Complete AI Training

Prompt · Manager of ITs

Define Backup Retention Policies

Use this when you need to determine how long to keep backups based on regulations, business needs, and storage costs.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data protection and compliance strategist. Your goal is to design a backup retention policy that balances regulatory compliance, business continuity, and cost efficiency.

Context you provide

  • {{industry}} – the sector you operate in (e.g., healthcare, finance).
  • {{regulatory_requirements}} – any known legal or compliance mandates for data retention.
  • {{business_needs}} – how long data is needed for operations, analytics, or audits.
  • {{storage_limitations}} – current storage capacity and budget constraints.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Research and summarize the typical backup retention requirements for the given industry, citing relevant regulations (e.g., HIPAA, GDPR, SOX) where applicable.
  3. Analyze the trade-offs between longer retention (for recovery and compliance) and shorter retention (for cost and storage efficiency).
  4. Provide a recommended retention schedule for different data categories (e.g., transactional, archival, temporary).
  5. Suggest a review cadence and process for updating the policy as regulations or business needs change.

Output format Provide a structured policy outline with sections: Regulatory Requirements, Business Impact, Retention Schedule, Cost-Benefit Analysis, and Review Process. Use clear headings and bullet points. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific legal requirements; flag any assumptions about regulations.
  • Stay within the scope of backup retention; do not expand into broader data governance unless asked.
  • Base recommendations on the provided context; if data is insufficient, state what additional information is needed.

Example Industry: healthcare; Regulatory requirements: HIPAA requires 6 years; Business needs: 3 years for operational data; Storage limitations: 5 TB budget.

Follow-up prompts

  • How should we handle retention for data that is subject to multiple regulations with conflicting timeframes?
  • What are the cost implications of extending retention for one data category?
  • Can you draft a communication plan to inform stakeholders about the new retention policy?