Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The following is a Non-Final Office action. In response to Examiner’s Final Rejection of 6/20/2025, Applicant, on 12/19/2025, amended claims 1, 17 and 20; cancelled claims 8; added claim 21. Claims 1-7, 9-21 are pending in this application and have been rejected below.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this
application is eligible for continued examination under 37 CFR 1.114, and the fee set
forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action
has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on
12/19/2025 has been entered.
Response to Amendment
Applicant’s amendments are acknowledged.
Regarding 35 U.S.C. § 101 rejection, the amendment has been considered and is insufficient to overcome the rejection.
The 35 U.S.C. § 103 rejections are hereby amended pursuant to applicants amendments. Updated 35 U.S.C. § 103 rejections have been applied to amended claims. Please refer to the § 103 rejection for further explanation and rationale.
Response to Arguments
Applicant’s arguments filed December 19, 2025 have been fully considered but they are not persuasive and/or are moot in view of the revised rejections. Applicant’s arguments will be addressed herein below in the order in which they appear in the response filed December 19, 2025.
On pages 10-12 of the Remarks regarding 35 U.S.C. § 101, Applicant asserts that the amended claim goes beyond generality. It requires generation of a specific, multi-attribute artificial intelligence profile and dictates how that profile controls the avatar's actions. This specificity imposes technical constraints and defines the interaction between the model's outputs and the avatar's behavioral engine. This is not "mere instructions to apply an exception using a generic computer." Instead, it is a particular way of using a trained model to achieve a defined technological outcome. In response , Examiner finds that in step 2A Prong II and Step 2B, the amended limitations (e.g., model training on personal information (Applicant's originally filed specification, para. [0112]), generating the enumerated artificial intelligence profile and causing the avatar to act in accordance with it (Applicant's originally filed specification, para. [0103]) is using the artificial intelligence processing as a tool to perform the instructions of the abstract idea..
On page 13of the Remarks regarding 35 U.S.C. § 102/103, Applicant states prior art fails to disclose amended claim language “""using, by the one or more processors, the artificial intelligence model to generate an artificial intelligence profile to personalize a computerized avatar for the user, wherein the artificial intelligence profile comprises one or more of vocal characteristics of the user, relationships for the user, personal information for the user, likes for the user, dislikes for the user, visual characteristics for the user, and experiences of the user, and the computerized avatar acts in accordance with the artificial intelligence profile.”. In response, new ground(s) of rejection is made necessitated by amendment see MPEP 706.07a where Davis is now applied for Claims 1, 17 and 20 to support avatar features. Regarding the 35 U.S.C. § 103 rejection, Applicant’s arguments with respect to claims has been considered but are moot in view of the new grounds of rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1- 7 and 9-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1-7 and 9-16 are directed to a method for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user, Claims 17-19 are directed to a system for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user, and Claim 20 is directed to an article of manufacture for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user.
Claim 1 recites a method for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user, Claim 17 recites a system for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user and Claim 20 recites an article of manufacture for requesting personal information stored on a third-party server and marketing the personal information on behalf of the user, which include requesting personal information for a user stored on a third-party; receiving the personal information for the user from the third-party; and marketing the personal information for the user on behalf of the user. As drafted, this is, under its broadest reasonable interpretation, within the Abstract idea grouping of “Methods of Organizing Human Activities- managing interactions/ marketing”. The recitation of “processor”, “computing device”, “server”, “computer-readable storage medium” , and “memory”, provide nothing in the claim elements to preclude the step from being Methods of Organizing Human Activities- managing interactions/ marketing”. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. The claims primarily recite the additional element of using computer components to perform each step. The “processor”, “computing device”, “server”, “computer-readable storage medium” , and “memory” is recited at a high-level of generality, such that it amounts no more than mere instructions to apply the exception using a computer component. See MPEP 2106.05(f). Furthermore, the claim 1, claim 17 and claim 20 recite using one or more machine learning/artificial intelligence analysis techniques- (training, an artificial intelligence model using the personal information for the user; using the artificial intelligence model to curate personal data stored in data objects; using, the artificial intelligence model to generate an artificial intelligence profile to personalize a computerized avatar for the user, wherein the artificial intelligence profile comprises one or more of vocal characteristics of the user, relationships for the user, personal information for the user, likes for the user, dislikes for the user, visual characteristics for the user, and experiences of the user, and the computerized avatar acts in accordance with the artificial intelligence profile.. The specification discloses the machine learning/artificial intelligence analysis at a high-level of generality, providing examples of different techniques that may be applied. The general use of an artificial intelligence analysis does not provide a meaningful limitation to transform the abstract idea into a practical application. Therefore, currently, the machine learning/ artificial intelligence processing is solely used a tool to perform the instructions of the abstract idea. Regarding the additional element of the “computerized avatar” – it is it is M2106.05(d)- Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information). Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claims also fail to recite any improvements to another technology or technical field, improvements to the functioning of the computer itself, use of a particular machine, effecting a transformation or reduction of a particular article to a different state or thing, and/or an additional element applies or uses the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception. See 84 Fed. Reg. 55. In particular, there is a lack of improvement to a computer or technical field in data analysis.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of “processor”, “computing device”, “server”, “computer-readable storage medium” , “memory” and “computerized avatar” is insufficient to amount to significantly more. (See MPEP 2106.05(f) – Mere Instructions to Apply an Exception – “Thus, for example, claims that amount to nothing more than an instruction to apply the abstract idea using a generic computer do not render an abstract idea eligible.” Alice Corp., 134 S. Ct. at 235). Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept.
The claim fails to recite any improvements to another technology or technical field, improvements to the functioning of the computer itself, use of a particular machine, effecting a transformation or reduction of a particular article to a different state or thing, adding unconventional steps that confine the claim to a particular useful application, and/or meaningful limitations beyond generally linking the use of an abstract idea to a particular environment. See 84 Fed. Reg. 55. Viewed individually or as a whole, these additional claim element(s) do not provide meaningful limitation(s) to transform the abstract idea into a patent eligible application of the abstract idea such that the claim(s) amounts to significantly more than the abstract idea itself. With regards to receiving data and step 2B, it is M2106.05(d)- Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information).
Examiner concludes that the additional elements in combination fail to amount to significantly more than the abstract idea based on findings that each element merely performs the same function(s) in combination as each element performs separately. The claim is not patent eligible. Thus, taken alone, the additional elements do not amount to significantly more than the above-identified judicial exception (the abstract idea). Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually.
Dependent Claims 2-7 and 9-16 and 18-19 and 2 recite sending a request to the third-party to delete the personal information for the user; monitoring the personal information for the user to confirm that the third-party deleted the personal information for the user; outputting a set of instructions for the user to follow to send the request to the third-party; and automatically requesting that the third-party delete the personal information for the user using local user information to create the request; prior to requesting the personal information for the user, determining an identity of an individual that initiated requesting the personal information for the user to verify that the individual is either the user or a guardian for the user; wherein determining the identity of the individual comprises performing, by the one or more processors, an identity check process that includes one or more of: a driver’s license confirmation; a photo identification card confirmation; a username and password check; biometric authentication; address authentication using a global positioning system; multi–factor authentication using one or more of an email messaging service, a text messaging service, a short messaging service, or an authentication application; a security question check; and a personal identification number (PIN) check; receiving the personal information for the user directly from the third-party server via direct transmission; receiving the personal information for the user via a peer-to-peer transmission; monitoring, an email account associated with the user for an email message that includes the personal information in a body portion of the email message or as an attachment in the email message and extracting the personal information from the email message; and receiving the personal information for the user via an upload, that includes the personal information.; receiving an indication of user input providing one or more user marketing preferences; uploading the one or more user marketing preferences and the personal information for the user; removing personally identifiable information from the personal information to create an anonymous profile for the user including the one or more user marketing preferences, wherein the anonymous profile is one of a plurality of anonymous profiles, and wherein each anonymous profile of the plurality of anonymous profiles is associated with a different user; receiving a request for the plurality of anonymous profiles from a marketer; sending the plurality of anonymous profiles to the marketer; receiving an indication of a subset of anonymous profiles from the plurality of anonymous profiles, wherein each anonymous profile of the subset of anonymous profiles is associated with a user that the marketer is requesting to provide advertisements to, wherein the subset of anonymous profiles includes the anonymous profile for the user; sending the personally identifiable information for each of subset of anonymous profiles, including the personally identifiable information for the anonymous profile of the user, to the marketer with a request for a payment; receiving, the payment from the marketer; and distributing at least a portion of the payment to a payment account of the user and to a payment account of each user associated with an anonymous profile of the subset of anonymous profiles; wherein the payment account of the user comprises a bank account or an online wallet ; wherein the one or more user marketing preferences comprise one or more of: a list of specific marketers that the user wishes to market their personal data to; a list of specific marketers that the user wishes to hide their personal data from; a list of genres of marketers that the user wishes to market their personal data to; a list of genres of marketers that the user wishes to hide their personal data from; a limit for a number of marketers that the user wishes to sell their personal data to over a given period of time; and a minimum price threshold that the user requires from marketers to sell their personal data; removing the personally identifiable information from the personal information for the user prior to uploading the personal information; monitoring, a group of one or more third-party services to determine what personal information for the user is stored on each of the third-party services of the group of one or more third-party services; verifying based on locally stored user information, that the personal information for the user stored on each of the third-party services of the group of one or more third-party services is accurate; and issuing, to a first third party service of the group of one or more third-party services, a request to update any personal information on the first third party service that is inaccurate; generating a privacy report based on the determination of what personal information for the user is stored on each of the third-party services of the group of one or more third-party services; and outputting, by the privacy report.; wherein the computerized avatar is included in a graphical environment and is configured to interact with one or more other users of a social media platform in the graphical environment of the user; and further narrowing the abstract idea. These recited limitations in the dependent claims do not amount to significantly more than the above-identified judicial exceptions in Claims 1, 17 and 20. Regarding Claims 2 -7, 9-11, 13-16 ,18-19 and 21 and the additional elements of “processor” ; “computing device”; “physical device” ;“clearinghouse server”; “third-party server” and “computerized avatar” and it is M2106.05(d)- Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information) and MPEP 2106.05(d)(II) i. storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc. Regarding Claim 8 recites using one or more artificial modelling techniques. The specification discloses the artificial intelligence at a high-level of generality, providing examples of different techniques that may be applied. The general use of a machine learning algorithm does not provide a meaningful limitation to transform the abstract idea into a practical application. Therefore, currently, the artificial intelligence is solely used a tool to perform the instructions of the abstract idea.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-7, 9 and 14-18 and 20-21 are rejected under 35 U.S.C. 103 as being unpatentable over Malhotra et al., US Publication No. 20200344219A1 [hereinafter Malhotra], in view of Carlisle et al., US Publication No. 20180349483 A1, [hereinafter Carlisle], and in further view of Davis, US Publication No. 20130257876 A1, [hereinafter Davis].
Regarding Claim 1, Malhotra teaches
A method comprising: requesting, by one or more processors of a computing device, personal information for a user stored on a third-party server (Malhotra Par. 72-“ In various embodiments, an organization, corporation, etc. may be required to provide information requested by an individual for whom the organization stores personal data. As a particular example, an organization may be required to provide an individual with a listing of, for example: (1) any personal data that the organization is processing for an individual, (2) an explanation of the categories of data being processed and the purpose of such processing; (3) categories of third parties to whom the data may be disclosed; (4) etc. In particular embodiments, when processing a data subject access request (e.g., a request for such information), a data subject access request processing system may be configured to: (1) receive a data subject access request from a data subject, the data subject access request comprising one or more requests related to the one or more rights described herein (e.g., a request for a copy of the data subject's personal data, a request regarding how long personal data associated with the data subject is being stored by the system, etc.); (2) process the request in any suitable manner described herein; (3) fulfill the request based at least in part on one or more request parameters; (4) store one or more pieces of metadata associated with the processing of, fulfillment of, and/or response to the request; and/or (5) archive one or more pieces of data associated with the request based on one or more data retention rules.”; Par. 6);
receiving, by the one or more processors, the personal information for the user from the third-party server (Malhotra Par. 18-“ in response to receiving the data subject access request: (1) generating a unique URL; and (2) at least temporarily providing access to an electronic form for completing a data subject access request at the unique URL. In various embodiments, automatically taking the at least one defensive action comprises, at least partially in response to receiving the data subject access request: (1) setting a session cookie on the browser of a client computer that is attempting to submit the data subject access request; (2) using the session cookie to determine whether the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator; and (3) in response to determining that the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator, rejecting the data subject access request.”; Par. 72);
marketing, by the one or more processors, the personal information for the user on behalf of the user. (Malhotra Par. 308- “FIG. 40 depicts an exemplary webform that a particular entity may include on a website for completion by one or more customers or users of the website. As may be understood from FIG. 40, the webform may collect personal data such as, for example: (1) first name; (2) last name; (3) organization name; (4) country of residence; (5) state; (6) phone number; (7) e-mail address; (8) website; and/or (9) any other suitable personal data. As may be further understood from this figure, an entity (e.g., or a system controlled by the entity) may use the webform to collect such personal data as part of one or more processing activities (e.g., e-mail marketing, online surveys, event marketing, etc.). In various embodiments, the system may be configured to scan a particular webform to identify a particular processing activity for which the entity is collecting the personal data.”; Par. 309-“ In various embodiments, the system may, for example: (1) robotically fill out the webform (e.g., using one or more virtual profiles); (2) analyze one or more pieces of computer code associated with the webform (e.g., JavaScript, HTML, etc.); and (3) map one or more business processes that utilize the data collected via the webform based at least in part on the analyzed one or more pieces of computer code. In particular embodiments, a particular entity that utilizes a webform to collect personal data for use in a particular processing activity (e.g., business process) may analyze one or more pieces of computer code associated with the webform to determine: (1) one or more systems associated with the entity to which data entered the webform is routed (e.g., one or more data assets that serve as a destination asset to data entered via the webform); (2) a purpose for the collection of the data entered via the webform (e.g., a processing activity that utilizes the destination asset discussed above; (3) a type of data collected via the webform; and/or (4) any other suitable information related to the collection of data via the webform.”)
Malhotra teaches machine learning techniques and the feature is expounded upon by Carlisle:
training, by the one or more processors, an artificial intelligence model using the personal information for the user; using, by the one or more processors, the artificial intelligence model to curate personal data stored in data objects. (Carlisle Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
using, by the one or more processors, the artificial intelligence model to personalize a computerized avatar for the user… (Carlisle Par. 261; Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
Malhotra is directed to processing user requests and Carlisle improves upon the user interactions. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user display and interface of Malhotra, as taught by Carlisle, by utilizing artificial intelligence with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra with the motivation of improving navigable graphical user interface, and may be driven by artificial intelligence (Carlisle Par.2).
Malhotra in view of Carlisle teach artificial intelligence with avatar use and the feature is expounded upon by Davis:
…wherein the artificial intelligence profile comprises one or more of vocal characteristics of the user, relationships for the user, personal information for the user, likes for the user, dislikes for the user, visual characteristics for the user, and experiences of the user, and the computerized avatar acts in accordance with the artificial intelligence profile (Par. 2- This disclosure relates generally to animated avatars designed to simulate personality characteristics for entertainment and other applications, and, more particularly, to devices, systems, and methods adapted to capture personality and behavioral profile characteristics of a person and to provide an interactive experience with an animated avatar where the avatar simulates personality and behavioral profile characteristics based on at least a portion of the captured personality and behavioral profile characteristics.; Par. 58; Par. 62; Par. 82) .
Malhotra and Carlisle are directed to artificial intelligence analysis with use of avatar. Davis improves upon avatar utilization. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon avatar features of Malhotra in view of Carlisle, as taught by Davis, by utilizing additional avatar features with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle with the motivation of improved animated avatars with improved capabilities and features (Davis Par.12).
Regarding Claim 2,
The method of claim 1, further comprising: sending, by the one or more processors, a request to the third-party server for the third-party server to delete the personal information for the user stored on the third-party server (Malhotra Par. 77-“ In still other embodiments, as may be appreciated in light of this disclosure, the processing of particular data subject access request may result in the at least temporary storage of personal data (e.g., which may, for example, be subject to the same legal and/or industry standards related to the collection, processing, and storage of personal data). For example, when processing a particular data subject access request, the system may collect at least some personal data from a data subject (e.g., or other requestor on behalf of the data subject) in order to identify the data subject. As such, in order to fulfil the data subject access request (e.g., which may include a request to delete any data associated with the data subject), the system may need to collect identifying personal data from the data subject in order to use that data to determine what personal data the organization or system is storing that is associated with that data subject.”).
Regarding Claim 3,
The method of claim 2, further comprising: monitoring, by the one or more processors, the personal information for the user stored on the third-party server to confirm that the third-party server deleted the personal information for the user. (Malhotra Par. 212-“ Returning to Step 2130, the system is configured to take one or more actions based at least in part on the request. In some embodiments, the system is configured to take one or more actions for which the request was submitted (e.g., display the personal data, delete the personal data, correct the personal data, etc.). In particular embodiments, the system is configured to take the one or more actions substantially automatically. In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; and (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject's personal data from the various systems (e.g., by automatically assigning a plurality of tasks to delete data across multiple business systems to effectively delete the data subject's personal data from the systems). In particular embodiments, the step of facilitating the deletion may comprise, for example: (1) overwriting the data in memory; (2) marking the data for overwrite; (2) marking the data as free (e.g., and deleting a directory entry associated with the data); and/or (3) any other suitable technique for deleting the personal data. In particular embodiments, as part of this process, the system uses an appropriate data model (see discussion above) to efficiently determine where all of the data subject's personal data is stored.”).
Regarding Claim 4 and Claim 5, Malhotra teaches The method of claim 2 , wherein sending the request to the third-party server for the third-party server to delete the personal information for the user stored on the third- party server comprises one or more of: …and The method of claim 1, wherein requesting the personal information for the user comprises one or more of: …
outputting, by the one or more processors, a set of instructions for the user to follow to send the request to the third-party server; and automatically requesting, by the one or more processors, that the third-party server delete the personal information for the user stored on the third-party server using local user information stored on the computing device to create the request. (Malhotra Par. 212-“ Returning to Step 2130, the system is configured to take one or more actions based at least in part on the request. In some embodiments, the system is configured to take one or more actions for which the request was submitted (e.g., display the personal data, delete the personal data, correct the personal data, etc.). In particular embodiments, the system is configured to take the one or more actions substantially automatically. In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; …”; Par. 375-“ Alternatively, or in addition, the chatbot may be configured to facilitate the submission of a DSAR through one or more other means or mechanisms. For example, the chatbot may ask the user if they would like to submit a DSAR and, if the user responds in the affirmative, the chatbot may provide instructions to the user regarding one or more next steps to take in order to submit a DSAR, for example, through a website, a call center, and/or other DSAR submission platform associated with the entity.”).
Regarding Claim 6,
The method of claims 1, further comprising: prior to requesting the personal information for the user, determining, by the one or more processors, an identity of an individual that initiated requesting the personal information for the user to verify that the individual is either the user or a guardian for the user. (Malhotra Par. 345-“ In some embodiments, the system may receive the request from the data subject. In other embodiments, the system may receive the request from one or more individuals on behalf of the data subject (e.g., a legal guardian of the data subject or other individual authorized to make the request on the data subject's behalf). “;Par. 383-“ In various embodiments, at Step 5470, the system may be configured to automatically receive and fulfill such requests by, for example: (1) receiving a DSAR (or an indication that the user would like to submit a DSAR and presenting and receiving the information needed to process the DSAR); (2) in response to receiving the DSAR, verifying and/or facilitating the verification of the requestor's identity;))”
Regarding Claim 7,
The method of claim 6, wherein determining the identity of the individual comprises performing, by the one or more processors, an identity check process that includes one or more of a driver's license confirmation; a photo identification card confirmation; a username and password check; biometric authentication; address authentication using a global positioning system; multi-factor authentication using one or more of an email messaging service, a text messaging service, a short messaging service, or an authentication application; a security question check; and a personal identification number (PIN) check. (Malhotra Par. 178-198-“ Intelligent Identity Scanning Module- Turning to FIG. 26, in particular embodiments, the Intelligent Identity Scanning Module 2600 is configured to scan one or more data sources to identify personal data stored on one or more network devices for a particular organization, analyze the identified personal data, and classify the personal data (e.g., in a data model) based at least in part on a confidence score derived using one or more machine learning techniques. The confidence score may be and/or comprise, for example, an indication of the probability that the personal data is actually associated with a particular data subject (e.g., that there is at least an 80% confidence level that a particular phone number is associated with a particular individual.)”
Regarding Claim 8 - Cancelled
Regarding Claim 9,
The method of claim 1, wherein receiving the personal information for the user from the third-party server comprises one or more of: receiving, by the one or more processors, the personal information for the user directly from the third-party server via direct transmission (Malhotra Par. 6- “A data subject access request processing system, according to various embodiments, comprises: one or more data subject access request management servers; a plurality of local storage nodes, each of the plurality of local storage nodes being physically located in a distinct geographic location; one or more processors; and memory. In some embodiments, the one or more processors are configured for: (1) receiving, from a remote computing device, at the one or more data subject access request management servers, a data subject access request for a data subject, the request comprising one or more request parameters; (2) identifying, based at least in part on the data subject access request, a particular local storage node of the plurality of local storage nodes; (3) routing the data subject access request from the one or more data subject access request management servers to the particular local storage node; (4) processing the request at the particular local storage node by identifying one or more pieces of personal data associated with the data subject, the one or more pieces of personal data being stored in one or more data repositories associated with a particular organization; Par. 18; Par. 72”);
receiving, by the one or more processors, the personal information for the user via a peer-to-peer transmission (Malhotra Par. 89- “In particular embodiments, the computer 200 may be connected (e.g., networked) to other computers in a LAN, an intranet, an extranet, and/or the Internet. As noted above, the computer 200 may operate in the capacity of a server or a client computer in a client-server network environment, or as a peer computer in a peer-to-peer (or distributed) network environment.”);
monitoring, by the one or more processors, an email account associated with the user for an email message that includes the personal information in a body portion of the email message or as an attachment in the email message and extracting the personal information from the email message (Malhotra Par. 312- “In various embodiments, any system described herein may be configured for: (1) analyzing electronic correspondence associated with a data subject (e.g., the emails within one or more email in-boxes associated with the data subject, or a plurality of text messages); (2) based on the analysis, identifying one or more entities (e.g., corporate entities) that that the data subject does not actively do business with (e.g., as evidenced by the fact that the data subject no longer opens emails from the entity, has set up a rule to automatically delete emails received from the entity, has blocked texts from the entity, etc.);”; Par. 317- “The system may, for example, scan an e-mail's subject field, body, sender, etc. to identify, for example: (1) a name of the subject company; (2) an e-mail domain associated with the subject company; and/or (3) any other suitable information which may identify the subject entity as the sender of the e-mail.”);
and receiving, by the one or more processors, the personal information for the user via an upload from a physical device, operably connected to the computing device, that includes the personal information. (Malhotra Par. 86; As may be understood from FIG. 1, the Data Model Generation and Population System 100 includes one or more computer networks 115, a Data Model Generation Server 110, a Data Model Population Server 120, an Intelligent Identity Scanning Server 130, One or More Databases 140 or other data structures, one or more remote computing devices 150 (e.g., a desktop computer, laptop computer, tablet computer, smartphone, etc.), and One or More Third Party Servers 160. In particular embodiments, the one or more computer networks 115 facilitate communication between the Data Model Generation Server 110, Data Model Population Server 120, Intelligent Identity Scanning Server 130, One or More Databases 140, one or more remote computing devices 150 (e.g., a desktop computer, laptop computer, tablet computer, smartphone, etc.), and One or More Third Party Servers 160. Although in the embodiment shown in FIG. 1, the Data Model Generation Server 110, Data Model Population Server 120, Intelligent Identity Scanning Server 130, One or More Databases 140, one or more remote computing devices 150 (e.g., a desktop computer, laptop computer, tablet computer, smartphone, etc.), and One or More Third Party Servers 160 are shown as separate servers, it should be understood that in other embodiments, one or more of these servers and/or computing devices may comprise a single server, a plurality of servers, one or more cloud-based servers, or any other suitable configuration.”)
Regarding Claim 14,
The method of claim 1, further comprising: monitoring, by the one or more processors, a group of one or more third-party services to determine what personal information for the user is stored on each of the third-party services of the group of one or more third-party services. (Malhotra Par. 212-“ Returning to Step 2130, the system is configured to take one or more actions based at least in part on the request. In some embodiments, the system is configured to take one or more actions for which the request was submitted (e.g., display the personal data, delete the personal data, correct the personal data, etc.). In particular embodiments, the system is configured to take the one or more actions substantially automatically. In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; and (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject's personal data from the various systems (e.g., by automatically assigning a plurality of tasks to delete data across multiple business systems to effectively delete the data subject's personal data from the systems). In particular embodiments, the step of facilitating the deletion may comprise, for example: (1) overwriting the data in memory; (2) marking the data for overwrite; (2) marking the data as free (e.g., and deleting a directory entry associated with the data); and/or (3) any other suitable technique for deleting the personal data. In particular embodiments, as part of this process, the system uses an appropriate data model (see discussion above) to efficiently determine where all of the data subject's personal data is stored.”; Par. 239; Par. 290).
Regarding Claim 15,
The method of claim 14, further comprising: verifying, by the one or more processors and based on locally stored user information, that the personal information for the user stored on each of the third-party services of the group of one or more third-party services is accurate; and issuing, by the one or more processors and to a first third party service of the group of one or more third-party services, a request to update any personal information on the first third party service that is inaccurate. (Malhotra Par. 325-“ In various embodiments, the system is configured to, in response to determining that the data subject no longer actively does business with the entity, automatically generate, populate, and/or submit a data subject access request to the entity. In various embodiments, the data subject access request may include: (1) a request to delete some or all of the data subject's personal data that is being processed by the entity (e.g., in the form of a “right to be forgotten” request); (2) a request to rectify inaccurate personal data of the data subject that is being processed by the entity; (3) a request to access of a copy of personal information of the data subject processed by the entity; (4) a request to restrict the processing of the data subject's data by the entity; and/or (5) a request to transfer the data subject's data from the entity to a specified controller.; Par. 191; Par. 206).
Regarding Claim 16,
The method of claim 14, further comprising: generating, by the one or more processors, a privacy report based on the determination of what personal information for the user is stored on each of the third- party services of the group of one or more third-party services; and outputting, by the one or more processors, the privacy report. (Malhotra Par. 207-“ As may be understood in light of this disclosure, a particular organization may undertake a plurality of different privacy campaigns, processing activities, etc. that involve the collection and storage of personal data. In some embodiments, each of the plurality of different processing activities may collect redundant data (e.g., may collect the same personal data for a particular individual more than once), and may store data and/or redundant data in one or more particular locations (e.g., on one or more different servers, in one or more different databases, etc.). In this way, a particular organization may store personal data in a plurality of different locations which may include one or more known and/or unknown locations. As such, complying with particular privacy and security policies related to personal data (e.g., such as responding to one or more requests by data subjects related to their personal data) may be particularly difficult (e.g., in terms of cost, time, etc.). In particular embodiments, a data subject access request fulfillment system may utilize one or more data model generation and population techniques (e.g., such as any suitable technique described herein) to create a centralized data map with which the system can identify personal data stored, collected, or processed for a particular data subject, a reason for the processing, and any other information related to the processing.; Par. 249-“ In particular embodiments, the visual representation may be used by a particular entity to demonstrate compliance with respect to one or more regulations related to the transfer of personal data. In such embodiments, the visual representation may serve as a report that indicates the legal basis of any transfer performed by the entity (e.g., and further serve as documentation of the entity's compliance with one or more legal regulations).”).
Regarding Claim 17, Malhotra teaches
A computing device comprising: a memory; and one or more processors configured to: request personal information for a user stored on a third-party server; (Malhotra Par. 72-“ In various embodiments, an organization, corporation, etc. may be required to provide information requested by an individual for whom the organization stores personal data. As a particular example, an organization may be required to provide an individual with a listing of, for example: (1) any personal data that the organization is processing for an individual, (2) an explanation of the categories of data being processed and the purpose of such processing; (3) categories of third parties to whom the data may be disclosed; (4) etc. In particular embodiments, when processing a data subject access request (e.g., a request for such information), a data subject access request processing system may be configured to: (1) receive a data subject access request from a data subject, the data subject access request comprising one or more requests related to the one or more rights described herein (e.g., a request for a copy of the data subject's personal data, a request regarding how long personal data associated with the data subject is being stored by the system, etc.); (2) process the request in any suitable manner described herein; (3) fulfill the request based at least in part on one or more request parameters; (4) store one or more pieces of metadata associated with the processing of, fulfillment of, and/or response to the request; and/or (5) archive one or more pieces of data associated with the request based on one or more data retention rules.”; Par.6; ) ;
receive, the personal information for the user from the third-party server (Malhotra Par. 18-“ in response to receiving the data subject access request: (1) generating a unique URL; and (2) at least temporarily providing access to an electronic form for completing a data subject access request at the unique URL. In various embodiments, automatically taking the at least one defensive action comprises, at least partially in response to receiving the data subject access request: (1) setting a session cookie on the browser of a client computer that is attempting to submit the data subject access request; (2) using the session cookie to determine whether the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator; and (3) in response to determining that the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator, rejecting the data subject access request.”; Par. 72);
market the personal information for the user on behalf of the user. (Malhotra Par. 308- “FIG. 40 depicts an exemplary webform that a particular entity may include on a website for completion by one or more customers or users of the website. As may be understood from FIG. 40, the webform may collect personal data such as, for example: (1) first name; (2) last name; (3) organization name; (4) country of residence; (5) state; (6) phone number; (7) e-mail address; (8) website; and/or (9) any other suitable personal data. As may be further understood from this figure, an entity (e.g., or a system controlled by the entity) may use the webform to collect such personal data as part of one or more processing activities (e.g., e-mail marketing, online surveys, event marketing, etc.). In various embodiments, the system may be configured to scan a particular webform to identify a particular processing activity for which the entity is collecting the personal data.”; Par. 309-“ In various embodiments, the system may, for example: (1) robotically fill out the webform (e.g., using one or more virtual profiles); (2) analyze one or more pieces of computer code associated with the webform (e.g., JavaScript, HTML, etc.); and (3) map one or more business processes that utilize the data collected via the webform based at least in part on the analyzed one or more pieces of computer code. In particular embodiments, a particular entity that utilizes a webform to collect personal data for use in a particular processing activity (e.g., business process) may analyze one or more pieces of computer code associated with the webform to determine: (1) one or more systems associated with the entity to which data entered the webform is routed (e.g., one or more data assets that serve as a destination asset to data entered via the webform); (2) a purpose for the collection of the data entered via the webform (e.g., a processing activity that utilizes the destination asset discussed above; (3) a type of data collected via the webform; and/or (4) any other suitable information related to the collection of data via the webform.”)
Malhotra teaches machine learning techniques and the feature is expounded upon by Carlisle:
train an artificial intelligence model using the personal information for the user; and use the artificial intelligence model to curate personal data stored in data objects. (Carlisle Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
and use the artificial intelligence model to generate an artificial intelligence profile to personalize a computerized avatar for the user,… (Carlisle Par. 261; Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
Malhotra is directed to processing user requests and Carlisle improves upon the user interactions. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user display and interface of Malhotra, as taught by Carlisle, by utilizing artificial intelligence with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra with the motivation of improving navigable graphical user interface, and may be driven by artificial intelligence (Carlisle Par.2).
Malhotra in view of Carlisle teach artificial intelligence with avatar use and the feature is expounded upon by Davis:
… wherein the artificial intelligence profile comprises one or more of vocal characteristics of the user, relationships for the user, personal information for the user, likes for the user, dislikes for the user, visual characteristics for the user, and experiences of the user, and the computerized avatar acts in accordance with the artificial intelligence profile (Par. 2- This disclosure relates generally to animated avatars designed to simulate personality characteristics for entertainment and other applications, and, more particularly, to devices, systems, and methods adapted to capture personality and behavioral profile characteristics of a person and to provide an interactive experience with an animated avatar where the avatar simulates personality and behavioral profile characteristics based on at least a portion of the captured personality and behavioral profile characteristics.; Par. 58; Par. 62; Par. 82) .
Malhotra and Carlisle are directed to artificial intelligence analysis with use of avatar. Davis improves upon avatar utilization. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon avatar features of Malhotra in view of Carlisle, as taught by Davis, by utilizing additional avatar features with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle with the motivation of improved animated avatars with improved capabilities and features (Davis Par.12).
Regarding Claim 18,
The computing device of claim 17, wherein the one or more processors are further configured to: send a request to the third-party server for the third-party server to delete the personal information for the user stored on the third-party server; and monitor the personal information for the user stored on the third-party server to confirm that the third-party server deleted the personal information for the user. (Malhotra Par. 77-“ In still other embodiments, as may be appreciated in light of this disclosure, the processing of particular data subject access request may result in the at least temporary storage of personal data (e.g., which may, for example, be subject to the same legal and/or industry standards related to the collection, processing, and storage of personal data). For example, when processing a particular data subject access request, the system may collect at least some personal data from a data subject (e.g., or other requestor on behalf of the data subject) in order to identify the data subject. As such, in order to fulfil the data subject access request (e.g., which may include a request to delete any data associated with the data subject), the system may need to collect identifying personal data from the data subject in order to use that data to determine what personal data the organization or system is storing that is associated with that data subject.; Par. 212-“ Returning to Step 2130, the system is configured to take one or more actions based at least in part on the request. In some embodiments, the system is configured to take one or more actions for which the request was submitted (e.g., display the personal data, delete the personal data, correct the personal data, etc.). In particular embodiments, the system is configured to take the one or more actions substantially automatically. In particular embodiments, in response a data subject submitting a request to delete their personal data from an organization's systems, the system may: (1) automatically determine where the data subject's personal data is stored; and (2) in response to determining the location of the data (which may be on multiple computing systems), automatically facilitate the deletion of the data subject's personal data from the various systems (e.g., by automatically assigning a plurality of tasks to delete data across multiple business systems to effectively delete the data subject's personal data from the systems). In particular embodiments, the step of facilitating the deletion may comprise, for example: (1) overwriting the data in memory; (2) marking the data for overwrite; (2) marking the data as free (e.g., and deleting a directory entry associated with the data); and/or (3) any other suitable technique for deleting the personal data. In particular embodiments, as part of this process, the system uses an appropriate data model (see discussion above) to efficiently determine where all of the data subject's personal data is stored.”).
Regarding Claim 20, Malhotra teaches
A non-transitory computer-readable storage medium comprising instructions that, when executed by one or more processors of a computing device, cause the one or more processors to: request personal information for a user stored on a third-party server; (Malhotra Par. 72-“ In various embodiments, an organization, corporation, etc. may be required to provide information requested by an individual for whom the organization stores personal data. As a particular example, an organization may be required to provide an individual with a listing of, for example: (1) any personal data that the organization is processing for an individual, (2) an explanation of the categories of data being processed and the purpose of such processing; (3) categories of third parties to whom the data may be disclosed; (4) etc. In particular embodiments, when processing a data subject access request (e.g., a request for such information), a data subject access request processing system may be configured to: (1) receive a data subject access request from a data subject, the data subject access request comprising one or more requests related to the one or more rights described herein (e.g., a request for a copy of the data subject's personal data, a request regarding how long personal data associated with the data subject is being stored by the system, etc.); (2) process the request in any suitable manner described herein; (3) fulfill the request based at least in part on one or more request parameters; (4) store one or more pieces of metadata associated with the processing of, fulfillment of, and/or response to the request; and/or (5) archive one or more pieces of data associated with the request based on one or more data retention rules.”; Par.6; Par. 15 ) ;
receive, the personal information for the user from the third-party server (Malhotra Par. 18-“ in response to receiving the data subject access request: (1) generating a unique URL; and (2) at least temporarily providing access to an electronic form for completing a data subject access request at the unique URL. In various embodiments, automatically taking the at least one defensive action comprises, at least partially in response to receiving the data subject access request: (1) setting a session cookie on the browser of a client computer that is attempting to submit the data subject access request; (2) using the session cookie to determine whether the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator; and (3) in response to determining that the data subject access request is being submitted from a domain associated with a third-party DSAR aggregator, rejecting the data subject access request.”; Par. 72);
market the personal information for the user on behalf of the user. (Malhotra Par. 308- “FIG. 40 depicts an exemplary webform that a particular entity may include on a website for completion by one or more customers or users of the website. As may be understood from FIG. 40, the webform may collect personal data such as, for example: (1) first name; (2) last name; (3) organization name; (4) country of residence; (5) state; (6) phone number; (7) e-mail address; (8) website; and/or (9) any other suitable personal data. As may be further understood from this figure, an entity (e.g., or a system controlled by the entity) may use the webform to collect such personal data as part of one or more processing activities (e.g., e-mail marketing, online surveys, event marketing, etc.). In various embodiments, the system may be configured to scan a particular webform to identify a particular processing activity for which the entity is collecting the personal data.”; Par. 309-“ In various embodiments, the system may, for example: (1) robotically fill out the webform (e.g., using one or more virtual profiles); (2) analyze one or more pieces of computer code associated with the webform (e.g., JavaScript, HTML, etc.); and (3) map one or more business processes that utilize the data collected via the webform based at least in part on the analyzed one or more pieces of computer code. In particular embodiments, a particular entity that utilizes a webform to collect personal data for use in a particular processing activity (e.g., business process) may analyze one or more pieces of computer code associated with the webform to determine: (1) one or more systems associated with the entity to which data entered the webform is routed (e.g., one or more data assets that serve as a destination asset to data entered via the webform); (2) a purpose for the collection of the data entered via the webform (e.g., a processing activity that utilizes the destination asset discussed above; (3) a type of data collected via the webform; and/or (4) any other suitable information related to the collection of data via the webform.”)
Malhotra teaches machine learning techniques and the feature is expounded upon by Carlisle:
train an artificial intelligence model using the personal information for the user; and use the artificial intelligence model to curate personal data stored in data objects. (Carlisle Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
and use the artificial intelligence model to generate an artificial intelligence profile to personalize a computerized avatar for the user,… (Carlisle Par. 261; Par.293 -“ In an embodiment, the descriptive user-specific data is stored in a descriptive user data model that drives the artificial intelligence (e.g., the predictive model described herein) to bias search results, content, and/or the like for the associated user. For example, the application may use the descriptive user data model to train the artificial intelligence for a particular user. In an embodiment, training the artificial intelligence includes a feedback loop. For example, the artificial intelligence may access the descriptive user data model to retrieve descriptive data indicative of a user bias. The artificial intelligence may then bias the results of a user search, analyze the user's interaction with the search results (e.g., which search results the user finds helpful and/or which search results the user does not find helpful), and updates the descriptive user data model based on those interactions.; Par. 391-“ he description of the requestor and/or request, which may be the same as the description displayed in response to selection of alert 344, may comprise the requester's thumbnail image or avatar, name, profession, and/or location (e.g., city and state of current residence), the request type (e.g., recommendation, advice, etc.), a request description, an input (e.g., link or virtual button) for accepting the request, an input for declining the request, and/or an input for viewing more details about the request.”)
Malhotra is directed to processing user requests and Carlisle improves upon the user interactions. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user display and interface of Malhotra, as taught by Carlisle, by utilizing artificial intelligence with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra with the motivation of improving navigable graphical user interface, and may be driven by artificial intelligence (Carlisle Par.2).
Malhotra in view of Carlisle teach artificial intelligence with avatar use and the feature is expounded upon by Davis:
… wherein the artificial intelligence profile comprises one or more of vocal characteristics of the user, relationships for the user, personal information for the user, likes for the user, dislikes for the user, visual characteristics for the user, and experiences of the user, and the computerized avatar acts in accordance with the artificial intelligence profile (Par. 2- This disclosure relates generally to animated avatars designed to simulate personality characteristics for entertainment and other applications, and, more particularly, to devices, systems, and methods adapted to capture personality and behavioral profile characteristics of a person and to provide an interactive experience with an animated avatar where the avatar simulates personality and behavioral profile characteristics based on at least a portion of the captured personality and behavioral profile characteristics.; Par. 58; Par. 62; Par. 82) .
Malhotra and Carlisle are directed to artificial intelligence analysis with use of avatar. Davis improves upon avatar utilization. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon avatar features of Malhotra in view of Carlisle, as taught by Davis, by utilizing additional avatar features with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle with the motivation of improved animated avatars with improved capabilities and features (Davis Par.12).
Regarding Claim 21,
Malhotra teach artificial intelligence with avatar use and the feature is expounded upon by Carlisle:
wherein the computerized avatar is included in a graphical environment and is configured to interact with one or more other users of a social media platform in the graphical environment of the user. (Carlisle Par. 2- The embodiments described herein are generally directed to a social media system, and, more particularly, to a social media system that provides an improved navigable graphical user interface, and may be driven by artificial intelligence and/or record transactions in a blockchain for gamification and/or other functions of the system.; Par. 261) .
Malhotra is directed to processing user requests and Carlisle improves upon the user interactions. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user display and interface of Malhotra, as taught by Carlisle, by utilizing artificial intelligence with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra with the motivation of improving navigable graphical user interface, and may be driven by artificial intelligence (Carlisle Par.2).
Claims 10, 13 and Claim 19 are rejected under 35 U.S.C. 103 as being unpatentable over Malhotra et al., US Publication No. 20200344219A1 [hereinafter Malhotra], in view of Carlisle et al., US Publication No. 20180349483 A1, [hereinafter Carlisle], n further view of Davis, US Publication No. 20130257876 A1, [hereinafter Davis] and in further view of Tenneti et al., US Publication No. 20130332987 A1, [hereinafter Tenneti].
Regarding Claim 10 and Claim 19, Malhotra in view of Carlisle in further view of Davis teach The method of claim 1, further wherein marketing the personal information comprises:… and The computing device of claim 17, wherein the one or more processors being configured to market the personal information for the user comprises the one or more processors being configured to:…
Malhotra in view of Carlisle in view of Davis fail to teach the following feature taught by Tenneti:
receiving, by the one or more processors, an indication of user input providing one or more user marketing preferences (Tenneti Par. 27-“ In the context of managing, sharing, and aggregating personal information between multiple devices and/or services, the confidentiality of certain private personal information related to the users should be maintained. In some circumstances, maintaining confidentiality of personal information may be mandated by local laws, privacy regulations, and/or by user preference. Accordingly, systems and methods may be deployed that allow for managing the confidentiality of user personal information.”);
uploading, by the one or more processors, the one or more user marketing preferences and the personal information for the user to a clearinghouse server (Tenneti Par. 165-“ Utilizing an anonymous P2P network may assure users that their data 33is reported anonymously and that their playlists, ad lists, and/or the like are queried and downloaded and/or uploaded anonymously. In one embodiment, to demonstrate anonymity to users in a transparent manner, a response that a client receives from a server may be stamped with their IP address (e.g., with signatures) and/or another suitable means of identification so that a client can see that a request was routed randomly and that the server did not receive any information that identified the origin of the data.”;);
removing, by the clearinghouse server, personally identifiable information from the personal information to create an anonymous profile for the user including the one or more user marketing preferences, wherein the anonymous profile is one of a plurality of anonymous profiles, and wherein each anonymous profile of the plurality of anonymous profiles is associated with a different user server (Tenneti Par. 73-“ In certain embodiments, prior to sharing personal information 504, 406, devices 500, 502 may anonymize and/or otherwise filter the personal information 504, 506. In some embodiments, anonymizing the personal information may comprise removing and/or filtering certain PII information from personal information 504, 506, such that shared information transmitted from a device may not be used to uniquely identify (e.g., identify with a certain degree of specificity) the user of a device. For example, prior to sharing personal information 504 with device 502 and/or clearinghouse 512, device 500 may generate anonymized personal information 508. Anonymized personal information 508 may include personal information associated with a user of the device 500 that may be used in ad-targeting and/or content distribution methods disclosed herein, but not include PII and/or other information that may be used to uniquely identify the user.”);
receiving, by the clearinghouse server, a request for the plurality of anonymous profiles from a marketer (Tenneti Par.83-84; Par. 135; Par. 154; Par. 165- In one embodiment, to demonstrate anonymity to users in a transparent manner, a response that a client receives from a server may be stamped with their IP address (e.g., with signatures) and/or another suitable means of identification so that a client can see that a request was routed randomly and that the server did not receive any information that identified the origin of the data.”);
sending, by the clearinghouse server, the plurality of anonymous profiles to the marketer (Tenneti Par. 83-84-“ Systems and methods disclosed herein may facilitate sharing and aggregation of user profile information for use, for example, in systems such as those described in the '406 application designed to be utilized by a large variety of consumer devices. For example, embodiments disclosed herein may be implemented in mobile handsets, set-top boxes, PDAs, ultra mobile personal computers (“UMPCs”), PCs, media gateway devices, and/or the like. Such devices may interact with multiple services that participate in a content and/or advertisement ecosystem allowing the devices to download advertisements and content. Systems and methods disclosed herein may interact with a large number of service entities. For example, on the advertisement side, these entities may include direct advertisers, ad-networks, and/or ad exchanges that auction ad space to a wide range of advertisers. On the content side, service entities may include, for example, content creators, content publishers, content aggregators, content retailers, and/or the like.);
receiving, by the clearinghouse server, an indication of a subset of anonymous profiles from the plurality of anonymous profiles, wherein each anonymous profile of the subset of anonymous profiles is associated with a user that the marketer is requesting to provide advertisements to, wherein the subset of anonymous profiles includes the anonymous profile for the user (Tenneti Par. 106-“ In some embodiments, aggregated personal information may be used to improve a service offering for all users who collectively are members of an aggregate group, without a way to directly identify a particular user and/or impinge on a user's privacy.)
sending, by the clearinghouse server, the personally identifiable information for each of subset of anonymous profiles, including the personally identifiable information for the anonymous profile of the user, to the marketer with a request for a payment (Tenneti Par. 34- Information about the user, the user's device, and the user's content preferences and content usage habits can be used in the advertisement selection process. In addition, information about which advertisements were rendered can be collected and sent to one or more clearinghouses and/or other remote services (e.g., clearinghouse 110) to facilitate the provision of payment or other compensation from advertisers 102 to content owners or providers 106. Alternatively, or in addition, such information could be sent directly from the user's device to the content provider 106 and/or advertisement provider 102.; Par. 106;);
receiving, by the clearinghouse server, the payment from the marketer; and distributing, by the clearinghouse server, at least a portion of the payment to a payment account of the user and to a payment account of each user associated with an anonymous profile of the subset of anonymous profiles (Tenneti Par.34; Par. 93-As discussed above, the network services 726 and/or the user device 730 may interface with one or more trusted services 728. The trusted service 728 may, among other things, include a clearinghouse 708 configured to facilitate the provision of payment or other compensation from advertisers and content owners and/or distributors. For example, using audit records on ad or content rendering provided to the trusted service 728 by the user device 730, the trusted service may facilitate appropriate payment to content distributor 702 and/or an ad provider 706 via an appropriate feedback, revenue and/or billing API.);
Malhotra, Carlisle, Davis and Tenneti are directed to query processing . It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user request processing of Malhotra in view of Carlisle in further view of Davis, as taught by Tenneti, by utilizing additional data analysis with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle in further view of Davis with the motivation of improving a service offering for all users who collectively are members of an aggregate group, (Tenneti Par.106).
Regarding Claim 13,
Malhotra in view of Carlisle in further view of Davis in further view of Tenneti teach The method of claim 10,…
Malhotra in view of Carlisle in further view of Davis fail to teach the following feature taught by Tenneti:
wherein uploading the personal information to the clearinghouse server comprises: removing, by the one or more processors, the personally identifiable information from the personal information for the user prior to uploading the personal information to the clearinghouse server. (Tenneti Par. 106-“ In some embodiments, aggregated personal information may be used to improve a service offering for all users who collectively are members of an aggregate group, without a way to directly identify a particular user and/or impinge on a user's privacy.; Par. 165- In one embodiment, to demonstrate anonymity to users in a transparent manner, a response that a client receives from a server may be stamped with their IP address (e.g., with signatures) and/or another suitable means of identification so that a client can see that a request was routed randomly and that the server did not receive any information that identified the origin of the data.”));
Malhotra, Carlisle, Davis and Tenneti are directed to query processing. It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user request processing of Malhotra in view of Carlisle in further view of Davis, as taught by Tenneti, by utilizing additional data analysis with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle in further view of Davis with the motivation of improving a service offering for all users who collectively are members of an aggregate group, (Tenneti Par.106).
Claims 11-12 are rejected under 35 U.S.C. 103 as being unpatentable over Malhotra et al., US Publication No. 20200344219A1 [hereinafter Malhotra], in view of Carlisle et al., US Publication No. 20180349483 A1, [hereinafter Carlisle], in further view of Davis, US Publication No. 20130257876 A1, [hereinafter Davis], and in further view of Tenneti et al., US Publication No. 20130332987 A1, [hereinafter Tenneti] in further view of Tucciarone et al., US Publication No. 20040122730 A1, [hereinafter Tucciarone].
Regarding Claim 11,
Malhotra in view of Carlisle in further view of Davis in further view Tenneti teach The method of claim 10,…
Malhotra in view of Carlisle in further view of Davis in further view of Tenneti fail to teach the following feature taught by Tucciarone:
wherein the payment account of the user comprises a bank account or an online wallet provided by the clearinghouse server. (Tucciarone Par. 118-“ Associated with this customization screen are an ok to add key 897, an undo key 898, a next search key 899, a my profile key 848, a my account history key 850, a my wallet key 852 and a cancel key 851. Should the subscriber want to accept the current preferences as a new active request he would use the ok to add key 897. Should the subscriber desire to cancel the current preferences and return the customize request panel to some default setting he would hit the undo key 898. Should the subscriber want to add a preferences for a new request he would invoke the next search key 899. Should the subscriber wish to modify his profile he would invoke the my profile key 848. Should the subscriber wish to view the details of his account he would invoke the my account history key 850. Should the subscriber wish to either see the details of his online cash status or else make a purchase he would invoke the my ewallet key 852. Should the subscriber decide to not customize his current request he can use the cancel key 851 to return to the previous screen 802.”)
Malhotra, Carlisle, Tenneti and Tucciarone are directed to processing user personal information requests It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user request processing of Malhotra in view of Carlisle in further view of Davis in further view of Tenneti, as taught by Tucciarone, by utilizing additional data analysis with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle in further view of Davis in further view of Tenneti with the motivation of providing for the requests, so indicated, to be self-tailored or customized by the user according to the user's preferences, (Tucciarone Par.18).
Regarding Claim 12,
Malhotra in view of Carlisle in further view of Davis in further view of Tenneti teach The method of claim 10,…
Malhotra in view of Carlisle in further view of Davis in further view of Tenneti fail to teach the following feature taught by Tucciarone:
wherein the one or more user marketing preferences comprise one or more of: a list of specific marketers that the user wishes to market their personal data to; a list of specific marketers that the user wishes to hide their personal data from; a list of genres of marketers that the user wishes to market their personal data to; a list of genres of marketers that the user wishes to hide their personal data from; a limit for a number of marketers that the user wishes to sell their personal data to over a given period of time; and a minimum price threshold that the user requires from marketers to sell their personal data. (Tucciarone Par. 22-“ The present invention acts as an information exchange system, which seeks to optimize the matching up of the requests from multiple users for information with their associated multiple criteria/preferences and personal profiles on the one hand, with, on the other hand, the information inventory of multiple suppliers' with their associated multiple specifications, objectives and mandatories. In this embodiment, the user or subscriber has an Information Account and the Supplier or Information Provider has an Information Account each of which maintains active and historical records of requests made, criteria for such requests and a record of delivered results and associated email behaviors and financial transactions as appropriate.”; Par. 85-“ From this dashboard they are able to set parameters such as budget, targeting, performance criteria, etc. Before the Supplier can use the dashboard, the Supplier must first be authenticated by the Authentication Server 240.”; Table A)
Malhotra, Carlisle, Davis, Tenneti and Tucciarone are directed to processing user personal information requests It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have improve upon user request processing of Malhotra in view of Carlisle in further view of Davis in further view of Tenneti, as taught by Tucciarone, by utilizing additional data analysis with a reasonable expectation of success of arriving at the claimed invention. One of ordinary skill in the art would have been motivated to make the modification to the teachings of Malhotra in view of Carlisle in further view of Davis in further view of Tenneti with the motivation of providing for the requests, so indicated, to be self-tailored or customized by the user according to the user's preferences, (Tucciarone Par.18).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US Publication No. 20080033869A1 to Steele et al.- Abstract-“ An Anonymous Transaction Service (ATS) solves or alleviates the problems outlined above. The ATS provides anonymous, automated, risk-based differential pricing that allows consumers to receive offers from multiple suppliers with only a single credit report. The ATS facilitates any offer between a supplier and consumer that first requires an evaluation of the risk associated with making the offer. The ATS can be used for any product or service, such as credit cards, home mortgages, automobile loans, appliance loans, debt consolidation loans, insurance products, advertising and dating services, to name only a few.”
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Chesiree Walton, whose telephone number is (571) 272-5219. The examiner can normally be reached from Monday to Friday between 8 AM and 5 PM. If any attempt to reach the examiner by telephone is unsuccessful, the examiner’s supervisor, Patricia Munson, can be reached at (571) 270-5396. The fax telephone numbers for this group are either (571) 273-8300 or (703) 872-9326 (for official communications including After Final communications labeled “Box AF”).
Another resource that is available to applicants is the Patent Application Information Retrieval (PAIR). Information regarding the status of an application can be obtained from the (PAIR) system. Status information for published applications may be obtained from either Private PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, please feel free to contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Applicants are invited to contact the Office to schedule an in-person interview to discuss and resolve the issues set forth in this Office Action. Although an interview is not required, the Office believes that an interview can be of use to resolve any issues related to a patent application in an efficient and prompt manner.
Sincerely,
/CHESIREE A WALTON/ Examiner, Art Unit 3624