IP Library › Granted Patent US 12,739,124
Granted Patent B1
US 12,739,124 · App. 19/537,814 · Granted Sep 15, 2026

Contextual privacy fingerprinting engine (CPFE)

Inventor: Eitan Caspi (Kfar-Yona, IL)
H04L9/3213G06F21/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,124
App. No.
19/537,814
Granted
Sep 15, 2026
Kind
B1
Abstract

There is provided a method comprising: extracting candidate contextual metadata associated with a data processing event, filtering the candidate contextual metadata to reject fields matching patterns correlated with identifiable data, for generating contextual metadata excluding data identifiable with at least one specific identity, dynamically computing a regulatory anchor set for the data processing event based on the contextual metadata, the regulatory anchor set comprising state anchors indicating a dynamic state computed based on current operation and/or current context, feeding the regulatory anchor set into a deterministic reasoning engine configured for verification of the privacy policy by applying jurisdictional rules, computing, by the reasoning engine, a verification indication and an explanation trace without using data identifiable with at least one specific identity, and generating a non-identifiable verification token (NICT) including the verification indication and the explanation trace, wherein the NICT excludes data identifiable with at least one specific identity.

Claims (133)

1 . A computer implemented method of automated verification of a privacy policy, comprising:

monitoring a data processing system for a data processing event;

extracting candidate contextual metadata associated with the data processing event,

filtering the candidate contextual metadata to reject fields matching patterns correlated with identifiable data, including: email address, phone number, name, device identifier, cookies, pseudonym, network addresses, and hashed identifiers, for generating contextual metadata excluding data identifiable with at least one specific identity;

dynamically computing, by at least one of a connector executing within the data processing system and a server, a regulatory anchor set for the data processing event based on the contextual metadata, the regulatory anchor set comprising a plurality of state anchors indicating a dynamic state computed based on current operation and/or current context;

feeding the regulatory anchor set into a deterministic reasoning engine configured for verification of the privacy policy by applying jurisdictional rules;

computing, by the reasoning engine, a verification indication and an explanation trace without using data identifiable with at least one specific identity;

generating a non-identifiable verification token (NICT) including the verification indication and the explanation trace, wherein the NICT excludes data identifiable with at least one specific identity; and

in response to the NICT indicating a breach of the privacy policy, transmitting to the data processing system instructions for blocking execution of the data processing event.

2 . The computer implemented method of claim 1 , further comprising, in response to the NICT indicating conditional execution, transmitting to the data processing system instructions for temporarily pausing execution of the data processing event, and ensuring implementations of specific safeguards encoded in the NICT before resuming execution of the data processing event.

3 . The computer implemented method of claim 1 , wherein a plurality of NICTs are computed for a plurality of data processing events, and further comprising:

storing the plurality of NICTs in a database; and

providing an interface for executing a query on the plurality of NICTs, wherein the query is selected from: identifying NICTs where consent state is expired and operation is export, identifying NICTs where retention has expired but processing continued, aggregating NICTs by risk score exceeding a threshold, identifying convergence clusters spanning multiple systems, and identifying NICTs where required safeguards are missing.

4 . The computer implemented method of claim 1 , wherein the regulatory anchor set and/or NICT are non-identifying of a specific personal identity, not derived from attributes of the specific personal identify, non-reversible for identification of the specific personal identity, and cannot be used to reconstruct personal data, identity information, and/or person-related entities.

5 . The computer implemented method of claim 1 , further comprising:

detecting, by a convergence engine, a plurality of related data processing events from a plurality of different data processing systems based on contextual similarity;

computing a respective regulatory anchor set for each data processing event to generate a plurality of regulatory anchor sets,

computing a convergence confidence score based on at least one or combination of:

an anchor similarity score comparing anchor sets of the plurality of related events,

a temporal alignment score measuring temporal proximity, and

a cross-system reliability coefficient;

in response to the convergence confidence score exceeding a threshold, generating a privacy fingerprint data structure by: merging the plurality of regulatory anchor sets from the plurality of related events, and structuring the merged plurality of regulatory anchor sets into at least one privacy fingerprint encoding verification data, wherein the privacy fingerprint excludes personal data and personal identifiers; and

wherein feeding the regulatory anchor set into the deterministic reasoning engine comprises feeding the privacy fingerprint into the deterministic reasoning engine.

6 . The computer implemented method of claim 5 , wherein:

the monitoring and the filtering are implemented by a respective connector locally installed in each of the plurality of different data processing systems,

the contextual metadata is extracted by the respective connector from each corresponding data processing system and sent to the server,

the server generates the plurality of regulatory anchor sets and generates the privacy fingerprint, and operates the deterministic reasoning engine.

7 . The computer implemented method of claim 5 , wherein the privacy fingerprint data structure comprises at least one of:

a legal-state vector encoding at least one of: at least one candidate legal basis, a consent state indicator, a jurisdiction identifier, and a list of regulatory constraints;

a retention-state vector encoding at least one of: a retention policy code and an expiration timestamp;

a risk-state vector encoding: a risk score, a list of risk factors, and a list of required safeguards;

a technical-context vector encoding at least one of: a system origin identifier, a processing action code, and a list of systems involved in the convergence; and

a jurisdictional-context vector encoding: at least one applicable jurisdiction.

8 . The computer implemented method of claim 1 , wherein the state anchors are selected from:

a purpose anchor encoding a purpose vector,

an operation anchor encoding a canonical operation code,

a sensitivity anchor encoding an event sensitivity score,

a transfer boundary anchor indicating whether the event crosses a boundary,

a jurisdiction anchor indicating a jurisdiction,

a lawful basis anchor indicating lawful basis candidates,

a retention anchor and/or expiration anchor indicating whether retention is expired,

a risk and/or safeguards anchor indicating a risk score,

a behavioral pattern and/or anomaly anchor indicating anomalous patterns,

a convergence confidence anchor indicating a common processing context,

a legal explanation and/or decision trace anchor indicating deterministic decision trace,

a provenance evidence chain anchor indicating provenance,

a technical context and/or execution environment anchor encoding execution context, and

an adaptive monitoring and/or feedback state anchor implementing closed-loop monitoring.

9 . The computer implemented method of claim 8 , wherein the purpose anchor is computed by:

extracting a feature vector from the contextual metadata;

applying a multi-signal purpose classifier to generate a purpose probability distribution over a plurality of canonical purpose classes;

selecting a purpose band based on the purpose probability distribution;

computing a confidence score based on a maximum probability value and a quality coefficient derived from signal completeness; and

computing a purpose drift measure by calculating a divergence between the purpose probability distribution and a baseline purpose distribution for similar events.

10 . The computer implemented method of claim 8 , wherein the lawful-basis anchor encodes:

a lawful basis selected from: consent, contract, legal obligation, vital interests, public task, and legitimate interest;

a consent state selected from: valid, expired, missing, withdrawn, not required, and unknown; and

a list of constraint codes specifying conditions that must be satisfied for the data processing event to comply with the privacy policy.

11 . The computer implemented method of claim 8 , wherein the retention anchor encodes:

an allowed time-to-live value;

an age value representing time elapsed since data creation;

an expiration Boolean indicating whether retention has expired;

a retention band selected from: active, near expiry, expired, and unknown; and

a deletion capability classification indicating whether the data processing system supports automated deletion.

12 . The method of claim 8 , wherein the regulatory anchor set further comprises at least one of:

a transfer boundary anchor encoding at least one of: a boundary classification selected from: internal, internal extract-transform-load (ETL), to third party, cross-border, and unknown; a third-party Boolean; a cross-border Boolean; a destination class; and a geographic destination identifier;

a jurisdiction anchor encoding at least one of: a primary jurisdiction identifier, at least one secondary jurisdiction identifier, a controller locus identifier, and a subject locus identifier; and

a technical context anchor encoding at least one of: an execution mode selected from: application programming interface (API) call, batch job, export job, sync task, and ETL pipeline; a data flow direction selected from: inbound, outbound, and internal; and an integration type selected from: native, custom API, software as a service (SaaS), and file export.

13 . The method of claim 8 , wherein the operation anchor is computed by:

extracting operation signals from the contextual metadata including at least one of: application programming interface (API) endpoint patterns, database operation types, job scheduler metadata, and network flow direction;

applying a multi-signal operation classifier to generate an operation probability distribution over canonical operation codes;

selecting a canonical operation code from: read, query, write, update, delete, export, share, and sync; and

computing an operation confidence score and an operation drift measure.

14 . The computer implemented method of claim 8 , wherein the deterministic reasoning engine computes the verification indication and the explanation trace by:

loading the regulatory anchor set into memory;

identifying applicable jurisdictional rules based on the jurisdiction anchor in the regulatory anchor set;

evaluating conditions of the jurisdictional rules against values encoded in the state anchors;

accumulating decision effects according to a rule hierarchy;

selecting at least one legal basis from candidate legal bases in the lawful basis anchor based on satisfaction of rule conditions; and

generating the explanation trace comprising: identifiers of triggered rules, anchor values evaluated, conditions satisfied, and the selected legal basis.

15 . The computer implemented method of claim 8 , wherein the risk anchor is computed by:

computing a sensitivity score based on a category exposure multiplier derived from data categories in the contextual metadata, and a volume escalation effect derived from processing volume metrics;

determining a transfer boundary classification indicating whether the data processing event crosses at least one of: an internal boundary, a third-party boundary, and a cross-border boundary;

applying a risk model to the sensitivity score and the transfer boundary classification to generate the risk score; and

determining required safeguards based on the risk score and jurisdictional requirements.

16 . The computer implemented method of claim 1 , wherein the data processing system comprises a plurality of heterogeneous data processing system, and further comprising:

mapping different fields of the plurality of heterogeneous data processing system to canonical verification-context signals for performing semantic normalization of multi-source contextual data,

wherein the regulatory anchor set is computed based on the canonical verification context-signals.

17 . The computer implemented method of claim 1 , further comprising: during a bootstrap phase, performing system profiling by:

receiving, from a connector monitoring the data processing system, schema data describing data objects in the data processing system without receiving personal data,

applying a machine learning (ML) model to the schema data to infer data categories and sensitivity classifications, and

generating a monitoring plan specifying which events to monitor and which anchors to compute; and

transmitting the monitoring plan to the connector for implementation.

18 . The computer implemented method of claim 17 , further comprising: computing a behavioral anomaly anchor by:

calculating at least one of: a rate anomaly score, a burst anomaly score, and a temporal coherence score from aggregate telemetry data,

computing an anomaly score from the calculated scores, and

when the anomaly score exceeds a threshold, updating the monitoring plan to increase at least one of: sampling rate, evidence collection level, and enabled optional anchors; and transmitting the updated monitoring plan to the connector.

19 . The computer implemented method of claim 1 , further comprising:

anchoring a multi-dimensional anchor template to the data processing event, wherein the multi-dimensional anchor template includes at least one of:

(i) a legal dimension indicating jurisdictional requirements, consent requirements, candidate legal bases, and retention policies,

(ii) a contextual dimension including at least one of purpose codes,

processing actions, and data categories,

(iii) a risk dimension indicating base risk scores, risk factors and technical constraints,

selecting a type of the multi-dimensional anchor template from a plurality of multi-dimensional anchor templates of different types based on template selection criteria applied to the contextual metadata; and

computing the regulatory anchor set by instantiating the selected multi-dimensional anchor template with values from the contextual metadata.

20 . The computer implemented method of claim 19 , further comprising:

storing the plurality of multi-dimensional anchor templates in an anchor repository, wherein each multi-dimensional anchor template is versioned and associated with at least one of:

an anchor type identifier, a jurisdiction pattern, a purpose code pattern, and a data category pattern; and

resolving the selected multi-dimensional anchor template by:

matching the contextual metadata against the jurisdiction pattern, purpose code pattern, and data category pattern of each anchor template, and

selecting the multi-dimensional anchor template with highest priority among matching templates.

21 . A system for automated verification of a privacy policy, comprising;

a plurality of connectors, each connector configured for installation in a data processing system of a plurality of data processing systems and for

monitoring the data processing system for a data processing event;

extracting non-identifying contextual metadata associated with the data processing event,

extracting candidate contextual metadata associated with the data processing event,

wherein the candidate contextual metadata excludes data identifiable with at least one specific identity;

processing the candidate contextual metadata against a predefined schema to reject fields matching patterns correlated with identifiable data, including: email address, phone number, name, device identifier, cookies, pseudonym, network addresses, and hashed identifiers, for generating contextual metadata excluding data identifiable with at least one specific identity; and

transmitting the contextual metadata over a network to a server;

at least one processor of the server in network communication with the plurality of connectors, the at least one processor executing a code for:

dynamically computing a regulatory anchor set for the data processing event based on the contextual metadata, the regulatory anchor set comprising a plurality of state anchors indicating a dynamic state computed based on current operation and/or current context;

feeding the regulatory anchor set into a deterministic reasoning engine configured for verification of the privacy policy by applying jurisdictional rules;

computing a verification indication and an explanation trace by the reasoning engine without using data identifiable with at least one specific identity; and

generating a non-identifiable verification token (NICT) including the verification indication and the explanation trace, wherein the NICT excludes data identifiable with at least one specific identity; and

in response to the NICT indicating a breach of the privacy policy, transmitting to the data processing system instructions for blocking execution of the data processing event.

22 . A non-transitory medium storing program instructions for automated verification of a privacy policy, which when executed by at least one processor, cause the at least one processor to:

extract candidate contextual metadata associated with the data processing event,

filter the candidate contextual metadata to reject fields matching patterns correlated with identifiable data, including: email address, phone number, name, device identifier, cookies, pseudonym, network addresses, and hashed identifiers, for generating contextual metadata excluding data identifiable with at least one specific identity;

dynamically compute, by at least one of a connector executing within the data processing system and a server, a regulatory anchor set for the data processing event based on the contextual metadata, the regulatory anchor set comprising a plurality of state anchors indicating a dynamic state computed based on current operation and/or current context;

feed the regulatory anchor set into a deterministic reasoning engine configured for verification of the privacy policy by applying jurisdictional rules;

compute, by the reasoning engine, a verification indication and an explanation trace without using data identifiable with at least one specific identity; and

generate a non-identifiable verification token (NICT) including the verification indication and the explanation trace, wherein the NICT excludes data identifiable with at least one specific identity; and

in response to the NICT indicating a breach of the privacy policy, transmit to the data processing system instructions for blocking execution of the data processing event.

References Cited (13)
US 9280684B1 · Kragh · 2016 [cited by examiner]
US 11790111B2 · Wang · 2023 [cited by examiner]
US 11888981B2 · Androulaki · 2024 [cited by examiner]
US 20150101007A1 · Fujioka · 2015 [cited by examiner]
US 20210342759A1 · Beaumont · 2021 [cited by examiner]
US 20220083934A1 · Brannon · 2022 [cited by examiner]
US 20220179979A1 · Goswami · 2022 [cited by examiner]
US 20220309416A1 · Barday · 2022 [cited by examiner]
US 20220358240A1 · Neal · 2022 [cited by examiner]
US 20250323663A1 · Li · 2025 [cited by examiner]
US 20260050745A1 · Galvin · 2026 [cited by examiner]
US 20260073334A1 · Maheshkar · 2026 [cited by examiner]
US 20260080099A1 · Bhavani Sankar · 2026 [cited by examiner]