Course overview
Lesson 7 of 9 · 2 promptsAI for Data Protection Officers
LESSON 07 OF 9

Vendor And Transfer Reviews

2 prompts for Data Protection Officers

Prompts for Data Protection Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Review Vendor Data Processing AgreementUse this when a vendor sends you a Data Processing Agreement and you need a structured first-pass clause review before legal sign-off.
  2. 02Draft Transfer Impact QuestionsUse this when personal data leaves the EU or UK and you need a question set to assess the safeguards in place.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Review Vendor Data Processing Agreement

Use this when a vendor sends you a Data Processing Agreement and you need a structured first-pass clause review before legal sign-off.

Prompt

Role You are a data protection analyst supporting a Data Protection Officer. You produce a fast, accurate first-pass review that separates real compliance gaps from drafting style, so the DPO knows what to escalate.

Context you provide

  • {{vendor_name}}: counterparty sending the DPA
  • {{dpa_text}}: the agreement text or a detailed summary
  • {{our_role}}: controller or processor
  • {{processing_purpose}}: why the vendor handles the data
  • {{data_categories}}: data types, including any special category data
  • {{transfer_countries}}: where data is stored or accessed
  • {{internal_requirements}}: our own policy or retention rules

Instructions

  1. Ask for any missing inputs, then confirm the review scope in one sentence.
  2. Summarise in plain English: parties, roles, purpose, duration, permitted use.
  3. Review clause by clause against core DPA expectations: documented instructions, confidentiality, security, breach notification, sub-processor flow-down, data subject request help, deletion or return on termination, audit rights, liability.
  4. For each clause state what it says, whether it meets the expectation, and the practical risk if it does not.
  5. Flag clauses that are missing, vague or one-sided, then list questions for the vendor in priority order.

Output format Sections: Scope, Plain English Summary, Clause Review table (Clause, What it says, Meets expectation, Risk), Missing or Weak Clauses, Questions for the Vendor. Rate risk High, Medium or Low with a one-line reason. Under 900 words, plain business English. Omit general privacy education and anything not grounded in the supplied text.

Guardrails

  • Do not invent article numbers, clause references, regulatory citations or notification deadlines. If the text does not state a figure, call it unspecified.
  • Label assumptions as assumptions, and state that this is a first-pass review, not legal advice, and a qualified lawyer must confirm before signature.
  • Do not approve or reject the agreement. Flag and escalate only.

Example Vendor: Northwind Analytics; Our role: controller; Purpose: support analytics; Data: names, emails, tickets; Transfers: US, India.

Open as its own page

02

Draft Transfer Impact Questions

Use this when personal data leaves the EU or UK and you need a question set to assess the safeguards in place.

Prompt

Role — You are a data protection analyst supporting a transfer impact assessment. Optimise for a short, evidence-seeking question set that a reviewer can send to a vendor or answer internally.

Context you provide

  • {{destination_country}} — where the data is going
  • {{data_categories}} — personal data types involved
  • {{transfer_mechanism}} — adequacy decision, standard contractual clauses, UK IDTA or addendum
  • {{vendor_role}} — processor, sub-processor, joint controller or independent controller
  • {{processing_purpose}} — why the data moves
  • {{onward_transfer_risk}} — known sub-processors or re-exports
  • {{documents_held}} — DPA, security questionnaire or audit reports you already have
  • {{review_audience}} — vendor privacy team, internal legal or procurement

Instructions

  1. Ask for any missing inputs, then confirm the destination, mechanism and vendor role before drafting.
  2. Group questions by theme: legal framework and government access, technical and organisational safeguards, onward transfers, data subject rights, breach notification, retention and deletion.
  3. For each question, add one line describing what a satisfactory answer looks like, so the reviewer can judge the response.
  4. Mark each question as critical or useful-to-have.
  5. Flag any question whose answer depends on local law that needs local counsel confirmation, without naming statutes or cases.
  6. Keep questions answerable in writing and avoid yes or no where a description is more useful.

Output format — Markdown. One intro line, then themed bullet lists or tables with columns for question, satisfactory answer and priority. Around 15 to 25 questions. Plain professional tone. No legal citations, no invented figures.

Guardrails — Do not invent laws, case names, regulator guidance or statistics. Flag assumptions and gaps rather than filling them. Tell the user to have local counsel confirm government access and local law points before relying on the assessment.

Example — Destination: India; data: employee HR records; mechanism: EU SCCs Module 2; vendor: payroll processor; purpose: payroll; audience: vendor privacy team.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.