Anonymous Data Aggregation for FCRA-Compliant Offer Candidacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional pre-screening techniques for determining user candidacy for offer sets require sharing sensitive user data, which poses risks of data breaches and restricts data analytics due to limited data provided by third parties, violating FCRA regulations.
Innovation Solution
A system within the offering entity performs candidacy determinations internally while maintaining user anonymity by leveraging identity resolution services from a third party to associate external data with a common identifier, enabling aggregation and analysis of data without revealing user identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party pre-screening services are used to determine user candidacy, then user data anonymity is maintained, but data analytics capability is restricted due to limited data provided by third parties
Solution Approach 1:
The system segments the data processing function into two parts: the third-party pre-screening service handles candidacy determination using aggregated data from multiple sources, while the offering entity retains access to enriched analytics data through the data enrichment service. This segmentation allows both anonymity preservation and analytics capability to coexist by distributing different functions across different system components.
Solution Approach 2:
The data enrichment service acts as an intermediary between the third-party pre-screening service and the offering entity. It receives limited data from the third party, enriches it with additional analytics data, and provides the enhanced information to the offering entity without exposing user identities. This intermediary enables the offering entity to gain deeper analytics insights while maintaining user anonymity throughout the process.
2Loss of information
If comprehensive user data is shared with third parties for candidacy determination, then analytics capability is improved, but user privacy protection is compromised
Solution Approach 1:
The system extracts only the essential elements needed for candidacy determination (aggregated data from multiple credit bureaus) and sends them to the third-party pre-screening service. The offering entity retains access to comprehensive analytics data through the data enrichment service, which enriches the extracted elements with additional insights. This extraction approach allows comprehensive analytics capability while minimizing user privacy exposure by sharing only necessary aggregated information.
3Loss of information
If internal candidacy determination is performed without third-party services, then data control and analytics capability are improved, but compliance with FCRA regulations becomes difficult
Solution Approach 1:
The system merges the advantages of both third-party pre-screening and internal data control. The offering entity combines the FCRA-compliant candidacy determination from the third-party pre-screening service with its own internal data enrichment capability. This merging allows the entity to maintain full data control and analytics capability while ensuring regulatory compliance through the use of a certified third-party service for the actual candidacy determination.
4Measurement precision
If aggregated data from multiple credit bureaus is processed, then candidacy determination accuracy is improved, but data aggregation complexity increases
Solution Approach 1:
The third-party pre-screening service performs the complex task of aggregating data from multiple credit bureaus beforehand, before the offering entity receives the candidacy determination request. This preliminary action simplifies the offering entity's system by eliminating the need to implement and maintain complex data aggregation infrastructure, while still achieving accurate candidacy determination through the pre-aggregated data from multiple sources.
Data Source
AI summary
A first system may receive first data of a user associated with a first identifier and second data of the user associated with a second identifier that exclude user identifying information from a first and second data source, respectively. A key may be received from a second system that associates the first and second identifier with a common identifier generated to preserve user anonymity at the first system. The key may be used to generate aggregated data for the user that includes the first and second data and is associated with the common identifier. The aggregated data may be processed to determine the user as a candidate for an offer set. The common identifier for the user is included in a candidacy list for the offer set, and provided to the second system to facilitate request processing associated with the presentation of the offer set to candidate users.


