Blockchain Audit Ledger for GDPR Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing technologies face significant challenges in complying with data regulations like GDPR, particularly in managing personal data effectively and generating auditable records, leading to substantial financial burdens and liabilities for organizations.

Innovation Solution

A computer system architecture that utilizes a compliance device driver to select and pseudonymize data fields, an automated compliance network appliance to transmit pseudonymized data to a private blockchain-based immutable audit ledger, and an automated compliance server to store data streams, ensuring seamless GDPR compliance and data privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data processing systems are used to manage personal data, then data collection and processing can be performed, but compliance with data regulations like GDPR cannot be effectively demonstrated, leading to severe financial penalties and liabilities

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data processing into two distinct pathways: a compliance pathway that creates immutable audit records on blockchain, and a operational pathway that maintains data processing efficiency. This segmentation allows the organization to meet regulatory requirements without compromising core business operations, resolving the contradiction between compliance reliability and system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a compliance co-processor as an intermediary component that sits between the operational data processing system and the blockchain ledger. This co-processor automatically captures relevant compliance data, transforms it into standardized audit records, and submits them to the blockchain, thereby bridging the gap between operational systems and regulatory requirements without requiring complete system redesign

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data processing capabilities are implemented to meet regulatory requirements, then data compliance can be achieved, but the financial burden and operational costs increase significantly

Engineering Contradiction:
Improveregulatory complianceVSAvoidfinancial burden
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The compliance co-processor is designed to automatically perform compliance-related tasks including data capture, validation, transformation, and submission to the blockchain ledger. This self-service capability eliminates the need for manual compliance monitoring and reporting, significantly reducing operational costs while maintaining reliable regulatory compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary compliance actions by continuously capturing and validating data as it is processed, rather than attempting to retroactively demonstrate compliance. Audit records are created in real-time with proper timestamps and hashes, ensuring compliance evidence is already prepared when regulators request it, thereby avoiding costly post-hoc compliance efforts

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If real-time audit trails are generated for all data processing activities, then compliance evidence can be provided, but the time required for data processing and breach notification increases

Engineering Contradiction:
Improveaudit trail completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The compliance co-processor implements partial monitoring by selectively capturing only the specific data elements and events that are relevant for compliance purposes, rather than creating audit trails for every single data processing operation. This selective approach maintains complete audit coverage for compliance-critical activities while avoiding the time overhead of exhaustive monitoring, thus resolving the contradiction between audit trail completeness and processing time

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10628833B2Computer architecture incorporating blockchain based immutable audit ledger for compliance with data regulations
Publication Date: 2020.04.21 TD PROFESSIONAL SERVICES LLC
  • US10628833B2 patent drawing
  • US10628833B2 patent drawing
  • US10628833B2 patent drawing

AI summary

A computer system architecture and method for providing compliance with data regulations, by: (a) collecting a data input stream with a data collection terminal; (b) using a compliance device driver resident in the data collection terminal to: (1) select data corresponding to pre-identified data compliance fields, and (2) apply a compliance markup language parser to generate pseudonymized data; and (c) using an automated compliance network appliance and an automated compliance server to: (1) transmit the pseudonymized data into immutable audit ledger, wherein the immutable audit ledger is assembled and verified by blockchain, and (2) transmit the data input stream into a data lake; (d) hosting access portals for accessing data: (1) stored in the data lake, and (2) stored in the immutable audit ledger.