ISMS Copilot
Product Updates

Cite the paragraph, not just the article

GDPR, DORA, UK GDPR, and CCPA/CPRA answers can now point at the exact provision, not a vague article title. That is the difference between a useful citation and one you still have to look up.

by ISMS Copilot··4 min read
Cite the paragraph, not just the article

A compliance answer that says "see GDPR Article 32" is only half useful. Article 32 has several paragraphs. The duty you care about is usually in one of them, or in a lettered point under a paragraph. If the assistant stops at the article number, you still open EUR-Lex (or your annotated copy) and finish the job yourself.

The same pattern shows up wherever detail matters: DORA third-party contract clauses, UK GDPR fine ceilings that differ from the EU text, CCPA deletion exceptions that live under subdivisions of a single section. An article-level summary lets a model sound confident while still freestyling the exact provision. For audit prep, vendor reviews, and policy drafting, that is the failure mode that costs time.

What we shipped

We rebuilt built-in knowledge for four frameworks so answers can cite at paragraph and point level (and for California privacy, at section and subdivision level), not just the article or section title.

This sits in chat, and the same knowledge is available over the API for teams that integrate programmatically. It is reference knowledge the assistant draws on when those frameworks are in play, not a separate mode you have to switch on.

Before and after

Before, the knowledge blocks for these frameworks were largely article-level: enough for a high-level orientation, thin when you asked a detail question. The model could invent a plausible-sounding point citation, or leave you with an article number that still required a primary-source check.

After, the built-in reference is structured at the grain practitioners already work in. When you ask about a processor clause, a DORA contractual term, a UK fine tier, or a CCPA deletion exception, the assistant can point at the specific paragraph, point, or subdivision rather than stopping one level above the answer.

It does not replace your judgment or your primary source. It closes the gap where "almost the right citation" used to be good enough for a chat reply and useless for the document you were writing.

Why this is the product, not a model upgrade

Frontier models get better at sounding right. They do not automatically get a maintained index of every GDPR paragraph, every DORA lettered contract point, and the UK-specific divergences from the EU text. That is knowledge work: structure the regulation at the grain people actually cite, keep it updated, and put it in front of the model when the question needs it.

The bet is simple. For serious compliance work, the valuable move is not a longer answer. It is an answer that names the provision you can verify. Point-level knowledge is how we make that the default for these frameworks.

Who it is for

  • Practitioners writing policies, DPIAs, vendor assessments, or audit responses who need a citation they can defend, not a chapter heading.
  • Teams in the UK who need UK GDPR answers that track UK law, not a soft import of EU-only rules.
  • US privacy work that turns on CCPA/CPRA subdivisions (deletion exceptions, opt-out methods, definitions of sale and sharing).
  • Financial-sector and ICT risk work under DORA, where contract and third-party articles are dense with lettered points.

If you only need a high-level overview of a framework, article-level was already fine. Point-level pays off when the next sentence of your draft has to name the exact duty.

Try it

Ask a detail question in chat on GDPR, DORA, UK GDPR, or CCPA/CPRA: a specific legal basis exception, a processor clause, a DORA contractual requirement, a UK fine ceiling, a California deletion exception. You should get a reply that points at the provision, not only the article or section title. If you integrate over the API, the same knowledge is available there.

We will keep expanding this grain to more frameworks. The ones above are live now: the places where a close-enough citation still leaves you looking up the provision yourself.

Related Posts