Consent Receipt Management System for Automated Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods for managing consent and personal data processing, leading to inadequate compliance with privacy and security policies, particularly in handling sensitive personal data and ensuring valid consent from data subjects.

Innovation Solution

A computer-implemented data processing method and system for managing consent receipts, which involves generating unique consent receipt keys, storing and associating subject identifiers, transaction identifiers, and capturing user interfaces to transmit consent records to data subjects, ensuring valid consent and compliance with data processing activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual consent management processes are used, then implementation simplicity is maintained, but compliance reliability with privacy policies deteriorates

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a consent management system as an intermediary between data subjects and data processors. This system automatically generates consent receipts, tracks consent status, and manages consent lifecycles, thereby ensuring compliance reliability without requiring complex manual processes throughout the organization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The consent management system enables automated self-service functionalities including automatic generation of consent receipts, automatic tracking of consent status, and automatic notification to data subjects. This automation maintains compliance reliability while reducing the operational burden and apparent complexity for users.

Inventive Principle:
Principle #25Self-service

2Reliability

If automated consent tracking is implemented, then consent validity is improved, but data processing complexity increases

Engineering Contradiction:
Improveconsent validityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms that automatically track and monitor consent status throughout the data processing lifecycle. The consent management system continuously updates consent records, monitors expiration dates, and provides real-time feedback on consent validity, ensuring reliable consent tracking without requiring complex manual verification processes.

Inventive Principle:
Principle #23Feedback

3Loss of information

If comprehensive consent records are maintained, then audit capability is improved, but storage requirements increase

Engineering Contradiction:
Improveaudit information completenessVSAvoiddata storage volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The consent management system extracts and stores only the essential consent information in a standardized format, including consent receipt identifiers, data subject identifiers, consent status, and expiration dates. By extracting only the critical audit information rather than storing all raw data, the system maintains complete audit capability while minimizing storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10706176B2Data-processing consent refresh, re-prompt, and recapture systems and related methods
Publication Date: 2020.07.07 ONETRUST LLC
  • US10706176B2 patent drawing
  • US10706176B2 patent drawing
  • US10706176B2 patent drawing

AI summary

In various embodiments, a Consent Refresh, Re-Prompt, and Recapture System is configured to interface with a Consent Receipt Management System in order to, for example: (1) monitor previously provided consent by one or more data subjects that may be subject to future expiration; (2) monitor a data subject's activity to anticipate the data subject attempting an activity that may require a level of consent (e.g., for the processing of particular data subject data) that is higher than the system has received; and/or (3) identify other changes in circumstances or triggering events for a data subject that may warrant a refresh or recapture (e.g., or attempted capture) of a particular required consent (e.g., required to enable an entity to properly or legally execute a transaction with a data subject). The system may then be configured to automatically refresh, re-prompt for, and/or recapture consent as necessary.