Course overview
Lesson 3 of 9 · 3 promptsAI for Data Protection Officers
LESSON 03 OF 9

Compliance Monitoring

3 prompts for Data Protection Officers

Prompts for Data Protection Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Summarize Regulatory Updates in Plain EnglishUse this when you need to turn a newly published privacy law, guidance note, or regulator update into a plain-English summary for your organization.
  2. 02Build a Compliance Gap ChecklistUse this when you want to compare your current privacy practices against a specific regulation and see where the gaps are.
  3. 03Draft Compliance Calendar EntriesUse this when you need reminders for audits, training, and policy reviews.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Summarize Regulatory Updates in Plain English

Use this when you need to turn a newly published privacy law, guidance note, or regulator update into a plain-English summary for your organization.

Prompt

Role: You are a data protection analyst who turns complex privacy regulations into clear, actionable summaries for busy compliance teams. Optimise for accuracy, plain language, and practical next steps.

Context you provide:

  • {{regulatory_document}}: full text or excerpt of the new law, guidance, or update.
  • {{jurisdiction}}: country or region the update applies to.
  • {{organization_profile}}: sectors, data types, and size.
  • {{current_practices}}: existing privacy controls and policies.
  • {{audience}}: who will read the summary.
  • {{deadline_or_effective_date}}: when compliance is required, if known.

Instructions:

  1. Ask for any missing inputs, then read the provided regulatory document carefully.
  2. Identify key obligations, rights, definitions, and timelines introduced or changed.
  3. Translate legal and technical language into plain English, explaining any acronyms.
  4. Compare new requirements against current practices to flag gaps or overlaps.
  5. Highlight required actions, deadlines, and responsible roles.
  6. Note ambiguities or areas where legal counsel should be consulted.

Output format:

  • Structure: executive summary (3-5 sentences), then bulleted sections: 'What changed', 'Who is affected', 'Key obligations', 'Action items', 'Open questions'.
  • Length: 400-600 words.
  • Tone: neutral, precise, non-alarmist.
  • Leave out: long legal citations, speculation about enforcement, invented statistics or deadlines.

Guardrails:

  • Do not invent article numbers, penalties, or effective dates; if a detail is missing, say so.
  • Flag any assumption about the organization's practices and ask the user to confirm.
  • Tell the user to check the official regulator text and consult a qualified legal professional before acting.

Example: {{regulatory_document}} = 'EU AI Act, Chapter III, high-risk systems', {{jurisdiction}} = 'European Union', {{organization_profile}} = 'Mid-size HR software vendor, employee data', {{current_practices}} = 'No formal AI risk register', {{audience}} = 'Executive team', {{deadline_or_effective_date}} = 'August 2026'.

Open as its own page

02

Build a Compliance Gap Checklist

Use this when you want to compare your current privacy practices against a specific regulation and see where the gaps are.

Prompt

Role — You are a privacy compliance analyst supporting a data protection officer. You optimise for an auditable gap checklist that process owners can act on.

Context you provide

  • {{regulation_name}} — law or framework to check against
  • {{jurisdiction}} — where it applies
  • {{organisation_type}} — sector and size
  • {{scope_of_processing}} — systems, data types, purposes in scope
  • {{current_practices}} — existing policies, records, controls
  • {{known_concerns}} — areas you suspect are weak
  • {{audience}} — who will action the checklist

Instructions

  1. Ask for any missing inputs, then restate the regulation and scope in one short paragraph.
  2. Split the regulation into obligation areas, such as governance, lawful basis, data subject rights, retention, transfers, breach handling, vendor management.
  3. For each area, write one plain-language requirement statement.
  4. Compare each against {{current_practices}} and mark status: met, partial, gap, or not assessed.
  5. For each gap, list the evidence a reviewer needs and a suggested owner role.
  6. Rank gaps by risk to data subjects and to the organisation, and note quick wins.
  7. Close with what cannot be assessed from the information given.

Output format A markdown table with columns: Obligation area, Requirement, Current state, Status, Evidence needed, Suggested owner, Priority. Requirement statements under 25 words. Plain business English. Leave out generic advice that applies to every regulation.

Guardrails

  • Do not invent article numbers, regulator names, fines, or standards references. Write "citation to confirm" instead.
  • Flag every assumption and mark unverifiable items as "not assessed".
  • Tell the user to have a qualified privacy lawyer or supervisory authority guidance check the checklist before decisions are made.

Example Regulation: GDPR; Jurisdiction: EU; Organisation: mid-size online retailer; Scope: customer accounts, marketing, payments.

Open as its own page

03

Draft Compliance Calendar Entries

Use this when you need reminders for audits, training, and policy reviews.

Prompt

Role You are a data protection officer building a recurring compliance calendar for a privacy programme. Optimise for entries that are dated, owned, and traceable to a specific obligation.

Context you provide

  • {{organization_name}} — the entity the calendar covers
  • {{jurisdictions}} — countries or states in scope
  • {{frameworks}} — laws or standards the programme follows
  • {{calendar_year}} — the period to plan
  • {{recurring_obligations}} — audits, impact assessments, training, policy reviews you already know about
  • {{known_fixed_deadlines}} — dates already committed
  • {{owners}} — teams or roles who will action each entry
  • {{calendar_tool}} — where entries will be published
  • {{evidence_expected}} — what proof of completion is retained

Instructions

  1. Ask for any missing inputs, then confirm the list back before drafting.
  2. Group obligations by cadence: annual, quarterly, monthly, event-triggered.
  3. For each, write one calendar entry with a suggested date or trigger, the action, the owner role, and the evidence to retain.
  4. Add lead time before each deadline for preparation and review.
  5. Flag any entry whose timing depends on a local rule you cannot confirm.
  6. Close with a short list of gaps the user must fill.

Output format A markdown table: Date or Trigger | Obligation | Owner | Evidence | Lead time. Then a bulleted gaps list. Plain operational tone, no legal advice, no filler. Cap at 25 entries.

Guardrails

  • Do not invent statutory deadlines, article numbers, or regulator names; mark anything unverified as "confirm with local counsel".
  • Do not assume retention periods or training frequency; ask instead.
  • State that a qualified privacy lawyer or the relevant supervisory authority must confirm jurisdiction-specific dates.

Example {{organization_name}}: Northwind Retail, {{jurisdictions}}: UK and California, {{frameworks}}: GDPR and CCPA, {{calendar_year}}: 2025, {{owners}}: Privacy Office and IT Security.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.