Workplace Sensor Data Redaction for Privacy-Controlled Release

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Employees and employers are uncomfortable with data privacy in workplace environments due to unclear data collection and use practices, leading to hesitance in implementing data-driven services that could provide significant benefits.

Innovation Solution

A system that provides employees with clear understanding and control over data collection and use through informed consent, allowing them to authorize data use in real-time and adjust preferences, with indicators for sensor status and data use, and accommodating individual privacy preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data collection and monitoring systems are implemented in the workplace, then productivity and collaboration benefits are improved, but employee privacy and comfort deteriorate

Engineering Contradiction:
Improveworkplace productivityVSAvoidemployee privacy concerns
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by obtaining employee authorization and informed consent before data collection begins. The commissioning process presents information about data collection purposes, types of data, and uses to employees in advance, allowing them to make informed decisions about their participation. This preliminary authorization step resolves the contradiction by establishing employee control over data collection before it impacts their privacy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamic data collection capabilities where employees can adjust their authorization preferences in real-time. The system adapts to individual employee choices by collecting data only from authorized employees and only for authorized purposes. This dynamic approach allows the system to maintain productivity benefits while respecting varying privacy preferences of different employees.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If comprehensive data collection is implemented, then data-driven services and insights are improved, but employee trust and comfort deteriorate

Engineering Contradiction:
Improvedata utilization valueVSAvoidemployee trust
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system segments data collection by employee, by data type, and by authorized use case. Each employee's authorization is handled separately, and data is collected and stored in a segmented manner that reflects individual preferences. This segmentation allows the system to maximize data utilization from authorized sources while maintaining employee trust through transparent, individualized control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms that provide employees with information about what data is being collected, how it is being used, and allow them to adjust their preferences. This feedback loop builds employee trust by making the data collection process transparent and giving employees ongoing control, while still enabling comprehensive data-driven services from the authorized data pool.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If data collection authorization processes are implemented, then employee control and privacy are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveemployee control over dataVSAvoidauthorization system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where employees can review, approve, and modify their data authorization preferences directly through the interface without requiring administrator intervention. The commissioning process is designed to be employee-driven, allowing them to take control of their own data preferences. This self-service approach simplifies the overall system by eliminating complex administrative approval workflows while maintaining strong employee control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system manages complexity by focusing on changing key parameters - specifically employee authorization states and data collection configurations - rather than implementing complex hierarchical approval systems. The commissioning process presents structured information and options that guide employees through authorization decisions without requiring them to understand underlying system complexities.

Inventive Principle:
Principle #35Parameter changes

4Loss of information

If informed consent processes are implemented, then employee understanding and privacy control are improved, but time and operational efficiency deteriorate

Engineering Contradiction:
Improveemployee understandingVSAvoidcommissioning time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system implements partial informed consent processes where employees are presented with information and options appropriate to their specific situation and the specific data collection context. Rather than requiring employees to review and understand all possible data collection scenarios in advance, the system provides targeted information about actual data collection purposes and types, reducing the time burden while maintaining adequate understanding.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12468837B1Data collection, storage and management system and method
Publication Date: 2025.11.11 STEELCASE INC
  • US12468837B1 patent drawing
  • US12468837B1 patent drawing
  • US12468837B1 patent drawing

AI summary

A method and system of controlling data collection and use, the method for use with at least a first sensor designed to sense at least a first parameter and an interface device, the method comprising the steps of receiving data values from the sensor, storing the received data values in a temporary private database that is inaccessible by at least a first application program, tracking time since collection for collected data values, presenting at least a first redaction option via the interface, upon selection of the first redaction option, rendering the at least a first data subset stored in the temporary database permanently inaccessible to the at least one application program and upon the tracked time since collection of stored data values reaching a threshold period, releasing the stored data values for use by the at least a first application program.