Sensitive Data Management System for Online Privacy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in managing and controlling their sensitive personal data shared with online sites, particularly concerning data retention, deletion, and privacy, exacerbated by security breaches and unlawful information sharing.
Innovation Solution
A system that detects and records sensitive data fields from user devices, stores site information with current dates, and allows users to manage their data by displaying site information and sending requests, such as deletion requests, to the online sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users share personal data with online sites for convenience, then ease of operation is improved, but user privacy and data security deteriorate
Solution Approach 1:
The system implements feedback by continuously monitoring data transmission between user devices and online sites, tracking what personal information is shared, where it is sent, and when it should be deleted. This feedback loop enables the system to notify users about their data exposure and automatically enforce deletion policies, creating a closed-loop privacy protection mechanism that operates in the background without interfering with user convenience.
Solution Approach 2:
The patent introduces an intermediary system that positions itself between users and online sites. This intermediary monitors data transmissions, identifies sensitive information, tracks retention periods, and automatically sends deletion requests to sites. By acting as a mediator, the system protects user privacy without requiring users to manually manage each data sharing instance, thus maintaining ease of operation while preventing privacy violations.
2Productivity
If online sites retain user data for business purposes, then productivity is improved, but compliance with privacy regulations deteriorates
Solution Approach 1:
The system applies preliminary action by establishing predetermined deletion policies based on privacy regulations and user preferences before data retention becomes a compliance issue. The system proactively tracks how long data has been retained, compares it against policy thresholds, and automatically initiates deletion processes before violations occur. This preemptive approach allows sites to maintain data for business productivity while ensuring regulatory compliance is never breached.
Solution Approach 2:
The patent implements self-service by enabling the system to automatically manage data retention and deletion without requiring continuous human intervention. Once deletion policies are configured, the system autonomously monitors data age, identifies data ready for deletion, and executes deletion requests across multiple sites. This self-service mechanism ensures ongoing compliance with privacy regulations while allowing business operations to proceed with full data retention where permitted.
3Adaptability or versatility
If users manually track and manage their personal data across multiple sites, then user control is improved, but loss of time increases
Solution Approach 1:
The system applies universality by creating a single multi-functional platform that consolidates multiple data management tasks. One system performs data tracking across numerous sites, retention period calculation, policy enforcement, deletion request generation, and user notification functions. This universal approach gives users comprehensive control over their personal data across all online interactions through a single interface, eliminating the need to manually track each site separately and significantly reducing the time users would otherwise spend on this task.
4Reliability
If automated systems monitor and delete user data, then compliance with privacy regulations is improved, but device complexity increases
Solution Approach 1:
The patent applies merging by combining multiple previously separate functions into a unified automated system. Instead of having separate mechanisms for tracking data, calculating retention periods, determining compliance status, and executing deletions, the system integrates all these functions into one cohesive automated platform. This consolidation achieves robust regulatory compliance while actually reducing overall system complexity by eliminating the need for multiple independent tracking and management systems.
Data Source
AI summary
An approach is provided that detects transmission of sensitive data fields from a user device to an online site. The approach determines the data types of the sensitive data fields and gathers site information from the online site which are stored in a data store along with the current date. Subsequently, the user can manage the data by displaying site information on a display of the user device. Each record of site information pertains to one of many online sites including the selected online site. The user makes a data management request at the user device pertaining to the selected site information. The approach then responsively transmits a request to the selected online site with the request being based on the received data management request. One example of a request is a deletion request that requests that the online site remove the user's sensitive data from the online site.


