Data Anonymization and Geo-Pinning for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to anonymize end user data and ensure it is transmitted and stored on systems pinned to a designated geo-location to protect user privacy and comply with regulations such as GDPR and HIPAA, as existing solutions inadequately address the misuse of personally identifiable information and lack geo-location constraints.

Innovation Solution

Systems and methods for data localization and anonymization involve receiving communication requests, determining the need for securing personally identifiable information, and processing them through anonymization or geo-pinning, using an API to specify when and how to anonymize or localize data, ensuring it is stored within specific regions, and employing a global cloud communications platform with anonymization and geo-pinning managers to manage data transmission and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personally identifiable information is collected and stored to provide services, then service quality is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improveservice qualityVSAvoidprivacy risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information from data records and stores it separately in secured PII storage, while retaining only anonymized data in communication logs. This separation allows service provision to continue while eliminating privacy risks associated with storing complete PII in accessible locations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a PII manager as an intermediary component that mediates between service operations and personal data. The PII manager controls access to personally identifiable information, allowing services to function while preventing unauthorized access that would compromise privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data is stored in centralized locations for efficient access, then service efficiency is improved, but compliance with geo-location regulations deteriorates

Engineering Contradiction:
Improveservice efficiencyVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data storage into multiple geographic regions with local data centers or cloud storage locations. Data is divided and stored in different jurisdictions according to regulatory requirements, allowing efficient local access while ensuring compliance with geo-location regulations for each region.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements location-aware data storage where data is stored in specific geographic locations based on regulatory requirements. Each region has customized storage policies that match local laws, ensuring that data accessed in a particular location complies with that location's regulations while maintaining overall service efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10778648B2Systems and methods for regional data storage and data anonymization
Publication Date: 2020.09.15 VONAGE BUSINESS INC
  • US10778648B2 patent drawing
  • US10778648B2 patent drawing
  • US10778648B2 patent drawing

AI summary

Systems and methods for data localization and anonymization are provided herein. In some embodiments, systems and methods for data localization and anonymization may include receiving a communication request to send a message or establish a call between a first service provider and an end user device associated with an end user, determining that the communication request is associated with a requirement for securing personally identifiable information (PII) of the end user, and processing the communication request based on the requirement for securing the PII of the end user, wherein the requirement includes at least one of (A) localization of the communication request processing or (B) anonymization of any data records associated with the communication request that includes the PII of end user.