AI-supported automation of the verification of DPAs for GDPR compliance

The customer

caralegal is a data protection management platform that stores thousands of data processing agreements (DPAs) for its customers. To ensure GDPR compliance, these DPAs need to be manually reviewed by lawyers - a costly and time-consuming process. Caralegal engaged Isico and Merantix to develop an AI-powered solution to make this review service affordable and scalable.

The challenge

  • The manual review of DPAs is repetitive, resource-intensive and varies depending on the lawyers' interpretation.
  • High legal fees discourage customers from requesting compliance checks and increase the legal risk.

We knew that AI would be the key for cara28, but the road ahead was open. With Merantix Momentum, we had a partner right from the start who spoke our language and took us along with clear, value-adding communication at eye level. The focus was always on quality and real benefits - this made every meeting a source of new ideas and productive decisions. I really appreciate this collaboration and look forward to what comes next.
Björn Möller
CEO

Solution

We developed an end-to-end NLP system to automate the AVV inspection in three phases: Feasibility study & technical concept development, development of the AI component with training and evaluation, marketing preparation & rollout.

In addition, we implemented and used Parrot, an internal labeling tool for Isico, to annotate contract clauses in a standardized way and thus speed up model training.

Results & effects

The developed solution achieves a 60% (or higher) agreement with experienced lawyers on GDPR compliance issues, enabling automated internal data protection impact assessment review processes for Isico and significantly reducing manual effort.

The solution is currently deployed as part of Caralegal's technical platform and provides fully automated DPA verification services to paying customers. The Parrot labeling tool developed for this project is now reusable for other AI projects in various industries.

Overview

About the company
  • Legal tech company specializing in data protection and AI governance
  • Provides a software platform for GDPR and EU AI law compliance
  • Cooperation with ISiCO Datenschutz GmbH

Implemented services
  • Feasibility study & requirements analysis
  • Development, training & evaluation of NLP models
  • Design & implementation of the internal labeling tool Parrot
  • Full-stack system development & integration
  • Automation of data protection impact assessments (DPA) in the business process

Project period
2021 - 2004
SHARE

Get in touch with us

  • Critical and holistic evaluation of the approach
  • Development of guidelines for reliable implementation
  • Free of charge and without obligation
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We would like to get to know you!

Start your AI journey with us now

Subscribe to the Merantix Momentum Newsletter now.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get in touch with us

  • Critical and holistic evaluation of the approach
  • Development of guidelines for reliable implementation
  • Free of charge and without obligation
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We would like to get to know you!

Start your AI journey with us now

Subscribe to the Merantix Momentum Newsletter now.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.