Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Computer Science editorial

Open AccessOA2026

Simplifying Requirements Engineering in the Context of the LGPD: An LLM-Based Investigation

Can Large Language Models Automate the Translation of Brazilian Data Protection Law into Software Requirements?
Cinara Gomes de Melo Carneiro; Renato de Freitas Bulcรฃo Netoยท 2026ยท DOI 10.48550/arXiv.2608.11454

The core problem

Compliance with privacy legislation presents a persistent and complex challenge to Requirements Engineering (RE). The core difficulty lies in translating abstract legal norms into concrete, verifiable software requirements. In the context of the Brazilian General Data Protection Law (LGPD), organizations must ensure that their software systems adhere to a wide array of principles, data subject rights, and processing conditions. Manual translation of these legal provisions is time-consuming, error-prone, and requires interdisciplinary expertise that many development teams lack.

This study addresses the following research question: Can Large Language Models (LLMs) simplify Requirements Engineering within the framework of the LGPD? The authors propose an approach that utilizes current legislation as input to automatically generate User Stories and Acceptance Test Scenarios. By leveraging the natural language understanding and generation capabilities of LLMs, the goal is to bridge the gap between legal compliance and software design, ensuring regulatory adherence from the very inception of a software project.

The investigation is grounded in the premise that LLMs can act as intermedi

Innovation

The evaluation results demonstrated high performance of the LLM-based approach. The generated User Stories and Acceptance Test Scenarios were found to be largely correct, complete, and clear, as judged by human experts. Quantitative metrics indicated that the LLM achieved a high accuracy rate in identifying the relevant legal requirements and translating them into appropriate software requirements.

Specifically, the study reported that the LLM was able to generate User Stories that covered the majority of the data subject rights and processing principles outlined in the LGPD. The Acceptance Test Scenarios were also deemed effective in capturing the conditions necessary for compliance verification. The time required to generate requirements using the LLM was significantly lower than manual efforts, suggesting a substantial efficiency gain.

However, the results also revealed some limitations. Certain complex legal provisions, particularly those involving nuanced interpretations or cross-references, posed challenges for the LLM. In a few cases, the generated requirements were overly generic or missed specific legal nuances. Despite these issues, the overall performance confirmed the

Compliance with privacy legislation presents a persistent and complex challenge to Requirements Engineering (RE). The core difficulty lies in translating abstract legal norms into concrete, verifiable software requirements. In the context of the Brazilian General Data Protection Law (LGPD), organizations must ensure that their software systems adhere to a wide array of principles, data subject rights, and processing conditions. Manual translation of these legal provisions is time-consuming, error-prone, and requires interdisciplinary expertise that many development teams lack.
This study addresses the following research question: Can Large Language Models (LLMs) simplify Requirements Engineering within the framework of the LGPD? The authors propose an approach that utilizes current legislation as input to automatically generate User Stories and Acceptance Test Scenarios. By leveraging the natural language understanding and generation capabilities of LLMs, the goal is to bridge the gap between legal compliance and software design, ensuring regulatory adherence from the very inception of a software project.

Why it matters

The findings suggest that LLMs can indeed simplify Requirements Engineering in the context of the LGPD. By automating the generation of User Stories and Acceptance Test Scenarios, LLMs reduce the manual burden on requirements engineers and help organizations achieve compliance more efficiently. This is particularly valuable for small and medium-sized enterprises that may lack dedicated legal and compliance teams.

The study contributes to the growing body of research on the application of AI in regulatory compliance. It highlights the potential of LLMs as tools for bridging the gap between law and software engineering. However, the authors caution that LLM-generated requirements should not be adopted blindly. Human oversight remains essential to validate the outputs and to address any legal ambiguities or errors. The approach is best seen as a decision-support system rather than a fully autonomous solution.

Future work could explore the integration of this approach into existing RE tools and methodologies. Additionally, expanding the evaluation to other privacy regulations, such as the GDPR, could provide further insights into the generalizability of the method. The study also opens avenues for investigating the use of fine-tuned LLMs specifically trained on legal texts to improve accuracy and reduce hallucinations. Overall, the research demonstrates a promising step towards more efficient and reliable compliance-driven requirements engineering.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ