End-of-Purpose Protocol With Purpose-Based Consensus Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex organizational landscapes with multiple integrated applications, managing data privacy and ensuring compliance with regulations such as blocking personal data when there is no legitimate purpose for processing it is challenging due to distributed end-of-purpose checks and replication issues, leading to inefficiencies and potential non-compliance.
Innovation Solution
Implementing an aligned purpose disassociation protocol that allows each system to make local 'can-disassociate' decisions and a central evaluation to determine a unified disassociation instruction, along with an integrated end-of-purpose protocol for consensus blocking, and an integrated personal data retrieval protocol for unified data reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If distributed end-of-purpose checks are performed across multiple applications, then data privacy compliance is improved, but system complexity and processing time increase
Solution Approach 1:
The patent introduces a data privacy integration service as an intermediary component that coordinates end-of-purpose checks across multiple applications. This service receives requests from initiating applications, manages the distributed checking process, and returns unified results, thereby improving compliance while abstracting away the complexity of distributed coordination from individual applications.
Solution Approach 2:
The system segments the end-of-purpose checking process into distinct components: initiating applications that request checks, a data privacy integration service that coordinates the process, and target applications that provide local checking capabilities. This segmentation allows each component to have specialized functionality while working together to achieve comprehensive compliance.
2Reliability
If distributed end-of-purpose checks are performed across multiple applications, then data privacy compliance is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by having applications pre-register their purpose information and data objects with the data privacy integration service before end-of-purpose checks are needed. This pre-positioning of information allows the integrated service to quickly coordinate checks without requiring extensive real-time communication between multiple applications.
Solution Approach 2:
The data privacy integration service implements feedback mechanisms where target applications return their local end-of-purpose check results to the integrated service, which then aggregates this feedback to determine the overall result. This structured feedback loop enables efficient coordination and reduces the time required for distributed checking by avoiding redundant communications.
3Loss of information
If purpose information is tracked across multiple applications, then unified data retrieval is improved, but information management complexity increases
Solution Approach 1:
The data privacy integration service provides universal functionality for managing purpose information across different applications and data types. It handles various operations including tracking, retrieving, and evaluating purpose information regardless of the specific application or data object involved, thereby unifying data retrieval while managing complexity centrally.
Solution Approach 2:
The integrated service acts as an intermediary layer between applications and purpose information, centralizing the management of purpose data. Applications interact with this service rather than directly managing purpose information themselves, which unifies retrieval operations while the service handles the complexity of information management internally.
Data Source
AI summary
The present disclosure involves systems, software, and computer implemented methods for integrated data privacy services. An example method includes determining to initiate an integrated end of purpose protocol for an object of an object type. Target applications are determined that are allowed to process objects of the object type for at least one purpose, based on identified purpose information. An end-of-purpose query is provided to the target applications and an end-of-purpose status is received from each target application that indicates whether the application is able to block the object. The received statuses are evaluated to determine whether an aligned end of purpose has been reached for the object. In response to determining that the aligned end of purpose has been reached for the object, a block command is provided to each of the multiple applications that instructs a respective application to locally block the object.


