
AI-supported automation of the verification of DPAs for GDPR compliance

The customer
The challenge

- The manual review of DPAs is repetitive, resource-intensive and varies depending on the lawyers' interpretation.
- High legal fees discourage customers from requesting compliance checks and increase the legal risk.

Solution

We developed an end-to-end NLP system to automate the AVV inspection in three phases: Feasibility study & technical concept development, development of the AI component with training and evaluation, marketing preparation & rollout.
In addition, we implemented and used Parrot, an internal labeling tool for Isico, to annotate contract clauses in a standardized way and thus speed up model training.
Results & effects

The developed solution achieves a 60% (or higher) agreement with experienced lawyers on GDPR compliance issues, enabling automated internal data protection impact assessment review processes for Isico and significantly reducing manual effort.
The solution is currently deployed as part of Caralegal's technical platform and provides fully automated DPA verification services to paying customers. The Parrot labeling tool developed for this project is now reusable for other AI projects in various industries.
Overview
- Legal tech company specializing in data protection and AI governance
- Provides a software platform for GDPR and EU AI law compliance
- Cooperation with ISiCO Datenschutz GmbH
- Feasibility study & requirements analysis
- Development, training & evaluation of NLP models
- Design & implementation of the internal labeling tool Parrot
- Full-stack system development & integration
- Automation of data protection impact assessments (DPA) in the business process