Legal Prompting - Drafting privacy notices with artificial intelligence
S01:E03

Legal Prompting - Drafting privacy notices with artificial intelligence

Episode description

How to use artificial intelligence to work on privacy notices without losing legal control. Three concrete operations: checking completeness against Article 13 of the GDPR, simplifying the language in compliance with Article 12, and adapting a base notice to different contexts, such as employees or apps. Each operation includes a structured prompt example. With the three Legal Prompting premises: human supervision, regulatory framework, and infrastructure choice.

Episode 3 of the Legal Prompting series — NicFab Podcast.

Newsletter and insights: nicfab.eu

Download transcript (.vtt)
0:09

Welcome back to the NicFab podcast dedicated to legal prompting.

0:14

I am Nicola Fabiano and this is the third episode.

0:18

Last time, we saw how to analyze a supervisory authority's decision using a structured prompt.

0:26

Today, we take the next step.

0:28

We move from analyzing someone else's document to producing one of our own.

0:35

We are talking about privacy notices.

0:38

The problem write a privacy notice for my website.

0:41

How many have already asked the model to do that?

0:45

The result looks like a privacy notice.

0:48

It has the right headings, cites the right articles and uses the right tone.

0:54

But there is nothing inside.

0:58

The processing activities are generic.

1:01

The legal basis are boilerplate.

1:03

The retention periods, when they are there at all, are made up.

1:09

The point is simple.

1:11

The model does not know what you do with personal data.

1:14

It cannot know. You know.

1:17

So what is it good for?

1:19

Three specific operations and I will show you each one with the relevant prompts.

1:25

First operation. Checking completeness.

1:29

You already have a privacy notice.

1:32

Maybe a consultant wrote it.

1:35

Maybe you inherited it.

1:37

You want to know if anything is missing.

1:41

This is a perfect task for the model.

1:43

Comparing a text against a list of requirements.

1:49

The prompt. Act as a DPO with experience in GDPR compliance audits.

1:58

I am providing you with a privacy notice issued under article 13 of the GDPR.

2:06

Verify whether it contains all elements required by paragraphs 1 and 2.

2:12

For each element, indicate present, absent or incomplete.

2:20

If incomplete, explain what is missing.

2:24

Present the result in tabular format.

2:28

Paste the text and you get a requirements map.

2:33

But be careful. The model sees form, not substance.

2:39

Data will be retained for as long as strictly necessary.

2:45

The model marks it as present.

2:48

In reality, it says nothing.

2:51

So the table is a starting point, not a green light.

2:57

Second operation. Simplifying the language.

3:01

Article 12 of the GDPR is clear.

3:05

Simple language, concise form, intelligible content.

3:10

But how many privacy notices actually meet that standard?

3:15

Very few. And when they do not, the notice itself becomes a transparency problem.

3:23

The prompt. Rewrite this paragraph of a privacy notice in clear language suitable for a non-expert user.

3:32

Maintain legal accuracy.

3:35

Where technical terms are needed, add an explanation in parentheses.

3:41

The tone should be professional, not bureaucratic.

3:45

This works particularly well on legal basis and international transfers.

3:52

But always review the result carefully.

3:55

The model in making the text more readable might cut something important.

4:02

For example, it might simplify legitimate interest without mentioning the balancing test against the data subject's rights.

4:12

And that is not a minor detail.

4:15

Third operation. Adapting to different contexts.

4:19

You have a solid privacy notice for your website.

4:22

Now you need one for employees.

4:26

Or for an app.

4:28

Or for a new service.

4:30

The model can help, but you must provide the specific information yourself.

4:37

The prompt. I am providing you with the privacy notice for our website.

4:43

I need to produce a version for employees.

5:15

The processing activities are

5:16

Notice. I have provided the processing activities, providers, and retention periods.

5:24

I did not ask the model to guess them.

5:27

If you do not provide this data, it will make them up.

5:32

And a privacy notice with made-up processing activities is worse than having none at all.

5:39

The three premises.

5:41

As always, the three premises from the first episode.

5:44

Human oversight.

5:47

A privacy notice drafted or reviewed with AI must be read in full before publication.

5:55

The signature is the controllers, not the models.

6:00

Regulatory framework.

6:02

In the employee prompt, you shared providers and internal processes.

6:08

If the model is cloud-based, that data is being transmitted to a third party.

6:15

Verify the data processing agreement with the provider first.

6:20

Infrastructure.

6:21

If you process special categories of data, consider a local model.

6:27

The structure of your processing activities is valuable information.

6:31

It does not necessarily need to end up on someone else's server.

6:37

My closing remarks.

6:39

Check. Simplify. Adapt.

6:42

Three operations where AI genuinely helps.

6:46

If you drive them with real data and verify the output yourself.

6:53

This is legal prompting applied to privacy notices.

6:57

Not a shortcut, but a method.

7:02

The model assists, but professional judgment remains yours.

7:08

Next time, we will talk about RAG.

7:12

Retrieval Augmented Generation.

7:16

What it is.

7:17

Why it can be very useful in the legal field.

7:21

And why, if poorly configured, it becomes a serious risk.

7:28

Subscribe to the newsletter at nickfab.eu.

7:33

Thank you for listening.

7:35

Until the next episode.