Consent-Centric Data Compliance Checking via Reconciliation Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in maintaining compliance with complex regulations and laws following data breach events, as existing systems lack efficient methods for consent-centric data compliance checking, leading to increased operational difficulties.

Innovation Solution

A processor-implemented method and system for consent-centric data compliance checking, which involves receiving applications, deriving purposes, capturing data subject consents, and reconciling consent information by sending read requests, decrypting, and concatenating data to determine consent lacking information, utilizing a compliance checking device and reconciliation engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations implement comprehensive compliance checking systems to meet complex data breach reporting requirements, then data protection compliance is improved, but device complexity and operational burden increase

Engineering Contradiction:
Improvedata protection complianceVSAvoidcompliance system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the compliance checking system into modular components: a reconciliation engine that compares data subject preferences against actual data usage, a purpose catalogue that categorizes data processing activities, and a consent management system. This modular architecture reduces overall system complexity while maintaining comprehensive compliance coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by maintaining a data subject preference master that pre-documented consent preferences and purposes before data processing occurs. The purpose catalogue pre-categorizes potential data processing activities, enabling proactive compliance checking rather than reactive remediation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If organizations manually track and reconcile data subject consents across multiple applications, then consent accuracy is improved, but loss of time and productivity decrease

Engineering Contradiction:
Improveconsent tracking accuracyVSAvoidcompliance checking time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates a digital copy of data subject preferences in the form of a preference master that can be automatically replicated and compared against actual data usage across multiple applications. This digital copying eliminates manual tracking while maintaining high accuracy through systematic reconciliation processes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The reconciliation engine implements continuous feedback by automatically comparing data subject preferences against actual data processing activities, identifying discrepancies, and generating reports that feed back into the consent management system for corrective action.

Inventive Principle:
Principle #23Feedback

3Reliability

If organizations encrypt and secure data subject preference information, then data security is improved, but ease of operation and access difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoiddata access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a secure vault as an intermediary component that stores encrypted data subject preferences. The reconciliation engine interacts with this vault through controlled interfaces, obtaining necessary information for compliance checking while maintaining security. The vault acts as a mediator between security requirements and operational needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11003768B2System and method for consent centric data compliance checking
Publication Date: 2021.05.11 TATA CONSULTANCY SERVICES LTD
  • US11003768B2 patent drawing
  • US11003768B2 patent drawing
  • US11003768B2 patent drawing

AI summary

Techniques for consent centric data compliance checking are disclosed. In an example embodiment, multiple applications associated with an organization are received. Further, a purpose for each of the multiple applications associated with the organization is derived. Furthermore, consents of data subjects are captured for the derived purpose of each of the multiple application in a data subject preference master. Also, reconciliation of the data subject preference master and data subjects' data available in the organization is performed to determine consent lacking information.