Welcome to Codeliance
They say a good product starts with a pain.
Mine started in 2017.
I had the honour of leading parts of the implementation of the General Data Protection Regulation (GDPR) at Google for Search Trust & Safety.
I remember the uncertainty.
Going back to the law again and again, trying to understand what was actually required:
- What data can we store?
- For how long?
- What are the exemptions?
Nothing felt clear.
At some point, I gathered around 40 people in one room.
We asked them to manually document their workflows - what they do, what data they touch, where it flows.
We tried to map reality to regulation.
It was… painful.
And this was Google.
With the resources, the expertise, and some of the best people in the world working on it.
We still struggled to translate legal requirements into something operational.
And back then - we didn’t even have AI.
What hasn’t changed
Eight years later, we’re no longer talking about one regulation.
We’re talking about dozens.
From the Digital Services Act to the Online Safety Act, and many more across the world.
And the same pattern keeps repeating:
- The law is written in legal language
- Teams try to interpret it
- Product and engineering try to implement it
- And somewhere in between, things get lost
Not because people aren’t capable.
Because the process itself doesn’t work.
The real problem
It took me 8 years and about 30 Trust & Safety regulations to realise:
This isn’t just a legal problem.
It’s a translation problem.
Between law and systems.
What we’re building
This is where Codeliance comes in.
We’re building a way to take regulatory requirements and turn them into something systems can actually work with.
In practice, that means:
Breaking down laws into concrete, structured obligations and connecting them to how systems actually behave.
Not just:
“You should have a reporting mechanism”
But:
- What happens when a user clicks “report”?
- What needs to be captured?
- What needs to be shown?
- What needs to be communicated back?
And importantly:
Can you actually verify that it works?
Today, too much of compliance is still manual - living in documents, interpretations, and assumptions.
We believe more of it can live closer to the system itself.
Where this is going
We’re still early.
We’re learning a lot from the teams we work with: what’s possible, what’s not, and where this approach actually helps.
But one thing is already clear:
Regulation is becoming system-level.
And compliance will need to be built the same way.
Try the DSA Quick Check
We built a simple self-assessment that helps you map a small part of your product - like reporting mechanisms - against DSA expectations.
It takes a few minutes, and gives you a clearer view of where things might break between regulation and product.
Welcome to Codeliance.