“Are we allowed to do this?” — answered from your own configuration, with the clause and the record it relied on.
Not one of these is exotic. Every one of them leaves somebody waiting while a person who knows both the law and your systems is found.
Marketing has a segment and a campaign. Whether those particular people agreed to be contacted for that particular purpose is a question about your records.
A new vendor wants a data feed. Is there a live agreement, does it cover this purpose, and does the notice name a recipient of this kind.
Someone asked for erasure and another statute says keep it. The answer is usually a refusal with grounds, and the grounds have to be named.
Or is it a §7 legitimate use. Treating everything as consent is the most common and most expensive habit of teams trained on other regimes.
An email went to the wrong recipient. Rule 7 has no materiality threshold, so the answer is yes far more often than people expect.
Notice what these have in common. Not one is answered by knowing the Act. Each needs the Act and your own configuration — which notice covers that purpose, whether that vendor’s agreement is live, what your retention schedule says. A general chatbot has exactly half of what is required, and will answer anyway.
Two sources, both of which this platform already holds. Neither one on its own answers a question anybody is actually asking.
The Act, the Rules and the notified schedules are looked up and quoted, not absorbed into a model’s weights. The difference matters: a retrieved passage can be shown to you and checked, and a memorised one cannot.
Your notices, purposes, vendor links, retention schedules and open matters. This is the half that turns a legal generality into an answer about your business, and it is the half nothing outside your tenant can see.
The provision it relied on and the record it read. So you can check that it understood your setup correctly before you act — which is the only way an answer like this is safe to use.
The Rules were notified in November 2025 and obligations phase in to May 2027. An answer records which version of the corpus it was given, so an answer from March can be understood in March’s terms rather than today’s.
Both matter. A system that has never declined a question in a demo is being asked easy ones.
“Can we send the diabetes camp invite to everyone who visited endocrinology last year?”
No — not to all of them. 1,204 of those patients accepted the health-camp purpose; the rest gave consent only for treatment. Camps are marketing, so §7 does not cover it and it needs §6 consent.
Cited: §6(1), your Patient Registration notice v2.1, purpose P3. The 1,204 is a count from your own records, not an estimate.“A patient is threatening to complain to the Board about a refusal we issued. Are we in a defensible position?”
That turns on whether the retention statute you cited actually applies to this record type, which is a legal judgement rather than a lookup. Here is the refusal, the grounds given and the date — take it to counsel.
The wrong answer here is a confident one. Escalation is the correct output, and it arrives with the file already assembled.§33(2) makes what you did, and how promptly, an express factor in any penalty. A record of having checked is exactly that.
Who asked, when, what they were told and what it relied on. A decision taken after checking looks entirely different from one taken without.
If your registry said the agreement was live and it later was not, the record shows what you were told at the time. That is a defence; a memory of having asked somebody is not.
The questions your organisation asked over a period say something true about how seriously it takes this, and they belong beside the rest of the record.
This is the reason to run it inside the compliance platform rather than beside it. A question asked in a chat window disappears. A question asked here becomes part of the same trail as the decision it informed — which is what a regulator is reconstructing when they ask what you knew and when.
A system that answers everything is not more useful. It is less trustworthy, because you can no longer tell which answers were grounded.
Where the answer turns on something it does not hold, it says which fact is missing and where it would come from — rather than producing something plausible.
Whether a position is defensible in your circumstances is not a retrieval problem. Those questions go to our empanelled lawyers, who answer them today.
Parts of this law have not been tested. Where an answer rests on a reading rather than on settled ground, saying so is the useful thing to do.
Our empanelled techno-legal consultants answer exactly these, and unlike a copilot they can tell you what to do about the answer and stand behind having said it.
Of the four modules being built, this is the one where a confident wrong answer does the most damage — because somebody acts on it.
The tell for a bad legal answer is usually confidence, and confidence is what these systems produce most reliably. Grounding every claim in a citation is the only real defence.
A Significant Data Fiduciary must verify that algorithmic software it deploys on personal data does not risk data principals’ rights. Including software it bought.
“The tool decided” is not diligence. If we cannot show you what an answer relied on, buying it would hand you an obligation rather than remove one.
Our empanelled techno-legal consultants, and for anyone who would rather not carry it at all, our advisory retainer holds the function outright. That is available now. For the harder questions it remains the better answer anyway — a copilot can tell you what the position is, a consultant can tell you what to do about it and stand behind having said so.
We are not putting a percentage on that, and you should be careful with anyone who does. A figure like "cuts legal spend by half" requires a body of customers measured before and after, and any vendor quoting one for a product still in build has not measured anything. What is reasonable to expect is that routine, factual questions stop consuming advisory time, and that the questions which do reach counsel arrive with your configuration already attached.
No, and the distinction is worth a moment. It retrieves from the Act, the Rules and the schedules and quotes what it used. A model trained on a corpus has absorbed it into weights you cannot inspect; a model retrieving from one can show you the passage. For a question you are going to act on, being able to read the source is the whole point — so "trained on the Act" is a claim we would rather not make even though it sounds stronger.
For understanding the Act, genuinely do — it is good at that and pretending otherwise would be silly. What it cannot do is answer the questions that actually block work, because those turn on your configuration: whether your notice covers this purpose, whether this vendor's agreement is live, what your retention schedule says. It does not know any of that, and it will answer anyway. That is the failure mode worth worrying about.
No, and we will not describe it that way when it ships. It tells you what your configuration and the statute say, with both cited, and routes judgement to people. Whether a position is defensible in your circumstances is what counsel is for, and our lawyers do that today.
This is the one we are least willing to rush and we are not giving a date. Join the waitlist and we will tell you when it reliably refuses the questions it should refuse — which is the test it has to pass, rather than how well it handles the easy ones.
Real client quotes, attributed by role and sector — we never name a client.
Working across
A free consultation with people who do this daily, and a platform that already records what you decided and when.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.