Legal Requirements Analysis: A Regulatory Compliance Perspective

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Modern software has been an integral part of everyday activities in many disciplines and application contexts. Introducing intelligent automation by leveraging artificial intelligence (AI) led to breakthroughs in many fields. The effectiveness of AI can be attributed to several factors, among which is the increasing availability of data. Regulations such as the General Data Protection Regulation (GDPR) in the European Union (EU) are introduced to ensure the protection of personal data. Software systems that collect, process or share personal data are subject to compliance with such regulations. Developing compliant software depends heavily on addressing legal requirements stipulated in applicable regulations, a central activity in the requirements engineering (RE) phase of the software development process. RE is concerned with specifying and maintaining requirements of a system-to-be, including legal requirements. Legal agreements which describe the policies organizations implement for processing personal data can provide an additional source to regulations for eliciting legal requirements. In this chapter, we explore a variety of methods for analysing legal requirements and exemplify them on GDPR. Specifically, we describe possible alternatives for creating machine-analysable representations from regulations, survey the existing automated means for enabling compliance verification against regulations and further reflect on the current challenges of legal requirements analysis. Analysing legal requirements is a core RE activity that relies to a large extent on natural language processing technologies. This chapter contributes with the necessary knowledge required for eliciting, representing and verifying legal requirements.

Original languageEnglish
Title of host publicationHandbook on Natural Language Processing for Requirements Engineering
PublisherSpringer Nature
Pages209-242
Number of pages34
ISBN (Electronic)9783031731433
ISBN (Print)9783031731426
DOIs
Publication statusPublished - 1 Jan 2025

Keywords

  • Artificial intelligence (ai)
  • General data protection regulation (gdpr)
  • Large language models (llms)
  • Legal compliance
  • Machine learning (ml)
  • Natural language processing (nlp)
  • Question-answering (qa)

Fingerprint

Dive into the research topics of 'Legal Requirements Analysis: A Regulatory Compliance Perspective'. Together they form a unique fingerprint.

Cite this