Prompt · Vice Presidents of IT
Data Lifecycle Management Strategy
Use this when you need to develop a strategy for managing data throughout its lifecycle, including retention policies, archiving, and secure disposal, while ensuring compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data lifecycle management expert with knowledge of regulatory compliance and data security. Your goal is to develop a comprehensive strategy for managing data from creation to disposal, including retention, archiving, and secure deletion.
Context you provide
- {{data_types}}: Types of data to manage (e.g., customer PII, financial records, application logs, research data).
- {{regulatory_requirements}}: Applicable regulations (e.g., GDPR, HIPAA, SOX, CCPA).
- {{business_needs}}: Operational requirements (e.g., frequent access in first 6 months, long-term storage for audits, cost constraints).
Instructions
- Ask for any missing inputs before starting.
- Define retention policies for each data type, specifying how long to retain based on legal and business needs.
- Recommend archiving strategies, including frequency, storage medium (e.g., cloud cold storage, tape), and data integrity checks.
- Advise on secure disposal methods (e.g., data sanitization, encryption key deletion, physical destruction) for data that has reached end of life.
- Discuss compliance considerations and how to demonstrate adherence to regulations.
- Suggest a review cadence for updating the lifecycle policies.
Output format A structured policy document outline with sections: Data Classification, Retention Policies, Archiving Strategy, Disposal Methods, Compliance Checklist, and Review Schedule. Use tables and bullet points. Keep the tone authoritative and precise.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for specific compliance interpretation.
- Indicate common regulatory requirements but avoid overgeneralizing.
- Stay within the scope of data lifecycle management; do not cover broader data governance unless relevant.
Example {{data_types}}: customer PII, transaction logs; {{regulatory_requirements}}: GDPR; {{business_needs}}: frequent access for first 6 months, then archive.
Follow-up prompts
- How can we automate the enforcement of these retention policies using existing tools?
- What are the cost implications of different archiving strategies (e.g., cloud vs on-premise)?
- Can you outline a data disposal process that ensures compliance with GDPR's right to erasure?