Privacy Vault Token Mediator for GDPR Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in managing and controlling private/sensitive information across various services and systems, particularly in ensuring compliance with regulations like GDPR, where individuals' data is scattered and companies face difficulties in obtaining consent for data access and deletion requests, leading to potential legal and financial burdens.

Innovation Solution

A consent-driven privacy disclosure control system that utilizes a privacy server with a vault, user interface, and retailer APIs to manage user consent and generate tokens for authorized access, ensuring that only registered users can access their private information based on recorded consent, thereby providing a centralized mechanism for compliance and data control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If companies spend large sums of money to map/classify individual information for GDPR compliance, then compliance capability is improved, but cost increases

Engineering Contradiction:
ImproveGDPR compliance capabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a privacy server as an intermediary between users and services. This server acts as a mediator that manages consent tokens and controls data access, eliminating the need for companies to perform expensive mapping and classification of individual information while maintaining GDPR compliance capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If individuals' private information floats through many systems, then information accessibility is improved, but control and security deteriorate

Engineering Contradiction:
Improveinformation accessibilityVSAvoidloss of control
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The privacy server serves as a central intermediary that all services must access through authenticated tokens. This prevents information from floating freely across systems while maintaining accessibility for authorized services, thereby resolving the contradiction between accessibility and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments data access control into discrete consent tokens associated with specific services and data types. This segmentation allows fine-grained control over which services can access which information, maintaining both accessibility for authorized services and control for users.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If companies implement strict data control standards, then security is improved, but operational complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidoperational complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

By implementing the privacy server as a mandatory intermediary, the system achieves strict data control and security without increasing operational complexity at the service level. Services simply need to obtain and present valid tokens, while the privacy server handles all complex authentication and authorization logic centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If all individual records must be made inaccessible when deletion is requested, then compliance is improved, but system complexity increases

Engineering Contradiction:
Improvedeletion complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The privacy server acts as a single point of control for deletion requests. When a user requests data deletion, the server can revoke consent tokens across all services, ensuring compliance without requiring each service to independently manage deletion complexity. The intermediary handles the coordination of data removal across the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12045371B2Consent-driven privacy disclosure control processing
Publication Date: 2024.07.23 NCR VOYIX CORP
  • US12045371B2 patent drawing
  • US12045371B2 patent drawing
  • US12045371B2 patent drawing

AI summary

A user provides retailer-specific consents for access and use to private/sensitive information of the user. The private/sensitive information is centrally stored in a privacy vault. Retail services (retailer) that the user subscribes to are provided a user-specific and consent-specific token representing the user and consents to usage of specific private/sensitive information of the user. When the retailer has a need for user-specific private/sensitive information, the retailer presents the user-specific and consent-specific token to the privacy vault. Assuming, the retailer was given access to the requested private/sensitive information defined in the token, the privacy results returns the requested information to the retailer; otherwise, an unauthorized message is returned from the privacy vault to the retailer. The user defines the consents to each retailer and a record of the consents is maintained in the privacy vault.