Sensitive Data Management System for Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in protecting and managing sensitive customer data, particularly when sharing information such as social security numbers, financial data, or birth dates, due to privacy laws and the need for explicit customer consent.

Innovation Solution

A sensitive data management system (SMS) that collects and stores customer data, separates it into general and sensitive categories, and requires explicit authorization from customers before sharing sensitive information, ensuring data protection and compliance with privacy laws.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If organizations share customer data through partnerships, then business collaboration and data utility are improved, but data security and privacy protection deteriorate

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a data sharing platform as an intermediary between organizations. This platform acts as a mediator that enables data sharing while implementing security controls, authorization mechanisms, and monitoring. The intermediary platform resolves the contradiction by providing a controlled environment where data can be shared (improving adaptability) while maintaining security protocols (preserving reliability).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments customer data into different categories and applies different sharing rules to each segment. By dividing data into sensitive and non-sensitive portions, and implementing granular access controls, the system allows necessary data sharing while protecting critical information. This segmentation enables selective sharing that improves collaboration without compromising overall security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If organizations implement stricter data protection measures, then data security is improved, but operational complexity and processing time worsen

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal data sharing platform that handles multiple security functions through a single system. The platform provides authorization, encryption, monitoring, and compliance management in one integrated solution, reducing the need for multiple separate security systems. This multi-functionality improves data protection while minimizing the complexity that would arise from implementing multiple separate measures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary authorization and classification of data before sharing occurs. By pre-establishing security protocols, authorization rules, and data categorization frameworks, the system avoids the need for complex real-time security decisions during data sharing operations. This preliminary action simplifies the operational process while maintaining strong security protections.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If organizations collect and store more customer information, then data utility and service quality are improved, but privacy risk and compliance burden worsen

Engineering Contradiction:
Improvedata completenessVSAvoidprivacy risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security and sharing rules to different portions of customer data based on their sensitivity and purpose. Rather than treating all data uniformly, the system implements local quality controls where sensitive data receives enhanced protection while less sensitive data can be shared more freely. This allows organizations to maintain complete customer information while applying appropriate privacy protections only where necessary.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The data sharing platform serves as an intermediary that manages the storage and protection of comprehensive customer information. By centralizing data management through this intermediary, the system can maintain complete customer profiles for service quality while implementing uniform security standards and compliance controls across all stored data, reducing overall privacy risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12299170B2Sensitive data management system
Publication Date: 2025.05.13 CAPITAL ONE SERVICES LLC
  • US12299170B2 patent drawing
  • US12299170B2 patent drawing
  • US12299170B2 patent drawing

AI summary

Disclosed herein are various embodiments for a sensitive data management system. An embodiment operates by receiving a web form from a transaction account of a web application associated with a first user, the form indicating a request for sensitive information of a second user. A request for an authorization to release the sensitive information to the web application. The authorization from the second user to release the sensitive information to the transaction account associated with the first user is received. The web form is populated with the sensitive information of the second user responsive to receiving the authorization from the second user to release the sensitive information, and the populated form including the sensitive information of the second user is provided to the web application.