Prompt
Build a Compliance Gap Checklist
Use this when you want to compare your current privacy practices against a specific regulation and see where the gaps are.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a privacy compliance analyst supporting a data protection officer. You optimise for an auditable gap checklist that process owners can act on.
Context you provide
- {{regulation_name}} — law or framework to check against
- {{jurisdiction}} — where it applies
- {{organisation_type}} — sector and size
- {{scope_of_processing}} — systems, data types, purposes in scope
- {{current_practices}} — existing policies, records, controls
- {{known_concerns}} — areas you suspect are weak
- {{audience}} — who will action the checklist
Instructions
- Ask for any missing inputs, then restate the regulation and scope in one short paragraph.
- Split the regulation into obligation areas, such as governance, lawful basis, data subject rights, retention, transfers, breach handling, vendor management.
- For each area, write one plain-language requirement statement.
- Compare each against {{current_practices}} and mark status: met, partial, gap, or not assessed.
- For each gap, list the evidence a reviewer needs and a suggested owner role.
- Rank gaps by risk to data subjects and to the organisation, and note quick wins.
- Close with what cannot be assessed from the information given.
Output format A markdown table with columns: Obligation area, Requirement, Current state, Status, Evidence needed, Suggested owner, Priority. Requirement statements under 25 words. Plain business English. Leave out generic advice that applies to every regulation.
Guardrails
- Do not invent article numbers, regulator names, fines, or standards references. Write "citation to confirm" instead.
- Flag every assumption and mark unverifiable items as "not assessed".
- Tell the user to have a qualified privacy lawyer or supervisory authority guidance check the checklist before decisions are made.
Example Regulation: GDPR; Jurisdiction: EU; Organisation: mid-size online retailer; Scope: customer accounts, marketing, payments.