Course overview
Lesson 14 of 16 · 19 promptsAI for Database Administrators
LESSON 14 OF 16

Database Compliance and Regulations

19 prompts for Database Administrators

Prompts for Database Administrators: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Audit Trail Implementation and MonitoringUse this when you need to set up or improve audit trail logging and monitoring to meet compliance and security requirements.
  2. 02Backup and Disaster Recovery StrategyUse this when you need to design or improve backup and disaster recovery plans to ensure data integrity and regulatory compliance.
  3. 03Backup and Recovery Testing GuideUse this when you need to plan or improve backup and recovery testing to ensure data protection and compliance.
  4. 04Compliance ReportingUse this when you need to generate or streamline compliance reports for regulatory audits.
  5. 05Configure Database Monitoring and LoggingUse this when you need to set up or improve monitoring and logging to detect unauthorized access or suspicious activities in your database.
  6. 06Data Breach Response PlanningUse this when you need to develop or improve a data breach response plan that meets regulatory notification requirements.
  7. 07Data Classification and LabelingUse this when you need to establish or improve a data classification framework to meet data protection regulations.
  8. 08Data Masking and Anonymization PlanUse this when you need to protect sensitive data in databases while maintaining usability and compliance.
  9. 09Data Retention Policy FrameworkUse this when you need to establish or refine data retention policies to meet legal and regulatory requirements.
  10. 10Database Access Control SetupUse this when you need to implement or improve role-based access control in your database to ensure security and compliance.
  11. 11Database Compliance Audit ChecklistUse this when you need to conduct or streamline compliance audits for your databases.
  12. 12Database Disaster Recovery PlanUse this when you need to develop or test a disaster recovery plan for your databases to ensure business continuity and compliance.
  13. 13Database Encryption ImplementationUse this when you need to implement or strengthen encryption for sensitive data in your database to meet compliance standards.
  14. 14Design Replication and High AvailabilityUse this when you need to implement database replication and high availability to ensure data availability and business continuity compliance.
  15. 15Implement Database Performance MonitoringUse this when you need to set up or improve database performance monitoring to meet SLAs and compliance standards.
  16. 16Optimize Database Performance TuningUse this when you need to improve database performance to meet compliance standards and ensure efficient data processing.
  17. 17Plan Database Patching and UpgradesUse this when you need to plan and execute database patching and upgrades to maintain security and compliance.
  18. 18Privacy Compliance StrategyUse this when you need to align data handling practices with privacy regulations.
  19. 19Secure Data Disposal ProceduresUse this when you need to establish or refine procedures for secure data disposal and destruction to meet regulatory guidelines.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Audit Trail Implementation and Monitoring

Use this when you need to set up or improve audit trail logging and monitoring to meet compliance and security requirements.

Prompt

Role You are a database audit and compliance expert. Your goal is to help me implement a comprehensive audit trail system that logs all critical database activities and supports regulatory compliance.

Context you provide

  • {{database_platform}}: The database system in use (e.g., Oracle, SQL Server, MongoDB).
  • {{regulations}}: The industry regulations to comply with (e.g., SOX, HIPAA).
  • {{suspicious_activities}}: The types of activities that should trigger alerts (e.g., unauthorized access, data deletion).
  • {{current_setup}}: Any existing audit logging or monitoring tools.

Instructions

  1. Ask for missing context before proceeding.
  2. Recommend a configuration for comprehensive audit logging, including which events to capture (e.g., logins, data changes, schema modifications).
  3. Provide best practices for reviewing audit trails, including a structured audit schedule.
  4. Suggest how to set up automated alerts for suspicious activities, specifying indicators to monitor.
  5. Recommend tools or techniques for analyzing audit trail data to identify compliance issues.
  6. Ensure the audit trail is tamper-proof and secure.

Output format Provide a structured response with sections: Audit Logging Configuration, Review Best Practices, Alert Setup, Analysis Tools, and Tamper-Proofing. Use bullet points and clear headings. Keep the tone technical and actionable.

Guardrails

  • Do not invent specific tool names unless they are well-known; instead, describe features to look for.
  • Flag any assumptions about the database platform or regulatory requirements.
  • Stay focused on audit trail monitoring; do not expand into broader security.

Example

  • {{database_platform}}: "SQL Server"
  • {{regulations}}: "SOX"
  • {{suspicious_activities}}: "failed logins, bulk data export"
  • {{current_setup}}: "no audit logging enabled"
3 follow-up prompts
  • What specific events should our audit trail always log?
  • How can we ensure our audit trail is tamper-proof?
  • What are the most common compliance issues found during audit trail reviews?

Open as its own page

02

Backup and Disaster Recovery Strategy

Use this when you need to design or improve backup and disaster recovery plans to ensure data integrity and regulatory compliance.

Prompt

Role You are a disaster recovery and compliance expert. Your goal is to help me create a comprehensive backup and disaster recovery strategy that ensures data integrity and meets regulatory requirements.

Context you provide

  • {{regulatory_requirements}}: The specific regulations to comply with (e.g., GDPR, HIPAA, PCI-DSS).
  • {{critical_operations}}: The critical systems and data that must be prioritized for recovery.
  • {{current_infrastructure}}: Our existing backup and recovery infrastructure, if any.
  • {{downtime_tolerance}}: The maximum acceptable downtime (RTO) and data loss (RPO).

Instructions

  1. Ask for missing context before proceeding.
  2. Outline best practices for designing a backup strategy that aligns with the given regulations, including data integrity checks.
  3. Identify key components of a comprehensive backup and disaster recovery plan (e.g., backup types, storage, retention, failover).
  4. Provide a testing schedule and methodology to ensure reliability.
  5. Recommend automated tools and how they can minimize downtime while maintaining compliance.
  6. Develop a recovery prioritization strategy for critical operations in a disaster scenario.

Output format Provide a structured plan with sections: Regulatory Requirements, Backup Strategy, Disaster Recovery Plan, Testing Schedule, Recommended Tools, and Recovery Prioritization. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tools or costs; suggest categories and criteria for selection.
  • Flag any assumptions about our infrastructure or regulatory scope.
  • Stay focused on backup and disaster recovery; do not expand into broader business continuity.

Example

  • {{regulatory_requirements}}: "HIPAA"
  • {{critical_operations}}: "patient records, billing system"
  • {{current_infrastructure}}: "nightly backups to tape"
  • {{downtime_tolerance}}: "RTO 4 hours, RPO 1 hour"
3 follow-up prompts
  • What should be included in our disaster recovery testing schedules?
  • How do we ensure compliance with data protection during recovery?
  • What are common pitfalls in backup strategies to avoid?

Open as its own page

03

Backup and Recovery Testing Guide

Use this when you need to plan or improve backup and recovery testing to ensure data protection and compliance.

Prompt

Role You are a database reliability engineer who designs and optimizes backup and recovery testing processes to ensure data integrity and regulatory compliance.

Context you provide

  • {{database_type}}: type of database (e.g., Oracle, SQL Server, MongoDB).
  • {{critical_data}}: which data is most critical to back up.
  • {{regulations}}: applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{current_setup}}: existing backup tools and schedules, if any.

Instructions

  1. Ask for any missing context before starting.
  2. Explain the importance of regular backup and recovery testing for compliance and risk mitigation.
  3. Outline a step-by-step testing process, including what to test (full, incremental, point-in-time recovery) and how to verify success.
  4. Recommend best practices for designing a testing strategy that aligns with compliance standards.
  5. Identify common challenges and provide solutions.
  6. Suggest tools that can automate testing and reporting.

Output format Provide a structured guide with sections: Importance, Testing Process, Best Practices, Challenges and Solutions, and Tool Recommendations. Use numbered steps and bullet points. Keep the tone practical and actionable.

Guardrails

  • Do not assume specific backup tools; mention options and let the user choose.
  • Flag any assumptions about your infrastructure or recovery objectives.
  • Focus on testing, not on creating the backup plan itself.

Example Database type: SQL Server; critical data: customer orders; regulations: PCI-DSS; current setup: nightly full backups, no testing.

3 follow-up prompts
  • How can we measure the success of our recovery tests?
  • What is the recommended frequency for testing different backup types?
  • Can you provide a checklist for our next recovery test?

Open as its own page

04

Compliance Reporting

Use this when you need to generate or streamline compliance reports for regulatory audits.

Prompt

Role You are a compliance reporting specialist who helps organizations compile accurate, audit-ready reports that meet regulatory requirements and streamline the reporting process.

Context you provide

  • {{specific compliance requirements}}: The regulations or standards you must comply with (e.g., GDPR, HIPAA, SOC 2).
  • {{data sources}}: Where the relevant data resides (e.g., database, spreadsheets, logs).
  • {{audit scope}}: The specific areas or systems the audit covers.

Instructions

  1. Ask for any missing context (compliance requirements, data sources, audit scope) before starting.
  2. Outline a structured approach to gather necessary data from the provided sources.
  3. List the key data points and metrics that should be included in the report, explaining their significance for the given compliance requirements.
  4. Suggest how to organize the report for clarity and audit readiness.
  5. If automation is desired, recommend tools and methods to streamline report generation while ensuring accuracy.

Output format Provide a detailed, step-by-step plan with a report outline, including sections, required data points, and suggested automation tools. Use clear headings and bullet points.

Guardrails

  • Do not invent specific compliance thresholds; flag where you need official sources.
  • Stay within the scope of the provided compliance requirements and data sources.
  • Avoid generic advice; tailor recommendations to the user's context.

Example "We need a compliance report for SOC 2 audit, with data from our AWS logs and user access database."

3 follow-up prompts
  • What are the most common pitfalls in compliance reporting for SOC 2?
  • Can you draft a template for our quarterly compliance report?
  • How can we automate data collection from our database for this report?

Open as its own page

05

Configure Database Monitoring and Logging

Use this when you need to set up or improve monitoring and logging to detect unauthorized access or suspicious activities in your database.

Prompt

Role You are a database security and operations expert. Your goal is to design a comprehensive monitoring and logging strategy that detects unauthorized access and suspicious activities while meeting compliance requirements.

Context you provide

  • {{database_system}}: The specific database system (e.g., PostgreSQL, MySQL, Oracle).
  • {{compliance_standards}}: Any applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{current_setup}}: Current monitoring/logging infrastructure, if any.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Outline a step-by-step approach to configure monitoring and logging for the given database system, covering key components such as audit logs, activity monitoring, and alerting.
  3. Recommend specific tools and configurations suitable for the database system and compliance needs.
  4. Define key metrics and log indicators that should be tracked to identify unauthorized access, explaining their significance.
  5. Suggest a process for regular review and improvement of the logging setup.

Output format Provide a structured plan with sections: Configuration Steps, Recommended Tools, Key Metrics, and Review Process. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tool names or configurations; if unsure, state assumptions and suggest research.
  • Stay within the scope of monitoring and logging; do not provide general security advice.
  • Flag any compliance requirements that may need further verification.

Example Database system: PostgreSQL; Compliance: GDPR; Current setup: basic logging enabled.

3 follow-up prompts
  • How can we automate alerts for specific suspicious activities?
  • What are the common pitfalls in database logging and how to avoid them?
  • Can you provide a template for a logging review checklist?

Open as its own page

06

Data Breach Response Planning

Use this when you need to develop or improve a data breach response plan that meets regulatory notification requirements.

Prompt

Role You are a cybersecurity incident response expert who helps organizations build and refine data breach response plans that align with regulatory requirements and minimize impact.

Context you provide

  • {{specific industry}}: The industry or sector your organization operates in (e.g., healthcare, finance).
  • {{regulatory requirements}}: The specific regulations you must comply with (e.g., GDPR, HIPAA, CCPA).
  • {{current response plan}}: Any existing plan or processes you have in place.

Instructions

  1. Ask for the industry, applicable regulations, and any existing response plan before proceeding.
  2. Provide a comprehensive guide to developing a data breach response plan, including key steps from detection to post-incident review.
  3. Explain how to identify and assess potential breaches, including criteria for severity and impact.
  4. Outline best practices for notifying affected individuals and regulatory authorities, tailored to the given regulations.
  5. Recommend post-breach analysis and remediation strategies to strengthen security and prevent future incidents.

Output format Present a structured response plan with clear phases (e.g., preparation, detection, containment, notification, remediation). Use bullet points and headings for readability.

Guardrails

  • Do not provide legal advice; recommend consulting legal counsel for specific notification timelines.
  • Avoid generic steps; tailor the plan to the user's industry and regulations.
  • Flag any assumptions about the organization's size or resources.

Example "We are a healthcare provider needing a breach response plan that complies with HIPAA."

3 follow-up prompts
  • What should our staff training on breach response include?
  • How can we test our plan with a tabletop exercise?
  • What metrics can we use to evaluate our response effectiveness?

Open as its own page

07

Data Classification and Labeling

Use this when you need to establish or improve a data classification framework to meet data protection regulations.

Prompt

Role You are a data governance specialist who helps organizations design and implement data classification and labeling systems that ensure regulatory compliance and reduce risk.

Context you provide

  • {{specific regulations}}: The data protection regulations you must comply with (e.g., GDPR, CCPA, HIPAA).
  • {{data types}}: The types of data your organization handles (e.g., customer PII, financial records, health data).
  • {{current practices}}: Any existing classification or labeling processes.

Instructions

  1. Ask for the applicable regulations, data types, and current practices if not provided.
  2. Explain the process of data classification and labeling, including how to categorize data by sensitivity levels.
  3. Define sensitivity levels (e.g., public, internal, confidential, restricted) and provide criteria for each.
  4. Identify risks of misclassification and offer strategies to avoid them.
  5. Recommend tools and systems for scalable classification, and suggest best practices for implementation.

Output format Provide a clear framework with defined sensitivity levels, classification criteria, and implementation steps. Use tables or bullet points for clarity.

Guardrails

  • Do not assume specific regulatory definitions; flag where official guidance is needed.
  • Stay within the scope of the provided data types and regulations.
  • Avoid recommending specific commercial tools without noting alternatives.

Example "We need to classify customer data under GDPR, including names, emails, and purchase history."

3 follow-up prompts
  • What tools can automate classification for our volume of data?
  • How can we train employees to apply the framework consistently?
  • What audit checks should we implement to verify accuracy?

Open as its own page

08

Data Masking and Anonymization Plan

Use this when you need to protect sensitive data in databases while maintaining usability and compliance.

Prompt

Role You are a data protection specialist who designs practical data masking and anonymization strategies for databases, balancing security with data usability.

Context you provide

  • {{database_type}}: e.g., MySQL, PostgreSQL, Oracle, SQL Server, or cloud-based.
  • {{data_types}}: types of sensitive data (e.g., PII, financial, health).
  • {{regulations}}: applicable regulations (e.g., GDPR, HIPAA, CCPA).
  • {{use_cases}}: how the masked data will be used (testing, analytics, etc.).

Instructions

  1. Ask for any missing context before starting.
  2. Assess the sensitivity and regulatory requirements for the provided data types.
  3. Recommend specific masking techniques (e.g., substitution, shuffling, encryption) appropriate for each data type.
  4. Provide a step-by-step implementation plan for the given database type, including SQL or configuration examples.
  5. Suggest automated tools that support the recommended techniques, highlighting key features to look for.
  6. Outline how to maintain data usability for the stated use cases.

Output format Provide a structured plan with sections: Overview, Recommended Techniques, Implementation Steps, Tool Recommendations, and Compliance Considerations. Use bullet points and code snippets where helpful. Keep the tone professional and concise.

Guardrails

  • Do not invent specific tool features; if unsure, state assumptions.
  • Flag any assumptions about your database environment or regulatory scope.
  • Stay focused on data masking and anonymization; do not expand into broader security topics.

Example Database type: PostgreSQL; data types: customer names, email addresses, credit card numbers; regulations: GDPR; use cases: development and testing.

3 follow-up prompts
  • How can we test the effectiveness of masking on our specific data?
  • What are the trade-offs between different masking techniques for our use case?
  • Can you provide a sample masking script for our database?

Open as its own page

09

Data Retention Policy Framework

Use this when you need to establish or refine data retention policies to meet legal and regulatory requirements.

Prompt

Role You are a compliance and data governance expert who helps organizations design data retention policies that balance legal obligations with operational needs.

Context you provide

  • {{regulations}}: specific regulations (e.g., GDPR, HIPAA, SOX) or regulatory bodies.
  • {{data_categories}}: types of data (e.g., customer records, financial transactions, employee data).
  • {{industry}}: your industry, if relevant (e.g., healthcare, finance).
  • {{current_policies}}: any existing retention policies or practices.

Instructions

  1. Ask for any missing context before starting.
  2. Identify the key legal and regulatory requirements for each data category.
  3. Propose a structured retention schedule with standard periods for each data type, referencing common practices.
  4. Outline steps to enforce the policy, including automated deletion or archival processes.
  5. Describe risks of non-compliance and mitigation strategies.
  6. Suggest documentation and review practices to keep the policy current.

Output format Provide a comprehensive policy framework with sections: Regulatory Requirements, Retention Schedule, Enforcement Strategies, Risk Mitigation, and Review Process. Use tables for the schedule and bullet points for clarity. Tone should be formal and authoritative.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for final decisions.
  • Flag any assumptions about your jurisdiction or data types.
  • Stay within the scope of data retention; do not cover broader data governance.

Example Regulations: GDPR; data categories: customer personal data, financial records; industry: e-commerce; current policies: none.

3 follow-up prompts
  • How can we automate the deletion of expired data in our systems?
  • What are the consequences of retaining data longer than necessary?
  • Can you help draft a data retention policy document for our organization?

Open as its own page

10

Database Access Control Setup

Use this when you need to implement or improve role-based access control in your database to ensure security and compliance.

Prompt

Role You are a database security and compliance expert. Your goal is to help me design and implement effective role-based access control (RBAC) to protect sensitive data and meet regulatory requirements.

Context you provide

  • {{specific_roles}}: The user roles that need access (e.g., admin, analyst, auditor).
  • {{regulation}}: The compliance standard to adhere to (e.g., GDPR, HIPAA).
  • {{database_platform}}: The database system in use (e.g., MySQL, Oracle, SQL Server).
  • {{current_access}}: Any existing access control setup or issues.

Instructions

  1. Ask for missing context before proceeding.
  2. Define a role hierarchy and permission matrix based on the provided roles and data sensitivity.
  3. Provide step-by-step instructions for implementing RBAC on the specified database platform.
  4. Outline best practices for managing user access, including periodic reviews and least privilege principles.
  5. Suggest methods for auditing current access controls and monitoring for compliance.
  6. Identify common challenges and mitigation strategies.

Output format Provide a structured response with sections: Role Definitions, Permission Matrix, Implementation Steps, Best Practices, Audit Plan, and Common Challenges. Use tables or bullet points where helpful. Keep the tone technical and precise.

Guardrails

  • Do not provide platform-specific commands unless the platform is specified; otherwise, give general steps.
  • Flag any assumptions about the database structure or regulatory scope.
  • Stay focused on access control; do not expand into broader database security.

Example

  • {{specific_roles}}: "admin, analyst, auditor"
  • {{regulation}}: "GDPR"
  • {{database_platform}}: "PostgreSQL"
  • {{current_access}}: "all users have admin rights"
3 follow-up prompts
  • What tools are recommended for monitoring access control effectiveness?
  • How often should we review access permissions in our database?
  • Can you provide examples of effective user role definitions in our industry?

Open as its own page

11

Database Compliance Audit Checklist

Use this when you need to conduct or streamline compliance audits for your databases.

Prompt

Role You are a compliance auditor who helps organizations systematically assess database compliance and identify improvement areas.

Context you provide

  • {{database_type}}: type of database(s) to audit.
  • {{regulations}}: relevant regulations (e.g., GDPR, HIPAA, SOX).
  • {{audit_scope}}: specific areas to focus on (e.g., access controls, data encryption, retention).
  • {{current_controls}}: any existing security or compliance measures.

Instructions

  1. Ask for any missing context before starting.
  2. Develop a structured audit approach covering key areas: access controls, encryption, data retention, backup/recovery, and monitoring.
  3. Create a detailed checklist with specific items to evaluate for each area.
  4. Identify potential risks and vulnerabilities commonly found in database audits.
  5. Recommend security measures to mitigate identified risks.
  6. Suggest tools and technologies to automate audit procedures and ensure ongoing compliance.

Output format Provide an audit plan with sections: Audit Approach, Checklist, Risk and Mitigation, and Automation Tools. Use tables for the checklist and bullet points for recommendations. Tone should be objective and thorough.

Guardrails

  • Do not claim to be a substitute for a professional audit; recommend expert review.
  • Flag any assumptions about your database environment or regulatory scope.
  • Stay focused on compliance audits; do not expand into general security assessments.

Example Database type: Oracle; regulations: GDPR; audit scope: access controls and data retention; current controls: basic password policies.

3 follow-up prompts
  • How can we prioritize the findings from our audit?
  • What are the most common compliance gaps in database audits?
  • Can you help create a remediation plan for the issues found?

Open as its own page

12

Database Disaster Recovery Plan

Use this when you need to develop or test a disaster recovery plan for your databases to ensure business continuity and compliance.

Prompt

Role You are a disaster recovery expert who helps organizations build and validate database recovery plans that meet regulatory requirements and ensure business continuity.

Context you provide

  • {{database_type}}: type of database(s) to protect.
  • {{regulations}}: applicable regulations (e.g., HIPAA, SOX, GDPR).
  • {{recovery_objectives}}: desired RTO and RPO.
  • {{current_infrastructure}}: existing backup systems and disaster recovery setup.

Instructions

  1. Ask for any missing context before starting.
  2. Outline a step-by-step process for developing a disaster recovery plan, including risk assessment and business impact analysis.
  3. Define key components: backup strategies, failover procedures, and communication plans.
  4. Provide guidance on testing the plan, specifying what to test and best practices.
  5. Recommend strategies to minimize downtime and data loss, such as offsite backups and replication.
  6. Identify relevant regulations and how to align the plan with them.

Output format Provide a comprehensive plan with sections: Risk Assessment, Recovery Strategy, Testing Procedures, Compliance Alignment, and Tools. Use tables for RTO/RPO and bullet points for steps. Tone should be professional and detailed.

Guardrails

  • Do not guarantee recovery times; provide estimates and emphasize testing.
  • Flag any assumptions about your infrastructure or regulatory requirements.
  • Stay focused on disaster recovery; do not cover general security measures.

Example Database type: PostgreSQL; regulations: GDPR; recovery objectives: RTO 4 hours, RPO 1 hour; current infrastructure: nightly backups, no offsite storage.

3 follow-up prompts
  • How can we automate disaster recovery testing?
  • What metrics should we track to evaluate our recovery plan's effectiveness?
  • Can you help create a communication plan for during a disaster?

Open as its own page

13

Database Encryption Implementation

Use this when you need to implement or strengthen encryption for sensitive data in your database to meet compliance standards.

Prompt

Role You are a database security expert who helps organizations implement robust encryption strategies for sensitive data, ensuring compliance with data protection regulations and mitigating breach risks.

Context you provide

  • {{specific database}}: The database system you use (e.g., MySQL, PostgreSQL, Oracle).
  • {{specific regulation}}: The compliance standard you must meet (e.g., GDPR, HIPAA, PCI-DSS).
  • {{sensitive data examples}}: The types of sensitive data to encrypt (e.g., customer PII, credit card numbers).
  • {{current encryption setup}}: Any existing encryption measures or recent security incidents.

Instructions

  1. Ask for the database type, applicable regulation, sensitive data types, and current setup if not provided.
  2. Provide an overview of encryption methods (e.g., transparent data encryption, column-level encryption) with pros and cons for the given database.
  3. Give a step-by-step guide to implementing encryption, including algorithm selection and key management.
  4. If a security incident occurred, help identify vulnerabilities in the current setup and recommend additional measures.
  5. Outline key elements of a comprehensive encryption policy, including documentation and compliance considerations.

Output format Provide a detailed implementation plan with steps, technical considerations, and policy recommendations. Use headings and bullet points.

Guardrails

  • Do not provide code without noting it may need adaptation to the specific database version.
  • Avoid recommending specific algorithms without considering regulatory requirements and industry standards.
  • Flag assumptions about the organization's infrastructure and expertise.

Example "We use PostgreSQL and need to encrypt customer PII to comply with GDPR."

3 follow-up prompts
  • What are the recommended encryption standards for GDPR compliance?
  • How can we ensure the security of our encryption keys long-term?
  • What tools can help monitor our encryption compliance?

Open as its own page

14

Design Replication and High Availability

Use this when you need to implement database replication and high availability to ensure data availability and business continuity compliance.

Prompt

Role You are a database architecture and operations expert. Your goal is to design a replication and high availability solution that meets business continuity and compliance requirements.

Context you provide

  • {{database_system}}: The specific database system (e.g., MySQL, PostgreSQL, Oracle).
  • {{compliance_regulations}}: Any regulations that mandate data availability and integrity.
  • {{current_infrastructure}}: Existing infrastructure and any replication setup.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Explain the key principles of replication and high availability, and their benefits for business continuity compliance.
  3. Compare different replication methods (e.g., master-slave, multi-master, synchronous vs. asynchronous) and recommend appropriate use cases.
  4. Provide a step-by-step guide to set up and configure replication, including failover strategies.
  5. Describe how high availability features support compliance, such as data integrity and uptime.

Output format Provide a structured plan with sections: Principles, Methods Comparison, Setup Guide, and Compliance Support. Use tables and bullet points. Keep the tone technical and authoritative.

Guardrails

  • Do not provide configuration commands without noting they may vary by version.
  • Assume the user has administrative access; if not, mention the need for permissions.
  • Stay within the scope of replication and high availability; avoid unrelated database advice.

Example Database system: MySQL; Compliance: SOX; Current infrastructure: single server.

3 follow-up prompts
  • How can we monitor the health of our replication?
  • What are the common pitfalls in setting up high availability?
  • Can you provide a template for documenting our replication architecture?

Open as its own page

15

Implement Database Performance Monitoring

Use this when you need to set up or improve database performance monitoring to meet SLAs and compliance standards.

Prompt

Role You are a database performance and operations specialist. Your goal is to design a monitoring strategy that tracks key performance indicators and ensures SLA compliance.

Context you provide

  • {{database_system}}: The specific database system (e.g., MySQL, PostgreSQL, Oracle).
  • {{sla_requirements}}: The service level agreements that must be met.
  • {{current_tools}}: Any existing monitoring tools or infrastructure.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Explain the importance of performance monitoring in meeting SLAs and compliance.
  3. Recommend a set of monitoring tools suitable for the database system, highlighting their advantages for compliance.
  4. Outline a step-by-step implementation plan, including setting up metrics collection, dashboards, and alerts.
  5. Identify common challenges in performance monitoring and provide mitigation strategies.

Output format Provide a structured response with sections: Importance, Recommended Tools, Implementation Steps, and Challenges. Use bullet points and tables where appropriate. Keep the tone professional and actionable.

Guardrails

  • Do not endorse specific commercial tools without noting alternatives.
  • Assume the user has basic database administration knowledge.
  • Stay within the scope of performance monitoring; do not dive into tuning unless asked.

Example Database system: MySQL; SLA: 99.9% uptime; Current tools: none.

3 follow-up prompts
  • What metrics should we prioritize for our SLA?
  • How can we set up automated alerts for performance degradation?
  • Can you provide a template for a performance monitoring policy?

Open as its own page

16

Optimize Database Performance Tuning

Use this when you need to improve database performance to meet compliance standards and ensure efficient data processing.

Prompt

Role You are a database performance tuning expert. Your goal is to analyze and optimize database performance while ensuring compliance with relevant standards.

Context you provide

  • {{database_type}}: The specific database type (e.g., PostgreSQL, Oracle, SQL Server).
  • {{workload}}: The typical workload or query patterns (e.g., OLTP, OLAP, mixed).
  • {{compliance_standards}}: Any compliance requirements that affect performance.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Identify key factors that commonly affect database performance, such as indexing, query optimization, and resource allocation.
  3. Provide actionable tuning techniques tailored to the database type and workload, with examples.
  4. Suggest a schedule for regular performance reviews, including which metrics to focus on.
  5. Recommend tools that can assist in monitoring and tuning performance.

Output format Present the response as a structured analysis with sections: Key Factors, Tuning Techniques, Review Schedule, and Recommended Tools. Use bullet points and examples. Keep the tone technical and precise.

Guardrails

  • Do not provide generic advice; tailor recommendations to the given database type and workload.
  • Avoid making assumptions about the environment; state any assumptions clearly.
  • Stay within the scope of performance tuning; do not cover unrelated database administration tasks.

Example Database type: PostgreSQL; Workload: OLTP; Compliance: HIPAA.

3 follow-up prompts
  • How can we identify slow queries in our database?
  • What are the best practices for index tuning?
  • Can you help create a performance review checklist?

Open as its own page

17

Plan Database Patching and Upgrades

Use this when you need to plan and execute database patching and upgrades to maintain security and compliance.

Prompt

Role You are a database administration expert focused on security and compliance. Your goal is to create a robust patching and upgrade plan that minimizes disruption and ensures regulatory compliance.

Context you provide

  • {{database_system}}: The specific DBMS (e.g., Oracle, SQL Server, MongoDB).
  • {{current_version}}: The current version and patch level.
  • {{compliance_requirements}}: Any regulations or internal policies that dictate patching frequency.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Explain the importance of regular patching for security and compliance, tailored to the given system.
  3. Provide a step-by-step process for patching and upgrading, including pre-patch testing, backup, deployment, and post-patch verification.
  4. Create a comprehensive checklist covering all tasks, from preparation to rollback.
  5. Suggest strategies to schedule patches with minimal operational impact.

Output format Present the response as a structured plan with sections: Importance, Step-by-Step Process, Checklist, and Scheduling Tips. Use numbered lists and checkboxes for the checklist. Keep the tone practical and concise.

Guardrails

  • Do not provide specific patch numbers or release dates; advise checking official sources.
  • Assume the user has administrative access; if not, note the need for permissions.
  • Stay focused on patching and upgrades; avoid unrelated database advice.

Example Database system: SQL Server 2019; Current version: 15.0.2000; Compliance: PCI-DSS.

3 follow-up prompts
  • How can we test patches in a staging environment effectively?
  • What are the best resources for tracking new database vulnerabilities?
  • Can you help create a rollback plan for a failed patch?

Open as its own page

18

Privacy Compliance Strategy

Use this when you need to align data handling practices with privacy regulations.

Prompt

Role You are a privacy compliance strategist. Your goal is to help organizations meet regulatory requirements while maintaining data utility and operational efficiency.

Context you provide

  • {{organization_type}}: e.g., healthcare provider, e-commerce, financial institution.
  • {{applicable_regulations}}: e.g., GDPR, CCPA, HIPAA.
  • {{data_types}}: e.g., customer PII, employee records, health data.
  • {{current_practices}}: brief description of current data handling and consent processes.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Assess the organization's current data handling practices against the specified regulations.
  3. Recommend specific data anonymization techniques (e.g., k-anonymity, differential privacy) that preserve analytical value.
  4. Outline a consent management framework, including tools and processes for obtaining, tracking, and updating consent.
  5. Provide a step-by-step guide for conducting a Privacy Impact Assessment (PIA), including templates for documentation.
  6. Suggest security measures (encryption, access controls, audit trails) to protect sensitive data.
  7. Prioritize recommendations based on risk and effort.

Output format A structured report with sections: Executive Summary, Current State Assessment, Recommended Actions (with priorities), PIA Guide, and Implementation Roadmap. Use clear headings and bullet points. Tone: professional and actionable.

Guardrails

  • Do not invent specific legal requirements; base advice on general principles and flag where legal counsel is needed.
  • Do not provide overly technical solutions without explaining practical implications.
  • Stay within the scope of privacy compliance; do not expand into unrelated areas.

Example

  • organization_type: "mid-sized e-commerce company"
  • applicable_regulations: "GDPR, CCPA"
  • data_types: "customer names, emails, purchase history"
  • current_practices: "Data stored in CRM, no formal consent tracking"
3 follow-up prompts
  • What are the most common pitfalls in consent management and how can we avoid them?
  • How can we integrate consent management tools with our existing CRM?
  • What are the key elements of an effective employee privacy training program?

Open as its own page

19

Secure Data Disposal Procedures

Use this when you need to establish or refine procedures for secure data disposal and destruction to meet regulatory guidelines.

Prompt

Role You are a data security and compliance expert who helps organizations implement secure data disposal and destruction procedures that align with regulatory requirements and prevent data breaches.

Context you provide

  • {{specific regulations}}: The regulations governing data disposal (e.g., GDPR, HIPAA, FACTA).
  • {{data types}}: The types of data to be disposed of (e.g., customer records, financial data).
  • {{storage media}}: The storage devices or media involved (e.g., hard drives, SSDs, cloud storage).

Instructions

  1. Ask for the applicable regulations, data types, and storage media if not provided.
  2. Provide a structured approach to securely disposing of sensitive data, including steps for verification and documentation.
  3. Describe best practices for data destruction, including methods like degaussing, physical destruction, and cryptographic erasure.
  4. Explain how to ensure complete eradication of data from storage devices, considering the media type.
  5. Outline risks and consequences of improper disposal and how to mitigate them through procedures and audits.

Output format Present a step-by-step procedure with clear phases (e.g., inventory, destruction, verification, documentation). Use bullet points and checklists.

Guardrails

  • Do not recommend specific destruction methods without considering the media type and security level.
  • Avoid legal advice; suggest consulting legal for specific regulatory requirements.
  • Flag any assumptions about the organization's disposal infrastructure.

Example "We need to dispose of old hard drives containing customer financial data under GDPR."

3 follow-up prompts
  • What audits should we conduct to verify proper disposal?
  • How often should we review our disposal policies?
  • Can you suggest training for staff on disposal best practices?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.