Method for transmitting data with selective disclosure
The selective disclosure method for personal data simplifies transactions by separating data access into two stages, ensuring only authorized entities access relevant data, reducing costs and enhancing security and user control.
Patent Information
- Application Number
- PCT/EP2025/053801
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-14
- Filing Date
- 2025-02-13
- Publication Date
- 2025-08-21
AI Technical Summary
Existing methods for transmitting personal data involve multiple stages and entities, leading to inefficiencies, unnecessary data transmission, and increased costs, particularly when intermediary entities are involved, as they often require separate transactions and access to all user data, which is not always necessary.
A method for selective disclosure of personal data involving two separate steps: initial disclosure of 'main' data to an intermediary entity and subsequent disclosure of 'additional' data to the final service provider, ensuring only authorized entities access the relevant data, with a data transmission platform managing these transactions.
This approach simplifies data transactions by reducing unnecessary data transmission and costs, ensuring only authorized entities access the necessary data, thereby enhancing data security and user control.
Smart Images

Figure EP2025053801_21082025_PF_FP_ABST
Abstract
Description
Selective disclosure data transmission method
[0001] The invention relates to the transmission of personal data of a user.
[0002] When a provider of any service, for example a bank, requests the sending of personal data to a user, in particular to justify a personal situation of this user, it is common for the user to obtain this data online through another service provider with which the requested data is stored. For example, this involves the user obtaining proof of address stored with an electricity supplier, the latter supplier then acting as data provider, and sending this proof to the bank. This work of searching for and obtaining personal data by the user from various online data providers, also repeated from time to time for several recipient service providers, is tedious.The work of processing and verifying the transmitted documents by the service provider receiving the documents generates a certain cost and a long delay. In addition, by providing these raw documents, which include a lot of personal data, the user transmits, in addition to the data required by the receiving service provider, additional personal data not required, for example, information relating to their electricity bills, which is inconvenient for them.
[0003] To address these issues, a method for securely transmitting a user's personal data is known in the prior art, according to document FR3091797 in the name of the applicant, in which the user's personal data is accessed from a data provider, the data is minimized by selecting the relevant data, and the relevant data is then transmitted to an online service provider with which the user interacts. Thus, the user's data relevant to the online service provider, and only this relevant data, is selected from the data provider and transmitted directly to the online service provider, without user intervention other than consent, thereby ensuring data reliability, process speed, and user control over their personal data.
[0004] However, it may happen that a transaction involving a user's personal data must be carried out in several stages, in particular through the transmission of some of the user's data in the first instance, then the transmission of other data from the same user in the second instance and possibly only if that user is selected. It may also happen that an intermediary entity, separate from the final service provider, is involved in the transaction and is interested in obtaining certain data but is not intended to be aware of the other user data intended for the service provider.
[0005] For example, when a real estate broker is looking for a rental candidate as a landlord's agent, he obtains data from a large number of candidates, in particular their respective declarations concerning their respective personal situations, and he also obtains the supporting documents for these declarations, such as the respective tax notices of all these candidates. However, he is only intended to study the declarations of the candidates, in order to select a small number of candidates on this basis and to transmit their data to the landlord. In a second step, the landlord is intended to study the evidence, and this only for the candidates selected by the broker on the basis of their declarations.Thus, it is costly and unnecessary for the lessor to settle a transaction involving evidence concerning all candidates when it is not intended to take cognizance of those of the candidates not selected by the broker, just as it is costly and unnecessary for the broker to settle a transaction involving the evidence of all candidates when it is not intended to study them, but only to study their respective declarations. In certain contexts, the intermediary entity and the final recipient entity do not even have, by regulation, the same access rights to a user's data.
[0006] Generally speaking, there are therefore transactions of personal user data involving a data provider, a recipient service provider and an intermediary entity, in which neither the intermediary entity nor the service provider has to know all the data obtained for all users from the data provider, each of these entities being only interested, or even authorized, in obtaining certain data and / or for certain users only.
[0007] One solution to this type of transaction is to perform two separate transactions, one targeting the intermediary entity, and then another transaction, only for certain users and certain data, targeting the actual end service provider. However, this solution is complex to implement and inconvenient for both parties. It notably involves validating two transactions for certain users when they consider themselves to be experiencing a single process. In some cases, this solution also involves transmitting data twice, once to one entity, and again to a second entity, which is costly.
[0008] The invention aims in particular to simplify transactions involving users' personal data, from a data provider to a service provider involving an intermediary entity and to provide adjusted possibilities for settling these transactions for each of the interested parties.
[0009] To this end, the invention relates to a method for transmitting personal data with selective disclosure, implemented by computer and comprising the following steps: - for each user of a set of users, obtaining main personal data and additional personal data of this user from one or more data providers, - main disclosure, to an entity authorized to access the main data, of the main data of the users of the set of users, - additional disclosure, to an entity authorized to access the additional data, of the additional data of the users of a subset of users among the set of users, the subset not comprising all the users of the set.
[0010] "Personal data" means any information relating to a natural person that is intended to remain under their control. This may include, for example, data relating to their income, address, identity, family, profession, etc.
[0011] The user's "main data" is personal data of that user that is intended to be disclosed first and for all users in the user group. This includes data that asserts users' personal situations without demonstrating them. It thus allows an entity, in particular the entity authorized to access the main data, to make a selection between all these users as part of a selection process with at least two stages, for example in the context of selecting a candidate for a property rental. "Additional data" is personal data of the user that is intended to be disclosed at a later stage, and only for a subset of users, in particular for users selected after the disclosure of the main data.This includes data that can be used to further explore the personal circumstances of these users, in particular to substantiate the claims made in the primary data. It is on the basis of this data, or all of the primary data and additional data of the user subset, that one or more users can be selected or move on to the next stage of the selection process.
[0012] The choice of personal data as belonging to the “main data” or to the “complementary data” is made by the user and / or by a third party entity, for example by an entity in charge of implementing the method of the invention, depending on the type of data concerned. In particular, for the same document from a data provider, a main data item and a complementary data item can be deduced. For example, for proof of address from an electricity supplier, the main data item is the home address alone, the complementary data item is the proof itself allowing the source of this address to be authenticated.
[0013] Instead of "main data" and "supplementary data", we could speak of "intermediate data" and respectively of "final data", or more generally of "first data" and respectively of "second data". Corollarily, instead of "main disclosure and "supplementary disclosure", we could speak of "intermediate disclosure" and "final disclosure" or of "first disclosure" and "second disclosure".
[0014] A "data provider" means an entity that makes personal data of the user available to the user. This includes service providers, such as an electricity supplier, a bank, a government website such as the tax office, which make documents, such as an electricity bill, a bank statement or a tax assessment, containing personal data of this user available to the user in connection with the services that these service providers offer. By making these documents accessible to the user, they form data providers within the meaning of the invention. The data are made available, with the consent of the user, to the method of the invention.
[0015] The term "entity authorized to access the main data" refers to any entity, in particular any natural or legal person, authorized by regulation and / or by the user to access the main data of this user. This includes, for example, brokers. In the context of the method of the invention, we could also speak of an "intermediate entity" or more generally of a "first entity".
[0016] The term "entity authorized to access additional data" refers to any entity, in particular any natural or legal person, authorized by regulation and / or by the user to access the additional data of this user. This includes, in particular, service providers requiring the personal data of a limited number of users previously selected by the intermediary entity. In the context of the method of the invention, one could also speak of "final entity", "service provider", "recipient service provider" or more generally of "second entity".
[0017] Thus, each user in a set of users is only affected by a single transaction of all their data. However, this transmission process includes two separate data disclosure steps, which allows some of the data to be disclosed first and other data, for only some of the users, second. An intermediary entity can therefore sort between users after the first disclosure, while a receiving service provider can access the additional data after the second disclosure, and only for the users selected by the intermediary entity. Transactions involving an intermediary entity are therefore simplified and offer new possibilities for controlling access to personal data.In particular, each entity can settle the part of the transaction that concerns it independently of all data transmitted by the data provider.
[0018] "Disclosure" means making the content of data accessible, in a comprehensible manner, to an entity. Conversely, data transmitted in encrypted form to an entity is not considered to be "disclosed" to that entity if that entity does not have the means to decrypt it and therefore access the content "in plain text", that is to say in a comprehensible, readable, decrypted form, of the data. The expression "disclosure in plain text" or "disclosure of data in plain text" could be used.
[0019] Other optional features follow, taken alone or in combination.
[0020] Preferably, the step of obtaining primary personal data and additional personal data of this user from one or more data providers is implemented by a data transmission platform, the data transmission platform being separate from the entity authorized to access the primary data and the entity authorized to access the additional data.
[0021] Thus, the platform allows the process to be implemented; it is a separate entity from the entities directly concerned and interested in the data. In particular, the platform is not intended to use the data other than by transmitting it to the interested entities.
[0022] Advantageously, the main data and the additional data are not disclosed to the data transmission platform.
[0023] In other words, the platform is not authorized to access the content of the main data and the additional data. Thus, the platform obtains this data and discloses it to the relevant entities, but it does not have access to this data itself. Logically, no user or entity controlling the platform can access this data "in the clear," outside of authorized entities.
[0024] Alternatively, the platform has access to the content of this data but is not authorized to disclose this data to a user of the platform outside the authorized entities.
[0025] Thus, the platform can carry out operations based on the content of the data, but their confidentiality with respect to third parties remains assured.
[0026] Advantageously, after the main disclosure, and before the additional disclosure, the method comprises a step of selecting the subset of users.
[0027] Thus, depending on the content of the master data disclosed to the entity authorized to access the master data, only certain users from the set of users are selected to be the subject of the additional disclosure. This selection may, for example, be carried out by the entity authorized to access the master data. It may be carried out via a selection module of a data transmission platform.
[0028] Preferably, the main disclosure is made during a first time period, and the additional disclosure is made during a second time period subsequent to the first time period.
[0029] Thus, for each user, not all of their data is disclosed at the same time. This two-step division makes it possible, for example, to first disclose all the main data for all users in the set, to select a subset of the users in the set based on this main data, and then, in the second step, to disclose the additional data of the users in this subset. This process necessarily involves two distinct time periods associated respectively with the main and additional disclosures.
[0030] Advantageously, at least one additional data item of a user includes proof of an assertion made by at least one main data item of that user.
[0031] Thus, if the main data is a value declared by the user, the additional data is, for example, an official document or one from a company recognized as reliable, repeating this value, demonstrating the correctness of the main data.
[0032] Preferably, the entity authorized to access the main data and the entity authorized to access the additional data are two separate entities.
[0033] Thus, the first is for example a broker, the second for example a lessor whose purpose is only to take cognizance of the personal data of the candidates selected by the broker.
[0034] Advantageously, the entity authorized to access the main data is not authorized to access the additional data, and / or the entity authorized to access the additional data is not authorized to access the main data.
[0035] Thus, these authorization constraints may come from the user and / or be regulatory. For example, the user may only want to make their supporting documents accessible to a lessor and not to a real estate broker. These constraints help to reinforce data minimization, by only disclosing the data to interested entities and not to any other entity. This implies in particular that an entity collecting data can only access it if it is authorized to do so.
[0036] Alternatively, the entity authorized to access the main data and the entity authorized to access the additional data are one and the same entity.
[0037] For example, a service provider first studies the main data of all candidates to select a subset, before studying the supporting documents, i.e. the additional data, of only the candidates in the selected subset.
[0038] Preferably, to carry out the disclosure of a user's additional personal data to the entity authorized to access the additional data, the following steps are implemented: - requesting the user's consent for the disclosure of his or her additional personal data to the entity authorized to access the additional data; - obtaining the user's consent.
[0039] Thus, before the additional disclosure step, the user's consent for this additional disclosure is requested and obtained. The user can thus freely decide whether or not he agrees to disclose his additional data.
[0040] Preferably, the method comprises, before requesting consent, a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent, a step of obtaining the user's consent for some or all of the entities on the list.
[0041] Thus, the user can provide consent only to certain previously identified entities. This identification can be carried out by the entity authorized to access the main data.
[0042] Advantageously, at least one of the disclosure steps among the main and additional disclosures, preferably both the main and additional disclosure steps, are carried out in return for remuneration granted directly or indirectly to an organizing entity making the process available to users, to the entity authorized to access the main data and to the entity authorized to access the additional data, the organizing entity being for example a data transmission platform.
[0043] Thus, the organizer of the process is remunerated by the process actors based on the data disclosed to each of the entities. This remuneration can, for example, be made directly by the main or complementary entities concerned by the data disclosures.
[0044] Preferably, the method comprises, after the step of obtaining the main data and the complementary data of the users, for each user of the set of users, a step of forming a digital token of authenticity of the user, the digital token of authenticity of the user comprising the main personal data of this user and the complementary personal data of this user, this token of the user certifying the authenticity of these main data and these complementary data of this user, and in which the main disclosure is carried out by providing, to the entity authorized to access the main data, access to the main data of the tokens of the users of the set of users, and the complementary disclosure is carried out by providing, to the entity authorized to access the complementary data,access to additional data from the tokens of users in the user subset.,
[0045] Thus, this token is the digital equivalent of a paper certificate containing the data, certifying the authenticity of the data and the user's consent to the sharing of this data. This token ensures the integrity of the data and allows its disclosure to authorized entities in a simple and efficient manner.
[0046] Advantageously, the method comprises the following steps: - for each user of the set of users, after the step of obtaining the data: **encryption of the additional personal data of the user, such that the user's authenticity token comprises the user's main personal data in clear text and the user's additional data in encrypted form; **upon the main disclosure of this user's main data to the entity authorized to access the main data, disclosure of the main data in clear text and the encrypted additional data; - for each of the users of the subset of users for which the additional data is disclosed, to disclose this additional data to the entity authorized to access the additional data, decryption of this additional data.
[0047] So the token includes all the data, and the entity authorized to access the main data can access the contents of this token, but the additional data is encrypted in it, so that only the entity authorized to access the additional data can read it.
[0048] Preferably, the digital authenticity token is a token that meets the standard called “JSON Web Token”.
[0049] This standard allows for the secure exchange of tokens between multiple parties, in this case between the data provider and the entities. This secure exchange is achieved by verifying the integrity and authenticity of the data.
[0050] Advantageously, the entity authorized to access the main data is at least one of the following types: **a mortgage or insurance broker; **a real estate agent; **a car dealership advisor
[0051] and the entity authorized to access the additional data is at least one of the following types:** a lessor;** an insurance agent;** a bank.
[0052] The invention also provides a computer program comprising instructions which, when the program is executed by a computer, cause the latter to implement the steps of the method described above.
[0053] Also provided according to the invention is a computer-readable recording medium comprising instructions which, when executed by a computer, cause the latter to implement the steps of the method described above.
[0054] The invention also provides a data transmission platform, comprising:- a module for obtaining main personal data and additional personal data of users of a set of users from one or more data providers,- a module for the main disclosure, to an entity authorized to access the main data, of the main data of the users of the set of users,- a module for the additional disclosure, to an entity authorized to access the additional data, of the additional data of the users of a subset of users from among the set of users, the subset not comprising all the users of the set.
[0055] A "personal data transmission platform" means a digital platform, therefore implemented by computer means, serving as a trusted third party between users, providers of personal data for these users, and entities authorized to access some or all of this personal data. It is made up of computer modules responsible for specific tasks such as obtaining data from data providers and disclosing it to entities. It may include one or more interfaces accessible online, allowing, for example, a user to provide consent to the transmission of their data. Brief description of the figures
[0056] The invention will be better understood on reading the following description, given solely by way of example and with reference to the appended drawings in which:
[0057] is a diagram of a data transmission system according to one embodiment of the invention;
[0058] is a diagram of a data transmission method according to an embodiment of the invention. Detailed description
[0059] A selective disclosure data transmission system 1 according to an embodiment of the invention is shown. The system 1 aims to obtain and transmit, in a first step, main data 2 of a set 3 of users to a real estate broker 4, which forms an entity authorized, by the users of the set 3, to access this main data 2. This main data 2 is formed of information relating in particular to the income of the users of this set 3 of users. The system 1 aims to transmit, in a second step and for a subset 5 of these users, smaller than the set 3, that is to say not including all the users of the set 3, additional data 6 of the users of this subset 5, to a real estate lessor 8, which forms an entity authorized to access the additional data 6, after selection of the subset 5 by the broker 4.These additional data are notably formed by the tax notices of the users of subset 5, which form the proof of the income indicated in the main data 2. In other words, the additional data 6 of the users includes the proof of the assertions made by the respective main data of these users. The broker 4 and the lessor 8 form two separate entities.
[0060] Alternatively, additional data 6 may contain information other than evidence of the main data 2. This may involve, for example, providing details about the user, details not provided by the main data.
[0061] System 1 comprises providers 7 of personal data of users of set 3. Each of these data providers is associated with a respective database 9. Although the providers share the same numerical reference 7 and the associated databases respectively share the same numerical reference 9, each of the providers is distinct from one another and the databases are distinct from one another. For example, these providers 7 are an electricity supplier, a website of the tax department, a website of a primary health insurance fund, a website of a mutual health insurance company. In this example, we will focus on the tax department, each having online spaces specific to their users. Each of the providers provides the data of a user of set 3. Alternatively, a provider provides the data of several, or even all, users of set 3.For example, the tax department provides the tax notices of each of the users in set 3.
[0062] System 1 includes a selective disclosure data transmission platform 11.
[0063] The platform 11 comprises computer means 15 for implementing various computer modules described below. These means include in particular a processor 12 and a memory 13 conventional for those skilled in the art. The memory is formed of a computer-readable recording medium 13. This recording medium comprises a computer program 14 comprising instructions which, when the program is executed by a computer, here by the processor 12, cause the latter to implement the steps of the method 100 described below. In other words, considering the computer-readable recording medium 13 or any other medium on which the program 14 is written, this medium 13 comprises instructions which, when executed by a computer, here by the processor 12, cause the latter to implement the steps of the method 100. The data transmission platform is separate from the broker 4 and the lessor 8.It is also separate from Data Provider 7.
[0064] The computer modules described below make it possible to implement the method 100 described below.
[0065] The platform 11 comprises a module 16 for obtaining the main personal data 2 and the additional personal data 6 of the users of the subset 3 from the suppliers 7, that is to say in particular from the tax department on the online spaces of each of the users. The module 16 is configured to obtain the amount of a reference income of each user of the set 3 and consider it as a main data 2 of each of these users. This module 16 is also configured to classify the tax notice itself as an additional data 6 forming the proof of the main data 2 for each of these users. Other forms of main data are possible.For example, alternatively, the main data is a statement of the type "the reference income of this user is greater than X euros", X being a threshold configurable by a third party, the module obtaining this information from the tax notice. Similarly, alternatively, the additional data is not the tax notice itself but another proof document certifying that the income exceeds a reference threshold. Finally, naturally, for each user, other types of main and additional data, associated for example with their address, can be obtained if necessary.
[0066] The platform 11 comprises a data encryption module 18 for encrypting the complementary data 6 of the users of the set 3 of users.
[0067] The platform 11 comprises a module 20 for forming respective authenticity tokens 22 of each user of the set 3 of users, the digital authenticity token 22 of a user comprising the main personal data of this user and the additional personal data in encrypted form of this user, this token 22 of the user certifying the authenticity of these main data and these additional data of this user. Each token therefore comprises the main data 2 and additional data 6 of a single user of the set 3 of users. In addition, each token comprises a means of contacting the user, for example an email address or a telephone number of the user.
[0068] The platform 11 includes a main disclosure module 24, to an entity authorized to access the main data 2, therefore here to the real estate broker 4, the main data 2 of the users of the set 3 of users.
[0069] The platform 11 comprises a module 26 for selecting a subset 5 of users from the set 3 of users. This module 26 notably provides an interface available to an entity authorized to carry out the selection, in particular for the broker 4 or generally for the entity authorized to access the main data of the users, the interface allowing this entity to carry out this selection.
[0070] The platform 11 includes a module 28 for additional disclosure, to an entity authorized to access the additional data, therefore here to the lessor 8, of the additional data 6 of the users of the subset 5 of users among the set 3 of users.
[0071] We will now describe the method 100 for transmitting personal data with selective disclosure, implemented by the platform 11.
[0072] Step 101 is, for each user of the set 3 of users, obtaining the main personal data 2 and the additional personal data 6 of this user from one or more data providers 7, in our example in particular from the personal spaces of the users within their online spaces with the tax department. This step 101 is implemented by the module 16 for obtaining this data, which assigns the “main” or “additional” character to the data obtained depending on their content. In particular, no user of the platform other than the broker 4 and the lessor 8 has access to the data. Alternatively, this choice is made by the user or by a third-party entity, for example an entity in charge of the platform 11.
[0073] Alternatively, the platform 11, including the data obtaining module 16, does not have access to the content of the data. The choice of the “main” or “complementary” nature of the data is then made automatically based on a type of data or by a third-party entity.
[0074] Step 102 is, for each user of the set 3 of users, a step of encryption of the additional personal data 6 of the user. This step is implemented by the encryption module 18.
[0075] Step 103 is, for each user of the set 3 of users, a step of forming the digital authenticity token 22 of the user. This digital authenticity token 22 is a token meeting the standard called “JSON Web Token”. This authenticity token 22 of the user includes the main personal data 2 of the user in clear text and the additional data 6 of the user in encrypted form. This step also includes the integration of a means of contact, for example an email address or a telephone number, of the user. This step is implemented by the formation module 20 of the token 22.
[0076] Step 104 is the main disclosure, to the broker 4, and generally to an entity authorized to access the main data, of the main data 2 of the users of the set 3 of users. This main disclosure is carried out by providing, to the entity authorized to access the main data, access to the data of the tokens 22 of the users of the set 3 of users. The main data 2 are disclosed in clear text and the additional data 6 are disclosed in encrypted form, so that the entity authorized to access the main data cannot become aware of the additional data 6 in clear text. This main disclosure is carried out during a first period of time.It is carried out in return for remuneration granted to the platform 11, and more particularly to the organizing entity making the platform 11 and therefore the process 100 available to the users of the set 3, the broker 4 and the lessor 8. Thus, the broker 4 remunerates the platform 11, by regulation when the data are disclosed, by a non-illustrated interface of the platform. This remuneration can be carried out by other means and at other times.
[0077] Step 105 is the selection, by the broker 4, of a subset 5 of users not including all the users of the subset 3. This step is carried out by the broker 4 itself, through an interface of the selection module 26. Alternatively, this step could be carried out by other means.
[0078] Step 106 is, for each user of subset 5 of selected users, the request from the user for consent for the disclosure of his additional personal data 6, to the lessor 8 and generally to an entity authorized to access the additional data.
[0079] Step 107 is obtaining user consent for this additional disclosure.
[0080] These steps 106 and 107 are implemented through a non-illustrated interface of the platform 11. In particular, the user has a personal account on the platform 11, which allows him to confirm or not his consent. Alternatively, these steps are implemented by other means, for example by SMS or by email. The request for consent is sent to the user's contact means integrated into his token.
[0081] Step 108 is the additional disclosure, to the lessor 8, that is to say to an entity authorized to access the additional data 6, of the additional data 6 of the users of the subset 5 of users among all the users. This step is implemented by the additional disclosure module 28. To do this, for each of the users of the subset 5 of users for whom the additional data 6 are disclosed, the module 28 performs the decryption of these additional data 6 for the lessor 8 and for the lessor 8 only when only the lessor 8 is the entity authorized to access the additional data 6. The decrypted additional data 6 are therefore made accessible to the lessor 8 only via an interface of the additional disclosure module, the broker 4 not having access to these additional data 6 in clear.This disclosure is made during a second period subsequent to the first time period. This disclosure is also made in return for remuneration granted to the platform 11. This remuneration is made by the lessor 8. Alternatively, it is made by another entity, for example by the broker 4, who then re-invoices the invoiced amount to the lessor 8.
[0082] Alternatively, one or both compensation steps may not occur.
[0083] The invention is not limited to the embodiments presented and other embodiments will become apparent to those skilled in the art.
[0084] In particular, certain steps described in the presented embodiment are not implemented in all the embodiments envisaged. The request for consent from the user and consequently the integration of a means of contacting the user in the token are, for example, advantageous optional steps in certain application cases, when the user wishes for example greater control over the disclosure of his data.
[0085] In a variant corresponding to a case potentially comprising several entities authorized to access the additional data, before step 106 of requesting consent, the method 100 comprises a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent in step 107, a step of obtaining the user's consent for some or all of the entities on the list. The identification step is carried out for example by the broker 4, who identifies several potential real estate agencies for candidates looking for rental, for example. In a sub-variant, if the list is not defined, all the real estate agencies registered on the platform 11 and authorized by default to access the additional data can access it.
[0086] Similarly, alternative steps to tokenization and / or encryption of additional data could be implemented to disclose the data to authorized entities. These steps are nevertheless advantageous in terms of simplicity and security of data transmission.
[0087] Some steps involve access configurations that could be different. In particular, in the embodiment presented, the entity authorized to access the main data is not authorized to access the additional data, and the entity authorized to access the additional data is not authorized to access the main data. However, as a variant, the entity authorized to access the main data is authorized to access the additional data, and / or the entity authorized to access the additional data is authorized to access the main data, all combinations being possible.
[0088] Furthermore, as a variant, the entity authorized to access the main data and the entity authorized to access the additional data are one and the same entity. For example, the lessor 8 performs the selection itself instead of the broker 4. This process remains advantageous for the lessor 8 at least in economic terms because the lessor 8 only becomes aware of and pays for the additional data of the users it has selected after the main disclosure.
[0089] Furthermore, alternatively, further disclosure steps are provided, possibly to other authorized entities, during other respective time periods.
[0090] Furthermore, although the examples used were a real estate broker and a landlord, any entity is possible. As other non-limiting examples, the entity authorized to access the main data could be an insurance broker or a real estate agent, while the entity authorized to access the additional data could be an insurance agent or a bank. Similarly, the entity authorized to access the main data could be a car dealership advisor, for example, located in a small village. Indeed, although they collect a lot of personal data, they do not need to have access to certain data. Data providers can also be of any type.
[0091] Finally, it is noted that in the embodiment presented, all the users of the set 3 are the subject of the main disclosure step of their main data 2, and all the users of the subset 5 are the subject of the additional disclosure step of their additional data 6. However, as a variant, only a first subset of the set 3 is the subject of the main disclosure step of the main data, then a subset of users of this subset, that is to say a second subset of users, originating from the first subset of users and not including all the users of the first subset, is the subject of the additional disclosure step. List of references
[0092] 1: Data transmission system2: Main personal data3: User set4: Real estate broker / Entity authorized to access main data5: User subset6: Additional personal data7: Data provider8: Landlord / Entity authorized to access additional data9: User database11: Data transmission platform12: Processor13: Computer-readable recording medium14: Computer program15: Computer means16: Personal data obtaining module18: Encryption module20: Digital authenticity token formation module22: Digital authenticity token24: Main disclosure module26: Selection module28: Additional disclosure module100: Data transmission method
Claims
Method (100) for transmitting personal data with selective disclosure, implemented by computer and characterized in that it comprises the following steps: - for each user of a set (3) of users, obtaining (101) main personal data (2) and complementary personal data (6) of this user from one or more data providers (7), - main disclosure (104), to an entity (4) authorized to access the main data, of the main data (2) of the users of the set (3) of users, - complementary disclosure (108), to an entity (8) authorized to access the complementary data, of the complementary data (6) of the users of a subset (5) of users among the set (3) of users, the subset (5) not comprising all the users of the set (3). Method (100) according to the preceding claim, wherein the main disclosure (104) is carried out during a first period of time, and the complementary disclosure (108) is carried out during a second period subsequent to the first period of time. Method (100) according to one of the preceding claims, in which at least one complementary data item (6) of a user comprises proof of an assertion made by at least one main data item (2) of this user. Method (100) according to any one of the preceding claims, in which the entity (4) authorized to access the main data and the entity (8) authorized to access the complementary data are two separate entities. Method (100) according to the preceding claim, in which the entity (4) authorized to access the main data is not authorized to access the complementary data (6), and / or the entity (8) authorized to access the complementary data is not authorized to access the main data (2). Method (100) according to any one of claims 1 to 3, in which the entity authorized to access the main data and the entity authorized to access the complementary data are one and the same entity. Method (100) according to any one of the preceding claims, in which, to carry out the disclosure (108) of the additional personal data of a user to the entity authorized to access the additional data, the following steps are implemented: - request (106) from the user for consent for the disclosure of his additional personal data (6) to the entity (8) authorized to access the additional data; - obtaining (107) the user's consent. Method (100) before the preceding claim, comprising, before requesting consent, a step of identifying a list of entities authorized to access the additional data, and, upon requesting consent, a step of submitting the list to the user, and, upon obtaining consent, a step of obtaining the user's consent for some or all of the entities on the list Method (100) according to any one of the preceding claims, in which at least one of the disclosure steps (104, 108) among the main (104) and complementary (108) disclosures, preferably both the main and complementary disclosure steps, are carried out in return for remuneration granted directly or indirectly to an organizing entity making the method available to users, to the entity authorized to access the main data and to the entity authorized to access the complementary data, the organizing entity being for example a data transmission platform. Method (100) according to any one of the preceding claims, comprising, after the step of obtaining (101) the main data (2) and the complementary data (6) of the users, for each user of the set (3) of users, a step of forming (103) a digital authenticity token (22) of the user, the digital authenticity token (22) of the user comprising the main personal data (2) of this user and the complementary personal data (6) of this user, this token (22) of the user certifying the authenticity of these main data and these complementary data of this user, and in which the main disclosure (104) is carried out by providing, to the entity (4) authorized to access the main data (2), access to the main data (2) of the tokens (22) of the users of the set (3) of users, and the complementary disclosure (108) is carried out by providing,to the entity (8) authorized to access the additional data (6), access to the additional data (6) of the tokens (22) of the users of the subset (5) of users., Method (100) according to the preceding claim, comprising the following steps:- for each user of the set (3) of users, after the step of obtaining (101) the data:**encryption (102) of the complementary personal data (6) of the user, such that the authenticity token (22) of the user comprises the main personal data (2) of the user in clear text and the complementary data (6) of the user in encrypted form;**during the main disclosure (104) of the main data (2) of this user to the entity (4) authorized to access the main data (2), disclosure of the main data in clear text and of the encrypted complementary data;- for each of the users of the subset (5) of users for which the additional data (6) are disclosed, to disclose this additional data (6) to the entity (8) authorized to access the additional data, decryption of this additional data (6).; Method (100) according to claim 10 or 11, wherein the digital authenticity token (22) is a token meeting the standard called “JSON Web Token”. Method (100) according to any one of the preceding claims, in which:- the entity authorized to access the main data is of at least one of the following types:**a mortgage or insurance broker;**a real estate agent;**a car dealership advisor;- the entity authorized to access the additional data is of at least one of the following types:** a lessor;** an insurance agent;** a bank. A computer program (14) comprising instructions which, when the program is executed by a computer, cause the computer to implement the steps of the method (100) according to any one of the preceding claims. A computer-readable recording medium (13) comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method (100) according to any one of claims 1 to 13. Data transmission platform (11), characterized in that it comprises:- a module for obtaining (16) main personal data (2) and additional personal data (6) of users of a set (3) of users from one or more data providers (7),- a main disclosure module (24), to an entity (4) authorized to access the main data, the main data (2) of the users of the set (3) of users,- a complementary disclosure module (28), to an entity (8) authorized to access the complementary data, the complementary data (6) of the users of a subset (5) of users among the set (3) of users, the subset (5) not comprising all the users of the set (3).
Citation Information
Patent Citations
Advanced secure personal data transmission platform
FR3091797A1
Method for automatically updating a user's data
FR3116134A1
Systems and methods for managing tokens and filtering data to control data access
US11379614B1