CTV Privacy Consent Management Using Server-Side Hashed IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for managing consumer privacy in Connected TV (CTV) and Over-the-Top (OTT) applications are inadequate due to the lack of functional mechanisms for compliance with privacy regulations like CCPA and GDPR, as they cannot store information on devices like mobile and web applications, necessitating server-side solutions that are not currently available.

Innovation Solution

A system and method for managing consumer privacy in CTV and OTT applications by recording consent transactions and storing necessary information server-side, utilizing a central repository for selective curation, logging, and distribution of longitudinal customer preference records, with a single user-level view across data collection points, and providing a user interface for easy preference management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CTV and OTT applications use server-side storage for consent information, then compliance with privacy regulations is achieved, but device-level privacy management capabilities are lost

Engineering Contradiction:
Improvecompliance with privacy regulationsVSAvoiddevice-level privacy management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a consent management platform (CMP) as an intermediary system between the CTV/OTT application and the server. The CMP runs within the application interface, allowing users to manage their consent preferences locally through a user-friendly interface, while the actual consent data is stored and managed on the server side. This mediator enables both server-side compliance and user-friendly device-level management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If CTV and OTT applications implement non-compliant consent solutions, then service functionality is maintained, but regulatory compliance is violated

Engineering Contradiction:
Improveservice functionalityVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting and storing consent information server-side before any data processing occurs. The consent management platform captures user preferences and consent transactions in advance, creating a compliant foundation that enables subsequent service functionality while ensuring regulatory requirements are met from the outset.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If CTV and OTT applications lack device-level storage, then server-side centralized management is enabled, but user preference persistence becomes challenging

Engineering Contradiction:
Improvecentralized server-side managementVSAvoiduser preference persistence
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the server continuously stores, updates, and retrieves consent information based on user interactions. The consent management platform on the device receives feedback from the server about stored preferences and ensures they are persisted across sessions. This feedback loop guarantees user preference persistence through server-side storage while maintaining centralized management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12541618B2Privacy manager for connected tv and over-the-top applications
Publication Date: 2026.02.03 LIVERAMP
  • US12541618B2 patent drawing
  • US12541618B2 patent drawing
  • US12541618B2 patent drawing

AI summary

A system for processing privacy permissions for consumers utilizing vendor applications allows for recording, storing, and retrieving consent transactions performed by the users (data subjects) in data schemas. The system uses a number of hash-generated IDs, such that when a request is received to retrieve subject data, an organization ID (associated with the vendor or application) and identifying value (associated with the subject) are hashed to create a subject ID. The subject ID, organization ID, and a schema ID for the schema associated with the subject are hashed to create a subject data ID, which is then used to retrieve consent transactions and permissions associated with the subject.