PrivComp-KG : Leveraging Knowledge Graph and Large Language Models for Privacy Policy Compliance Verification
Leon Garza, Lavanya Elluri, Anantaa Kotal, Aritran Piplai, Deepti Gupta, and Anupam Joshi

TL;DR
This paper introduces PrivComp-KG, a knowledge graph combined with large language models to verify privacy policy compliance efficiently, addressing challenges in interpreting complex regulations and ambiguous policies.
Contribution
The paper presents a novel knowledge graph framework, PrivComp-KG, integrated with LLMs and semantic web techniques for automated privacy compliance verification.
Findings
Successfully verified privacy policy compliance across multiple organizations.
Demonstrated effective retrieval of regulatory information using PrivComp-KG.
Enhanced accuracy in identifying policy-regulation mismatches.
Abstract
Data protection and privacy is becoming increasingly crucial in the digital era. Numerous companies depend on third-party vendors and service providers to carry out critical functions within their operations, encompassing tasks such as data handling and storage. However, this reliance introduces potential vulnerabilities, as these vendors' security measures and practices may not always align with the standards expected by regulatory bodies. Businesses are required, often under the penalty of law, to ensure compliance with the evolving regulatory rules. Interpreting and implementing these regulations pose challenges due to their complexity. Regulatory documents are extensive, demanding significant effort for interpretation, while vendor-drafted privacy policies often lack the detail required for full legal compliance, leading to ambiguity. To ensure a concise interpretation of the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Data Quality and Management · Access Control and Trust
Methodstravel james · ALIGN
