PrietoExpósito

Método

Trabajar jurídicamente sobre tecnología es intervenir en decisiones que ya están en marcha: sistemas que se compran, productos que se construyen, incidentes que ocurren. El método ordena esa intervención: un proceso de cuatro etapas y unos principios, numerados y públicos, que gobiernan cómo se recorre. Se publican por dos razones: para que el cliente sepa qué esperar, y como compromiso de cumplirlos.

El proceso: cuatro etapas

Entender

Cómo funciona la tecnología, qué decisión debe tomarse y quién interviene. Se examina el sistema y se habla con quien lo construye antes de emitir opinión: un dictamen sobre un sistema que nadie ha examinado es un dictamen sobre un supuesto.

Encajar

Roles, obligaciones, riesgos, contratos y prioridades: qué norma alcanza a qué sistema, qué papel ocupa la empresa y qué importa primero, ordenado por su impacto real en el negocio.

Diseñar

Controles, documentos, procesos y responsabilidades: la respuesta jurídica convertida en piezas que la organización puede operar y, llegado el caso, exhibir.

Implantar y probar

Llevarlo a operación, formar a quien lo usa, conservar la evidencia y revisar cuando el sistema o la norma cambian. El trabajo no termina al entregar documentos.

Los principios

Las etapas describen el recorrido; estos principios gobiernan cómo se recorre.

1. Entender antes de opinar

1.1 Leer el sistema, no solo el contrato

Un dictamen sobre un sistema que nadie ha examinado es un dictamen sobre un supuesto. Antes de opinar se solicita acceso a lo que exista: arquitectura, flujos de datos, documentación técnica. La formación técnica permite examinarlo directamente.

1.2 Hablar con quien lo construye

La realidad técnica de una empresa no está solo en sus políticas: está en el equipo que la construye. Una conversación con quien desarrolla el sistema aporta más que un cuestionario extenso.

2. El riesgo es del negocio, no del papel

2.1 Priorizar por impacto

No todos los incumplimientos tienen la misma relevancia. Los riesgos se ordenan por su coste potencial real (sanción, contrato, continuidad del producto) y se abordan en ese orden: atender primero lo crítico vale más que aspirar a completarlo todo a la vez.

2.2 La medida justa

El asesoramiento se dimensiona al riesgo real de cada empresa. Cuando el riesgo es bajo, así se hace constar, aunque suponga un encargo menor: la confianza vale más que el expediente.

3. Respuestas con las que se pueda decidir

3.1 Las tres preguntas

Todo entregable responde tres preguntas, en este orden: qué establece la norma, qué riesgo se asume en el caso concreto y cuál es la recomendación. Un informe que no responde la tercera está incompleto.

3.2 En el idioma del negocio

Los entregables se redactan para quien ha de decidir, con el detalle técnico-jurídico en anexo para quien lo precise. Un informe con el que no se puede tomar una decisión no ha cumplido su función.

4. Sin sorpresas

4.1 Todo por escrito antes de empezar

Alcance, plazos y honorarios se fijan por escrito, en la hoja de encargo con EJASO, antes de comenzar el trabajo: proyecto cerrado o cuota periódica, según la naturaleza del asunto.

4.2 Conflictos e independencia

Antes de aceptar un encargo se verifica la ausencia de conflicto de intereses. Cuando un asunto excede la especialidad, se dirige a los equipos especialistas de EJASO, un despacho multidisciplinar.

4.3 Secreto profesional desde el primer correo

Cuanto se confía está protegido por el secreto profesional de la abogacía desde la primera conversación, exista o no encargo posterior.

5. Construir cuando toca

5.1 Si una obligación es repetible, es software

Cuando una obligación de cumplimiento se repite de forma idéntica en cada empresa, la respuesta más útil no es otro informe, sino una herramienta. Con ese propósito existe Laryan. La experiencia de construir software y la del ejercicio profesional se refuerzan mutuamente.

Para plantear un asunto: lmprieto@ejaso.com.

Method

Working as a lawyer on technology means stepping into decisions already in motion: systems being bought, products being built, incidents happening. The method orders that intervention: a four-stage process, and a set of numbered, public principles that govern how it is carried out. They are published for two reasons: so the client knows what to expect, and as a commitment to uphold them.

The process: four stages

Understand

How the technology works, what decision must be made and who is involved. The system is examined and the people who build it are heard before any opinion is given: an opinion on a system nobody has examined is an opinion on an assumption.

Frame

Roles, obligations, risks, contracts and priorities: which rule reaches which system, what role the company plays and what matters first, ordered by its real impact on the business.

Design

Controls, documents, processes and responsibilities: the legal answer turned into pieces the organisation can operate and, if it comes to it, produce as evidence.

Implement and test

Take it into operation, train the people who use it, preserve the evidence and review when the system or the rule changes. The work does not end when documents are delivered.

The principles

The stages describe the route; these principles govern how it is travelled.

1. Understand before giving an opinion

1.1 Read the system, not just the contract

A legal opinion on a system nobody has examined is an opinion on an assumption. Before opining, access is requested to whatever exists: architecture, data flows, technical documentation. Technical training allows a direct examination.

1.2 Talk to the people who build it

A company’s technical reality is not only in its policies: it is in the team that builds it. A conversation with whoever develops the system yields more than a lengthy questionnaire.

2. Risk belongs to the business, not the paperwork

2.1 Prioritise by impact

Not every instance of non-compliance carries the same weight. Risks are ordered by their real potential cost (a penalty, a contract, the product’s continuity) and addressed in that order: attending to the critical first is worth more than attempting everything at once.

2.2 The right measure

Advice is sized to each company’s real risk. Where the risk is low, that is stated plainly, even if it means a smaller engagement: trust is worth more than the file.

3. Answers you can decide with

3.1 The three questions

Every deliverable answers three questions, in this order: what the law establishes, what risk is assumed in the specific case, and what the recommendation is. A report that does not answer the third is incomplete.

3.2 In the language of the business

Deliverables are written for the person who must decide, with the technical-legal detail in an annex for whoever requires it. A report one cannot decide with has not served its purpose.

4. No surprises

4.1 Everything in writing before we start

Scope, timeline and fees are set in writing, in the engagement letter with EJASO, before work begins: a fixed project or a periodic fee, depending on the nature of the matter.

4.2 Conflicts and independence

Before accepting an engagement, the absence of conflicts of interest is verified. Where a matter exceeds the specialty, it is directed to EJASO’s specialist teams: a full-service firm.

4.3 Professional privilege from the first email

Whatever is entrusted is protected by legal professional privilege from the first conversation, whether or not an engagement follows.

5. Build when it is the right answer

5.1 If an obligation is repeatable, it is software

When a compliance obligation repeats identically in every company, the most useful answer is not another report but a tool. That is why Laryan exists. The experience of building software and the experience of legal practice reinforce each other.

To raise a matter: lmprieto@ejaso.com.

Hablemos.Let's talk.

Consultas de empresas, medios de comunicación e instituciones.Enquiries from companies, media and institutions.