
This paper introduces the SPIRIT H2020 Project. The SPIRIT identity resolution service has been designed to learn about identity patterns, to build up a social graph related to them, and thereby facilitate LEA’s investigation work. The paper will briefly discuss the main task of identity resolution, the privacy controller system, the SPIRIT prototype that will realise the solution, and the ontology to embed privacy into the system. It also discusses a specific technical and legal challenge—i.e., semantic interoperability when integrating SPIRIT data—and its coordination at the agency level with human decision making—systemic interoperability. This paper takes into account the SPIRIT testing prototype and the first revision version (proof of concept prototype).
High-quality legislative drafting requires not only linguistic fluency, but also in-depth legal expertise. In this paper we focus on the second problem and we develop a frame-based, semi-formal model useful in identification and discussion of potential legislative errors. We present a partial systematization of (potential) legislative errors in terms of the types of expert knowledge necessary to ascertain them. The systematization is based on the anticipated interpretation of the statutory text.
On the awareness of the dynamism pertaining to data and its processing, this paper investigates the problem of having two mutually exclusive definitions of personal and non-personal data in the legal framework in force. The taxonomic analysis of key terms and their context of application highlights the risk to crystalize the whole system upon which the digital single market is built, suffocating its future development. With this premise, the paper discusses the extent of the two main data processing tools provided by the GDPR, questioning the ex-ante categorization of data and its outcome, supporting stakeholders in overcoming this issue.
The open data movement is leading to the massive publishing of court records online, increasing transparency and accessibility of justice, and to the design of legal technologies building on the wealth of legal data available. However, the sensitive nature of legal decisions also raises important privacy issues. Current practices solve the resulting privacy versus transparency trade-off by combining access control with (manual or semi-manual) text redaction. In this work, we claim that current practices are insufficient for coping with massive access to legal data (restrictive access control policies is detrimental to openness and to utility while text redaction is unable to provide sound privacy protection) and advocate for a in-tegrative approach that could benefit from the latest developments of the privacy-preserving data publishing domain. We present a thorough analysis of the problem and of the current approaches, and propose a straw man multimodal architecture paving the way to a full-fledged privacy-preserving legal data publishing system.
The present paper proposes a structural operational semantics and the related semantics for normative systems. The proposed approach focuses on explicitly representing in force obligations and violations as events in a temporal framework, determining the state of a normative system. In the paper we use a set of core principles, defining some of the properties required when reasoning about norms, to motivate the semantics of the approach. Finally, we show that the proposed approach is capable of reasoning about more complex legal scenarios.
The enactment of the General Data Protection Regulation (GDPR) has been the response of the European Union to the growing data-driven economy backed up by the largest companies in the world. It provides the data protection and portability needed by individuals that “unconsciously” generate personal data for “free” services offered by providers that lack transparency on their use. Meanwhile, the rise of Distributed Ledger Technologies (DLTs) offers new possibilities for the management of general purpose data, hence being suitable for handling personal data in a trustless scenario. These decentralized technologies bring a new concept of contract called smart because of its ability to be self-executable. DLTs and smart contracts, together with the use of Semantic Web standards, allows the creation of a decentralized digital space controlled entirely by an individual, where his personal data can be stored and transacted.
The recent advances in AI have broad implications, e. g., onto explainability, accountability, and responsibility – in particular in legal settings. In this paper, we provide a conceptual view on design properties of such respective AI systems, where we focus on two specific approaches to explainable artificial intelligence (AI) for legal settings. The first approach aims at designing explainable AI using legal requirements – in a research and design methodology; the second one deals with a design strategy for ensuring requirements of computational ethical reasoning systems in and for which explainability is a core element.
Comparison between cases is a core issue in case-based reasoning. In this paper, we discuss a logical comparison approach in terms of the case model formalism. By logically generalizing the formulas involved in case comparison, our approach identifies analogies, distinctions and relevances. An analogy is a property shared between cases. A distinction is a property of one case ruled out by the other case, and a relevance is a property of one case, and not the other, that is not ruled out by the other case. The comparison approach is applied to HYPO-style comparison (where distinctions and relevances are not separately characterized) and to the temporal dynamics of case-based reasoning using a model of real world cases.
This paper presents the result of the research project Lexdatafication that aims to model the legal knowledge information of Italy in Akoma Ntoso. The University of Bologna, in cooperation with IPZS, the Official Gazette entity, developed a framework capable to exploit the existing legacy databases of Normattiva in Akoma Ntoso. Additionally, Constitutional Court decisions were converted in Akoma Ntoso using the existing XML and metadata dataset provided by the open data portal. This output was linked to the legislative information. The collection of the documents in AKN constitutes a great annotated corpus in machine-consumable format capable to produce relevant legal data analytics applications and visualizations to support both practitioners and citizens in legal information retrieval.
It is usually said that technical solutions should operate ethically, in compliance with the law and subject to good governance principles. In this position paper we face the problem of behavioural compliance and law enforcement in the case of hate speech and extremism online. Law enforcement and behavioural compliance are ways of coping with the objective of stopping the spread of hate and radicalisation online. We contend that a combination of regulatory instruments, incentives, training, proactive self-awareness and education can be effective to create legal ecosystems to improve the present situation.
In this paper we present a suite of tools named TimeLex, that includes different systems able to process temporal information from legal texts. The first tool, called lawORdate, helps preprocessing legal references in texts in Spanish that can be misleading when trying to find dates in texts. The second one, Añotador, is a temporal tagger (this is, a tool that finds temporal expressions, such as dates or durations) that identifies temporal expressions in texts and provides a standard value for each of them. Finally, a third tool, called WhenTheFact, extracts relevant events from judgments, allowing a full processing of the temporal dimension of this kind of texts, and being a first step towards the complete temporal information processing in the legal domain.
The EU General Data Protection Regulation (GDPR) imposes different requirements for data controllers collecting personal data to protect individuals' privacy. This fact triggered many studies and projects to investigate Privacy Enhancing Technologies (PETs) for the fulfillment of the compliance requirements. In this paper, after reviewing some of the current challenges and gaps in GDPR compliance, we argue the use of Semantic Technologies in PETs in the form of an Intelligent Compliance Agent (ICA) to support data controllers in carrying out a Data Protection Impact Assessment (DPIA). Models and ontologies representing entities involved in the DPIA process can help data controllers determine the risk of their processing activities. Additionally, an inference engine, equipped with a knowledge base of DPIA-related obligations, can effectively assist data controllers in taking specific actions when a legal fact is triggered based on met conditions.
This introduction presents the fifth volume of a series started twelve years ago: the AI Approaches to the Complexity of Legal Systems (AICOL). The introduction revises the recurrently addressed topics of technology, Artificial Intelligence and law and presents new challenges and areas of research, such as the AI ethical and legal turn, hybrid and conflictive intelligences, regulatory compliance and AI explainability. Other domains not yet fully explored include the regulatory models of theWeb of Data and the Internet of Things that integrate legal reasoning and legal knowledge modelling.
What eventually determines the semantics of algorithmic decision-making is not the program artefact, nor—if applicable—the data used to create it, but the preparatory (enabling) and consequent (enabled) practices holding in the environment (computational and human) in which such algorithmic procedure is embedded. The notion of responsibility captures a very similar construct: in all human societies actions are evaluated in terms of the consequences they could reasonably cause, and of the reasons that motivate them. But to what extent does this function exist in computational systems? The paper aims to sketch links between several of the approaches and concepts proposed for responsible computing , from AI to networking, identifying gaps and possible directions for operationalization.
As AI systems are increasingly applied in real-life situations, it is essential that such systems can give explanations that provide insight into the underlying decision models and techniques. Thus, users can understand, trust and validate the system, and experts can verify that the system works as intended. At the Dutch National Police several applications based on computational argumentation are in use, with police analysts and Dutch citizens as possible users. In this paper we show how a basic framework of explanations aimed at explaining argumentation-based conclusions can be applied to these applications at the police.
There is an increasing need for norms to be embedded in technology as the widespread deployment of big data analysis applications increases. However, existing methodologies do not provide automated policy enforcement mechanisms especially for policies derived from legislation and contractual agreements. Consequently, data access is hindered and collaborations derailed due to fear data misuse and high non-compliance fees. This research aims to automate normative controls in healthcare, such as data sharing agreements, and ultimately, enforce these policies for compliant data usage and access which encourages collaboration and facilitates research outcomes while maintaining accountability. This paper outlines the PhD research questions, current approaches and preliminary results.
We present in this paper: (i) a regulatory quadrant to describe the rule of law; (ii) a cluster of concepts to describe instruments and processes of the law; (iii) the methodology followed to select the technical papers concerning regulatory compliance; and (iv) an initial mapping to frame the selected papers about legal compliance that we used in our final survey. The result is a conceptual clustering that is useful to analyse and differentiate Compliance by Design (CbD) and Compliance through Design (CtD).
This paper aims to describe a research project focused on the digital representation of information related to the privacy and data protection domain. Currently, privacy policies are used by data controllers as a tool to achieve compliance with data protection regulations such as the EU GDPR, instead of being a privacy instrument at the disposal of both controllers and data subjects. On the other hand, data subjects lack the tools to effectively establish preferences when it comes to the processing and disclosure of their personal data, as well as to easily exercise their rights. In this regard, this paper discusses the challenges of the implementation of a service based on decentralised Web technologies and Semantic Web standards and specifications to facilitate the communication between data subjects and data controllers in the light of the GDPR. The main challenges that this service intends to address are linked to the exercising of GDPR-related rights and obligations, the negotiation of privacy terms and the governance of access to personal data stores. A case study in the healthcare and genomics domain will be explored to experiment with the developed tools. Early-stage results related to the implementation of semantic policies for the representation of GDPR rights and obligations are presented.
Rights expression languages (RELs) aim to express and govern legally binding behavior within technological environments. The Open Digital Rights Language (ODRL), used to represent statements about the usage of digital assets, is among the most known RELs today and has become a W3C recommendation to enhance the web's functionality and interoperability. This paper reflects on the representational power of ODRL from a practical perspective; utilizing use cases and examples, we discuss the challenges, issues, and limitations we came across while investigating the language as a potential solution for the regulation of data-sharing infrastructures.