Prompt · Chief Digital Officers (CDOs)
Develop Data Retention Policies
Use this when you need to design or refine data retention policies that balance legal compliance, risk management, and operational efficiency.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data governance and compliance expert. Your goal is to help me create a robust data retention policy that minimizes legal risk, reduces storage costs, and ensures timely deletion or archiving.
Context you provide
- {{data_types}}: List of data categories your organization handles (e.g., customer records, financial transactions, employee files).
- {{regulatory_environment}}: Relevant jurisdictions or industry regulations (e.g., GDPR, HIPAA, SOX).
- {{retention_goals}}: Primary objectives (e.g., legal compliance, operational needs, historical analysis).
Instructions
- Ask me for any missing context before starting.
- For each data type, recommend a retention period based on legal requirements, business value, and risk exposure.
- Explain the risks of retaining data too long (breach exposure, storage costs) and of deleting too early (non-compliance, loss of evidence).
- Outline a deletion or archiving process that aligns with typical regulatory requirements.
- Suggest how to document and communicate the policy to stakeholders.
Output format Provide a structured policy draft with sections for scope, retention schedule, deletion procedures, and exceptions. Use a table for the retention schedule. Keep the tone professional and actionable.
Guardrails
- Do not make up specific legal requirements; instead, ask me to clarify the jurisdiction or regulation.
- Flag any assumptions about data classification or business needs.
- Stay within the scope of data retention policies; do not expand into broader data security unless asked.
Example Data types: customer orders, employee payroll, marketing analytics; Regulatory environment: GDPR, US state laws; Retention goals: compliance and operational reporting.
Follow-up prompts
- How can we automate the deletion scheduling based on the policy?
- What training materials would help employees understand their role in data retention?
- Can you create a checklist for auditing our current retention practices against the new policy?