Rules-Based Data Access System for Compliance Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in determining and ensuring compliance with various laws, regulations, and contractual restrictions when accessing or sharing customer data, leading to inefficiencies and potential legal risks due to the complexity of governing standards.

Innovation Solution

A rules-based data access system that categorizes customer data based on type and applicable policies, evaluates shareability rules considering customer preferences, the requesting entity, and the providing entity, and provides access while demonstrating compliance through an auditable template.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If companies share data with affiliates or third parties to create efficiencies and increase accuracy, then productivity and data accuracy are improved, but legal risks and compliance complexity increase

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidcompliance risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between data providers and data requestors. This system automatically evaluates data shareability by interpreting complex legal standards and policies, thereby enabling efficient data sharing while mitigating compliance risks through automated legal analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual legal analysis and compliance review processes with an automated computer-based system. This mechanical substitution allows for rapid, consistent evaluation of data shareability against multiple legal standards without human intervention, improving both efficiency and reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If companies do not share data to avoid noncompliance risks, then legal risks are minimized, but productivity and data accuracy deteriorate

Engineering Contradiction:
Improvecompliance safetyVSAvoiddata sharing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables organizations to self-assess their data sharing compliance status automatically. By providing tools for organizations to evaluate their own data shareability against applicable legal standards, the system maintains compliance safety while enabling productive data sharing without requiring external legal review for each transaction.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary legal analysis and compliance evaluation before data sharing transactions occur. This advance assessment identifies which data can be shared compliantly, allowing organizations to proceed with productive data sharing activities without risking noncompliance, thereby resolving the contradiction between safety and efficiency.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple laws and regulations govern data sharing, then comprehensive legal coverage is achieved, but system complexity and difficulty of determination increase

Engineering Contradiction:
Improvelegal coverageVSAvoidcompliance system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal system that can handle multiple different legal standards and regulations through a single automated platform. The system is designed to interpret and apply various legal frameworks (such as FCRA, HIPAA, GDPR) uniformly, reducing the perceived complexity by providing a single interface for managing compliance across multiple jurisdictions and regulations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts its evaluation parameters based on the specific data type, jurisdiction, and applicable legal framework. By automatically changing the relevant legal parameters and standards being applied, the system manages complexity through adaptive parameter selection rather than requiring manual configuration for each legal regime.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If manual evaluation of data shareability is performed, then flexibility in decision-making is maintained, but time consumption and operational inefficiency increase

Engineering Contradiction:
Improvedecision flexibilityVSAvoidevaluation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent replaces manual legal evaluation processes with automated computer-based analysis. This substitution maintains adaptability by programmatically applying complex legal logic while dramatically reducing the time required for evaluation, eliminating the trade-off between flexibility and speed that characterizes manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms that allow for iterative refinement of data shareability decisions. By automatically analyzing outcomes and adjusting evaluations based on accumulated data and experience, the system maintains high adaptability while operating at automated speeds, resolving the contradiction between flexible decision-making and time efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12141321B1Rules-based data access systems and methods
Publication Date: 2024.11.12 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12141321B1 patent drawing
  • US12141321B1 patent drawing
  • US12141321B1 patent drawing

AI summary

Methods and systems for rules-based data access are described. In some embodiments, a request for access to customer data by a requesting entity is received; the data is categorized; the person's preferences with respect to allowing access to data are compiled; a requesting entity is determined; and the providing entity that collected each requested data item is determined. Data shareability rules are evaluated based on the policies that regulate the access of the customer data and the requesting entity, and the customer data is provided to the requesting entity according to the evaluation.