Cross-Border User Data Matching Under Sovereignty Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to facilitate cross-border data sharing and utilization while respecting data sovereignty regulations such as GDPR and HIPAA, limiting the ability to correlate user data across different regions, industries, or organizations without explicit user consent.

Innovation Solution

A method and system for correlating user data across data borders by accessing databases in different regions, analyzing user data to identify matching subsets, and reporting these matches without transferring the data, using techniques like fuzzy matching and probabilistic correlations, and optionally anonymizing or hashing personally identifying information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is shared across borders to enable user correlation and targeted marketing, then productivity and commercial value are improved, but compliance with data sovereignty regulations (GDPR, HIPAA) deteriorates

Engineering Contradiction:
Improvedata utilization efficiencyVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments data into two distinct components: personally identifiable information (PII) that remains restricted within regional boundaries, and hashed identifiers that can be shared across borders. This segmentation allows the system to maintain GDPR and HIPAA compliance while enabling cross-border user correlation through the shared hashed identifiers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized data interface as an intermediary layer between regional data systems. This interface receives, validates, and processes data according to regional regulations before making it available for cross-border correlation. The intermediary ensures that data sovereignty requirements are met while facilitating international data utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user data is restricted within regional boundaries to comply with GDPR and HIPAA, then regulatory compliance is improved, but the ability to correlate user data across regions deteriorates

Engineering Contradiction:
Improveregulatory complianceVSAvoidcross-border data correlation capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates hashed copies of user identifiers that preserve the ability to correlate users across regions without copying or transferring the actual PII. These hashed identifiers can be shared and compared internationally while the original sensitive data remains protected within regional boundaries, preventing information loss in cross-border correlation.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If explicit user consent is required for each data sharing instance, then data sovereignty protection is improved, but ease of operation and commercial scalability deteriorate

Engineering Contradiction:
Improvedata sovereignty protectionVSAvoiddata sharing efficiency
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary actions by obtaining user consent once through standardized mechanisms (such as cookie banners) and storing the consent status with the user's hashed identifier. This preliminary consent action enables subsequent cross-border data correlations without requiring repeated consent requests, improving operational efficiency while maintaining data sovereignty protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12561466B2Data collaboration with sovereignty
Publication Date: 2026.02.24 AMADEUS SAS
  • US12561466B2 patent drawing
  • US12561466B2 patent drawing
  • US12561466B2 patent drawing

AI summary

A system and method is described for correlating user data across a data border between regions. A method includes obtaining access to a first database of user data stored by a first data manager in a first region and obtaining access to a second database of user data stored by a second data manager in a second region. At least one event is identified that is triggered by a user or a data manager in the first or second region. The second database of user data is then analysed to identify a subset of user data for one or more users correlated with the event. The identified subset of user data is then compared with user data in the first database to obtain a matching subset of user data from the first database. The matching subset of user data is then reported from the first database to the first data manager.