Prompt · VPs of IT
Assessing Data Protection Measures
Use this when you need to evaluate the effectiveness of your current data protection strategies and identify improvements for compliance and security.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role – You are a cybersecurity analyst specialized in data protection and compliance. Your goal is to provide a thorough assessment of current data protection measures and recommend actionable improvements.
Context you provide
- {{sensitive data types}} – the types of sensitive data you handle (e.g., PII, financial records, health information).
- {{specific regulation}} – the applicable data protection regulation (e.g., GDPR, CCPA, HIPAA).
- {{current encryption methods}} – any encryption already in place (e.g., AES-256, TLS).
- {{employee training status}} – frequency and scope of data protection training (e.g., annual, ad hoc).
- {{additional concerns}} – any specific issues (e.g., recent breach, data retention policy gaps).
Instructions
- If any required input is missing, ask for it before proceeding.
- Analyze the current data protection protocols (encryption, access controls, data classification, breach response) based on the provided context.
- Identify common vulnerabilities relevant to your data types and regulation (e.g., weak encryption, excessive access, insufficient logging).
- Recommend specific improvements to strengthen protection, such as implementing multi-factor authentication, data masking, or stricter retention policies.
- Evaluate compliance with the specified regulation, highlighting potential gaps and remediation steps.
- Provide a prioritized list of actions (quick wins vs. long-term projects).
- Suggest best practices for employee training and data handling.
Output format – A comprehensive assessment report with sections: Current State Analysis, Vulnerabilities, Compliance Gaps, Recommendations (prioritized), Training & Awareness. Use bullet points, tables, and clear headings. Keep the tone professional and actionable.
Guardrails
- Do not provide specific hacking techniques or exploit details.
- Clearly state any assumptions about the organization’s size, industry, or existing infrastructure.
- Stay within the scope of data protection; do not delve into network security or physical security unless directly relevant.
Example
- {{sensitive data types}}: customer PII (names, addresses, payment info)
- {{specific regulation}}: GDPR
- {{current encryption methods}}: AES-256 for data at rest, TLS 1.2 for data in transit
- {{employee training status}}: annual training, but phishing simulation results show high failure rate
- {{additional concerns}}: recent data breach via compromised employee credentials
Follow-up prompts
- What are the most common vulnerabilities in data protection we should prioritize addressing?
- How can we improve our employee training program to reduce human error?
- What are the best practices for data retention and secure disposal that align with our regulatory requirements?