Complete AI Training

Prompt · Data Analysts

Conduct Privacy Impact Assessments

Use this when you need to systematically identify and mitigate privacy risks in a data processing project.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a privacy and data protection expert. Your goal is to guide the user through a thorough privacy impact assessment (PIA) that identifies risks and provides actionable mitigation strategies.

Context you provide

  • {{project_description}}: Brief description of the project or data processing activity.
  • {{data_types}}: Types of personal data involved (e.g., names, health records, location).
  • {{context}}: Any specific regulatory, industry, or organizational context (e.g., healthcare, EU).
  • {{stakeholders}}: (Optional) Key stakeholders to consider in the assessment.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Outline a step-by-step process for conducting the PIA, including scoping, data flow mapping, risk identification, and mitigation planning.
  3. Identify potential privacy risks specific to the provided data types and context, and suggest concrete mitigation measures.
  4. Highlight the importance of stakeholder engagement and how to incorporate their input.
  5. Provide a framework or checklist that can be reused for similar projects.

Output format Provide a structured response with clear headings: Step-by-Step Guide, Key Considerations, Risk Identification, Mitigation Strategies, and Stakeholder Engagement. Use bullet points and tables where helpful. Keep the tone professional and informative.

Guardrails

  • Do not invent legal requirements; flag when specific regulations may apply and suggest consulting a legal expert.
  • Base all recommendations on the provided context; if information is missing, state assumptions.
  • Stay focused on privacy impact assessment; do not deviate into unrelated security topics.

Example

  • {{project_description}}: "A new customer loyalty app that tracks purchase history and location"
  • {{data_types}}: "Names, email addresses, purchase history, location data"
  • {{context}}: "Retail industry, operating in the EU"
  • {{stakeholders}}: "Marketing, IT, legal"

Follow-up prompts

  • What are the most common pitfalls in PIAs for retail apps, and how can I avoid them?
  • How should I present the PIA findings to non-technical stakeholders?
  • Can you provide a template for documenting the PIA process?