gitmodelmujtaba/gdpr-compliance-explorer
GDPR Interactive Compliance Explorer & Knowledge Graph
   
An offline-first, client-side legal analytics and privacy engineering platform for Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR), featuring 936 line-by-line normative triples, interactive Cytoscape.js knowledge graph, executable W3C SHACL/Prolog compliance engines, automated Article 35 DPIA risk wizard, DSAR SLA manager, and DevSecOps static linter.
๐ง Knowledge Engineering Architecture & Methodology
Traditional legal-tech solutions rely heavily on stochastic Large Language Models (LLMs) that frequently hallucinate legal citations, miss nuanced cross-article conditions, or misattribute passive statutory duties. This platform is built upon a deterministic 6-Phase Knowledge Engineering Pipeline:
[EUR-Lex Official Journal CELEX:32016R0679]
โ
โผ
Phase 1: Statutory Knowledge Acquisition & Normalization
โ
โผ
Phase 2: Semantic Disambiguation & Active-Voice Attribution
โ
โผ
Phase 3: Formal Ontological Modeling (936 Triples & Graph)
โ
โผ
Phase 4: Executable Compliance Engines (W3C SHACL & Prolog)
โ
โผ
Phase 5: Privacy-as-Code & Privacy Engineering Operations
โ
โผ
Phase 6: 4-Tier Cryptographic SHA-256 Provenance Ledger1. Statutory Knowledge Acquisition & Text Normalization
- Authoritative Grounding: Direct, deterministic ingestion from the Official Journal of the European Union (OJ L 119, 4.5.2016, p. 1-88; CELEX:32016R0679).
- Exhaustive Statutory Scope: 100% complete line-by-line coverage across all 99 Articles (Chapters IโXI) and 173 Recitals.
- Zero Hallucination Guarantee: Every statement is anchored to its verbatim canonical text snippet with automated SHA-256 hashing.
2. Semantic Disambiguation & Active-Voice Attribution
- Challenge: EU legal drafting extensively uses passive voice (e.g., "personal data shall be processed lawfully..."), creating ambiguity about which actor bears liability.
- Solution: Complete agent disambiguation mapping statutory duties to explicit legal actors:
Data ControllerJoint ControllerData Processor/Sub-processorData SubjectSupervisory Authority (DPA)European Data Protection Board (EDPB)European Commission
3. Formal Ontological Modeling
- 936 Normative Subject-Predicate-Object (SPO) Triples:
- Fully categorized by Modal Deontic Operators:
- `OBLIGATION`: Mandatory statutory duties ("shall", "must")
- `PROHIBITION`: Explicit legal bans ("shall not", "prohibited")
- `PERMISSION`: Conditional statutory rights or derogations ("may", "permitted")
- `DEFINITION`: Foundational ontological terms ("means", "denotes")
- `SANCTION`: Statutory penalty thresholds under Article 83
- Unified Knowledge Graph Topology:
- 3,212 Legal Nodes: Concepts, processing operations, actor roles, and rights.
- 4,500+ Relational Edges: Cross-article references, conditional requirements, delegation flows, and jurisdictional bridges.
- Domain Data Dictionary:
- 21 domain classes, 1,000+ controlled vocabulary terms, and standardized predicate taxonomies.
4. Executable Compliance Engines & Symbolic Reasoning
- W3C SHACL (Shapes Constraint Language): Executable RDF/Turtle validation shapes (
gdpr_shacl_shapes.ttl) for automated compliance checks against Article 30 ROPA records and Article 37 DPO appointments. - EDPB Guidelines 04/2022 Statutory Penalty Calculator: Two-tier dynamic calculation engine evaluating turnover percentages (2% vs 4%) and statutory ceilings (โฌ10M vs โฌ20M).
- Cross-Regulatory Harmonization: Formal cross-walks aligning GDPR requirements against ISO/IEC 27701:2019 (PIMS), ISO/IEC 27001:2022, CCPA/CPRA, and HIPAA Security Rule.
5. Privacy-as-Code & Privacy Engineering Operations
- DevSecOps Static Linter: In-browser and CLI static analysis for Terraform (
aws_s3_bucket,google_storage_bucket,azurerm_storage_account) and OpenAPI 3.0 specs with standard SARIF v2.1.0 reports. - Article 35 DPIA Wizard: Automated EDPB WP 248 rev.01 high-risk processing screening with inherent/residual risk scoring matrix and cryptographic audit certificate generation.
- DSAR SLA Workflow Orchestrator: Article 12(3) statutory 1-month SLA tracking, Article 17(3) statutory exemption validation, and formal legal response drafting.
6. Cryptographic Provenance Ledger
- 4-Tier SHA-256 verification tree ensuring tamper-evident legal certainty from primary EUR-Lex gazette down to granular UI elements.
๐ 100% Client-Side Privacy Architecture
- Zero Server-Side Storage: Runs entirely within your browser client.
- No External API Dependencies: All 936 triples, 3,212 entities, SHACL shapes, and DPIA rules are embedded statically.
- Air-Gapped Ready: Operates completely offline without sending data over external networks.
