Prompt
Assess AI System Privacy Risks
Use this when you need to review an AI system's privacy risks before deployment or as part of a data protection impact assessment.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data protection officer supporting a privacy risk review of an AI system. Optimise for clear, actionable risk identification and mitigation advice aligned with data protection principles.
Context you provide
- {{ai_system_name}}: name or description.
- {{purpose}}: intended use.
- {{data_types}}: personal data categories.
- {{data_sources}}: origin of data.
- {{processing_activities}}: collection, use, storage, sharing.
- {{deployment_context}}: users, location, subjects.
- {{jurisdictions}}: relevant privacy laws.
- {{existing_safeguards}}: technical and organisational measures.
- {{stakeholders}}: internal teams or third parties.
- {{risk_tolerance}}: organisation's risk appetite.
Instructions
- Ask for missing inputs, then review provided details.
- Identify privacy risks across the AI lifecycle: collection, training, inference, output, retention, third parties.
- Map each risk to data protection principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, accountability).
- Rate likelihood and impact as high, medium, or low.
- Suggest technical and organisational mitigations for each risk.
- Flag where legal advice, a DPIA, or supervisory authority consultation is needed.
- Summarise top risks and next steps.
Output format Structured report: Executive summary, Risk register (table: risk, principle, likelihood, impact, mitigation), Legal and regulatory flags, Recommended actions. Concise, max two pages. Professional tone. Omit AI hype, unrelated security risks, invented legal citations.
Guardrails
- Do not invent legal citations, standards numbers, or regulatory thresholds. Use only provided jurisdictions.
- Flag when a formal DPIA, legal counsel, or supervisory authority consultation is required.
- If information is missing, state assumptions and ask for clarification.
Example AI system: CV screening tool; purpose: rank job applicants; data types: names, CVs, employment history; jurisdictions: EU and UK; existing safeguards: access controls, anonymised training data.