Welcome back to the NicFab podcast dedicated to legal prompting.
I am Nicola Fabiano and this is the third episode.
Last time, we saw how to analyze a supervisory authority's decision using a structured prompt.
Today, we take the next step.
We move from analyzing someone else's document to producing one of our own.
We are talking about privacy notices.
The problem write a privacy notice for my website.
How many have already asked the model to do that?
The result looks like a privacy notice.
It has the right headings, cites the right articles and uses the right tone.
But there is nothing inside.
The processing activities are generic.
The legal basis are boilerplate.
The retention periods, when they are there at all, are made up.
The point is simple.
The model does not know what you do with personal data.
It cannot know. You know.
So what is it good for?
Three specific operations and I will show you each one with the relevant prompts.
First operation. Checking completeness.
You already have a privacy notice.
Maybe a consultant wrote it.
Maybe you inherited it.
You want to know if anything is missing.
This is a perfect task for the model.
Comparing a text against a list of requirements.
The prompt. Act as a DPO with experience in GDPR compliance audits.
I am providing you with a privacy notice issued under article 13 of the GDPR.
Verify whether it contains all elements required by paragraphs 1 and 2.
For each element, indicate present, absent or incomplete.
If incomplete, explain what is missing.
Present the result in tabular format.
Paste the text and you get a requirements map.
But be careful. The model sees form, not substance.
Data will be retained for as long as strictly necessary.
The model marks it as present.
In reality, it says nothing.
So the table is a starting point, not a green light.
Second operation. Simplifying the language.
Article 12 of the GDPR is clear.
Simple language, concise form, intelligible content.
But how many privacy notices actually meet that standard?
Very few. And when they do not, the notice itself becomes a transparency problem.
The prompt. Rewrite this paragraph of a privacy notice in clear language suitable for a non-expert user.
Maintain legal accuracy.
Where technical terms are needed, add an explanation in parentheses.
The tone should be professional, not bureaucratic.
This works particularly well on legal basis and international transfers.
But always review the result carefully.
The model in making the text more readable might cut something important.
For example, it might simplify legitimate interest without mentioning the balancing test against the data subject's rights.
And that is not a minor detail.
Third operation. Adapting to different contexts.
You have a solid privacy notice for your website.
Now you need one for employees.
Or for an app.
Or for a new service.
The model can help, but you must provide the specific information yourself.
The prompt. I am providing you with the privacy notice for our website.
I need to produce a version for employees.
The processing activities are
Notice. I have provided the processing activities, providers, and retention periods.
I did not ask the model to guess them.
If you do not provide this data, it will make them up.
And a privacy notice with made-up processing activities is worse than having none at all.
The three premises.
As always, the three premises from the first episode.
Human oversight.
A privacy notice drafted or reviewed with AI must be read in full before publication.
The signature is the controllers, not the models.
Regulatory framework.
In the employee prompt, you shared providers and internal processes.
If the model is cloud-based, that data is being transmitted to a third party.
Verify the data processing agreement with the provider first.
Infrastructure.
If you process special categories of data, consider a local model.
The structure of your processing activities is valuable information.
It does not necessarily need to end up on someone else's server.
My closing remarks.
Check. Simplify. Adapt.
Three operations where AI genuinely helps.
If you drive them with real data and verify the output yourself.
This is legal prompting applied to privacy notices.
Not a shortcut, but a method.
The model assists, but professional judgment remains yours.
Next time, we will talk about RAG.
Retrieval Augmented Generation.
What it is.
Why it can be very useful in the legal field.
And why, if poorly configured, it becomes a serious risk.
Subscribe to the newsletter at nickfab.eu.
Thank you for listening.
Until the next episode.