GDPR Infrastructure for Microservices Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a comprehensive infrastructure to effectively manage and comply with the General Data Protection Regulation (GDPR) requirements, particularly in handling personal data across multiple applications, including data subject rights, data protection, and compliance reporting.

Innovation Solution

A cloud computing platform infrastructure with a general data privacy regulator module, retention engine, data privacy compliance module, and data subject privacy request module, along with a programming model that includes data privacy annotations, to monitor and manage personal data flow, enforce deletion policies, and ensure compliance with GDPR regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single application is used to manage personal data, then the application can handle its own data requirements, but it cannot provide an overview of personal data usage across multiple applications

Engineering Contradiction:
Improvedata management capabilityVSAvoidoverview of personal data usage
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system segments personal data management into two layers: application-level handlers that manage individual application data, and a centralized GDPR infrastructure that aggregates data from multiple applications. This segmentation allows each application to maintain independence while the centralized system provides comprehensive oversight of all personal data usage across the organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized GDPR infrastructure module that acts as an intermediary between multiple applications and data subjects. This intermediary collects, aggregates, and manages personal data from various applications, enabling comprehensive data usage overview while maintaining application-level operational independence through standardized interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive GDPR compliance monitoring is implemented across all data operations, then data protection and compliance are improved, but system complexity and operational overhead increase

Engineering Contradiction:
ImproveGDPR complianceVSAvoidcompliance monitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing standardized data handling protocols and automated compliance checks before data processing operations. The GDPR infrastructure is configured in advance with retention policies, deletion rules, and monitoring mechanisms that automatically execute during normal data operations, reducing the need for complex real-time compliance verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service mechanisms where the GDPR compliance system automatically monitors, audits, and enforces data protection rules without requiring manual intervention. The infrastructure autonomously tracks personal data flows, generates compliance reports, and executes data subject rights requests, reducing operational overhead while maintaining high compliance reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automated data deletion is implemented to fulfill the right to be forgotten, then data subject rights are protected, but data retention and access requirements may be compromised

Engineering Contradiction:
Improvedata subject rights fulfillmentVSAvoiddata retention compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic data retention management where deletion policies are not static but adapt based on multiple factors including data subject requests, legal requirements, and business needs. The GDPR infrastructure evaluates each data item against configurable retention rules and legal grounds, allowing flexible balancing between automated deletion for rights fulfillment and selective retention when legally required.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the compliance monitoring system continuously tracks data retention status and automatically adjusts deletion operations. When data subject deletion requests are received, the system evaluates them against retention policies and legal requirements, providing feedback loops that ensure both data subject rights are honored and necessary data is preserved according to compliance obligations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10839099B2General data protection regulation (GDPR) infrastructure for microservices and programming model
Publication Date: 2020.11.17 SAP SE
  • US10839099B2 patent drawing
  • US10839099B2 patent drawing

AI summary

A system for protecting personal data is disclosed. The system includes a general data privacy regulator module having a dataflow controller configured to monitor data communicated to and from one or more business applications, and having a retention engine configured to retain personal information from the data communicated to and from the business application according to at least one data privacy regulation. The system further includes a data privacy compliance module connected with the general data privacy regulator module, and configured with the data privacy regulation to monitor the dataflow controller and report to a client computer. The system further includes a data subject privacy request module connected with the general data privacy regulator module and the data privacy compliance module, and configured to receive one or more requests from the cloud computing platform about a data subject stored by the business application and generate an action based on the one or more requests.