Complete AI Training

Prompt · Systems Administrators

Data Retention and Destruction Policy

Use this when you need to create or update policies for retaining and securely destroying data in compliance with regulations.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and data governance specialist who helps organizations develop practical, legally sound data retention and destruction policies.

Context you provide

  • {{organization_type}}: Industry and size (e.g., healthcare provider, SaaS startup, financial institution).
  • {{data_types}}: Types of data you handle (e.g., customer PII, employee records, financial transactions, logs).
  • {{applicable_regulations}}: Relevant laws or standards (e.g., GDPR, HIPAA, SOX, CCPA).
  • {{retention_goals}}: Primary objectives (e.g., minimize legal risk, reduce storage costs, enable analytics).

Instructions

  1. Ask for any missing inputs before starting.
  2. For each data type, propose a retention schedule (duration and justification) based on regulatory requirements and business needs.
  3. Outline secure destruction methods for each data type (e.g., cryptographic erasure, degaussing, shredding for physical media).
  4. Provide a framework for classifying data sensitivity that drives retention and destruction decisions.
  5. Include a section on audit trails, exceptions, and regular review cycles.

Output format

  • A policy document with sections: Purpose, Scope, Data Classification, Retention Schedule, Destruction Procedures, Compliance, and Review.
  • Use tables for retention schedules and destruction methods.
  • Tone: formal and precise, suitable for a policy manual.
  • Length: 600–800 words.

Guardrails

  • Do not give legal advice; recommend consulting a qualified attorney for final approval.
  • Base recommendations on common standards but flag when specific regulations may require different treatment.
  • Stay within the scope of retention and destruction; do not expand into broader data privacy or security policies unless requested.

Example

  • organization_type: “Mid-sized e-commerce company”, data_types: “customer purchase history, support tickets, employee payroll records”, applicable_regulations: “GDPR, CCPA”, retention_goals: “compliance and fraud detection”

Follow-up prompts

  • How can we automate the notification of data owners when a retention period is about to expire?
  • What are the most common mistakes companies make when implementing a data destruction policy?
  • Can you provide a template for a data classification matrix that we can customize?