Centralized PII Management Engine for Cross-Provider Data Removal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of network transactions over the Internet has resulted in numerous entities storing and controlling vast amounts of personal identifying information (PII), making it difficult for individuals to track and manage their data, and for entities to comply with regulations like GDPR, which requires proper management of PII to ensure data privacy rights.

Innovation Solution

A computer-implemented method manages PII by receiving requests from requestors to perform actions such as removal or transfer of PII, authenticating the request, determining applicable restrictions, broadcasting the request to multiple service providers, verifying responses, and compiling a reply, all while logging interactions for compliance purposes, using a centralized management engine that interacts with service profiles and data quality verification structures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple entities store and control PII across distributed systems, then data availability and service functionality are improved, but data management complexity and compliance difficulty increase

Engineering Contradiction:
Improvedata availabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized PII management system that acts as an intermediary between individuals and multiple service providers. This central system receives, tracks, and coordinates PII requests across all entities, simplifying management for individuals while maintaining data availability across distributed service providers through standardized interfaces and audit trails.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If PII is stored across numerous service providers, then service functionality and data utility are improved, but individual control and regulatory compliance become more difficult

Engineering Contradiction:
Improveservice functionalityVSAvoidindividual control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal PII management system that provides multi-functional capabilities including request reception, authentication, restriction determination, broadcasting to service providers, response verification, and audit logging. This single system handles all PII management operations across diverse service providers, making individual control easier while preserving service functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a centralized system manages PII requests across multiple providers, then compliance and consistency are improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvecompliance consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the PII management process into distinct functional modules: request reception, authentication, restriction determination, broadcasting, response verification, and audit logging. Each module handles a specific aspect of compliance, making the overall system more manageable despite its comprehensive nature, while ensuring consistent compliance across all service providers.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11783015B2Management systems for personal identifying data, and methods relating thereto
Publication Date: 2023.10.10 MASTERCARD INT INC
  • US11783015B2 patent drawing
  • US11783015B2 patent drawing
  • US11783015B2 patent drawing

AI summary

Systems and methods are provided for managing personal identifying information (PII). An exemplary method includes receiving, from a requestor, a request to remove PII for at least one individual from multiple service providers. In response, a computing device authenticates the requestor, determines whether a restriction on the PII or the individual applies to the request, and broadcasts the request to the service providers. The computing device receives a response to the request from each of the service providers indicating removal of the PII and compiles a reply to the request, based on each response, where the reply includes a confirmation of removal of the PII. The computing device then transmits the reply to the requestor and logs the request from the requestor and the response from each of the services providers in an audit data structure, thereby permitting compliance with PII controls to be demonstrated.