Next Article in Journal
Technological Advancements of Hybrid Rocket Engines for Sustainable and Competitive In-Space Propulsion Applications
Previous Article in Journal
LLM for Japanese Text OCR: Automating Kuzushiji Recognition Using Decoder-Only OCR Architecture
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Proceeding Paper

Evaluating Compliance Approaches in Data Analysis Between Teams and Artificial Intelligence †

by
Saverio Gianluca Crisafulli
1,*,
Angelo Riccardi
1,
Gianfranco Piscopo
2,* and
Maria Longobardi
2
1
iInformatica Srl, Via della Scienza 24, 75100 Matera, Italy
2
Department of Mathematics and Applications “R. Caccioppoli”, University of Naples “Federico II”, 80126 Naples, Italy
*
Authors to whom correspondence should be addressed.
Presented at the 15th International Scientific Conference TechSys 2026—Engineering, Technologies and Systems, Plovdiv, Bulgaria, 14–16 May 2026.
Eng. Proc. 2026, 150(1), 9; https://doi.org/10.3390/engproc2026150009
Published: 16 July 2026

Abstract

The purpose of this paper is to present and evaluate some compliance-oriented approaches designed and patented by the company Elabordati of Matera, which operates in the business services sector with particular reference to administrative, accounting and tax services, together with a comparison with approaches generated by the generative artificial intelligence ChatGPT, with the aim of making a comparison and providing insights to the academic world in terms of data analysis. The two approaches highlighted concern the assessment of the mandatory nature of a DPO, presented in the first part of the paper, and the assessment of enterprise value, presented in the same way in the second part of this paper. Finally, for each approach presented, a subjective comparison is made by the generative artificial intelligence itself.

1. Assessment of the Obligatoriness of a DPO

1.1. Approach Designed by Elabordati

The first approach we present in the paper concerns an automated system for assessing whether the appointment of a DPO is mandatory, linked to the GDPR (General Data Protection Regulation). This study is framed within the literature on neural networks, generative artificial intelligence, ChatGPT, GDPR, compliance, and enterprise-value certification [1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20].
The GDPR, officially known as Regulation (EU) 2016/679, represents one of the most significant and comprehensive data protection regulations in the European Union. Entering into force on 25 May 2018, the GDPR replaced the previous Directive 95/46/EC and introduced several sweeping changes to the way organisations manage and protect personal data.
One of the key aspects of the GDPR is the strengthening of individuals’ rights over their own data, which includes the right of access, the right to rectification, the right to vanish (also known as the ‘right to be forgotten’), the right to restrict processing, the right to data portability and the right to object. The regulation requires organisations to obtain explicit and informed consent for the processing of personal data and to be transparent about the manner and purpose of the processing. Furthermore, the GDPR introduces the principle of ‘privacy by design’ and ‘privacy by default’, obliging companies to consider data protection from the design stage of new products and services.
One of the key elements of the GDPR is the figure of the DPO, a mandatory role for certain types of organisations, particularly those that process data on a large scale or handle sensitive data or data relating to criminal convictions and offences. The DPO is responsible for ensuring that the organisation complies with data protection regulations. This includes supervising data protection policies, training staff, conducting regular audits and cooperating with supervisory authorities. The DPO must possess specific professional skills, including a complete knowledge of data protection laws and practices. He or she must be able to operate independently, without being subject to external influences that could compromise his or her ability to ensure compliance with the GDPR. In terms of his or her relationship with the organisation, the DPO reports directly to the highest level of management and must be adequately resourced to perform his or her duties effectively. However, to date the DPO represents a figure that is not yet fully understood by the business community in Italy, with particular reference to the south of the country. This ranges from unnecessary voluntary appointments (e.g., in small hotels) to absent appointments in companies that process health data or carry out large-scale processing.
Elabordati’s approach combines an expert system publicly accessible on the web by means of an appropriate quiz that allows for a guided determination of the mandatory nature of the figure. The form for assessing the mandatory nature of the appointment of a DPO is based on the formula in the figure, characterised by:
  • Number of individuals managed (n sogg in relation to the reference population of the specific municipality p(i), adjusted by a correction factor theta(i));
  • Number of particular data managed (with the relevant tau parameter (0 to 1) linked to the maximum risk of particular data managed);
  • Numbers of employees.
D P O r e q = i n s o g g ( i ) × ϑ ( i ) p ( i ) + d p a r t × τ m a x + n d i p 250 1 .
The formula above reports the mandatory DPO appointment assessment form designed by Elabordati.
If the value obtained is higher than or equal to one, the system returns the mandatory appointment of the DPO.
The human–machine interface (HMI) shown in the Figure 1 allows digital and real-time feedback on the need for a DPO. It is also useful for assessing whether it is advisable to appoint a DPO (for values close to 0.8).

1.2. Approach Suggested by Generative Artificial Intelligence

According to ChatGPT, a chatbot based on artificial intelligence and machine learning developed by OpenAI, to determine whether a company must appoint a DPO in compliance with the GDPR, we can use a quantitative evaluation method based on a weighted metric that considers three key criteria established by the GDPR: regular and systematic monitoring of individuals, large-scale processing of sensitive data, and status as a public authority or public body. Each criterion is assessed through a series of specific questions that are scored on a scale from 0 to 10, where 0 indicates no relevance and 10 maximum relevance.
For the criterion of regular and systematic monitoring, aspects such as online monitoring of customer or employee activities and the use of physical surveillance systems, such as security cameras and workstation monitoring, are assessed. For large-scale processing of sensitive data, health, biometric and criminal conviction data are considered, verifying the extent and sensitivity of the processing. Finally, it is assessed whether the company is a public authority or a public body, excluding courts in the exercise of their judicial functions.
The scores assigned to each question are added up to obtain a total score. For example, if a company scores eight points for online monitoring, seven points for physical surveillance, six points for processing health data, five points for biometric data and four points for criminal data, the total score will be 30. A threshold is set, e.g., 15 points, above which it is considered mandatory to appoint a DPO. In this case, with a total score of 30, the company should appoint a DPO.
To confirm the obligation to appoint a DPO, the company should review its data monitoring and processing activities internally, consult a GDPR legal expert for a detailed analysis and, if necessary, proceed with the appointment of a DPO with the required expertise to ensure compliance with data protection regulations.

1.3. Evaluation of the Two Methods by Artificial Intelligence

Below is shown the evaluation of the two previously presented methods, carried out directly by ChatGPT-3.5.
‘The method proposed by Elabordati and my method share the objective of determining the mandatory nature of appointing of a DPO under the GDPR, but differ significantly in the approach and complexity of the assessment.
Elabordati’s method uses an automatic system based on a formula that incorporates three main variables: the number of individuals managed, the number of particular data items managed and the number of employees. This approach is accessible via the web and provides real-time feedback through a human–machine interface. A distinctive aspect is the use of municipality-specific correction factors and a risk parameter for sensitive data, which makes the assessment contextual and company-specific. If the calculated value exceeds the threshold of one, the appointment of a DPO is considered mandatory, with suggestions for appointments recommended when the value is close to 0.8.
My method, on the other hand, takes a more qualitative approach based on a series of specific questions relating to the criteria set out in the GDPR: regular and systematic monitoring, large-scale processing of sensitive data and status as a public authority or public body. Each question is scored on a scale from 0 to 10, and the scores are then added together to obtain a total score. If the total score exceeds a predefined threshold, the company should consider it mandatory to appoint a DPO. This method is more manual, requires an internal review of activities and, if necessary, consultation with legal experts.
In summary, the Elabordati method is more automated and quantitative, exploiting a specific formula and offering immediate feedback through a web interface, making it more practical for a wide range of companies. However, it requires a precise understanding of the correction factors and the risk parameter, which may not be intuitive for all users. My method is more direct and qualitative, based on a series of thoughtful questions that require more active participation of the company and a manual review of the results. This approach can be more transparent and easy to understand, but less straightforward than the automation offered by Elabordati’s system.’

2. Evaluation of Enterprise Value Certification

2.1. Approach Designed by Elabordati

Enterprise value is a fundamental concept in business economics and strategic management. It refers to the set of resources, capabilities and competitive advantages a company possesses that help generate profits and sustain long-term growth. Understanding the value of a company is essential for a variety of reasons, ranging from financial valuation to strategic planning to operational management and investment policy-making. The value of a company is not limited to tangible assets, such as property, equipment and inventories, but also includes intangible aspects that are often the real drivers of business success such as brand reputation, intellectual property, management quality, human capital, customer and supplier relationships, and innovation capacity. These intangible assets are often more difficult to quantify, but are crucial to a company’s competitiveness and resilience in the marketplace.
Assessing business value is a complex process that requires in-depth analysis of financial performance, growth prospects, associated risks, and industry dynamics. Analysts use various methods to estimate the value of a company, including the discounted cash flow (DCF) method, market multiples, and benchmarking with other companies in the industry. Each of these methods has its strengths and weaknesses, but together they provide an integrated and consistent view of company value.
Enterprise value is fundamental to multiple strategic and operational decisions. For investors, it is a key criterion for evaluating investment opportunities and portfolio management. For business leaders, it is a guide for defining growth strategies, managing capital, and evaluating corporate performance. It is also closely linked to the creation of value for stakeholders, including shareholders, employees, customers, and the community at large. A company that succeeds in increasing its value not only guarantees financial returns to its shareholders, but also contributes to the economic and social well-being of the communities in which it operates. This concept of creating shared value is increasingly relevant in today’s economic environment, where sustainability and corporate social responsibility have become strategic priorities for many organisations.
The approach designed and protected by Elabordati concerns a system for the analysis and certification of company value characterised by a module for the management of master data in which all the relevant company data are uploaded, by a module for the upload of categorised documents in which all the dossiers (incorporation, taking over, anti-money laundering, privacy) in the form of a concatenated workflow and the relevant documentation, by a time schedule module for recording and managing all company compliance communications and deadlines under tax regulations, also taking into account incentive-related opportunities thanks to the use of a knowledge base that relates to individual regulations, by a semantic knowledge base relating to the analysis of accounting and company data by means of appropriate algorithms that consider numerical and textual economic information obtained by means of a text mining module from documentation and the OSINT (Open Source Intelligence) module for information recruiting from the web relating to company feedback and benchmarking of competitors in the industry and companies in other sectors also by means of the analysis of intellectual property obtained from individuals (trademarks and patents) by a user interface to access the system and a module of business risk prediction with determination of a business signature linked to components that determine the business value, that is recorded in the blockchain over time together with business risk alerts.
The company signature C_Index is therefore given by the analysis made on the economic data over time B_index (delta(t)), by the component A_index related to the intangible assets owned by the company, weighted by the compliance with the deadlines over time S_index, balanced by the incentives I_index, in relation to the benchmark BK_index of companies in the same sector or in another sector of the same size M_index.
C _ index = B _ index ( delta ( t ) ) × A _ index × S _ index × I _ index / ( BK _ index × M _ index )
This system was the subject of innovative software development owned by Elabordati itself.

2.2. Approach Suggested by Generative Artificial Intelligence

According to ChatGPT, a discounted cash flow (DCF) approach can be used to analyse and certify enterprise value. This method evaluates the company based on its ability to generate future cash flows, discounted to their present value using an appropriate rate of discount. The DCF evaluation consists of several steps: cash flow projection, determination of the discount rate and calculation of the net present value (NPV).
In order to project future cash flows, the company’s historical financial performance, market conditions and growth expectations are analysed and, consequently, future revenues, operating costs, capital investments and changes in working capital are estimated. For example, a company that had an operating cash flow of EUR 5 million last year could expect annual growth of 5% over the next five years, leading to estimated future cash flows of EUR 5.25 million, EUR 5.51 million, EUR 5.79 million, EUR 6.08 million and EUR 6.38 million, respectively.
The discount rate, often the weighted average cost of capital (WACC), reflects the investment risk and cost of capital of the company. Assuming that the company’s WACC is 10%, future cash flows are discounted using this rate to obtain their present value.
By calculating the net present value (NPV), the present values of future cash flows are summed together. Using the example above, cash flows of EUR 5.25 million, EUR 5.51 million, EUR 5.79 million, EUR 6.08 million and EUR 6.38 million discounted at a rate of 10% yield present values of approximately EUR 4.77 million, EUR 4.56 million, EUR 4.36 million, EUR 4.17 million and EUR 3.98 million, respectively. The sum of these present values gives an NPV of about EUR 21.84 million.
Finally, to complete the evaluation, the terminal value is added, which is the present value of the cash flows generated beyond the projection period, assuming perpetual growth. If a perpetual growth of 2% beyond the fifth year is assumed, the terminal value can be calculated and discounted to the present value. This value is added to the NPV to obtain the total enterprise value. For example, if the discounted terminal value is estimated to be €40 million, adding this to the NPV of €21.84 million gives a total enterprise value of approximately €61.84 million.
This DCF method offers a detailed evaluation based on future cash flows, reflecting the company’s ability to generate value over time.

2.3. Evaluation of the Two Methods by Artificial Intelligence

Similarly to the previous section, the evaluation of the two presented methods, carried out by ChatGPT, is given below.
Elabordati’s approach and my proposed method for analysing and certifying enterprise value differ significantly in terms of complexity, automation and aspects considered in the evaluation.
Elabordati offers a highly automated and integrated system that uses several modules to collect, manage and analyse complex business data. It includes a module for managing company master data, a module for uploading and managing categorised company documentation, and a deadline module for compliance communications and tax deadlines. The semantic knowledge base and text mining and OSINT algorithms analyse both numerical and textual data, including feedback and competitor benchmarks. A risk prediction module determines a company’s signature, the C_Index, which is calculated by taking into account various economic components, intangible assets, compliance with deadlines, incentives and benchmarking with other companies. This system records data in blockchain to ensure transparency and security.
My method, based on discounted cash flows (DCFs), is more straightforward and less automated. It focuses on projecting future cash flows, determining the appropriate discount rate and calculating the net present value (NPV). DCF valuation involves analysing the company’s historical financial performance, market conditions and growth expectations. This involves estimating future sales, operating expenses, capital expenditure and changes in working capital. The discount rate, usually the weighted average cost of capital (WACC), is applied to discount future cash flows to their present value. Finally, the terminal value is added to obtain the total enterprise value.
In summary, the approach proposed by Elabordati offers a dynamic and complex valuation by integrating various automated modules and advanced technologies such as text mining and OSINT, and recording data in blockchain to ensure transparency and security. My DCF approach is more traditional and focused on future cash flows, requires detailed analysis of financial performance and market conditions but does not include the same automation and integration of non-financial data as in Elabordati’s approach.

3. Conclusions

The GDPR represents a milestone in data privacy protection, introducing a set of rights for individuals and responsibilities for organisations. Its implementation has led to significant changes in data management practices, promoting greater transparency, security and accountability, and has had a major impact not only in Europe, but globally. In this context, the role of the DPO is very complex and multidimensional, requiring a combination of legal, technical and organisational skills. He or she must be highly competent and trustworthy, able to navigate between regulatory requirements and business dynamics to ensure effective protection of personal data. His or her presence is crucial in building and maintaining the trust of individuals in the organisations that process their data, thus contributing to a more secure and transparent digital environment.
Here, interesting and innovative approaches proposed by Elabordati were presented and contrasted with those of generative artificial intelligence. From this comparison, it emerged that Elabordati’s method for evaluating the DPO’s appointment is more practical and straightforward, although it requires an understanding of the corrective factors, in comparison to that of generative artificial intelligence, which is more intuitive and transparent, but requires manual review of the results. On the other hand, regarding the evaluation for the certification of enterprise value, Elabordati’s approach is more complex and technologically advanced, unlike the DCF method proposed by ChatGPT, which is more traditional and focused on financial aspects.

Author Contributions

Conceptualization, S.G.C., A.R., G.P. and M.L.; methodology, S.G.C., A.R., G.P. and M.L.; software, S.G.C., A.R., G.P. and M.L.; validation, S.G.C., A.R., G.P. and M.L.; formal analysis, S.G.C., A.R., G.P. and M.L.; investigation, S.G.C., A.R., G.P. and M.L.; resources, S.G.C., A.R., G.P. and M.L.; data curation, S.G.C., A.R., G.P. and M.L.; writing—original draft preparation, S.G.C., A.R., G.P. and M.L.; writing—review and editing, S.G.C., A.R., G.P. and M.L. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Conflicts of Interest

Authors Saverio Gianluca Crisafulli and Angelo Riccardi were employed by the company iInformatica Srl. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

References

  1. Aggarwal, C. Neural Networks and Deep Learning; Springer: Cham, Switzerland, 2018; Volume 10, p. 3. [Google Scholar]
  2. Baı, J.Y.; Zawackı-Rıchter, O.; Muskens, W. Re-examining the Future prospects of Artificial Intelligence in Education in Light of the GDPR and ChatGPT. Turk. Online J. Distance Educ. 2024, 25, 20–32. [Google Scholar] [CrossRef]
  3. Budhwar, P.; Chowdhury, S.; Wood, G.; Aguinis, H.; Bamber, G.J.; Beltran, J.R.; Varma, A. Human resource management in the age of generative artificial intelligence: Perspectives and research directions on ChatGPT. Hum. Resour. Manag. J. 2023, 33, 606–659. [Google Scholar] [CrossRef]
  4. Chuma, E.L.; De Oliveira, G.G. Generative AI for business decision-making: A case of ChatGPT. Manag. Sci. Bus. Decis. 2023, 3, 5–11. [Google Scholar] [CrossRef]
  5. Deng, J.; Lin, Y. The benefits and challenges of ChatGPT: An overview. Front. Comput. Intell. Syst. 2022, 2, 81–83. [Google Scholar] [CrossRef]
  6. Dwivedi, Y.K.; Pandey, N.; Currie, W.; Micu, A. Leveraging ChatGPT and other generative artificial intelligence (AI)-based applications in the hospitality and tourism industry: Practices, challenges and research agenda. Int. J. Contemp. Hosp. Manag. 2024, 36, 1–12. [Google Scholar] [CrossRef]
  7. Fui-Hoon Nah, F.; Zheng, R.; Cai, J.; Siau, K.; Chen, L. Generative AI and ChatGPT: Applications, challenges, and AI-human collaboration. J. Inf. Technol. Case Appl. Res. 2023, 25, 277–304. [Google Scholar] [CrossRef]
  8. Giacalone, M.; Sinitò, D.C.; Calciano, M.V.; Santarcangelo, V. A novel Big Data approach for record and represent compliance in the COVID-19 era. Big Data Res. 2022, 27, 100290. [Google Scholar] [CrossRef]
  9. Lucchi, N. ChatGPT: A case study on copyright challenges for generative artificial intelligence systems. Eur. J. Risk Regul. 2023, 1–23. [Google Scholar]
  10. Khan, M.S. A multidimensional approach towards addressing existing and emerging challenges in the use of ChatGPT. AI Ethics 2023, 5, 333–339. [Google Scholar] [CrossRef]
  11. Jovanovic, M.; Campbell, M. Generative artificial intelligence: Trends and prospects. Computer 2022, 55, 107–112. [Google Scholar] [CrossRef]
  12. Rane, N. ChatGPT and Similar Generative Artificial Intelligence (AI) for Smart Industry: Role, challenges and opportunities for industry 4.0, industry 5.0 and society 5.0. In Challenges and Opportunities for Industry; Preprints.org: Basel, Switzerland, 2023; p. 4. [Google Scholar]
  13. Rane, N.; Choudhary, S.; Rane, J. Intelligent Manufacturing through Generative Artificial Intelligence, Such as ChatGPT or Bard. Available online: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4681747 (accessed on 8 July 2026).
  14. Rondinone, M.; Brio, F.A.M.; Bellucci, M.; Riccardi, A.; Annecca, G. Sistema per la Big Data analytics per uno studio di elaborazione dati in ottica GDPR. Patent No. 102017000149596, 27 December 2017. [Google Scholar]
  15. Santarcangelo, V.; Lamacchia, A.; Vitullo, S.; Di Lecce, M.; Giacalone, M. Explainable artificial intelligence (XAI) through artificial intelligence from a human in the loop (HITL) perspective: An interview with ChatGPT. In IES 2023-Statistical Methods for Evaluation and Quality: Techniques, Technologies and Trends; Il Viandante: Rome, Italy, 2023; pp. 664–669. [Google Scholar]
  16. Shi, Y. Study on security risks and legal regulations of generative artificial intelligence. Sci. Law J. 2023, 2, 17–23. [Google Scholar] [CrossRef]
  17. Tancredi, M.; Iacovone, V.; Carlucci, G. Metodo e sistema per l’analisi e certificazione del valore d’impresa. Patent No. 102019000025798, 30 December 2019. [Google Scholar]
  18. Yakışır, C. An Evaluation of the ChatGPT Decision, Which Italy Blocked Access on the Grounds of Violation of the GDPR. Available online: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4423779 (accessed on 8 July 2026).
  19. Wamba, S.F.; Queiroz, M.M.; Jabbour, C.J.C.; Shi, C.V. Are both generative AI and ChatGPT game changers for 21st-Century operations and supply chain excellence? Int. J. Prod. Econ. 2023, 265, 109015. [Google Scholar] [CrossRef]
  20. Voigt, P.; Von dem Bussche, A. The EU general data protection regulation (GDPR). In A Practical Guide, 1st ed.; Springer International Publishing: Cham, Switzerland, 2017. [Google Scholar]
Figure 1. Figure (a) shows the home page of the web dashboard containing information on the GDPR, while figure (b) shows the quiz through which the expert system will determine whether the DPO is mandatory.
Figure 1. Figure (a) shows the home page of the web dashboard containing information on the GDPR, while figure (b) shows the quiz through which the expert system will determine whether the DPO is mandatory.
Engproc 150 00009 g001
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Crisafulli, S.G.; Riccardi, A.; Piscopo, G.; Longobardi, M. Evaluating Compliance Approaches in Data Analysis Between Teams and Artificial Intelligence. Eng. Proc. 2026, 150, 9. https://doi.org/10.3390/engproc2026150009

AMA Style

Crisafulli SG, Riccardi A, Piscopo G, Longobardi M. Evaluating Compliance Approaches in Data Analysis Between Teams and Artificial Intelligence. Engineering Proceedings. 2026; 150(1):9. https://doi.org/10.3390/engproc2026150009

Chicago/Turabian Style

Crisafulli, Saverio Gianluca, Angelo Riccardi, Gianfranco Piscopo, and Maria Longobardi. 2026. "Evaluating Compliance Approaches in Data Analysis Between Teams and Artificial Intelligence" Engineering Proceedings 150, no. 1: 9. https://doi.org/10.3390/engproc2026150009

APA Style

Crisafulli, S. G., Riccardi, A., Piscopo, G., & Longobardi, M. (2026). Evaluating Compliance Approaches in Data Analysis Between Teams and Artificial Intelligence. Engineering Proceedings, 150(1), 9. https://doi.org/10.3390/engproc2026150009

Article Metrics

Back to TopTop