667] - If account sharing is unavoidable, measures to ensure accountability are required.

[0668] - Restrictions on printing and downloading personal information

[0669] The relevant evidence is as follows.

[0670] 1. List of personal information handlers

[0671] 2. Status of access rights to personal information processing systems

[0672] The evaluation criteria are as follows:

[0673] Y - The personal information handler account is granted minimal permissions.

[0674] P - Personal information handler account permissions are minimal, but some people are granted excessive permissions.

[0675] N - Does not restrict the permissions of the personal information handler account

[0676] Sixteenth, the details of the 16th inspection item.

[0677] Question) When a personnel change, such as a transfer or retirement, occurs, are access rights to the personal information processing system changed or deleted without delay?

[0678] - Changes in personal information processing system authority due to changes in business

[0679] - Delete retiree accounts in the personal information processing system

[0680] The relevant evidence is as follows.

[0681] 1. Retirement and Job Change Procedure

[0682] 2. History of account deletion or access rights changes

[0683] The evaluation criteria are as follows:

[0684] Y - Access rights are immediately revoked in the event of personnel transfers such as retirement.

[0685] N - Access rights are not immediately revoked upon personnel transfer, such as retirement.

[0686] Seventeenth, details of the 17th inspection item.

[0687] Q) Are you keeping a record of the granting, modification, and deletion of access rights to your personal information processing system?

[0688] - Records of changes in personal information processing system access rights are kept for at least 3 years.

[0689] - Includes minimum information to ensure accountability, such as account name, name, affiliation, and authority.

[0690] The relevant evidence is as follows.

[0691] 1. Changes to personal information processing system access rights

[0692] 2. Application for Change of Access Rights

[0693] The evaluation criteria are as follows:

[0694] Y - Records of changes in personal information handler access rights are safely stored for at least three years.

[0695] P - Records of changes in access rights of personal information handlers are being kept, but the change history cannot be clearly confirmed or is not kept for more than 3 years.

[0696] N - Does not record changes in access rights of personal information handlers

[0697] The eighteenth, detailed content of the 18th inspection item.

[0698] Question) Are you taking any measures, such as automatically blocking access to the personal information processing system if no work is done for a certain period of time?

[0699] - Personal information processing system session timeout, token expiration time setting, etc.

[0700] The relevant evidence is as follows.

[0701] 1. Evidence of setting maximum connection time limit

[0702] The evaluation criteria are as follows:

[0703] Y - Personal information processing system timeout function is applied

[0704] N - Personal information processing system timeout function is not applied

[0705] Nineteenth, the details of the 19th inspection item.

[0706] Question) When access to the personal information processing system from outside via an information and communications network is required, are secure authentication methods being applied?

[0707] - Secure authentication methods: OTP, certificate, security token, etc.

[0708] - Secure connection methods: VPN, dedicated line, etc.

[0709] The relevant evidence is as follows.

[0710] 1. Evidence of setting up a secure authentication method or connection method when accessing the personal information processing system from outside.

[0711] The evaluation criteria are as follows:

[0712] Y - Remote access to the personal information processing system from outside is restricted.

[0713] N - Does not restrict remote access to the personal information processing system from outside.

[0714] The twentieth, detailed content of the 20th inspection item.

[0715] Question) Are you restricting internet access for important terminals that process personal information?

[0716] - If the following tasks are possible, it is considered an important terminal.

[0717] 1. Personal information can be downloaded or destroyed from the personal information processing system.

[0718] 2. Access rights to the personal information processing system can be set.

[0719] The relevant evidence is as follows.

[0720] 1. Evidence of Internet blocking settings on important terminals

[0721] The evaluation criteria are as follows:

[0722] Y - Internet use on important terminals is restricted.

[0723] N - Does not restrict Internet use on important terminals

[0724] N / A - Not eligible for network separation

[0725] Twenty-first, the details of the 21st inspection item.

[0726] Question) Are you restricting access to the personal information processing system by IP address, etc.?

[0727] - Allow access only to specific IPs / MACs through firewalls, etc.

[0728] - Allow access only to specific IPs / MACs using the router's ACL function.

[0729] - Use access control solutions to allow access only to authorized personnel.

[0730] The relevant evidence is as follows.

[0731] 1. Evidence of restricted access to personal information processing systems

[0732] 2. Evidence of security solution operation

[0733] The evaluation criteria are as follows:

[0734] Y - Access control is set when accessing the personal information processing system.

[0735] P - Access control is inadequate when accessing the personal information processing system.

[0736] N - Do not set access control when accessing the personal information processing system.

[0737] Twenty-second, detailed contents of the 22nd inspection item.

[0738] Question) Are you safely applying and managing the authentication method for personal information handlers or data subjects in the personal information processing system?

[0739] - Application of authentication methods (password, OTP, etc.) according to internal management plan or guidelines

[0740] - Restrict access to the personal information processing system if authentication fails a certain number of times.

[0741] The relevant evidence is as follows.

[0742] 1. Provision of authentication methods within the internal management plan

[0743] 2. Setting the authentication method threshold

[0744] The evaluation criteria are as follows:

[0745] Y - Applying authentication methods and setting thresholds for personal information processing systems.

[0746] P - Authentication methods are applied to personal information processing systems, but thresholds are not set.

[0747] N - No authentication method applied to personal information processing system"

[0748] Twenty-third, details of the 23rd inspection item.

[0749] Question) When searching or printing personal information, are you minimizing the number of personal information items to be printed to only the information necessary for business purposes and applying safety measures to safely manage printouts and copies?

[0750] - Establish policies / regulations / guidelines for protecting and managing output and copies

[0751] - Safety measures such as watermarking, output history recording, and destruction confirmation

[0752] - When printing personal information (printing, displaying on screen, creating files, etc.), print it to the minimum extent possible within the scope of access rights by specifying the purpose.

[0753] - Whether to mask when viewing the entire list of personal information through the personal information processing system

[0754] The relevant evidence is as follows.

[0755] 1. Evidence of personal information masking

[0756] The evaluation criteria are as follows:

[0757] Y - Security measures are applied when viewing the full list of personal information.

[0758] N - No security measures applied when viewing the full list of personal information

[0759] The twenty-fourth, detailed inspection item 24.

[0760] Question) Are you storing and managing access records, including essential items, for the personal information processing system of the personal information handler for more than one year?

[0761] - Required items: identifier, access date and time, access location information, information on the subject of the information processed, and tasks performed.

[0762] - In the cases below, they must be stored and managed for more than 2 years.

[0763] 1. In the case of a personal information processing system that processes personal information of more than 50,000 data subjects.

[0764] 2. In the case of a personal information processing system that processes unique identification information or sensitive information.

[0765] 3. In case the personal information processor is a telecommunications service provider

[0766] ※ Explanation of required items for connection log

[0767] - Identifier: Account information such as ID assigned to identify the user in the personal information processing system.

[0768] - Access date and time: Time of access or time of work performed (year-month-day, hour:minute:second)

[0769] - Access information: IP address of the computer or server of the person accessing the personal information processing system, etc.

[0770] - Processed information subject information: Identification information (ID, customer number, student number, employee number, etc.) that allows the personal information handler to determine whose personal information was processed.

[0771] - Performance tasks: Information that allows the personal information handler to know the details of personal information processed using the personal information processing system (collecting, creating, linking, connecting, recording, storing, holding, processing, editing, searching, printing, correcting, recovering, using, providing, disclosing, destroying, etc. may be considered performance tasks)

[0772] The relevant evidence is as follows.

[0773] 1. Access log of personal information processing system

[0774] The evaluation criteria are as follows:

[0775] Y - Access records of personal information processing systems are stored and managed for at least one or two years, including all required information.

[0776] P - Access records for the personal information processing system are being kept, but some information is missing or the access record retention period is not appropriate.

[0777] N - Access records of personal information processing systems are not kept.

[0778] Twenty-fifth, the 25th inspection item details.

[0779] Question) Are you checking the access records of the personal information processing system at least once a month?

[0780] - Check for excessive personal information inquiries, access outside of working hours, and reasons for downloading personal information.

[0781] - When downloading personal information, it is mandatory to check the reason for downloading.

[0782] The relevant evidence is as follows.

[0783] 1. Personal information processing system access log inspection plan

[0784] 2. Personal information processing system access log inspection report

[0785] The evaluation criteria are as follows:

[0786] Y - Checking the appropriateness of the access records and reasons for downloading personal information from the personal information processing system (at least once a month)

[0787] P - We are checking the appropriateness of the personal information processing system access records and reasons for downloading personal information, but we do not conduct inspections more than once a month.

[0788] N - The access records of the personal information processing system and the reasons for downloading personal information are not checked for appropriateness.

[0789] Twenty-sixth, the 26th inspection item details.

[0790] Question) Are you taking necessary measures in your personal information processing system, personal information handler's computer, and mobile device to prevent personal information from being disclosed or leaked to unauthorized persons through Internet homepages, P2P, sharing settings, etc.?

[0791] - Block access to harmful sites such as P2P

[0792] - Shared folder restrictions

[0793] - Application of security solutions such as DLP and DRM

[0794] The relevant evidence is as follows.

[0795] 1. Evidence of blocking access to harmful websites on the personal information handler's terminal

[0796] 2. Evidence of shared folder restriction settings

[0797] 3. Evidence of security solution operation

[0798] The evaluation criteria are as follows:

[0799] Y - Measures are being established to prevent personal information leakage and exposure on personal information handler terminals.

[0800] N - No measures are set up on the personal information handler's terminal to prevent personal information leakage or exposure.

[0801] Twenty-seventh, the 27th inspection item details.

[0802] Question) Are you establishing and applying a password policy for personal information handlers or data subjects who access the personal information processing system?

[0803] - The minimum password length is set to 10 characters when combining at least two types of uppercase letters, lowercase letters, numbers, and special characters, or 8 characters when combining at least three types of characters.

[0804] - Set an expiration date for your password, change it at least once every six months, and prevent the use of two passwords interchangeably.

[0805] - If you enter your password incorrectly more than 5 times, access restrictions such as account locking and delay settings will be applied.

[0806] - Set passwords that are easy to guess, such as consecutive numbers, birthdays, phone numbers, or passwords that are similar to IDs, to be unavailable.

[0807] ※ Not applicable if password is not used as an authentication method"

[0808] The relevant evidence is as follows.

[0809] 1. Password policy within the internal management plan

[0810] 2. Password policy set in the personal information processing system

[0811] 3. Password change date status

[0812] The evaluation criteria are as follows:

[0813] Y - Set a secure password that meets the password standards and change it regularly.

[0814] N - You are using a weak password or your password policy settings are not being applied.

[0815] Twenty-eighth, the 28th inspection item details.

[0816] Question) Are you storing your password using one-way encryption?

[0817] - Application of a secure one-way encryption algorithm higher than SHA-2

[0818] - Refer to the latest information, such as the KISA encryption algorithm and key length usage guide.

[0819] ※ Not applicable if password is not used as authentication method

[0820] The relevant evidence is as follows.

[0821] 1. Evidence of application of encryption algorithm to password

[0822] The evaluation criteria are as follows:

[0823] Y - A secure encryption algorithm is applied when storing passwords.

[0824] N - No secure encryption algorithm is used when storing passwords.

[0825] The twenty-ninth, 29th inspection item details.

[0826] Question) Are users' resident registration numbers, passport numbers, driver's license numbers, alien registration numbers, credit card numbers, account numbers, and biometric information encrypted and stored using a secure encryption algorithm?

[0827] - Writing of applied symmetric key encryption algorithms (SEED, ARIA-128 / 192 / 256, AES-128 / 192 / 256, HIGHT, etc.)

[0828] - Writing of applied public key encryption algorithms (RSAES-OAEP, RSAES-PKCS1, etc.)

[0829] The relevant evidence is as follows.

[0830] 1. Evidence of personal information encryption application

[0831] 2. Encryption algorithm evidence

[0832] The evaluation criteria are as follows:

[0833] Y - Personal information is encrypted and stored using a secure encryption algorithm.

[0834] N - Personal information is stored without encryption using a secure encryption algorithm.

[0835] The thirtieth, detailed content of the 30th inspection item.

[0836] Question) When sending and receiving passwords, personal information, and authentication information via information and communications networks, are they encrypted?

[0837] - Apply SSL (https) or install an encryption program"

[0838] The relevant evidence is as follows.

[0839] 1. SSL certificate information

[0840] 2. Evidence of personal information encryption through encryption solutions, etc.

[0841] The evaluation criteria are as follows:

[0842] Y - Personal information and authentication information transmitted and received via information and communications networks are encrypted.

[0843] N - Personal information and authentication information transmitted and received via information and communications networks are not encrypted.

[0844] Here are the details of the thirty-first inspection item.

[0845] Question) When storing personal information on PCs, mobile devices, and auxiliary storage media, is it encrypted?

[0846] - When downloading files from the personal information processing system, they are downloaded with the password settings applied.

[0847] - Manually set a password for personal information files (such as password settings provided by office programs)

[0848] - When using auxiliary storage media, use secure USB, etc.

[0849] - DRM applied

[0850] The relevant evidence is as follows.

[0851] 1. Evidence that encryption has been applied when storing personal information files on a PC, auxiliary storage media, etc.

[0852] The evaluation criteria are as follows:

[0853] Y - Personal information is encrypted and stored.

[0854] N - Do not encrypt personal information when storing it

[0855] Thirty-second, detailed inspection item 32.

[0856] The relevant evidence is as follows.

[0857] 1. Password key management procedures

[0858] The evaluation criteria are as follows:

[0859] Y - Establishing and implementing secure encryption key management procedures.

[0860] N - Failure to establish and implement secure encryption key management procedures

[0861] Thirty-third, details of the 33rd inspection item.

[0862] Question) Are you installing and operating a security program to check for and treat malware on your personal information handler's PC?

[0863] - Automatic update or update at least once a day

[0864] - Real-time monitoring and daily scheduled inspections

[0865] The relevant evidence is as follows.

[0866] 1. Security program installation history

[0867] 2. Security program inspection details

[0868] 3. Security program update history

[0869] The evaluation criteria are as follows:

[0870] Y - I have installed a security program, am running real-time monitoring, and am performing updates once a day.

[0871] P - Security program installed but not updated once a day or set up real-time monitoring

[0872] N - Do not install or run security programs

[0873] Thirty-fourth, details of inspection item 34.

[0874] Question) If there is a security update notice for the application or operating system software being used on the personal information handler's PC, do you apply the update immediately?

[0875] The relevant evidence is as follows.

[0876] 1. A screen where you can check for security updates on the personal information handler's PC.

[0877] 2. Evidence that can confirm whether security updates are being applied to applications installed on the PC.

[0878] 3. Update-related notice

[0879] The evaluation criteria are as follows:

[0880] Y - Applying updates immediately when security updates are announced

[0881] N - Do not apply security updates immediately

[0882] Thirty-fifth, details of inspection item 35.

[0883] Question) Do you have a crisis response manual and backup and recovery plan in place to prepare for disasters such as fire, flood, and power outages, and do you regularly review them?

[0884] ※ If it does not fall under the types below, it may be excluded from the inspection items.

[0885] - Large corporations, medium-sized enterprises, and public institutions that process personal information of more than 100,000 data subjects.

[0886] - Personal information processors that are small and medium-sized enterprises or organizations that process personal information of more than 1 million data subjects.

[0887] The relevant evidence is as follows.

[0888] 1. Crisis Response Manual (Document)

[0889] 2. Backup and Recovery Policy and Procedures (Document)

[0890] The evaluation criteria are as follows:

[0891] Y - Establishing crisis response procedures, including backup and recovery plans.

[0892] P - Crisis response procedures are in place but backup and recovery plans are missing, or backup and recovery plans are in place but crisis response procedures are inadequate.

[0893] N - No crisis response procedures established"

[0894] Thirty-sixth, details of the 36th inspection item.

[0895] Question) In addition to the personal information provided by the consignor, when collecting additional personal information for the purpose of processing the consignor's business, are you obtaining consent in an appropriate manner, such as by notifying all necessary consent items and indicating important information?

[0896] - Required notification in consent form

[0897] 1. Purpose of collection and use of personal information

[0898] 2. Items of personal information to be collected

[0899] 3. Retention and use period of personal information

[0900] 4. The fact that you have the right to refuse consent and, if there are any disadvantages resulting from refusal of consent, the details of those disadvantages.

[0901] 5. (When provided to a third party) Recipient, purpose of use by recipient, period of use, items provided, right to refuse consent and disadvantages of consent

[0902] - How to display important information in the consent form

[0903] 1. The font size should be at least 9 points and at least 20% larger than other content to ensure easy reading.

[0904] 2. Clearly indicate the content through text color, thickness, or underlining.

[0905] 3. If there are many matters to agree on and it is difficult to clearly distinguish important matters, display them separately from other matters so that important matters can be easily identified.

[0906] The relevant evidence is as follows.

[0907] 1. Personal information collection and use consent screen

[0908] The evaluation criteria are as follows:

[0909] Y - We collect personal information by providing all required notices and obtaining consent.

[0910] N - Personal information is being collected without providing or omitting required notices.

[0911] Thirty-seventh, details of the 37th inspection item.

[0912] Question) Are you destroying personal information without delay after confirming that the retention period has expired or the business purpose has been achieved?

[0913] - Writing the conditions and cycle for destroying personal information

[0914] - Create a history of personal information destruction

[0915] - Request for the preparation of evidence of personal information destruction, such as a "Personal Information Destruction Confirmation Form"

[0916] The relevant evidence is as follows.

[0917] 1. Personal Information Destruction Procedure

[0918] 2. Setting up personal information destruction batches

[0919] 3. Personal Information Destruction Confirmation Form

[0920] 4. Personal information destruction history

[0921] The evaluation criteria are as follows:

[0922] Y - Establishing destruction criteria and procedures and managing post-destruction history.

[0923] P - Establishing destruction criteria or procedures, but not managing destruction history

[0924] N - No destruction criteria or procedures established

[0925] Thirty-eighth, details of the 38th inspection item.

[0926] Question) If personal information must be retained even after the purpose of use has been achieved, is it stored and managed separately from other personal information being operated?

[0927] - Writing the conditions and cycle for separate storage of personal information

[0928] The relevant evidence is as follows.

[0929] 1. Evidence of separate storage of personal information

[0930] The evaluation criteria are as follows:

[0931] Y - Personal information that needs to be kept even after the purpose has been achieved is kept safely separated from operational personal information.

[0932] N - Personal information that needs to be retained even after the purpose has been achieved is stored without being separated from operational personal information.

[0933] Thirty-ninth, details of inspection item 39.

[0934] Question) Are you destroying personal information in the following secure manner?

[0935] - Personal information stored in electronic file formats such as PCs, auxiliary storage media, and mailboxes is deleted in a way that makes it unrecoverable using a technical method that renders the records unrecoverable.

[0936] - In the case of personal information printed on paper, it is destroyed using a method that makes it unrecoverable, such as shredding or incineration.

[0937] The relevant evidence is as follows.

[0938] 1. Evidence of destruction of personal information stored in electronic file format

[0939] 2. Document shredder, document destruction box evidence

[0940] The evaluation criteria are as follows:

[0941] Y - Personal information is being destroyed in a secure manner.

[0942] N - Not destroying personal information

[0943] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0944] Referring to Figure 22 (2210), the inspection status of the inspection checklist is explained.

[0945] The inspection status is divided into inspection status, related laws and regulations, and related notices.

[0946] The relevant laws are Article 29 of the Personal Information Protection Act and Article 30 of the Enforcement Decree.

[0947] The relevant notice is Article 4 of the Personal Information Security Measures Standards.

[0948] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0949] Referring to Figure 23 (2310), the penalty provisions of the inspection checklist are explained.

[0950] Penalty provisions are divided into penalties and penalty provisions.

[0951] Penalties are divided into criminal penalties and administrative measures.

[0952] Punishments are divided into imprisonment and fines.

[0953] Administrative sanctions are categorized into fines and surcharges. Surcharges can be up to 50 million won.

[0954] The penalty provision is Article 75 of the Personal Information Protection Act.

[0955] According to Article 75 of the Personal Information Protection Act, a person who falls under any of the following items shall be subject to a fine of up to 50 million won.

[0956] 5) A person who has violated Article 23, Paragraph 2, Article 24, Paragraph 3, Article 25, Paragraph 6 (including cases where it applies pursuant to Article 25-2, Paragraph 4), Article 28-4, Paragraph 1, and Article 29 (including cases where it applies pursuant to Article 26, Paragraph 8) and has not taken necessary measures to ensure safety.

[0957] Above, the entire system of the present disclosure has been described with reference to FIGS. 1 to 23. Hereinafter, the present invention will be described in detail with reference to FIGS. 24 to 38.

[0958] Figure 24 is a diagram illustrating a configuration of a personal information interest management device according to the present disclosure.

[0959] The present invention consists of two inventions.

[0960] The first invention is a personal information interest management device and its control method. This is described in FIGS. 24 to 29.

[0961] The second invention is a prediction device including personal information and a control method thereof. This is described in FIGS. 30 to 38.

[0962] In the present invention, the object transmitted by the transmitting entity includes data, information, messages, and signals.

[0963] Data contains information.

[0964] Information contains messages.

[0965] A message contains a signal.

[0966] The first invention describes a personal information interest management device (Figs. 24 to 29).

[0967] Referring to FIG. 24, the personal information interest management device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[0968] The input module (2410) collects data.

[0969] The sensor module (2420) senses data.

[0970] The processor (2430) performs a control method according to the process.

[0971] That is, the processor (2430) collects user behavior data of viewing a consent form through the input module, analyzes the behavior data, determines abnormal and normal behavior based on the analysis result of the behavior data, processes the behavior data based on the determined result to calculate personal information interest, and assigns a grade based on the calculated personal information interest.

[0972] The processor (2430) collects the behavior data through the input module in a situation where consent is received that includes at least one of personal information, sensitive information, and advertising information.

[0973] The processor (2430) processes the behavior data to calculate the personal information interest based on a combination of measurement values ​​of the behavior data, at least one of the user's geographic location, age, gender, and industry characteristics of the service provider.

[0974] The processor (2430) calculates the personal information interest level by applying weights to the processed behavioral data. A detailed description of this is provided in Fig. 26.

[0975] The processor (2430) collects the above-described behavior data including sensitivity judgment items through the input module, and the sensitivity judgment items include whether or not consent items have been viewed and user pattern data, and the user pattern data includes at least one of mouse movement, whether or not scrolling has occurred, scroll speed, whether or not consent has been completely read, text drag words, text drag ratio, consent page viewing frequency, whether or not consent check has been reversed, whether or not consent has been printed, and whether or not capture has been performed.

[0976] The processor (2430) determines the user's sensitivity by considering whether the consent item has been viewed and the user pattern data.

[0977] The processor (2430) stops collecting the behavioral data if the sensitivity exceeds a preset threshold, and generates a sensitivity report based on the behavioral data collection results if the sensitivity is below the preset threshold. A detailed description of this is provided in Fig. 28.

[0978] The processor (2430) monitors the user's consent process corresponding to the above-mentioned behavior data, patterns the user's log process, analyzes the patterning result of the log process, analyzes the user's viewing rate for the content related to the consent form, evaluates the user's sensitivity for subsequent processing based on the patterning result and the analysis result of the viewing rate, and establishes a user management strategy based on the evaluated sensitivity.

[0979] When analyzing the above-mentioned reading rate, the processor (2430) classifies the user types into those who have fully read the document, those who have confirmed their consent, and those who have not confirmed their consent. A detailed description of this is provided in Fig. 29.

[0980] The second invention describes a personal information utilization device and its control method. (Figs. 30 to 38)

[0981] Referring to FIG. 24, a personal information inclusion prediction device (2400) that predicts the possibility of personal information inclusion in a question entered by a personal information handler includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[0982] The input module (2410) collects data.

[0983] The processor (2430) collects data for the above-mentioned question through the input module (2410), decomposes the input question into words, inputs the decomposed words into a first artificial intelligence model for analysis, and makes a first prediction of the likelihood of whether the words include personal information items based on the analysis result of the first artificial intelligence model, decomposes the input question into sentences based on the first prediction result, inputs the decomposed sentences into a second artificial intelligence model for analysis, and makes a second prediction of the likelihood of whether the sentence includes personal information items based on the analysis result of the second artificial intelligence model, and transmits the first prediction result or the second prediction result to the device of the personal information handler.

[0984] Here, the question refers to the question items set by the personal information handler.

[0985] Questions consist of sentences, words, etc. They include things requested of the person providing personal information.

[0986] If the first prediction result is valid, the processor (2430) transmits the first prediction result to the user's device. If the first prediction result is invalid, the processor (2430) decomposes the input item into sentence units. A detailed description of this is provided in Fig. 34.

[0987] The second AI model differs from the first AI model. A detailed description of this is provided in Figure 30.

[0988] The processor (2430) performs word tokenization (Tokenization) on the input item through morphological analysis to break it down into word units. A detailed description of this is provided in Fig. 32.

[0989] When collecting personal information, the processor (2430) determines the legal basis for the collection based on the industry and purpose of the company collecting the personal information. A detailed explanation of this is provided in Figure 34.

[0990] The processor (2430) trains at least one of the first artificial intelligence model and the second artificial intelligence model using a proxy label method. A detailed description thereof is provided in FIG. 35.

[0991] The processor (2430) recognizes personal information items in the sentence by referring to a named entity recognition (NER) task, classifies the recognized personal information items, and predicts whether the sentence includes a personal information item based on the classified personal information items.

[0992] The processor (2430) returns a logit for the input sentence token related to the sentence, determines the label with the highest probability value for each token related to the sentence, and calculates the maximum value according to the dimension of the label.

[0993] The processor (2430) calculates the probability value using the following mathematical formula.

[0994]

[0995] A detailed explanation of this is given in Fig. 37.

[0996] However, the components illustrated in FIG. 24 are not essential for implementing the present invention according to the present disclosure, and thus the present invention described in this specification may have more or fewer components than the components listed above.

[0997] Meanwhile, the processor (2430) of FIG. 24 may be identical to the processor (50) of FIG. 1 described above, and in this case, all operations and controls of FIGS. 1 to 23 described above may be performed identically by the processor (2430) of FIG. 24.

[0998] The display (2440) displays graphic images according to control commands from the processor (2430).

[0999] Memory (2450) stores at least one process for performing an operation and stores user input and data.

[1000] The communication module (2460) transmits and receives data with an external device.

[1001] Here, the external device includes an external device such as a smartphone, a PC, a laptop, a tablet PC, etc.

[1002] The camera module (2470) captures images of the front.

[1003] The camera module (2470) photographs a subject in front according to a control command from the processor (2430).

[1004] The communication module (2460) may include one or more components that enable communication with an external device, and may include, for example, at least one of a broadcast reception module, a wired communication module, a wireless communication module, a short-range communication module, and a location information module.

[1005] The input module (2410) is for inputting video information (or signals), audio information (or signals), data, or information input from a user, and may include at least one camera, at least one microphone, and at least one user input unit. Voice data or image data collected by the input module (2410) may be analyzed and processed into a user control command.

[1006] The display module (2440) displays (outputs) information processed in the present invention. For example, the present invention can display execution screen information of a running application program (e.g., an application), or UI (User Interface) or GUI (Graphical User Interface) information based on such execution screen information.

[1007] The memory (2450) can store data supporting various functions of the present invention, programs for the operation of the control unit, input / output data (e.g., music files, still images, moving images, etc.), and can store a plurality of application programs (or applications), data for the operation of the device, and commands. At least some of these application programs can be downloaded from an external server via wireless communication.

[1008] The memory (2450) may include at least one type of storage medium among a flash memory type, a hard disk type, an SSD (Solid State Disk type), an SDD (Silicon Disk Drive type), a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. In addition, the memory (2450) is separate from the present invention, but may be a database connected by wire or wirelessly, and may be implemented as a database system.

[1009] The processor (2430) may be implemented as at least one core, a memory storing data for an algorithm for controlling the operation of components within the present invention or a program reproducing the algorithm, and at least one processor (not shown) that performs the aforementioned operations using the data stored in the memory. In this case, the memory and the processor may be implemented as separate chips. Alternatively, the memory and the processor may be implemented as a single chip.

[1010] Additionally, the processor (2430) may control any one or a combination of the components described above to implement various embodiments according to the present disclosure described in FIGS. 24 to 38 below.

[1011] At least one component may be added or deleted to correspond to the performance of the components illustrated in Figure 24. Furthermore, it will be readily apparent to those skilled in the art that the relative positions of the components may be altered to correspond to the performance or structure of the system.

[1012] Meanwhile, each component illustrated in FIG. 24 refers to software and / or hardware components such as a Field Programmable Gate Array (FPGA) and an Application Specific Integrated Circuit (ASIC).

[1013] Figure 25 is a diagram illustrating a flowchart of a personal information interest management method according to the present disclosure.

[1014] The present invention is performed by a personal information interest management device (2400) or a processor (2430) of the personal information interest management device (2400).

[1015] Referring to FIG. 25, the processor (2430) collects data on the user's act of viewing the consent form through the input module (S2510).

[1016] The processor (2430) analyzes the above-mentioned behavior data (S2520).

[1017] The processor (2430) determines abnormal and normal behavior based on the analysis results of the above behavior data (S2530).

[1018] The processor (2430) processes the behavior data based on the determined result and calculates the personal information interest level (S2540).

[1019] The processor (2430) assigns a grade based on the calculated personal information interest level (S2550).

[1020] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1021] Referring to Figure 26 (2610), a method for managing personal information interest by analyzing the user's personal information interest based on behavioral data during the personal information consent process and managing it in a customized manner is specifically described.

[1022] The processor (2430) collects the behavior data through the input module (2410) in a situation where consent is received, including at least one of personal information, sensitive information, and advertising information.

[1023] The processor (2430) processes the behavior data to calculate the personal information interest based on a combination of measurement values ​​of the behavior data, at least one of the user's geographic location, age, gender, and industry characteristics of the service provider.

[1024] The processor (2430) calculates the personal information interest by reflecting the weight on the processed behavior data.

[1025] The technical features of the present invention are further described.

[1026] Obtaining legal consent in diverse situations, including from individuals with sensitive personal information, people with disabilities, children, and the elderly, requires a tailored approach and compliance with legal standards.

[1027] For this purpose, you can consider the following strategies:

[1028] 1. Common Strategy: Building Trust and Clarity

[1029] The present invention can ensure transparency. It can provide specific and clear information, such as the purpose of collection, method of use, storage period, and whether or not to share.

[1030] The present invention uses concise language. It avoids technical jargon and can be explained in easy-to-understand language.

[1031] This invention guarantees freedom of consent. It eliminates any disadvantages for non-consent and explicitly states that consent can be withdrawn at any time.

[1032] The present invention can provide alternatives, either by presenting alternatives that are possible without consent or by minimizing data.

[1033] 2. People who are sensitive to personal information

[1034] The present invention identifies preferences. Before providing consent, it listens to concerns about providing personal information and requests only the minimum amount of information necessary.

[1035] The present invention provides a personalized approach. It understands the individual's concerns and provides thorough explanations. For example, it provides detailed guidance on data encryption and security measures.

[1036] The present invention may provide technical options, such as providing an interface that allows users to directly adjust privacy settings.

[1037] The present invention can provide a neutral explanation. It can provide a neutral and balanced explanation of data utilization. For example, it can transparently share risks as well as this point.

[1038] 3. Disabled people

[1039] The present invention enhances accessibility for the disabled.

[1040] For the visually impaired, it supports Braille, audio files, and screen readers.

[1041] For the hearing impaired, sign language videos and subtitles are provided.

[1042] For intellectual disabilities, write in an easy-to-read format.

[1043] It can support communication.

[1044] Allows the use of assistive devices.

[1045] The present invention allows a representative (legal guardian) to assist in the consent process.

[1046] The present invention repeatedly verifies key information and asks for understanding.

[1047] 4. Children (minors)

[1048] This invention requires parental / legal guardian consent, as additional parental or guardian consent may be required depending on the child's age.

[1049] The present invention provides parents with a copy of the consent form and provides sufficient explanation.

[1050] The present invention uses child-friendly language.

[1051] The present invention is written using easy words and graphics so that children can understand it.

[1052] The present invention takes an educational approach. It simply educates users about how data is used and the risks involved. For example, "This information will only be used to send letters to your friends."

[1053] In the case of confirming consent, the child himself or herself can clearly express whether or not he or she consents.

[1054] 5. Elderly

[1055] The present invention provides one-on-one explanations to the elderly:

[1056] The present invention provides an opportunity to explain the consent form orally in person or to review it with a family member or trusted representative.

[1057] The present invention includes large print and clear formatting.

[1058] The present invention is designed to increase the font size and clearly distinguish the content structure for easy understanding.

[1059] The present invention provides additional consultation opportunities. It can provide consultation services to ask additional questions or facilitate understanding before consent.

[1060] 6. Compliance with international standards

[1061] This invention is GDPR compliant (Europe).

[1062] Comply with the principles of “legality, fairness, and transparency.”

[1063] Emphasizes the right to withdraw consent and the principle of data minimization.

[1064] This invention complies with the CCPA (California, USA).

[1065] Guarantees users' right to "opt out".

[1066] This invention complies with PIPA. (Korea)

[1067] Write in a way that the subject of the consent can understand.

[1068] 7. Technology Utilization

[1069] The present invention provides a digital consent interface.

[1070] The present invention can provide an interface with enhanced accessibility.

[1071] The invention can be broken down into context-specific, tailored questions (e.g., "Do you agree to the data storage period?").

[1072] The present invention is designed with privacy first.

[1073] The present invention requests only the minimum data that requires consent.

[1074] The present invention provides an option to automatically anonymize or encrypt data.

[1075] 8. Maintaining trust after agreement

[1076] For usage notifications, the present invention periodically updates where the data has been used.

[1077] In the case of easy withdrawal of consent, the present invention simplifies the withdrawal process and guides users to delete or return data.

[1078] In the case of providing a feedback channel, the present invention provides a dedicated contact point or platform for inquiries regarding the use of personal information.

[1079] FIG. 27 is a diagram illustrating an embodiment of a personal information interest management method according to the present disclosure.

[1080] The present invention comprises a user device (2710) and a processor (2430) of a personal information interest management device (2400).

[1081] The processor (2430) includes a behavior collection module (2431), a behavior analysis module (2432), and a personal information interest calculation module (2433).

[1082] The action collection module (2431) collects action data of the user viewing the consent form through the input module (2410).

[1083] The behavior analysis module (2432) analyzes behavioral data and determines abnormal and normal behavior based on the analysis results.

[1084] The personal information interest calculation module (2433) processes behavioral data based on the judgment result to calculate personal information interest and assigns a grade according to the personal information interest.

[1085] The user device (2710) transmits a message containing a response to the information collection item to the action collection module (2431).

[1086] The action collection module (2431) collects response time cycles for each item.

[1087] The behavior collection module (2431) transmits the response time cycle for each item to the behavior analysis module (2432).

[1088] The user device (2710) transmits a message including whether the consent form has been viewed and the consent processing details to the action collection module (2431).

[1089] The action collection module (2431) collects whether or not the consent form items have been viewed.

[1090] The behavior collection module (2431) collects user behavior data.

[1091] The behavior collection module (2431) transmits whether or not the consent form items have been viewed to the behavior analysis module (2432).

[1092] The behavior collection module (2431) transmits user behavior data to the behavior analysis module (2432).

[1093] Here, user behavior data includes pointer movement, scrolling, scrolling speed, scrolling ratio (left), text dragging, text drag words, text dragging ratio, frequency of viewing consent pages, whether consent checks are reversed, whether consent forms are printed, and whether screen system captures are taken.

[1094] The behavior analysis module (2432) analyzes abnormal behavior based on user behavior data.

[1095] The behavior analysis module (2432) stops collecting data when abnormal behavior exceeds the threshold.

[1096] If the abnormal behavior is less than the threshold, the behavior analysis module (2432) transmits the behavior analysis results to the personal information interest calculation module (2433).

[1097] The personal information interest calculation module (2433) processes behavioral data based on the judgment result to calculate personal information interest and assigns a grade according to the personal information interest.

[1098] The personal information interest calculation module (2433) calculates the personal information interest by processing the behavior data based on a combination of measurement values ​​of the behavior data, at least one of the user's geographical location, age, gender, purpose of consent, and industry characteristics of the service provider.

[1099] The personal information interest calculation module (2433) calculates personal information interest by reflecting weights on the above behavior data.

[1100] FIG. 28 is a diagram illustrating an example of customer sensitivity judgment according to the present disclosure.

[1101] Referring to FIG. 28, the processor (2430) includes a behavior collection module (2431), a behavior analysis module (2432), and a personal information interest calculation module (2433).

[1102] The processor (2430) can execute at least one of the functions of the behavior collection module (2431), the behavior analysis module (2432), and the personal information interest calculation module (2433).

[1103] The behavior collection module (24310) collects the behavior data including sensitivity judgment items through the input module (2410).

[1104] Here, the sensitivity judgment items include whether or not the consent items have been viewed and user pattern data.

[1105] User pattern data includes at least one of the following: mouse movement, scrolling, scrolling speed, whether the consent form was read completely, text drag words, text drag ratio, frequency of consent page views, whether consent was checked again, whether the consent form was printed, and whether the consent form was captured.

[1106] The behavior analysis module (2432) determines the user's sensitivity by considering at least one of the consent item viewing and user pattern data.

[1107] The behavior analysis module (2432) stops collecting the behavior data when the sensitivity exceeds a preset threshold.

[1108] If the sensitivity is below a preset threshold, the behavior analysis module (2432) transmits the results of the collection of the behavior data to the personal information interest calculation module (2433).

[1109] The Personal Information Interest Calculation Module (2433) generates a sensitivity report based on the results of collecting behavioral data.

[1110] Figure 29 is a diagram illustrating an example of user consent process behavior analysis according to the present disclosure.

[1111] Referring to FIG. 29 (2910), the processor (2430) monitors the user's consent process corresponding to the above-mentioned behavior data (S1).

[1112] The processor (2430) patterns the user's log process and analyzes the patterning result of the log process (S2).

[1113] Analyze user behavior according to the type of response button.

[1114] Here, the types of response buttons include radio buttons, drop-down lists, multiple choice questions, mouse movement (user hesitation), and other types.

[1115] The processor (2430) analyzes the user's viewing rate for the content related to the above consent form (S3).

[1116] When analyzing the above-mentioned reading rate, the processor (2430) analyzes the types of users by dividing them into users who have read the entire document, users who have confirmed consent, and users who have not confirmed consent.

[1117] Here, the consent verifier can be divided into 10% confirmation, 30% confirmation, and 70% confirmation.

[1118] The processor (2430) evaluates user sensitivity for subsequent processing based on the analysis results of the patterning results and the viewing rate (S4).

[1119] The processor (2430) establishes a user management strategy based on the evaluated sensitivity (S5).

[1120] Describes user management strategies.

[1121] First, handle the user immediately after consent is completed.

[1122] Second, set a notification cycle during the consent retention period. The notification cycle can be three months, six months, or one year.

[1123] Third, set up a notification method for the user after the consent is terminated.

[1124] Figure 30 is a diagram illustrating a flowchart of a prediction method including personal information according to the present disclosure.

[1125] The present invention is performed by a personal information-containing prediction device (2400) or a processor (2430) of the personal information-containing prediction device (2400).

[1126] Referring to FIG. 30, the processor (2430) collects data for the above question through an input module (S3010).

[1127] The processor (2430) breaks down the input item into word units (S3020).

[1128] The processor (2430) inputs the decomposed word into the first artificial intelligence model and analyzes it (S3030).

[1129] The processor (2430) first predicts the possibility of whether the word includes a personal information item based on the analysis result of the first artificial intelligence model (S3040).

[1130] The processor (2430) decomposes the input item into sentence units based on the first predicted result (S3050).

[1131] The processor (2430) inputs the decomposed sentence into the second artificial intelligence model and analyzes it (S3060).

[1132] Here, the second artificial intelligence model is different from the first artificial intelligence model.

[1133] The processor (2430) makes a second prediction of the possibility of whether the sentence includes a personal information item based on the analysis result of the second artificial intelligence model (S3070).

[1134] The processor (2430) transmits the first prediction result or the second prediction result to the personal information handler's device (S3080).

[1135] Figure 31 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1136] Referring to FIG. 31 (3110), a method for predicting the possibility of including personal information in a question entered by a user is specifically described.

[1137] The technical features of the present invention are further described.

[1138] The present invention is performed by a processor (2430).

[1139] 1. Explain the advantages of running the analysis artificial intelligence module twice.

[1140] (1) Securing result verification and reliability

[1141] You can repeat the analysis of the same data set to check the consistency of the results.

[1142] If the results are the same or similar, the stability and reliability of the analysis module are considered high.

[1143] (2) Removal of randomness

[1144] Some AI modules may have different results depending on their initialization state, random sampling, or internal algorithm characteristics.

[1145] By running the iterations, we can minimize these random factors and find a representative value.

[1146] (3) Comparison of detailed differences

[1147] By analyzing the differences between the first and second results, you can determine the sensitivity of your data or understand the variables (environment, settings, etc.) that influenced the analysis process.

[1148] (4) Deriving optimal results

[1149] If the output of a module is probabilistic (e.g., a machine learning model), you can run it multiple times to select the best result or use an average of the results.

[1150] (5) Error detection

[1151] You can check whether a module is likely to raise an error under certain conditions or identify exceptions.

[1152] 2. Explain how to decide which of the first and second results to adopt.

[1153] (1) Review of result consistency

[1154] If the two results are identical or similar, the two runs simply serve as a validation, so either result can be chosen. If there are differences, the cause of the difference should be analyzed.

[1155] (2) Confirm the purpose and criteria of analysis

[1156] If the criteria for selecting results are clear (e.g., high accuracy, optimization of a specific metric), each result is evaluated and the one that meets the criteria is selected.

[1157] (3) Example of standard

[1158] Machine learning: higher accuracy or F1-score.

[1159] Natural Language Processing: Higher Sentence Readability.

[1160] (4) Quality assessment of results

[1161] Evaluate the two results qualitatively or quantitatively and select the result with higher quality.

[1162] (5) Evaluation method

[1163] Qualitative evaluation checks whether it matches expert reviews and expectations.

[1164] Quantitative evaluation compares performance indicators (accuracy, precision, etc.).

[1165] (6) Review of averaging or synthesis possibilities

[1166] If the difference between the two results is not large, one method is to take the average or derive a result that combines the strengths of each.

[1167] (7) Additional execution to remove randomness

[1168] If the difference between the two results is large, run the module additionally to see if the results converge.

[1169] After running it more than 3 times, you can also select a representative value (average, majority vote).

[1170] 3. Tips for making decisions

[1171] (1) When the difference in results is minimal

[1172] Either select randomly or use the average value among the results.

[1173] (2) When there is a large difference in results

[1174] Investigate the cause of the difference (data quality, module settings, etc.).

[1175] Adjust settings, data, or environments and run additional tests to verify repeatedly.

[1176] (3) Results that are in line with the purpose

[1177] Select the result that best suits your specific analysis purpose (e.g., error detection, prediction accuracy).

[1178] Additional verification is performed to ensure the reliability of the results.

[1179] If possible, compare results with other analysis modules or conduct parallel reviews with domain experts.

[1180] FIG. 32 is a diagram illustrating a flowchart 1 of a prediction method including personal information according to the present disclosure.

[1181] Flowchart 1 of the present invention is connected to flowchart 2.

[1182] The present invention comprises a user device (3210) and a prediction device including personal information (3220).

[1183] The prediction device (3220) including personal information performs the same function as the prediction device (2400) including personal information.

[1184] The prediction device (3220) including personal information includes an interface (3221), a processor (3222), an engine (3223), and an artificial intelligence model (3224).

[1185] The processor (3222) performs the same function as the processor (2430) of the personal information-containing prediction device (2400).

[1186] According to one embodiment of the present invention, the processor (2430) can perform all individual functions of the interface (3221), the processor (3222), the engine (3223), and the artificial intelligence model (3224).

[1187] The user device (3210) transmits a message including the user's input information to the interface (3221).

[1188] The interface (3221) transmits the user's input information to the processor (3222).

[1189] The processor (3222) performs word tokenization (Token) through morphological analysis based on the user's input.

[1190] The processor (3222) transmits data including crawling data, user data, and collected items to the engine (322).

[1191] Engine (3223) performs the data learning process.

[1192] The engine (3223) stores the learning results in the artificial intelligence model (3224).

[1193] The artificial intelligence model (3224) loads the existing learning model and transmits it to the engine (3223).

[1194] Engine (3223) performs the first word unit analysis and performs artificial intelligence model analysis based on the existing learning model (first artificial intelligence model).

[1195] FIG. 33 is a diagram illustrating a flowchart 2 of a prediction method including personal information according to the present disclosure.

[1196] The processor (3222) verifies whether the predicted value (the first predicted result) is valid. Here, the predicted value is whether the question contains personal information.

[1197] If the predicted value is valid, the processor (3222) transmits the predicted value to the interface (3221).

[1198] The interface (3221) transmits the predicted value to the user device (3210).

[1199] If the predicted value is invalid, the processor (322) transmits the question sentence to the engine (3223).

[1200] Engine (3223) performs sentence-level analysis for the second time and performs artificial intelligence model analysis based on an artificial intelligence model (second artificial intelligence model) different from the existing learning model.

[1201] The engine (3223) transmits the prediction value (second prediction result) to the interface (3221).

[1202] The interface (3221) transmits a prediction value (first prediction result or second prediction result) to the user device (3210).

[1203] Figure 34 is a diagram illustrating the structure of a legal decision system according to the present disclosure.

[1204] Referring to FIG. 34 (3410), the processor (2430) can set the law for determining personal information according to the situation.

[1205] The processor (2430) checks the information entered when creating a service (S1).

[1206] The processor (2430) determines the law (S2).

[1207] Specifically, when collecting personal information, the processor (2430) may determine the basis for the law by using the industry of the collecting company, the purpose of collection, etc., and may use the information (industry, etc.) entered when creating the service.

[1208] The processor (2430) classifies the information into a Personal Information Act classification model, a Credit Information Act classification model, etc. based on the determined law (S3).

[1209] When collecting personal information, the processor (2430) determines the legal basis based on the industry and purpose of collection of the company collecting the personal information.

[1210] FIG. 35 is a diagram illustrating the structure of a proxy label method according to the present disclosure.

[1211] Referring to FIG. 35 (3510), a proxy label method is described.

[1212] The processor (2430) labels only a portion of the entire data (S1).

[1213] The processor (2430) labels the remaining portion of the entire data through inference after model learning (S2).

[1214] The processor (2430) modifies the data after inspection (S3).

[1215] The processor (2430) retrains with the modified data (S4).

[1216] The processor (2430) repeats the above process (S5).

[1217] Country-specific laws can also be added in the future. For example, laws from the United States, the United Kingdom, France, and Germany can be added.

[1218] The processor (2430) trains at least one of the first artificial intelligence model and the second artificial intelligence model by applying a proxy-label method.

[1219] Figure 36 is a diagram illustrating an example of personal information classification according to the present disclosure.

[1220] Referring to Figure 36 (3610), personal information is divided into the Personal Information Protection Act and the Enforcement Decree of the Personal Information Protection Act.

[1221] For example, under the Personal Information Protection Act, unique identification information includes resident registration number, passport number, driver's license number, and alien registration number.

[1222] Personally identifiable information includes mobile phone numbers, email addresses, medical record numbers, health protection numbers, photographs, videos, driver's license serial numbers, account numbers, card numbers, faces, irises, and voices.

[1223] The Enforcement Decree of the Personal Information Protection Act includes Articles 24 and 24-2 of the Personal Information Protection Act, and Article 2, Paragraph 1, A of the Personal Information Protection Act.

[1224] Figure 37 is a diagram illustrating the structure of a personal information classification system according to the present disclosure.

[1225] Referring to Figure 37 (3710), the structure of the personal information classification system is composed of input sentence -> classification model -> logit -> label probability value -> post-processing system -> tag probability value.

[1226] The processor (2430) recognizes personal information items in the sentence by referring to a named entity recognition (NER) task, classifies the recognized personal information items, and predicts whether the sentence includes a personal information item based on the classified personal information items.

[1227] The processor (2430) returns a logit for the input sentence token related to the sentence, determines the label with the highest probability value for each token related to the sentence, and calculates the maximum value according to the dimension of the label.

[1228] Explains the inference formula.

[1229] The model returns the logit for the input sentence tokens.

[1230] Here, the size of the logit is composed of the following mathematical formula 1.

[1231]

[1232] The prediction is composed of the following mathematical formula 2.

[1233]

[1234] The processor (2430) determines the label with the highest probability value for each token.

[1235] The processor (2430) calculates the probability value using the following mathematical expression 3.

[1236]

[1237] The processor (2430) calculates the maximum value along the label dimension.

[1238] Figure 38 is a diagram illustrating a personal information purpose search according to the present disclosure.

[1239] Referring to FIG. 38 (3810), the processor (2430) configures a data set composed of a title and a purpose corresponding to the title.

[1240] For example, if you enter a title into the Elastic Search engine, the processor (2430) searches for similar titles that match.

[1241] The various embodiments of the present disclosure are not intended to list all possible combinations but rather to illustrate representative aspects of the present disclosure, and the matters described in the various embodiments may be applied independently or in combinations of two or more.

[1242] The above-described program may include codes coded in a computer language, such as C, C++, JAVA, or machine language, that can be read by the processor (CPU) of the computer through the device interface of the computer, so that the computer reads the program and executes the methods implemented as a program. Such codes may include functional codes related to functions that define functions necessary for executing the methods, and may include control codes related to execution procedures necessary for the processor of the computer to execute the functions according to a predetermined procedure. In addition, such codes may further include memory reference-related codes regarding which location (address address) of the internal or external memory of the computer should reference additional information or media necessary for the processor of the computer to execute the functions. In addition, if the processor of the computer needs to communicate with any other computer or server located remotely in order to execute the functions, the code may further include communication-related code regarding how to communicate with any other computer or server located remotely using the communication module of the computer, and what information or media to send and receive during communication.

[1243] The above storage medium refers to a medium that stores data semi-permanently and can be read by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, examples of the storage medium include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage device. That is, the program can be stored in various recording media on various servers that the computer can access or in various recording media on the user's computer. In addition, the medium can be distributed across network-connected computer systems, so that computer-readable code can be stored in a distributed manner.

[1244] The steps of a method or algorithm described in connection with the embodiments of the present disclosure may be implemented directly in hardware, implemented as a software module executed by hardware, or implemented by a combination thereof. The software module may reside in a random access memory (RAM), a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable recording medium well known in the art to which the present disclosure pertains.

[1245] While the embodiments of the present disclosure have been described with reference to the attached drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.

Claims

1. In the personal information interest management device that analyzes and manages the user's personal information interest based on behavioral data during the personal information consent process, Input module to collect data; A communication module for transmitting and receiving data with an external device including a mobile device; Memory storing at least one process for managing personal information interests; Including a processor that controls the operation according to the above process, The above processor, Data on the user's actions of viewing the consent form is collected through the above input module, Analyze the above behavior data, Based on the analysis results of the above behavior data, abnormal and normal behavior are determined, Based on the above judgment results, the above behavior data is processed to calculate the level of interest in personal information, Assigning grades based on the calculated personal information interest level. Personal information interest management device.

2. In the first paragraph, the processor, In a situation where consent is obtained that includes at least one of personal information, sensitive information, and advertising information, the above-mentioned behavior data is collected through the above-mentioned input module. Personal information interest management device.

3. In the first paragraph, the processor, Computing the level of interest in personal information by processing the behavioral data based on a combination of the measurement values ​​of the above behavioral data, at least one of the user's geographic location, age, gender and industry characteristics of the service provider. Personal information interest management device.

4. In the third paragraph, the processor, Calculate personal information interest by reflecting weights on the processed above behavior data. Personal information interest management device.

5. In the first paragraph, the processor, The above behavior data including sensitivity judgment items are collected through the above input module, The above sensitivity judgment items include whether or not the consent items have been viewed and user pattern data. The above user pattern data includes at least one of mouse movement, scrolling, scrolling speed, whether the consent form has been completely read, text drag words, text drag ratio, consent page viewing frequency, whether consent check has been changed, whether the consent form has been printed, and whether capture has been made. Personal information interest management device.

6. In the fifth paragraph, the processor, The user's sensitivity is determined by considering whether the above consent items have been viewed and the above user pattern data. Personal information interest management device.

7. In the 6th paragraph, the processor, If the above sensitivity exceeds the preset threshold, the collection of the above behavioral data is stopped, If the above sensitivity is below a preset threshold, a sensitivity report is generated based on the results of collecting the above behavioral data. Personal information interest management device.

8. In the first paragraph, the processor, Monitor the user's consent process corresponding to the above behavior data, Patternize the log process of the above user, and analyze the patternization results of the above log process. Analyze the user's viewing rate regarding the contents of the above consent form, Based on the analysis results of the above patterning results and the above viewing rate, the user sensitivity for subsequent processing is evaluated, Establishing a user management strategy based on the assessed sensitivity; Personal information interest management device.

9. In paragraph 8, the processor When analyzing the above reading rate, the types of users are divided into users who have read the entire document, those who have confirmed consent, and those who have not confirmed consent. Personal information interest management device.

10. In the first paragraph, the processor Collect data for the above items through the input module, Break down the input items into word units, The above broken down words are input into the first artificial intelligence model and analyzed, Based on the analysis results of the first artificial intelligence model, a first prediction is made indicating the possibility of whether the word contains a personal information item, Based on the above first prediction result, the input item is decomposed into sentence units, The above decomposed sentence is input into the second artificial intelligence model and analyzed, Based on the analysis results of the second artificial intelligence model, a second prediction is made indicating the possibility of whether the sentence contains personal information items. Transmitting the first prediction result or the second prediction result to the device of the personal information handler; Personal information interest management device.

11. In the 10th paragraph, the processor If the first prediction result is valid, the first prediction result is transmitted to the user's device, If the above first prediction result is invalid, the input item is decomposed into sentence units. Personal information interest management device.

12. In paragraph 10, The second artificial intelligence model is characterized by being different from the first artificial intelligence model. Personal information interest management device.

13. In the 10th paragraph, the processor The input items are decomposed into word units through word tokenization using morphological analysis. Personal information interest management device.

14. In the 10th paragraph, the processor Training by applying a proxy label method to at least one of the first artificial intelligence model and the second artificial intelligence model, Personal information interest management device.

15. A method for managing personal information interest by analyzing and managing the user's personal information interest based on behavioral data during the personal information consent process performed on the device's processor. A step of collecting data on a user's act of viewing a consent form through the input module; A step of analyzing the above behavior data; A step of determining abnormal and normal behavior based on the analysis results of the above behavior data; A step of calculating personal information interest by processing the above-determined behavior data based on the above-determined results; and Including a step of assigning a grade according to the calculated personal information interest level, How to automate personal information management.

Citation Information

Patent Citations

  • Customer information collecting method and system

    JP2002150153A

  • Service consent confirmation system, terminal used therefor, consent form request program and computer readable recording medium storing consent request program

    JP2004213694A

  • Information processing device, information processing method, and information processing program

    JP2021106061A

  • Question management system, control method of question management service providing device and computer readable medium having computer program recorded therefor

    KR101572473B1

  • Semiconductor package

    KR1020240164225A