Blockchain Consent Management for GDPR Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack effective mechanisms for explicitly recording, managing, and verifying user consent for personal data usage, particularly in scenarios where consent conditions change or are complex, making it difficult for service providers to demonstrate compliance with regulations like GDPR.

Innovation Solution

A blockchain-based system that allows service providers to record and manage user consent, enabling third-party certification and providing tools for users to verify their agreement terms, using a trust provider to ensure data integrity and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user consent is managed through traditional service terms and conditions, then service providers can collect and use user information, but there is no reliable method to explicitly record, manage, and verify consent

Engineering Contradiction:
Improveconsent verification reliabilityVSAvoidconsent management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based consent management system as an intermediary between users and service providers. The blockchain records user consent agreements immutably, providing a trusted third-party verification mechanism. Service providers can verify consent through blockchain transactions without directly managing consent records, while users can prove their consent through cryptographic proofs. This intermediary system resolves the contradiction by providing reliable consent verification without requiring service providers to build complex consent management infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates cryptographic copies of consent agreements on the blockchain. Instead of storing complex consent management systems, the system records simplified consent transactions that can be verified through blockchain proofs. The consent agreement is copied into a standardized blockchain transaction format that maintains legal equivalence while enabling efficient verification. This copying approach reduces system complexity while maintaining reliability.

Inventive Principle:
Principle #26Copying

2Reliability

If service providers require users to agree to terms and conditions for information processing, then they can legally use user data, but they cannot demonstrate compliance when consent conditions change or are complex

Engineering Contradiction:
Improvecompliance demonstration capabilityVSAvoidconsent record completeness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The blockchain acts as an intermediary that preserves complete consent records independently of service providers. When consent conditions change, the system creates new blockchain transactions that reference or supersede previous consent agreements. These immutable records provide verifiable evidence of compliance without requiring service providers to maintain complete consent histories. The intermediary blockchain prevents loss of consent information through its distributed and immutable nature.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary recording of consent agreements on the blockchain before service providers process user information. This preliminary action ensures that consent records are established and preserved independently before any potential changes or losses occur. The blockchain creates a permanent record of consent terms, scope, and timing that can be later verified for compliance demonstration.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If users provide personal information to service providers, then services can be delivered, but users lack control over how their information is used and cannot verify consent terms

Engineering Contradiction:
Improveuser control over informationVSAvoidconsent term verification difficulty
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system creates verifiable cryptographic copies of consent terms on the blockchain that users can access and verify. Instead of relying on service providers to display or explain complex consent terms, users receive standardized blockchain proofs that encode the essential consent information. These cryptographic copies enable users to independently verify what they agreed to without needing to interpret complex legal language or trust service provider representations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The blockchain system provides immediate feedback to users about their consent status and the terms they agreed to. Through blockchain transactions and proofs, users can query and verify their consent records in real-time. This feedback mechanism empowers users with transparent visibility into how their information is authorized for use, enabling informed control over their personal data without requiring complex verification processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11438141B2Method and system for managing consent and utilization of information using blockchain
Publication Date: 2022.09.06 PIAMOND CORP
  • US11438141B2 patent drawing
  • US11438141B2 patent drawing
  • US11438141B2 patent drawing

AI summary

An information management method and system for managing consent for and use of information using a blockchain are provided. The information management method comprises: receiving a request to store a user agreement to the processing of the user's information from a service provider providing a service to the user; recording the user agreement on a blockchain; providing the service provider a response to the request to store the user agreement; receiving a third-party certification request for the provision of information from the user, regarding the information provided to the service provider; and providing a third-party certification for the provision of information to the user.