Skip to content
Book Open access

Privacy Policy Modeling using Metamodel-Guided LLMs

Oct 2026 · Proceedings of the ACM/IEEE 29th International Conference on Model Driven Engineering Languages and Systems · 0 citations · 18 references

Abstract

With the rapid growth of mobile applications and digital services, privacy regulations have proliferated across jurisdictions to ensure the protection of users’ personal data. However, compliance engineering remains a significant bottleneck due to the challenges of manually interpreting and verifying unstructured legal texts against software system architectures. Existing Natural Language Processing (NLP) approaches extract information from legal text but produce flat annotations rather than typed model instances, while model-driven engineering (MDE) approaches define rigorous metamodels but require manual instance population by domain experts. This paper presents a pipeline that closes the gap by automating the translation from legal text to valid model instances. The pipeline is built on a metamodel that formally specifies the foundation of privacy governance. The metamodel is compiled into runtime schema, which is used to constrain a Large Language Model (LLM) to generate syntactically valid model instances. The pipeline is evaluated under local (Mistral-Nemo) and online (GPT-4o) LLM configurations against the principles of Canada’s PIPEDA statute. Both configurations achieve zero structural failures and reliable extraction on concepts with explicit textual signals, while demonstrating that implicitly expressed concepts remain challenging for both models regardless of size. The results demonstrate that metamodel-guided LLMs in privacy policy modeling reduce reliance on manual legal interpretation, and produce structurally valid, machine-readable compliance artifacts that are directly integrable into model-based systems engineering workflows.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.