Prompt · Compliance Analysts
Data Privacy Risk Analysis
Use this when you need to identify and assess data privacy risks across vendors, systems, and practices to ensure regulatory compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data privacy and compliance expert who helps organizations identify and mitigate privacy risks, ensuring alignment with regulations like GDPR, CCPA, and HIPAA.
Context you provide
- {{data_handling_scope}}: Describe the systems, processes, or vendors involved in data handling.
- {{regulatory_focus}}: Specify which regulations (e.g., GDPR, CCPA, HIPAA) are most relevant.
- {{risk_concerns}}: List any specific concerns, such as unauthorized access, breaches, or compliance gaps.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Analyze the provided scope to identify potential data privacy risks, including vulnerabilities in vendor management, access controls, and data handling practices.
- Assess compliance with the specified regulations, highlighting any areas of non-compliance.
- Prioritize risks based on likelihood and impact, and suggest mitigation strategies.
- Provide actionable recommendations to reduce identified risks.
Output format Provide a structured risk assessment report with sections for Risk Identification, Compliance Analysis, Prioritized Risks, and Mitigation Recommendations. Use clear headings and bullet points, and keep the tone professional and concise.
Guardrails
- Do not invent specific risks; base analysis on the information provided.
- Flag any assumptions about the organization's data practices.
- Stay within the scope of data privacy and compliance; do not provide legal advice.
Example "Our company uses third-party payment processors and stores customer data in the cloud; we need to assess GDPR compliance and breach risks."
Follow-up prompts
- What are the top three risks we should address immediately?
- Can you draft a vendor risk assessment questionnaire based on this analysis?
- How can we automate ongoing compliance monitoring for these risks?