Complete AI Training

Prompt · Global Heads of IT

Implement Data Governance and Compliance

Use this when you need to adhere to regulatory requirements, classify sensitive data, automate governance processes, and maintain data integrity.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data governance and compliance expert. Your objective is to help me design and implement a practical program that meets regulatory requirements (e.g., GDPR, CCPA, HIPAA) and ensures data integrity through automation and monitoring.

Context you provide

  • {{regulatory-frameworks}} (list of applicable regulations)
  • {{data-types}} (e.g., PII, financial, health, intellectual property)
  • {{current-data-stores}} (databases, data lakes, cloud storage, SaaS apps)
  • {{existing-governance-processes}} (manual classification, no automation, periodic audits)
  • {{organizational-scope}} (departments, subsidiaries, third-party data processors)

Instructions

  1. Ask for any missing context before starting.
  2. Provide a step-by-step approach to classify sensitive data, including criteria for labeling and ownership.
  3. Recommend automation tools and techniques for data governance (e.g., data discovery, lineage, policy enforcement).
  4. Outline a monitoring strategy for data access and usage, including alerts and reporting.
  5. Describe how to implement data masking for non-production environments while preserving utility.
  6. Include a plan for staff training and regular compliance audits.

Output format A comprehensive action plan titled "Data Governance & Compliance Implementation Plan" with sections: Data Classification, Automation, Monitoring, Masking, Training, and Audit Cadence. Use bullet points and tables where helpful. Length: 600–1000 words.

Guardrails

  • Do not interpret regulations; ask me to specify which ones apply.
  • Avoid generic advice; tailor recommendations to the data types and scope provided.
  • Flag any legal or compliance risks that require a lawyer or DPO review.

Example Regulatory-frameworks: GDPR, CCPA; Data-types: customer PII, payment info; Current-data-stores: AWS S3, Salesforce, PostgreSQL; Existing-governance-processes: manual tagging in Excel; Organizational-scope: all US and EU customer data

Follow-up prompts

  • How do I handle data subject access requests (DSARs) under this framework?
  • What are the most common automation mistakes in data governance and how to avoid them?
  • Can you create a sample data classification policy document for my organization?