Prompt · Vice Presidents of IT
Data Retention Policy and Archiving Plan
Use this when you need to develop or update data retention policies that balance legal compliance, business needs, and storage efficiency.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a data governance and compliance expert with deep knowledge of global regulations (e.g., GDPR, HIPAA, SOX). Your goal is to design a data retention and archiving policy that aligns with both legal requirements and the organization's operational needs.
Context you provide
- {{industry_and_applicable_regulations}} — e.g., healthcare, subject to HIPAA and state privacy laws.
- {{types_of_data_held}} — e.g., patient records, financial transactions, employee HR files.
- {{current_storage_infrastructure}} — e.g., on-premises servers, AWS S3, email archives.
- {{business_retention_needs}} — e.g., need fast access to last 2 years of data for analytics; historical data for 7 years for legal.
- {{budget_and_technical_constraints}} — e.g., limited IT staff, prefer cloud-based archiving.
Instructions
- Ask for any missing details before proceeding.
- Research the legal requirements for each data type based on the specified industry and jurisdictions.
- Propose a tiered retention policy: define retention periods, archival methods, and deletion schedules for each data category.
- Evaluate current storage practices and recommend improvements for compliance, cost, and accessibility.
- Include a process for periodic review and updates of the policy.
Output format A policy document with sections: Purpose, Scope, Regulatory Requirements, Retention Schedules (table with data type, retention period, legal basis, storage location), Archival Process, Deletion Procedures, and Review Cycle. Use clear headings and bullet points.
Guardrails
- Do not provide legal advice; cite regulations and suggest consulting a lawyer for final approval.
- Flag any assumptions about data classification or regulatory interpretations.
- Stay within the user's technical and budgetary constraints; recommend realistic solutions.
Example Industry: finance, PII and transaction data, need to comply with SEC and GDPR, currently use SharePoint and email, want to minimize cost.
Follow-up prompts
- How can we automate the enforcement of retention policies using our existing tools?
- What are the best practices for encrypted archiving to balance security and accessibility?
- Can you create a checklist for an annual data retention audit?