1
00:00:10,300 --> 00:00:14,739
Welcome back to the NicFab podcast dedicated to legal prompting.

2
00:00:14,779 --> 00:00:18,219
I am Nicola Fabiano and this is the second episode.

3
00:00:19,239 --> 00:00:26,120
In the first episode, I introduced the topic, explained what legal prompting is, and set

4
00:00:26,120 --> 00:00:31,920
out three fundamental premises that will accompany every episode of this series.

5
00:00:32,900 --> 00:00:35,099
Let me briefly remind you.

6
00:00:35,759 --> 00:00:38,819
Language models do not reason like lawyers.

7
00:00:39,659 --> 00:00:45,840
The European regulatory framework imposes precise limits on the use of artificial intelligence

8
00:00:45,840 --> 00:00:47,520
in professional activities.

9
00:00:48,599 --> 00:00:53,380
The choice of model and infrastructure is not a technical decision.

10
00:00:54,139 --> 00:00:55,900
It is a compliance decision.

11
00:00:56,900 --> 00:00:59,319
Today we get into the practical side.

12
00:00:59,919 --> 00:01:06,059
We are going to talk about how to use artificial intelligence to analyze a decision issued

13
00:01:06,059 --> 00:01:08,480
by a data protection authority.

14
00:01:09,500 --> 00:01:13,360
Why start with the supervisory authority's decisions?

15
00:01:14,860 --> 00:01:22,980
Those who work in data protection, lawyers, DPOs, compliance officers, deal with supervisory

16
00:01:22,980 --> 00:01:25,220
authorities' decisions daily.

17
00:01:26,180 --> 00:01:31,199
And I am not talking only about one's own national authority.

18
00:01:32,139 --> 00:01:39,300
A DPO operating in European contexts must engage with decisions from the Italian Garante,

19
00:01:39,900 --> 00:01:48,199
the French CNIL, the UK's ICO, the German BFDI, the Irish, Belgian, and Austrian authorities,

20
00:01:48,199 --> 00:01:54,139
as well as the decisions and guidelines of the EDPB at European level.

21
00:01:55,099 --> 00:02:02,540
These are often lengthy, technically dense documents, with layered regulatory references

22
00:02:03,080 --> 00:02:05,199
written in different languages.

23
00:02:06,339 --> 00:02:13,699
Reading them takes time, understanding them requires expertise, extracting the information

24
00:02:13,699 --> 00:02:21,399
relevant to one specific case requires a method, that is, the most natural use case

25
00:02:21,399 --> 00:02:22,919
for legal prompting.

26
00:02:23,419 --> 00:02:29,360
Not because artificial intelligence can replace the lawyer's reading of the text that must

27
00:02:29,360 --> 00:02:36,979
be said clearly, but because it can accelerate a preliminary phase, orienting oneself within

28
00:02:36,979 --> 00:02:46,039
the document, identifying key points, structuring an initial analysis to be then verified in-depth.

29
00:02:47,059 --> 00:02:51,619
The problem saying analyze this decision is not enough.

30
00:02:52,660 --> 00:02:59,899
The first mistake, and I see it very often, is passing a decision into a chat window and

31
00:02:59,899 --> 00:03:05,419
writing something like analyze this document or tell me what it says.

32
00:03:06,020 --> 00:03:14,839
The result is usually a generic superficial summary that is of no use in a professional context.

33
00:03:15,699 --> 00:03:18,679
Sometimes it is also inaccurate.

34
00:03:19,660 --> 00:03:21,979
Why does this happen?

35
00:03:22,399 --> 00:03:26,080
Because the model has no context.

36
00:03:26,699 --> 00:03:29,179
It does not know who you are.

37
00:03:29,699 --> 00:03:34,220
It does not know why you are reading that decision.

38
00:03:34,820 --> 00:03:43,059
It does not know what you need to extract and it does not know in which regulatory framework

39
00:03:43,059 --> 00:03:46,039
or jurisdiction to place the analysis.

40
00:03:47,199 --> 00:03:55,479
Without precise instructions, it produces a generic output and a generic output in legal

41
00:03:55,479 --> 00:04:01,820
work is a useless output when it is not a dangerous one.

42
00:04:02,820 --> 00:04:05,720
The method building a structured prompt.

43
00:04:06,800 --> 00:04:12,300
Legal prompting applied to decision analysis requires a structured prompt.

44
00:04:13,300 --> 00:04:16,519
Let's see how to build one step by step.

45
00:04:17,779 --> 00:04:19,559
The first element is the rule.

46
00:04:20,220 --> 00:04:25,500
You need to tell the model in which professional capacity you are approaching the text.

47
00:04:26,500 --> 00:04:28,619
That is not a minor detail.

48
00:04:29,339 --> 00:04:36,859
A DPO reads a decision differently from a lawyer defending the data controller who

49
00:04:36,859 --> 00:04:43,279
reads it differently from a consultant assessing the impact on an entire sector.

50
00:04:44,239 --> 00:04:46,579
The role shapes the analysis.

51
00:04:47,619 --> 00:04:49,859
The second element is context.

52
00:04:50,660 --> 00:04:55,279
You need to explain why you are analyzing that decision.

53
00:04:56,200 --> 00:04:59,779
Are you verifying your organization's compliance?

54
00:05:00,660 --> 00:05:03,059
Are you preparing a legal opinion?

55
00:05:04,100 --> 00:05:11,739
Are you assessing whether a particular processing activity is at risk in light of a precedent?

56
00:05:12,739 --> 00:05:19,660
Are you comparing the approaches of two different authorities on the same issues?

57
00:05:20,660 --> 00:05:26,480
Context defines the scope of the analysis and makes the output relevant.

58
00:05:27,380 --> 00:05:30,179
The third element is specific instructions.

59
00:05:31,720 --> 00:05:33,299
What do you want to extract?

60
00:05:33,540 --> 00:05:40,839
The violations identified, the legal basis applied, the corrective measures imposed,

61
00:05:40,839 --> 00:05:49,320
the criteria for calculating the fine, the precedence cited and the interpretation of

62
00:05:49,320 --> 00:05:57,079
a specific GDPR article, the more precise the instruction, the more usable the output.

63
00:05:57,739 --> 00:06:00,359
The fourth element is the output format.

64
00:06:01,299 --> 00:06:09,500
Do you want a discursive analysis, a table with violation, provision and fine, a structured

65
00:06:09,500 --> 00:06:16,779
comparison with another decision, a list of points relevant to a specific impact assessment?

66
00:06:17,239 --> 00:06:26,739
The format must be specified, otherwise the model decides on its own and it rarely chooses

67
00:06:26,739 --> 00:06:29,559
the format most useful to the reader.

68
00:06:29,880 --> 00:06:31,760
A practical example.

69
00:06:32,799 --> 00:06:35,119
Let's take a concrete example.

70
00:06:35,920 --> 00:06:43,500
Suppose a DPO needs to analyze an enforcement decision issued by a supervisory authority

71
00:06:43,500 --> 00:06:47,279
for breach of transparency obligations.

72
00:06:48,160 --> 00:06:59,519
This topic cuts across all European jurisdictions because articles 13 and 14 of the GDPR apply everywhere.

73
00:07:00,519 --> 00:07:05,320
An ineffective prompt would be analyze this decision.

74
00:07:06,000 --> 00:07:12,739
A structured prompt following the legal prompt method would be something like this.

75
00:07:13,799 --> 00:07:23,519
Act as a data protection officer of an organization that processes data on a large scale within

76
00:07:23,519 --> 00:07:25,019
the European context.

77
00:07:26,019 --> 00:07:33,940
I need to assess whether my organization's privacy notices have shortcomings similar

78
00:07:33,940 --> 00:07:37,299
to those identified in this decision.

79
00:07:38,779 --> 00:07:41,500
Analyze the attached decision and extract

80
00:07:41,779 --> 00:07:49,940
1. The specific deficiencies identified by the authority in the privacy notices provided

81
00:07:49,940 --> 00:07:51,720
to data subjects.

82
00:07:51,720 --> 00:08:00,179
2. The provisions breached with precise reference to the relevant GDPR articles.

83
00:08:01,399 --> 00:08:06,760
3. The corrective measures imposed and their respective deadlines.

84
00:08:08,200 --> 00:08:15,640
4. The criteria used to calculate the fine with reference to the relevant GDPR guidelines.

85
00:08:16,640 --> 00:08:24,940
5. Any mitigating or aggravating circumstances recognized by the authority.

86
00:08:26,220 --> 00:08:32,520
Present the result in tabular format with one column for each element.

87
00:08:33,239 --> 00:08:40,739
At the end, add the paragraph on the practical implications for a DPO who needs to verify

88
00:08:40,739 --> 00:08:44,119
the compliance of their own privacy notices.

89
00:08:44,119 --> 00:08:51,520
The difference between the two prompts is enormous and the difference in the output

90
00:08:51,520 --> 00:08:53,520
is equally enormous.

91
00:08:54,859 --> 00:08:56,299
Note something important.

92
00:08:57,099 --> 00:09:03,380
This very same prompt works regardless of which authority issued the decision.

93
00:09:04,460 --> 00:09:12,000
It works with decisions from the Italian Garante, the CNIL and the Spanish Authority.

94
00:09:12,000 --> 00:09:14,280
The method is the same.

95
00:09:14,940 --> 00:09:16,320
The facts change.

96
00:09:16,820 --> 00:09:18,000
The language changes.

97
00:09:19,179 --> 00:09:22,919
But the prompt structure remains valid.

98
00:09:23,619 --> 00:09:24,179
The pitfall.

99
00:09:25,460 --> 00:09:31,000
Even with a well-structured prompt, there are pitfalls to be aware of.

100
00:09:31,780 --> 00:09:37,380
The first is the hallucination of regulatory references.

101
00:09:38,380 --> 00:09:46,219
The model may cite incorrect articles, embed paragraphs that do not exist,

102
00:09:46,780 --> 00:09:51,739
or attribute to a provisioned content that belongs to another.

103
00:09:52,219 --> 00:09:59,200
This risk increases when the decision is in a different language from the prompt,

104
00:09:59,840 --> 00:10:05,900
because the model must perform a double mediation, linguistic and legal.

105
00:10:05,900 --> 00:10:13,900
Every regulatory reference in the output must be verified, always, without exception.

106
00:10:15,520 --> 00:10:20,020
The second pitfall is the loss of argumentative nuance.

107
00:10:21,380 --> 00:10:26,320
Supervisory authorities' decisions have a precise structure.

108
00:10:27,320 --> 00:10:35,880
There is a substantial difference between a fact reported in the investigation's reconstruction,

109
00:10:36,900 --> 00:10:41,140
an argument put forward in the controller's defense,

110
00:10:41,700 --> 00:10:45,119
and a conclusion reached by the authority.

111
00:10:45,580 --> 00:10:49,659
The model may conflate these levels,

112
00:10:49,659 --> 00:10:56,960
attributing to the authority a position that was in fact the party's.

113
00:10:57,659 --> 00:11:02,080
In a professional context, this is a serious error.

114
00:11:03,099 --> 00:11:08,440
The third pitfall concerns precedence and cross-references.

115
00:11:09,280 --> 00:11:14,619
If the model cites previous decisions or ADPB guidelines,

116
00:11:14,979 --> 00:11:18,340
those references must be verified.

117
00:11:18,340 --> 00:11:27,820
They may not exist, or they may exist but say something different from what the model reports.

118
00:11:28,960 --> 00:11:33,820
I have seen models embed decision reference numbers,

119
00:11:34,320 --> 00:11:39,659
attribute to ADPB guidelines content that was never expressed,

120
00:11:40,840 --> 00:11:47,440
and confuse Article 29 Working Party opinions with the ADPB opinions.

121
00:11:47,440 --> 00:11:55,440
These errors in a legal opinion or a board report can have serious consequences.

122
00:11:56,760 --> 00:11:59,640
The three premises are applied.

123
00:12:00,820 --> 00:12:08,440
Let's return to the three premises from the first episode and see how they apply to this use case.

124
00:12:09,840 --> 00:12:10,760
Human oversight.

125
00:12:12,219 --> 00:12:16,520
The analysis output is not the final product.

126
00:12:16,520 --> 00:12:19,539
It's a starting point.

127
00:12:20,320 --> 00:12:25,179
The DPO, the lawyer, and the consultant must read the original decision,

128
00:12:26,460 --> 00:12:30,859
compare the model's analysis, verify every reference,

129
00:12:31,539 --> 00:12:37,719
and integrate it with their own expertise and contextual knowledge.

130
00:12:38,799 --> 00:12:41,900
Artificial intelligence does not replace the lawyer.

131
00:12:41,900 --> 00:12:51,239
It accelerates a phase of the work, but responsibility remains entirely human.

132
00:12:52,559 --> 00:12:53,780
Regulatory framework.

133
00:12:54,539 --> 00:13:01,479
The decision behind analyzed may contain personal data of the parties involved.

134
00:13:02,700 --> 00:13:10,000
Passing that text into a cloud-based model without having verified the provider's terms of service.

135
00:13:10,000 --> 00:13:19,479
The safeguards for international data transfer and the existence of an adequate data processing agreement

136
00:13:19,479 --> 00:13:22,119
that is a compliance issue.

137
00:13:23,320 --> 00:13:27,640
These may also apply when the decision is made public,

138
00:13:28,219 --> 00:13:33,659
because if it still contains identifiable personal data,

139
00:13:33,659 --> 00:13:40,979
the legal or institutional publication of the document does not automatically permit

140
00:13:40,979 --> 00:13:44,200
any subsequent reuse of such data.

141
00:13:44,739 --> 00:13:49,520
Any use of the text in a cloud-based model still requires

142
00:13:49,760 --> 00:13:57,599
an independent assessment of the legal basis, purpose, necessity, data minimization,

143
00:13:58,059 --> 00:14:02,500
the provider's role, and safeguards regarding data transfers.

144
00:14:02,500 --> 00:14:06,520
Choice of model and infrastructure.

145
00:14:07,840 --> 00:14:12,539
When analyzing decisions that contain confidential information,

146
00:14:13,500 --> 00:14:17,099
I am thinking of decisions not yet published,

147
00:14:18,460 --> 00:14:23,440
drafts, documents exchanged in the course of ongoing proceedings.

148
00:14:24,099 --> 00:14:30,799
A local model may be the most appropriate choice from a data protection perspective.

149
00:14:30,799 --> 00:14:39,179
It is not always necessary, but the question must be asked beforehand, not afterwards.

150
00:14:41,099 --> 00:14:46,159
Analyzing a data protection authority's decision with artificial intelligence

151
00:14:46,159 --> 00:14:52,140
is not about copying and pasting a text and waiting for an answer.

152
00:14:52,619 --> 00:14:55,799
It is a process that requires method,

153
00:14:57,039 --> 00:15:03,260
precision in instructions, and rigorous verification of the output.

154
00:15:04,299 --> 00:15:08,320
Legal prompting is exactly about this,

155
00:15:09,500 --> 00:15:16,619
transforming an approximate use of the tool into a professional and informed one.

156
00:15:17,260 --> 00:15:23,239
Indeed, in the next episode, we will discuss another concrete use case,

157
00:15:23,239 --> 00:15:30,979
drafting privacy notices with the assistance of artificial intelligence.

158
00:15:31,940 --> 00:15:38,039
We will look at how to structure prompts, which mistakes to avoid,

159
00:15:38,659 --> 00:15:47,659
and why a privacy notice generated without supervision can create more problems that it solves.

160
00:15:47,960 --> 00:15:51,780
If you want to learn more, visit my blog.

161
00:15:53,619 --> 00:15:54,780
nicfab.eu

162
00:15:55,780 --> 00:16:02,140
You will find an article on legal prompting, with references and useful links.

163
00:16:03,140 --> 00:16:06,020
And every Tuesday, in the NicFab newsletter,

164
00:16:06,380 --> 00:16:11,679
you will find the legal prompting column also in written format.

165
00:16:13,020 --> 00:16:16,679
Subscribe to the newsletter at nicfab.eu

166
00:16:16,679 --> 00:16:22,219
Thank you for listening. See you in the next episode.

