Privacy Compliance System for Mobile App Data Regulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile application vendors face challenges in ensuring consumer privacy while collecting and transmitting data, as users are concerned about the types of information collected and where it is transmitted, necessitating a method for selective information transmission to third-party systems while maintaining privacy confidence.

Innovation Solution

A system and method for selectively regulating information transmission from mobile devices to third-party privacy compliant target systems through instrumentation instructions, including a software developers kit (SDK) that integrates with mobile applications, allowing vendors to implement privacy policies based on vendor-specific information, enabling consistent rules for information transmission without requiring device or user registration, and allowing mobile device operators to configure additional restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If mobile application vendors transmit information to third-party systems for analytics and insights, then the ability to understand consumer interaction and provide insights is improved, but consumer privacy concerns increase

Engineering Contradiction:
Improveinformation transmission capabilityVSAvoidprivacy concerns
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the information transmission process by introducing a privacy compliance system that acts as an intermediary between mobile applications and third-party target systems. This system divides the data flow into controlled segments, allowing only privacy-compliant information to be transmitted while blocking non-compliant data, thus resolving the contradiction between information transmission needs and privacy protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The privacy compliance system serves as an intermediary component that sits between the mobile application vendor's instrumentation and the third-party target systems. It receives information from applications, evaluates it against privacy policies, and selectively forwards compliant information to third parties, thereby enabling information transmission while mitigating privacy concerns through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If privacy policies are implemented with vendor-specific information, then each vendor can independently manage privacy compliance, but the system complexity increases

Engineering Contradiction:
Improvevendor-specific privacy policy managementVSAvoidprivacy policy configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The privacy compliance system implements a universal framework that handles multiple vendors' privacy requirements through a single standardized interface. The system uses common data structures (such as concern-specific identifiers) and unified policy evaluation mechanisms that work across different vendors, reducing overall system complexity while maintaining vendor-specific customization capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If information is selectively transmitted based on privacy policies, then privacy compliance is improved, but the quantity of transmitted information decreases

Engineering Contradiction:
Improveprivacy complianceVSAvoidinformation transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system changes the parameters of information transmission by dynamically evaluating data against privacy policy criteria. Instead of transmitting all information uniformly, the system modifies transmission parameters based on compliance assessments, allowing full transmission of compliant data while blocking non-compliant portions, thus maintaining privacy reliability without unnecessarily reducing overall information flow

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11159573B1Selective regulation of information transmission from mobile applications to third-party privacy compliant target systems
Publication Date: 2021.10.26 QUANTCAST CORP
  • US11159573B1 patent drawing
  • US11159573B1 patent drawing
  • US11159573B1 patent drawing

AI summary

Selective regulation of information transmission from mobile applications to an external system. A privacy policy is configured for and mapped to each of a multiplicity of mobile application concerns, with each privacy policy comprising rules regulating the transmission of information to an external system. Instrumentation instructions can be integrated with a mobile application or mobile operating system. The instrumentation instructions direct the mobile device to submit a privacy policy request comprising an identifier from the mobile device to a third-party privacy compliance system and enable sending information from the mobile device to the external system, subject to the privacy policy. The privacy policy request is received at the third-party privacy compliance system which selects the privacy policy based on an identifier and sends the privacy policy to the mobile device for implementation.