System and methods of automated collection, decentralised storage, access control and secure usage of personal data related to subscribers of internet service providers

A decentralized system using one-time identifiers and federated data storage addresses privacy and market domination issues in digital advertising, enhancing user privacy and advertising relevance while improving publisher revenues.

WO2026035239A1PCT designated stage Publication Date: 2026-02-12MOROZENKO VITALII
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/UA2024/000044
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-07
Filing Date
2024-08-12
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing digital advertising methods face challenges in protecting user privacy, ensuring effective communication between advertisers and clients, finding relevant new customers, and transparent monetization of content, while avoiding market domination by tech giants that control large amounts of personal data.

Method used

A decentralized system using one-time identifiers and federated data storage to collect, manage, and utilize personal data from internet service providers, ensuring anonymity and secure access control, preventing cross-border data transfers, and eliminating unauthorized data use.

Benefits of technology

Enhances user privacy, increases advertising relevance, and improves publisher revenues by allowing secure, scalable data utilization without centralization, reducing dependence on tech giants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure UA2024000044_12022026_PF_FP_ABST
    Figure UA2024000044_12022026_PF_FP_ABST
Patent Text Reader

Abstract

An invention relates to systems and methods for collecting, storing and managing access to behavioural personal data of internet service providers' subscribers. The invention can be used to provide advertising targeting during automated bidding for digital media advertising space (oRTB bidding). A proposed system of the secure automated collection of personal data and automated control of access to electronic personal data is based on installing specific software parts of the system into the telecommunication companies, data vendors' and advertisers' servers. It also contains modules in the form of programming codes for integration into websites and / or mobile applications of publishers and advertisers. The system utilises various identifiers related to the similar user and uses for various participants as well as one-time identifiers for secure transactions within participants. A method for secure automated collection of personal data by using the system is also proposed as well as a method for connecting previously collected personal data to the system aiming for secure usage of personal data, automated management and targeting personalised ad impressions to the subscribers of telecommunication companies that install appropriate module of the system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHODS OF AUTOMATED COLLECTION, DECENTRALISED STORAGE, ACCESS CONTROL AND SECURE USAGE OF PERSONAL DATA RELATED TO SUBSCRIBERS OF INTERNET

[0002] SERVICE PROVIDERS

[0003] TECHNICAL FIELD

[0004] The invention relates to systems and methods for collecting, storing and automated usage of behavioural personal data related to internet service providers’ subscribers. The invention can be used to serve targeted advertising within programmatic bidding to the publishers’ advertising inventory.

[0005] TERMS AND CONCEPTS

[0006] The terms and concepts used to describe the invention have the following interpretation.

[0007] Programmatic advertising is an automated real-time process for selling and buying ad spaces. It enables ads to be served to relevant audiences on various websites and mobile applications using advertising solutions.

[0008] Adtech Solutions is a technology services that allow Publishers and Advertisers to participate in the programmatic advertising market.

[0009] Traffic monetisation solutions are technological services (e.g., Supply- Side Platforms, Header-bidding platforms, native ads networks) that allow Publishers to monetise Internet traffic by connecting available ad spaces to the programmatic marketplace. Such solutions perform online auctions on behalf of a Publisher and ensure the maximisation of revenue from each individual ad impression served to End Users.

[0010] Ad buying solutions (Demand Side Platforms) are a technological service that allows Advertisers to win the ability to serve ad impressions along with Publishers’ content within the programmatic market and in accordance with the ad campaign parameters defined by the Advertiser set in such service. Such parameters allow effectively managing advertising strategies by setting the Advertiser’s quantitative limits of the number of impressions per user, the relevant audience, the price the Advertiser agrees to pay for every ad impression, the advertising creative itself (banner or video) and other ad campaign parameters.

[0011] Electronic data is information presented in digital form in the form of digital characters, graphic symbols, video, sound data, or combinations thereof. This term does not refer to the semantic content of personal data but only to its form of use.

[0012] Telecom is a mobile or fixed-line internet services provider that provides telecommunication services connecting subscribers’ devices to the Internet.

[0013] End User means an individual who consumes content and generates traffic by visiting websites and / or using mobile applications of Advertisers and Publishers by using an electronic device that is connected to the internet through telecommunication service from internet service providers.

[0014] End User’s device - any device known today (mobile phone, personal computer, tablet, laptop) and existing in the future that contains a technical means of processing electronic data (e.g. processor), a means of storing electronic data (HDD, SSD, etc.), a means of visualising electronic data (screen, monitor, etc.), a means of exchanging electronic data (e.g. technical means of data transmission via IP protocols, WiFi, Bluetooth, etc.).

[0015] Advertisers are companies (FMCG brands, e-commerce, retailers, SME, etc.) that aim to communicate with an existing audience (retargeting) and attract a new relevant audience (targeting) by performing advertising campaigns.

[0016] Publishers are content creators (e.g. websites, digital media, games, apps) that generate internet traffic and are willing to monetise it by serving ads to audiences. Data Vendors are retailers, Telecoms, and any other companies that collect consented first-party data by providing services to End Users and who are willing to use this data for their own use or for data collaborations with other companies.

[0017] First-party data is the End User’s personal data that is collected by the services he / she uses (mobile applications, websites, telecommunications service providers, publishers, etc.) in accordance with his / her explicit consent to receive a given service.

[0018] End Users’ identifying parameters are identifiers that the Data Vendor uses to collect and profile collected personal data. Such parameters may include a phone number or email address obtained during authentication / registration for the Data Vendor’s service.

[0019] BACKGROUND

[0020] The digital advertising industry faces a number of challenges related to: protecting the personal data of End Users and not interfering with their privacy; maintaining effective communication between advertisers and their clients; finding relevant new customers for businesses; ensuring transparent monetisation of content in the programmatic advertising market by Publishers; and avoiding the domination on the market by few tech giants that leverage control of large amounts of personal data.

[0021] The digital advertising market uses real-time auctions (oRTB) for targeted ad serving, where ad-buying solutions acting on behalf of the Advertiser offer appropriate bids for the display of advertising to each individual End User when he / she visits the Publisher's website or mobile application that is connected to the programmatic market through traffic monetisation solutions. Thus, a key element of the ad serving effectiveness and the level of advertising revenues of Publishers is driven by the technical ability to identify an End User precisely, as well as the ability to tailor offers to an End User’s needs, which is directly depend on accessible behavioural data of End Users. Currently, there are several alternative solutions that enable communication between Advertisers and End Users when they visit the websites or mobile applications of Publishers.

[0022] 1. Traditional user identification methods used in digital advertising

[0023] Currently, there are several alternative solutions that ensure the identification of End Users when they visit the resources of the Publishers. The main alternative methods of identification are:

[0024] - Third-party cookies are identifiers that are uncontrollably set by companies and Internet services in End Users' web browsers, enabling End Users identification while they consume Internet content across different web pages. The essential issue with this identification method is the vulnerability of users' privacy. Currently, third-party cookies are blocked in most secure web browsers. Consequently, such a method cannot identify a large part of the Publishers' web traffic, decreasing its value for Advertisers and, as a result, negatively affecting the Publishers' revenues.

[0025] - Mobile device identifiers - used for End Users identification and ad serving within mobile applications. In devices running the Android operating system, this is the Android ID (AID), and in Apple devices, this is Apple's ID for advertising (IDF A). The main disadvantage of this identification method is the vulnerability of users’ privacy due to the uncontrolled dissemination of their personal data by mobile applications. Due to the vulnerability of users’ privacy, Apple has restricted uncontrolled access of mobile application developers to the IDFA, while preventing user identification and decreasing the advertising monetisation of these applications on Apple devices.

[0026] - Identification systems based on email addresses, which are obtained during user authentication (registration) on each individual website or mobile application. This method is not applicable to non-authenticated (transient) users or to authenticate users of Apple mobile devices where email-hashing protection during registration in mobile applications is available. Therefore, the majority of internet traffic is invisible for such identification methods and cannot provide a feasible method to cover the needs of the market.

[0027] - Probabilistic identification is an identification method that is based on collecting digital fingerprints of individuals from their devices and internet browsers (IP addresses, WiFi networks, browser version, screen resolution, etc). The collected end user's data is processed for the purpose of further algorithmic assumptions to identify users across the internet. The use of this method poses a threat of violation of the individuals’ privacy rights due to the fact that their data is collected without their transparent consent. In order to ensure a high level of privacy for their End Users, web browsers and mobile operating systems are constantly reducing the amount of freely available users’ data, which in turn reduces the efficiency and quality of probabilistic identification and, as a result, negatively affects the advertising revenues of Publishers.

[0028] To overcome the disadvantages of the above identification methods, they can be combined into identity graphs containing interlinks of different identifiers related to the same individual. However, the use of these identity graphs by various Internet services leads to uncontrolled exposure of the individual's personal data and non-compliance of such solutions with personal data protection legislation in many countries.

[0029] 2. Traditional solutions for the collection and use of End Users’ behavioural data used to personalise advertising offers when placing targeted advertising.

[0030] DMPs (Data Management Platforms) - aggregate large amounts of individuals’ behavioural data collected by various services that they use (e.g. mobile applications) and open access to data insights for the Adtech solutions aiming to create performing targeted advertising. The mutual exchange of data, both when collecting and aggregating data and when accessing data from digital advertising market participants, is performed using the identification methods described above. The disadvantage of this approach is the violation of individuals' privacy rights due to the constant exchange of third-party data without explicit consent. The tightening of legislation on the protection of users’ data privacy rights in most countries of the world has led to the non-compliance of these technical solutions with the requirements of the law and to the corresponding prohibition of data collection from citizens of the respective countries. In addition, these services use centralised storage of personal data and, as a result, execute permanent cross-border data transfers of personal data, which is illegal under personal data protection laws in the European Union and many other countries.

[0031] - Proprietary advertising services from Google and Meta - created using behavioural data collected by their services (Google Search, YouTube, Facebook, Instagram). Given the popularity of these services and mostly all End Users authenticated on these services, they do not need to collect behavioural data from other services and mobile applications relying only on their own behavioural data, avoiding the issue of third-party data sharing described in the previous method. As a result, Google and Meta hold a unique dominant position within the advertising market and control ad serving also outside their own services, controlling a large market share even when digital advertising is placed on third-party websites and mobile applications. The disadvantages of this method are the conflict of interest of Google and Meta, which simultaneously control online auctions for advertising on their own websites and mobile applications, and on the other hand, technologically moderate the placement of advertising on websites and mobile applications of third-party Publishers. Another issue of these services is an inability to apply controlled behaviour data on non-visible Publishers' traffic that is not identifiable because of the challenges to identifying non-authenticated traffic described above. In addition, Google and Meta use centralised data storage to execute permanent cross-border data transfer of personal data that is illegal under personal data protection laws in the European Community and many other countries.

[0032] - Contextual advertising is driven by behaviour data collected by every given Publisher during previous user visits. The main disadvantages of this method are the critical limitations of the amount of behavioural data collected by the Publisher, which significantly affect the value of advertising impressions for the Advertiser and, as a result, significantly limit the advertising revenues of the Publishers. In addition, this method makes it impossible to quantify the number of advertising views for each individual when he / she visits websites and uses mobile applications owned by different Publishers.

[0033] - Data Clean Rooms are solutions that execute secure data collaboration between companies that have previously collected behavioural data. Data insights obtained from such direct data collaborations can be utilised for ad targeting within ad inventory owned by one of the collaborating companies. The essential disadvantage of this method is the barrier to using the data insights to display advertisements outside collaborating companies' websites or mobile applications. Hence, this method cannot provide the required programmatic market scale.

[0034] SUMMARY

[0035] The invention is based on the task of creating a method for secure automated collection, access control and usage of personal data related to subscribers of internet service providers (hereinafter Telecom). Using personal data is aimed to tailor personalised advertising communication to individuals (hereinafter End User) who consume content created by Publishers without disclosing the person to whom the data belongs, as well as preventing personal data exposure across the web. The claimed system and methods overcome the disadvantages of the solutions discussed above, provide high security and efficiency in the process of identifying End Users when they visit websites and mobile applications, allow connecting first-party data and controlling secure access to it, ensure unified use of personal data from different sources and secure data collaborations between system participants in order to increase the personalisation of advertising impressions and the Publishers' ad revenues. At the same time, the system and methods claimed in the invention use federated (decentralised) personal data storage on the servers of the system participants and avoid centralised storage of End User personal data, which prevents any cross-border data transfer risks, as well as eliminates the risks of unauthorised physical access to personal data.

[0036] An additional task of the invention is to increase the security of the End User's personal data and his / her anonymity when visiting websites and using mobile applications by avoiding the usage of static identifiers (third-party cookies, email addresses and mobile device identifiers). The system and methods according to the invention use one-time End User identifiers, which are used to link personal data to a specific End User and do not identify the identity of this individual while do not disclosing his / her personal data even through the components of the system, as well as to other persons outside the system.

[0037] According to a first aspect of the present invention, a system for automated usage, access control and collection of personal data related to an individual (End User) who is a subscriber of a mobile or fixed-line internet service provider (Telecom) is proposed. The system comprises a) a device of the End User connected to the internet equipped with a processor, a means of storing electronic data, a means of visualising electronic data, a means of exchanging electronic data; b) an End User identification module installed on a server of at least one Telecom connected to the internet and configured to: determining the End User’s internal identifier provided by the Telecom and stored on the Telecom’s server in response to requests from an End User’s identification initiation module; initialisation of first-party data downloaded to the data storage and management modules, performed by replacing End Users’ identifying parameters with End Users’ identifiers associated with Data Vendors and / or Advertisers corresponding to End Users’ internal identifiers provided by the Telecom; generating one-time End Users’ identifiers linked to the End User internal identifier provided by the Telecom; c) a first-party data storage and management modules configured to collect first-party data and / or download previously collected outside the system first-party data, wherein the module is installed on a server connected to the internet of at least one Data Vendor, and the module is installed on a server connected to the internet of at least one Advertiser; d) the End User identification initiation module configured to initiate an End User’s device identification and integrated as a programming code into at least one website and / or mobile application of an Advertiser, and / or at least one website and / or mobile application of Publisher that is connected to the at least one traffic monetisation solution; e) an anonymised data access module integrated into at least one ad buying solution and configured to send requests to a request dispatcher for decryption of one-time End User's identifiers and / or for obtaining anonymised analytical information related to the one-time End User’s identifiers; f) the request dispatcher is software installed on a remote server connected to the internet that includes electronic data storage and a processor configured to: registration of Publishers, Advertisers, Data Vendors, advertising technology solutions, including traffic monetisation solutions and ad buying solutions; processing requests from the anonymised data access module, including requests for decryption of one-time End User’s identifiers; creation of new data segments in the form of a list of one-time End Users’ identifiers in response to the Advertiser's request to create a list of End Users who meet the behavioural characteristics specified by the Advertiser; sending the newly created data segments in the form of a list of one-time End Users’ identifiers to the ad buying solution chosen by the Advertiser; generating End Users’ identifiers associated with the anonymised data access module and / or the first- party data storage and management modules.

[0038] According to a second aspect of the present invention, a method for automated collection and use of personal data related to an End User who is a subscriber of Telecom performed by using the described above system is proposed. The method a) registration of traffic monetisation solutions to which websites and / or mobile applications of Publishers are connected, ad buying solutions used by Advertisers, and Advertisers by using a request dispatcher; b) an End User identification initiation module sends a request to an End User identification module to receive a one-time End User identifier related to an End User device following the End User’s visits to an Advertiser's website and / or mobile application containing the End User identification initiation module; c) the End User identification module determines an End User’s internal identifier that is provided by the Telecom, generates a one-time End User identifier linked to the End User's internal identifier provided by the Telecom, and then sends it to a first-party data storage and management module installed on Advertiser's server; d) the first-party data storage and management module sends a previously received one-time End User’s identifier to the selected by Advertiser ad buying solution, together with the Advertiser’s instructions on ad serving parameters and ad creative needed for the execution of ad campaign; e) the ad buying solution via an anonymised data access module requests the request dispatcher to decrypt the received one-time End Users’ identifiers and, on respond, the request dispatcher sends the corresponding End Users’ identifiers associated with the ad buying solution; f) a request from the End User identification initiation module to the End User identification module to receive a one-time End User identifier related to the End User device following the End User’s visits to the Publisher's website and / or mobile application that contains the End User identification initiation module; g) the End User identification module determines the End User’s internal identifier that is provided by the Telecom, generates a one-time End User identifier linked to the End User's internal identifier provided by the Telecom, and then sends it to the traffic monetisation solution that connected to the Publisher; h) the traffic monetisation solution sends the received one-time End User identifier to the ad buying solutions; i) the ad buying solution via the anonymised data access module sends a request to the request dispatcher containing the received one-time End User identifier for decrypting it into the End User identifier associated with the ad buying solution and / or matching it to the parameters for displaying the ad creative as previously set by the Advertiser; j) based on the response received from the request dispatcher, the automatic ad buying solution sends to the traffic monetisation solution a proposal for the placement of an advertising creative in accordance with the Advertiser's instructions to display the advertising creative to the identified End User’s device corresponding to the previously received one-time End User identifier; k) selection by the traffic monetisation solution of an offer for the display of an advertising creative to the End User along with the content on the website and / or in the mobile application while the End User is viewing the Publisher's content.

[0039] According to an embodiment of the method, the registration by using the request dispatcher includes assigning a partner-related identifier to each of Advertisers, traffic monetisation solutions and ad buying solutions, as well as registering the IP addresses of the related servers from where the relevant requests to the system will be received.

[0040] According to another embodiment of the method, the End User’s device identification by the End User identification module is performed by comparing the IP address of the End User device received in the request with the pair "IP address = End User’s internal identifier" provided by the Telecom continuously, in real-time.

[0041] According to another embodiment of the method, the End User’s device identification by the End User identification module is based on an encrypted End User internal identifier integrated into the internet packets of the End User’s device by the Telecom by using the packet content inspection and modification technology.

[0042] According to a third aspect of the present invention, a method for secure automated control of access and use of previously collected first-party data that is related to an End User who is a subscriber of Telecom performed by using the described above system is proposed.

[0043] According to an embodiment of the method, the registration by using the request dispatcher includes assigning a partner-related identifier to each of Data Vendors, Advertisers, traffic monetisation solutions and ad buying solutions, as well as registering the IP addresses of the related servers from where the relevant requests to the system will be received.

[0044] According to another embodiment of the method, the End Users’ identifying parameters uploaded by the Data Vendor to the first-party data management and storage module are the End Users’ telephone numbers and / or emails.

[0045] According to another embodiment of the method, the End User’s device identification by the End User identification module is performed by comparing the IP address of the End User device received in the request with the pair "IP address = End User’s internal identifier" provided by the Telecom continuously, in real-time.

[0046] According to another embodiment of the method, the End User’s device identification by the End User identification module is based on an encrypted End User internal identifier integrated into the internet packets of the End User’s device by the Telecom by using the packet content inspection and modification technology.

[0047] The technical result of using the invention is to ensure the anonymity of the End User when using telecommunication services and during the collection and use of personal data collected by the services End User uses, which is necessary to increase the relevance of targeted advertisements available for viewing by the End User through his / her telecommunication service access device, as well as to increase the protection of personal data of the End User when performing automated control of the technical result is achieved by using a set of interconnected one-time session identifiers for system elements, as well as different identifiers associated with companies End User uses. The set of these identifiers creates a multilayered system of decentralised identities that are interconnected by the system with the assistance of the technical capabilities of Telecoms to identify internet users across websites and apps without usage of vulnerable static identifiers. Moreover, the unique technical abilities of Telecoms to identify End Users across various browsers and mobile operations systems unlock unprecedented opportunities for Advertisers to avoid dependence on tech giants and Publishers to reach demands by Advertisers scale regardless of every given Publisher’s size and accessible behaviour data. The system of various types of identifiers includes an End User’s internal identifier provided by a Telecom; one-time End User identifiers used for secure interaction between system modules and for secure transfers within adtech solutions; End User identifiers associated with authorised Data Vendors, Advertisers, and / or ad buying solutions, which are unique to each of these participants, and therefore even participants registered in the system cannot perform unauthorised data transaction outside the system as well as cannot use data collected within system outside of it. In other words, using this set of identifiers combined with Telecoms’ technical capabilities allows to operate with the behavioural characteristics of the End User without revealing his / her personal data, which allows to collect anonymised information about the End User and use it safely for the implementation of the personalised advertising needs. The technical result is also achieved by the fact that it is collecting and using the personal data of the End User; no centralised personal data storage is used, while the End User has exceptional control over his / her own identification via interactions with the Telecom that provides internet service.

[0048] BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The invention is illustrated by an example of an implementation of a system for secure automated collection of personal data and automated control of access to personal data of an End User, as well as examples of a method for secure automated collection and use of personal data of an End User and a method for automated control of access to and use of personal data of an End User previously collected outside the system. These examples are illustrated by the following figures: Fig. 1 - block diagram of the system according to the invention; Fig. 2 - a diagram of the process of secure automated collection and use of personal data of the End User to one of the embodiments of the invention, where the Advertiser creates communication with visitors to its own website and / or mobile application (retargeting); Fig. 3 is a diagram of the process of automated control of access to and use of pre-collected personal data of the End User according to another embodiment of the invention, which increases the secured usage of personal data for performing the targeted advertising campaign based on first-party data previously collected outside the system. These examples and the images used do not limit other embodiments of the invention but only explain its essence.

[0050] DETAILED DESCRIPTION The system, according to the invention (Fig. 1) comprises an internet- connected End User’s device (100), an End User identification module (220), first-party data storage and management modules (530) and (430), an End User device identification initiation module (600), an anonymised data access module (800), and an internet-connected request dispatcher (900).

[0051] The telecommunications services End User device (100) is equipped with a processor, a means for storing electronic data, a means for visualising electronic data, and a means for exchanging electronic data. An example of such a device is a mobile phone, a personal computer, a tablet, a laptop.

[0052] The End User identification module (220) is connected to the internet and installed on a server (210) of at least one Telecom (200). The module (220) is configured to: determine an internal End User internal identifier provided by Telecom (200) and stored on the server (210) in accordance with requests from the End User device identification initiation modules (600); initialise first-party data uploaded by the Data Vendor (500) to the first-party data storage and management modules (530) and (430) by replacing End User identifying parameters included in the data with an End User identifier associated with the Data Vendor (500) corresponding to the internal End User identifier; generate one-time End Users’ identifiers linked to the End User internal identifier provided by Telecom (200).

[0053] The first-party data storage and management module (530) is installed on a connected internet server (510) of the Data Vendor (500), and the module (430) is installed on a connected to the internet server (410) of the Advertiser (400). Each of the modules (530) and (430) is configured to collect first-party data and / or upload first-party data previously collected outside the system. Regardless of the way the relevant data is obtained in modules (430) and (530), the system allows it to be used securely both for its Data Vendor (500) and / or Advertiser (400) own needs as well as for monetising this data by granting anonymised access and providing the possibility of creating new segments to third-party Advertisers (400) and their further secure use in authorised ad buying solutions (700).

[0054] The End User device identification initiation module (600) is programming code integrated into an internet-connected at least one website and / or mobile application (440) of a system-authorised Advertiser (400) and / or at least one website and / or mobile application (340) of a system-authorised Publisher (300), to which at least one system-authorised traffic monetisation solution (350) is connected.

[0055] The anonymised data access module (800) is integrated with at least one ad buying solution (700) and is configured to send requests to the request dispatcher (900) to decrypt the one-time End User's identifiers and / or to receive anonymised analytics information related to appropriate one-time identifiers.

[0056] The request dispatcher (900) comprises an electronic data store, an electronic data exchange facility, and a processor. The request dispatcher (900) is configured to register Advertisers (400), Data Vendors (500), Adtech solutions, including traffic monetisation solutions (350) and ad buying solutions (700); to process requests from the anonymised data access module (800), including requests for decryption of one-time End User identifiers; creating new data segments in the form of a list of one-time End User identifiers in response to a request from the Advertiser (400) to generate a list of End Users that meet the behavioural characteristics specified by the Advertiser (400); to send the created new data segments in the form of a list of one-time End User identifiers to the ad buying solution(700) selected by the Advertiser (400); to generate End User identifiers associated with the anonymised data access module (800) and / or first-party data storage and management modules (430), (530). Use the system described above for secure automated collection and use of personal data of the End User who is a subscriber of a Telecom in the following way.

[0057] The system described above includes such authorised elements as a set of websites and / or mobile applications of Publishers (300) and / or Advertisers (400), servers (510), (410), (210) of Data Vendors (500), Advertisers (400) and Telecoms (200). The End User’s device (100) is a means of accessing the Internet and interacting with the system elements, in particular, accessing the websites and / or mobile applications of Advertisers (400) and Publisher (300). It is equipped with an electronic data processor, a means of storing electronic data, a means of visualising electronic data, a means of exchanging electronic data, and is connected to the system by means of telecommunication service of the Telecom (200). The modules (220, 430, 530, 600, 800) and the request dispatcher (900) are connected to the system via the Internet by means of telecommunication means known now and those that will be known in the future. Registration in the system is carried out by the request dispatcher (900), which contains an electronic data processor, an electronic data storage, an electronic data exchange facility that allows it to register Advertisers (400), Data Vendors (500), advertising technology services, which include traffic monetisation solutions (350) and ad buying solutions (700), processing of electronic data and requests in the system, in particular, processing of requests from the module for access to anonymised data (800), including requests for decryption of one-time End User identifiers; creating new data segments in the form of a list of one-time End User identifiers in response to a request from the Advertiser (400) to generate a list of End Users that meet the behavioural characteristics specified by the Advertiser; sending the created new data segments in the form of a list of one-time End User identifiers to the ad buying solution selected by the Advertiser (400); generating End User identifiers associated with anonymised data access modules (800), Data Vendors (500) and / or Advertisers (400).

[0058] The End User identification module (220) is part of the hardware and software complex of the Telecom (200), which is connected to the system via the Internet - physically located in the electronic data storage of the server (210), uses the electronic data exchange facility of the server (210) to receive requests and send data, and the electronic data processing processor of the server (210) to identify the End User. In accordance with one embodiment of the invention, identification by the End User identification module (220) is performed by comparing the IP address of the End User's device received in the request with the pair "IP address = End User internal identifier”, which is provided by the Telecom (200) continuously, in real time. In accordance with another embodiment of the invention, the identification by the End User identification module (220) is based on an encrypted End User identifier that is integrated into the Internet packets of the End User device (100) by the Telecom(200) using packet content inspection and modification technology.

[0059] The First Party Data Storage and Management Modules (530) and (430) are part of the hardware and software complex of the Data Vendor server (510) and / or part of the hardware and software complex of the Advertiser server (430), which are connected to the system via the Internet. The modules (530) and (430) are physically located in the electronic data storage of the servers (510) and (410), respectively, and use the electronic data processors and electronic data exchange facilities of the respective servers (510) and (410) to collect personal data and / or upload previously collected personal data for secure use within the system.

[0060] The End User device identification initiation module (600) is software- integrated into an internet-connected website and / or mobile application (440) of at least one Advertiser (400) and / or at least one Publisher (300), to whose website and / or mobile application (340) the traffic monetisation solution (350) authorised in the system is connected. Said module (600) is designed to initiate the process of identifying the End User device (100) by sending a request to the End User identification module (220) to compare the IP address of the End User device received in the request with the pair "IP address = End User internal identifier”, which is generated by the Telecom (200) continuously, in real time or on the basis of an encrypted End User internal identifier integrated into the Internet packages of the End User device by the Telecom (200).

[0061] The anonymised data access module (800) is software-integrated into the ad buying solution (700) used by the Advertiser (400). Said module (800) is directly connected to the system via the Internet and is configured to process data processing requests and decrypt one-time End User identifiers into End User identifiers associated with appropriate ad buying solution by issuing requests to request dispatcher (900).

[0062] During the automated collection of personal data of the End User of telecommunication services, according to Figure 2, traffic monetisation solutions (350) are pre-registered in the system using a request dispatcher (900), to which the websites and / or mobile applications (340) of the Publishers (300) are connected, the ad buying solutions(700) used by the Advertisers (400), and the Advertisers (400) with a first-party data storage and management module (430) integrated therein, step (A) in Figure 2. For this purpose, the request dispatcher (900) processes requests for connection to the system from traffic monetisation solutions (350), from ad buying solutions (700), and from Advertisers (400). During this registration, the request dispatcher (900) also assigns partner identifiers for each of Advertisers (400) and Ad buying solutions (700), Data Vendors (500). The IP addresses of the servers from which the relevant requests to the system will be received are also registered using a request dispatcher (900). According to steps (B) in Fig. 2, upon visiting the website and / or mobile application (440) of the Advertiser (400), wherein the End User device identification initiation module (600) is programming code integrated, a request is sent to the End User identification module (220) for a one-time End User identifier by means of the End User device (100). If multiple Telecoms (200) are connected to the system, the request is sent to the respective End User identification module (220) of the Telecom (200) to which the End User is connected when visiting the website and / or using the mobile application (440), using, for example, IP Anycast technology.

[0063] In response to the request, the End User identification module (220) identifies the End User by determining an End User’s internal identifier provided by the Telecom (200) and obtained from the server (210) of the Telecom (200). The End User identification module (220) performs the identification by comparing the IP address of the End User device received in the request with the pair "IP address = End User internal identifier" generated by Telecom (200) on a continuous basis in real-time. Alternatively, the End User identification module (220) performs the identification based on an encrypted End User identifier that is integrated into the Internet packets of the End User device (100) by the Telecom (200) using packet content inspection and modification technology.

[0064] Following the determination of the End User’s internal identifier provided by the Telecom (200), the End User identification module (220) generates a onetime End User identifier linked to the determined internal identifier provided by the Telecom (200). The one-time identifier is generated only for the current internet session of the End User's visit to the website and / or mobile application (440). The usage of one-time identifiers makes it impossible for unauthorised parties to access the system and prevents those who are registered to use the system from using it in an unauthorised way outside the system functionality. Thus, this approach protects the End User from leaving a digital footprint online and being monitored by unauthorised actors.

[0065] The generated one-time End User identifier is sent by the End User identification module (220) to the Advertiser's server (410) to the first-party data storage and management module (430) (step (B) in Fig. 2). In case Advertiser (400) willing to display ad impression to the End User, Advertiser (400), via the first party data storage and management module (430), sends the received onetime End User identifier to the automatic ad placement service (700) used by the Advertiser (400) (step (D) in Figure 2). In addition to the one-time End User identifier, Advertiser (400) sends relevant advertising creative and display parameters of the advertising campaign, including frequency capping parameters, daytime, bid price for showing ads and other relevant ad campaign parameters.

[0066] The next step is the request from the ad buying solution (700) via the anonymised data access module (800) to the request dispatcher (900) (step (D) in Fig. 2) to receive anonymised analytical information about End User. This may be, for example, a request about the reach a quantitative limit of ad impressions to a particular End User within a time period specified by the Advertiser (400) in accordance with instructions provided by the Advertiser (400) to the ad buying solution (700) related to previously defined ad campaign. Otherwise, said request by the ad buying solution (700) to the request dispatcher (900) relates to decrypting the received one-time End User identifier into an End User identifier associated with the ad buying solution (700). In such circumstances, the ad buying solution (700) itself checks requested analytical information for a particular one-time End User identifier and / or provides related to the ad buying solution (700) End User’s identifier. The usage of various identifiers associated with different adtech solutions related to a similar End User prevents unauthorised data transactions even within trusted (registered) participants and also prevents usage of behaviour data related to the End User outside the system.

[0067] After the End User enters the website and / or mobile application (340) of the Publisher (300) using the device (100), a request is sent from End User identification initiation module (600) to the End User identification module (220) to obtain a one-time End User identifier (steps (E) in FIG. 2).

[0068] In response to the request, the End User identification module (220) identifies the End User by determining the internal End User identifier provided by the Telecom (200), similarly to step (B) described above, and when determining the internal End User identifier, generates a one-time End User identifier and then sends it to the traffic monetisation solution (350) to which the website and / or mobile application is connected (340).

[0069] The said traffic monetisation solution (350) sends the received one-time End User identifier to the ad buying solutions (700) (step (G) in Fig. 2). The usage of one-time identifiers eliminates risks of unauthorised participants to the system and risks of reverse engineering by hidden actors online. Therefore, the traffic monetisation solution (350) can send the identifier to any ad buying solution, while only registered ad buying solution (700) able to perform further secure actions with one-time identifier within the system.

[0070] In turn, the ad buying solution (700) registered in the system, through the anonymised data access module (800), sends a request to the request dispatcher (900) (step (H) in Fig. 2) regarding the correspondence of the End User under the received one-time End User identifier to one of the End Users having an End User identifier associated with the ad buying solution(700) used by the Advertiser (400) and the parameters for displaying the advertising creative set by the Advertiser. This eliminates the possibility of End User’s personal data being shared between Adtech solutions in the programmatic advertising market, which is inevitable with existing solutions that use static identifiers (third-party cookies).

[0071] According to step (I) in Fig. 2, the ad buying solution (700) then sends to the traffic monetisation solution (350) offers for the placement of the advertising creative according to the instructions of the Advertiser (400) to display the ad impression to the identified End User corresponding to the received one-time End User identifier. Having received offers for the placement of the advertising creative and the advertising creative of the Advertiser (400) from the ad buying solution (700), the traffic monetisation solution (350), to which the Publisher's website and / or mobile application (300) is connected, selects one of the offers received from various ad buying solutions according to the parameters determined by the Publisher (300). If the offer provided by the ad buying solution (700) is selected, it sends advertising creative provided by the Advertiser (400) in the previous stage. Then traffic monetisation solution appropriate wins, the traffic monetisation solution (350) displays the advertising creative to the End on the website and / or mobile application (340) of the Publisher (300) while the End User is viewing the content of the Publisher (300), according to step (I) in Fig. 2.

[0072] With the help of the above system, a method for automated control of access to and use of personal data of the End User, which is previously collected outside the system, is also implemented, as shown in Fig. 3. For this purpose, the request dispatcher (900), as in the previous example, performs registration (steps (A) in Fig. 3) of traffic monetisation solutions (350) to which Publishers (300) are connected, ad buying solutions (700) used by Advertisers (400), Advertisers (400) and Data Vendors (500) that control legally obtained first- party data. To perform this registration, the request dispatcher (900) processes requests for connection to the system from traffic monetisation solutions (350) to which the websites and / or mobile applications of the Publishers (300) are connected, ad buying solutions (700) used by the Advertiser (400), the Advertiser (400) and the Data Vendor (500). During registration, these elements of the system are assigned unique partner identifiers by which they are uniquely identified by the system, and also, the IP addresses of the servers from which the relevant requests to the system will be received are registered.

[0073] The registration of the Data Vendor (500) and installation of the first- party data storage and management module (530) to the Data Vendor’s server (510) enables the Data Vendor (500) to use first-party data previously collected outside the system. The usage of personal data within the system could be for the Data Vendor’s own needs. In this case Data Vendor can utilise anonymised data insights and / or use the uploaded first-party data for ad targeting with assistance of registered in the system ad buying solutions. Another option for uploading by Data Vendor (500) first-party data usage is opening access for secured data collaborations with other participants in the system and / or using this data by registered Advertisers (400) for secure ad targeting of digital advertising. To do so, the Data Vendor (500) uploads the first-party data it has selected, together with the End Users’ identifying parameters (e.g., the End Users’ mobile phone numbers, and emails), to the first-party data storage and management module (530) (step (B) in Fig. 3) installed on its internet-connected server (510). In other words, the first-party data remains under full control within the Data Vendor's server, preventing risks of unauthorised physical access to the personal data. In addition, federated storage of personal data by Data Vendors within the system prevents cross-border data transfers, which is prohibited by the privacy legislation of the European Union and many other countries.

[0074] Thereafter, a request for initialisation of the End User identifying parameters presented in the first-party data uploaded by the Data Vendor (500) is sent by the first-party data storage and management module (530) to the End User identification module (220) (step (B) in Fig. 3). Initialisation by the End User identification module (220) is performed using the pair "phone number = End User internal identifier” previously provided by the Telecom (200) to the End User identification module (220). As a result, the End user internal identifiers are associated with identifying parameters provided by the first-party storage and management module (530) for initialisation (500). The system also allows the use of other identifying parameters than the mobile phone number, such as the End User's email address, in case if appropriate pair linked to the End User’ internal identifiers are provided by Telecom or another identifying partner.

[0075] The End User identification module (220) transmits the received End Users’ internal identifiers to the first-party data storage and management module (530) via the request dispatcher (900), in accordance with step (D) of Fig. 3. The transit of the End Users’ internal identifiers via the request dispatcher (900) is necessary for replacement of End Users’ internal identifiers provided by Telecom (200) with End Users’ identifiers associated with every given Data Vendor (500). The request dispatcher (900) stores all links within existing identifiers and is able to cross-match available within the system identifiers related to the same End User. This prevents the collection of metadata (a list of customers of a particular Data Vendor contained in the initialisation request) by the Telecom (200), which is unacceptable for Data Vendors and Advertisers.

[0076] Received as a result of initialisation request End Users’ identifiers are associated with the Data Vendor (500) and correspond to the End Users internal identifiers provided by Telecom (200). In other words, initialisation of the End Users’ identifying parameters involves replacing the End User's identifying parameters (phone number) with internal identifiers associated with specific Data Vendor. This approach makes it possible to avoid the use of static identifiers (phone numbers) in the system, which enhances its security in terms of potential data leakage risks. The system also prevents the unauthorised use and exchange of personal data, even between authorised participants.

[0077] The Advertiser (400) sends to the request dispatcher (900) a request to recognise a list of End Users who meet the behavioural characteristics specified by the Advertiser (stage (D) in Fig. 3).

[0078] In response to the request, the request dispatcher (900) creates a new data segment in the form of a list of one-time End Users’ identifiers. To do so, the request dispatcher (900) makes requests (step (E) in Fig. 3) to first-party data storage and management modules (530) of the Data Vendors (500) that are connected to the system and that have behavioural data relevant to the Advertiser's request (400). As a result of such requests to the various modules (530), a multi-layered segment is created by the request dispatcher (900), containing the list of End Users who reflect appropriate characteristics based on data from the various Data Vendors (500) and, if necessary, data from the Advertiser (400) itself, in case Advertiser (400) has this first-party data uploaded to the first-party data storage and management (430). The request dispatcher (900) can provide to the anonymised information regarding the created list of End Users. For example, how many End Users does the segment covers or how many people from that data segment are present in the data segment provided by the Advertiser, what is the cost of using the data segment for ad targeting, etc. If the Advertiser (400) wishes to use the created data segment for displaying advertising (targeting) to the End Users present in the list, it orders the transfer of this segment to the ad buying solution (700) that registered in the system and selected by the Advertiser (400). To ensure the secure transmission of the specified data segment, the request dispatcher (900) generates one-time End Users’ identifiers related to the list of End Users presented in the data segment.

[0079] Next, a new data segment in the form of a list of one-time End Users’ identifiers is sent by the request dispatcher (900) to the anonymised data access module (800), which is integrated into the ad buying solution (700) selected by the Advertiser (400). At the same time, the Advertiser (400) sends to the specified ad buying solution (700) the advertising creative and the parameters for displaying the ordered advertising campaign (steps (E) in Fig. 3).

[0080] Upon receipt of the new data segment, the ad buying solution (700), via the anonymised data access module (800), sends a request to the request dispatcher (900) (step (G) of Figure 3) to decrypt the received one-time End Users’ identifiers, which are in the list of End User identifiers received from the request dispatcher (900) into End Users’ identifiers associated with the ad buying solution (700).

[0081] According to the step (H) in Fig. 3, after an End User visits a website and / or mobile application (340) of the Publisher (300) using a device (100), the End User device identification initiation module (600), which is programming code integrated into said website and / or mobile application (340) of the Publisher (300), sends a request to the End User identification module (220) for a one-time End User identifier related to the End User.

[0082] In response to the request, the End User identification module (220) identifies the End User by matching the IP address of the End User device received in the request with the pair "IP address = End User internal identifier" previously provided to the End User identification module (220) by the Telecom (200) on a continuous, real-time basis or based on an encrypted End User internal identifier that is integrated into the Internet packets of the End User’s device by Telecom (200).

[0083] Next, the End User identification module (220) generates a one-time End User identifier and then sends it to the traffic monetisation solution (350) (step (I) in Fig. 3), to which the website and / or mobile application (340) of the Publisher (300) is connected. Received by the traffic monetisation solution (350), to which the Publisher's website and / or mobile application (340) (300) is connected, the onetime End User identifier is sent to the connected ad buying solutions (700) (step (I) in Fig. 3).

[0084] Next, the ad buying solution (700) registered in the system sends a request to the request dispatcher (900) via the anonymised data access module (800) to match the End User according to the received one-time End User identifier to one of the End Users having an End User identifier associated with the ad buying solution (700) and the parameters for displaying the advertising creative to this End User as previously set by the Advertiser (400) (step (K) in Figure 3. 3). In response to the request, the request dispatcher (900) provides anonymised information (e.g., about reaching quantitative limits of ad impressions) or decrypts the one-time End User identifier into an End User identifier associated with the ad buying solution (700) for the subsequent determination by the said service (700) of the relevance for showing ad creative to the End User and also the price Advertiser (400) ordered to pay for such an ad impression.

[0085] According to step (L) in Fig. 3, the ad buying solution (700) then sends to the traffic monetisation solution (350) bid offer for serving ad impression to the corresponding to one-time End User identifier based on orders from Advertiser (400). Having received offers for the placement of the advertising creative from ad buying solutions, traffic monetisation solution (350) defines the winning offer and in case the Advertiser’s (400) offer wins, traffic monetisation solution (350) displays ad creative previously provided by the Advertiser (400) to ad buying solution (350) to the End User while he / she is viewing the content of the Publisher (300), according to step (M) in Fig. 3.

[0086] From the above examples of the invention, it is obvious that the claimed technical solution is industrially applicable for use with the use of modem software and hardware in the field of information technology. The claimed invention has a hitherto unknown set of essential features that characterise both the system and the methods and, therefore, is new. At the same time, an unexpected result was the ability of the system to implement the methods according to the invention for targeting advertising with: absolute confidentiality of End Users' personal data and prevention of unauthorised data collection while using the service of Telecom; avoidance of personal data exposure due to a closed system based on the use system of multilayered identifiers associated with the same user, while avoiding usage of vulnerable static identifiers as a core element of privacy issues online; to increase the amount of free services available for End Users’ usage in the Internet by enabling Publishers to have better traffic monetisation compared with known for now methods.

[0087] In addition, the implementation of the invention will allow:

[0088] For Publishers to increase the accuracy of End User identification with reference to their behavioural personal data, compared to well-known analogues, and as a result to increase Publishers’ ad revenues by displaying performing advertising reaching financial independence of the media in their competition with tech giants.

[0089] - For Advertisers to use more efficiently the possibilities of displaying targeted advertising on the websites and / or mobile applications of Publishers and, consequently, to reduce their dependence on advertising solutions from dominating tech giants;

[0090] - For Data Vendors to effectively monetise their first-party data without the risk of violating personal data protection laws and infringing on the privacy of their users; - For Telecoms to effectively protect the personal data of their subscribers and to carry out effective communication through the advertising programmatic market between Advertisers and Publishers;

[0091] - To limit market power of tech giants (Google, Meta) and to increase competitiveness in digital environment by enabling equal access to accurate from Advertisers and Publishers regardless their size. to increase national security by creating a local market for personal data protected from unauthorised access, cross-border data transfers and preventing impact on public opinion from foreign actors.

Claims

Claims1. A system for automated usage, access control and collection of personal data related to an individual (hereinafter End User) who is a subscriber of a mobile or fixed-line internet service provider (hereinafter Telecom), which includes: a) a device of the End User (100) connected to the internet equipped with a processor, a means of storing electronic data, a means of visualising electronic data, a means of exchanging electronic data; b) an End User identification module (220) installed on a server (210) of at least one Telecom (200) connected to the internet and configured to:- determining the End User’s internal identifier provided by the Telecom (200) and stored on the Telecom’s server (210) in response to requests from an End User’s identification initiation module (600);- initialisation of first-party data downloaded to the data storage and management modules (530), (430) performed by replacing End Users’ identifying parameters with End Users’ identifiers associated with Data Vendors (500) and / or Advertisers (400) corresponding to End Users’ internal identifiers provided by the Telecom (200);- generating one-time End Users’ identifiers linked to the End User internal identifier provided by the Telecom (200); c) a first-party data storage and management modules (530), (430) configured to collect first-party data and / or download previously collected outside the system first-party data, wherein the module (530) is installed on a server (510) connected to the internet of at least one Data Vendor (500), and the module (430) is installed on a server (410) connected to the internet of at least one Advertiser (400); d) the End User identification initiation module (600) configured to initiate an End User’s device identification and integrated as a programming code into at least one website and / or mobile application(440) of an Advertiser (400), and / or at least one website and / or mobile application (340) of Publisher (300) that is connected to the at least one traffic monetisation solution (350); e) an anonymised data access module (800) integrated into at least one ad buying solution (700) and configured to send requests to a request dispatcher (900) for decryption of one-time End User's identifiers and / or for obtaining anonymised analytical information related to the one-time End User’s identifiers; f) the request dispatcher (900) is software installed on a remote server connected to the internet that includes electronic data storage and a processor configured to:- registration of Publishers (300), Advertisers (400), Data Vendors (500), advertising technology solutions, including traffic monetisation solutions (350) and ad buying solutions (700);- processing requests from the anonymised data access module (800), including requests for decryption of one-time End User’s identifiers;- creation of new data segments in the form of a list of one-time End Users’ identifiers in response to the Advertiser's (400) request to create a list of End Users who meet the behavioural characteristics specified by the Advertiser (400);- sending the newly created data segments in the form of a list of onetime End Users’ identifiers to the ad buying solution (700) chosen by the Advertiser (400);- generating End Users’ identifiers associated with the anonymised data access module (800) and / or the first-party data storage and management modules (530), (430).

2. A method for automated collection and use of personal data related to an End User who is a subscriber of Telecom performed by using the system according to claim 1, comprising:a) registration of traffic monetisation solutions (350) to which websites and / or mobile applications (340) of Publishers (300) are connected, ad buying solutions (700) used by Advertisers (400), and Advertisers (400) by using a request dispatcher (900); b) an End User identification initiation module (600) sends a request to an End User identification module (220) to receive a one-time End User identifier related to an End User device (100) following the End User’s visits to an Advertiser's website and / or mobile application (440) containing the End User identification initiation module (600); c) the End User identification module (220) determines an End User’s internal identifier that is provided by the Telecom (200), generates a one-time End User identifier linked to the End User's internal identifier provided by the Telecom (200), and then sends it to a first-party data storage and management module (430) installed on Advertiser's server (410); d) the first-party data storage and management module (430) sends a previously received one-time End User’s identifier to the selected by Advertiser (400) ad buying solution (700), together with the Advertiser’s (400) instructions on ad serving parameters and ad creative needed for the execution of ad campaign; e) the ad buying solution (700) via an anonymised data access module (800) requests the request dispatcher (900) to decrypt the received one-time End Users’ identifiers and, on respond, the request dispatcher (900) sends the corresponding End Users’ identifiers associated with the ad buying solution (700); f) a request from the End User identification initiation module (600) to the End User identification module (220) to receive a one-time End User identifier related to the End User device (100) following the End User’svisits to the Publisher's website and / or mobile application (340) that contains the End User identification initiation module (600); g) the End User identification module (220) determines the End User’s internal identifier that is provided by the Telecom (200), generates a one-time End User identifier linked to the End User's internal identifier provided by the Telecom (200), and then sends it to the traffic monetisation solution (350) that connected to the Publisher (300); h) the traffic monetisation solution (350) sends the received one-time End User identifier to the ad buying solutions (700); i) the ad buying solution (700) via the anonymised data access module (800) sends a request to the request dispatcher (900) containing the received one-time End User identifier for decrypting it into the End User identifier associated with the ad buying solution (700) and / or matching it to the parameters for displaying the ad creative as previously set by the Advertiser (400); j) based on the response received from the request dispatcher (900), the automatic ad buying solution (700) sends to the traffic monetisation solution (350) a proposal for the placement of an advertising creative in accordance with the Advertiser's (400) instructions to display the advertising creative to the identified End User’s device corresponding to the previously received one-time End User identifier; k) selection by the traffic monetisation solution (350) of an offer for the display of an advertising creative to the End User along with the content on the website and / or in the mobile application (340) while the End User is viewing the Publisher's content.

3. The method of claim 2 wherein the registration by using the request dispatcher (900) includes assigning a partner-related identifier to each of Advertisers (400), traffic monetisation solutions (350) and ad buying solutions (700), as well asregistering the IP addresses of the related servers from where the relevant requests to the system will be received.

4. The method of claim 2 wherein the End User’s device identification by the End User identification module (220) is performed by comparing the IP address of the End User device received in the request with the pair "IP address = End User’s internal identifier" provided by the Telecom (200) continuously, in real-time.

5. The method of claim 2 wherein the End User’s device identification by the End User identification module (220) is based on an encrypted End User internal identifier integrated into the internet packets of the End User’s device (100) by the Telecom (200) by using the packet content inspection and modification technology.

6. A method for secure automated control of access and use of previously collected first-party data that is related to an End User who is a subscriber of Telecom performed by using the system according to claim 1, comprising: a) registration of traffic monetisation solutions (350) to which websites and / or mobile applications (340) of Publishers (300) are connected, ad buying solutions (700) used by Advertisers (400), Advertisers (400) and Data Vendors (500) by using a request dispatcher (900); b) the Data Vendor (500) uploads previously collected outside the system first-party data, which includes the End Users’ identifying parameters, to a first-party data storage and management module (530) installed on a server (510) of the Data Vendor (500) that is connected to the internet; c) the first-party data storage and management module (530) sends an initialisation request to an End User identification module (220) installed on a server (210) of the Telecom (200), containing the list of End Users’ identifying parameters;d) the End User identification module (220) replaces the End Users’ identifying parameters contained in the previously received request with an End Users’ internal identifiers provided by Telecom (200) and sends them to the first-party data storage and management module (530) through the requests dispatcher (900), where the requests dispatcher (900) replaces received End Users’ internal identifiers provided by Telecom (200) with End Users’ identifiers associated with the specific Data Vendor (500); e) the Advertiser (400) orders the request dispatcher (900) to generate a list of End Users who meet the behavioural characteristics specified by the Advertiser (400); f) the request dispatcher (900) creates a new data segment in the form of a list of one-time End Users’ identifiers by requesting the first-party data storage and management modules (530) of each Data Vendor (500), which have been connected to the system the first-party data with behavioural characteristics corresponding to the Advertiser's (400) request; g) the request dispatcher (900) sends the created in accordance with the request of the Advertiser (400) data segment in the form of a list of onetime End Users’ identifiers to an anonymised data access module (800) integrated into ad buying solution (700) selected by the Advertiser (400), together with the provision by the Advertiser (400) to the ad buying solution (700) instructions on ad serving parameters and ad creative needed for the execution of ad campaign; h) the ad buying solution (700) via the anonymised data access module (800) requests the request dispatcher (900) to decrypt the received onetime End Users’ identifiers, and, on respond, the request dispatcher(900) sends the corresponding End Users’ identifiers associated with the ad buying solution (700); i) a request from an End User identification initiation module (600) to the End User identification module (220) to receive a one-time End User identifier related to an End User device (100) following the End User’s visits to the Publisher's website and / or mobile application (340) that contains the End User identification initiation module (600); j) the End User identification module (220) determines the End User’s internal identifier that is provided by the Telecom (200), generates a one-time End User identifier linked to the End User's internal identifier provided by the Telecom (200), and then sends it to the traffic monetisation solution (350) that connected to the Publisher (300); k) the traffic monetisation solution (350) sends the received one-time End User identifier to the ad buying solutions (700); l) the ad buying solution (700) via the anonymised data access module (800) sends a request to the request dispatcher (900) containing the received one-time End User identifier for decrypting it into the End User identifier associated with the ad buying solution (700) and / or matching it to the parameters for displaying the ad creative as previously set by the Advertiser (400); m) based on the response received from the request dispatcher (900), the automatic ad buying solution (700) sends to the traffic monetisation solution (350) a proposal for the placement of an advertising creative in accordance with the Advertiser's (400) instructions to display the advertising creative to the identified End User’s device corresponding to the previously received one-time End User identifier; n) selection by the traffic monetisation solution (350) of an offer for the display of an advertising creative to the End User along with the contenton the website and / or in the mobile application (340) while the End User is viewing the Publisher's content (300).

7. The method of claim 6 wherein the registration by using the request dispatcher(900) includes assigning a partner-related identifier to each of Data Vendors (500), Advertisers (400), traffic monetisation solutions (350) and ad buying solutions (700), as well as registering the IP addresses of the related servers from where the relevant requests to the system will be received.

8. The method of claim 6 wherein the End Users’ identifying parameters uploaded by the Data Vendor (500) to the first-party data management and storage module (530) are the End Users’ telephone numbers and / or emails.

9. The method of claim 6 wherein the End User’s device identification by the EndUser identification module (220) is performed by comparing the IP address of the End User device received in the request with the pair "IP address = End User’s internal identifier" provided by the Telecom (200) continuously, in real-time.

10. The method of claim 6 wherein the End User’s device identification by the End User identification module (220) is based on an encrypted End User internal identifier integrated into the internet packets of the End User’s device (100) by the Telecom (200) by using the packet content inspection and modification technology.

Citation Information

Patent Citations

  • Systems and methods of tracking online advertisement exposure

    EP2856413A2

  • System and method for secure automated data collection

    US20080313636A1

  • Internet Data Usage Control System

    US20230342789A1

  • Systems and methods for secure transaction management and electronic rights protection

    US8055913B2

  • System and method for controlling access to personal user data

    US9325715B1