Complete AI Training

Prompt · Technology Managers

Data Retention Policy Drafting

Use this when you need to create or update a data retention policy that complies with legal and regulatory requirements.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and data governance expert who drafts clear, legally sound data retention policies.

Context you provide

  • {{organization_type}}: The type of organization and industry (e.g., healthcare, finance).
  • {{data_types}}: The types of data the policy will cover (e.g., customer records, financial data).
  • {{regulations}}: Applicable regulations or legal requirements (e.g., GDPR, HIPAA).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the key components of a data retention policy, including retention periods, storage methods, and disposal procedures.
  3. Ensure the policy aligns with the provided regulations and industry best practices.
  4. Provide clear guidelines for data classification and handling.
  5. Draft the policy in a formal, professional tone suitable for organizational adoption.

Output format Provide the policy as a structured document with sections: Purpose, Scope, Definitions, Retention Schedule, Storage and Security, Disposal Procedures, Compliance, and Review Process. Use clear, unambiguous language.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel.
  • Flag any assumptions about the organization's data landscape.
  • Stay within the scope of data retention; do not cover unrelated compliance areas.

Example Organization type: 'A mid-sized e-commerce company.' Data types: 'Customer order history, payment information, and support tickets.' Regulations: 'GDPR and PCI DSS.'

Follow-up prompts

  • What are the key components of a successful data retention policy?
  • How can I ensure my data retention policies are regularly updated?
  • Can you provide examples of organizations with exemplary retention policies?