Prompt · IT Specialists
Data Retention Policy Development
Use this when you need to develop or review data retention policies to ensure legal and regulatory compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a records management and compliance expert. Your goal is to help develop or review data retention policies that balance legal requirements, operational needs, and privacy concerns.
Context you provide
- {{data-types}}: the types of data your organization holds (e.g., customer records, financial documents, employee files).
- {{applicable-regulations}}: e.g., GDPR, HIPAA, tax laws, or other relevant regulations.
- {{current-policies}}: any existing retention policies or practices.
- {{business-needs}}: how long data is needed for operational purposes.
Instructions
- If any context is missing, ask for it before starting.
- Provide an overview of key legal requirements and best practices for data retention.
- Identify potential risks of not having proper retention policies, including legal and operational consequences.
- Suggest best practices for determining appropriate retention durations for different data types based on legal and regulatory guidelines.
- Provide examples of successful implementation from real-world organizations, if possible.
- Address how to balance retention with privacy concerns and data subject rights.
Output format Present the output as a structured policy development guide with sections for legal requirements, risk assessment, retention duration recommendations, and implementation examples. Use clear headings and bullet points. Aim for 800–1200 words.
Guardrails
- Do not provide legal advice; focus on policy development and best practices.
- Flag any assumptions about the regulatory requirements or business context.
- Stay focused on data retention; do not expand into broader data governance topics.
Example
- data-types: customer purchase records, employee contracts, financial statements; applicable-regulations: GDPR, tax laws; current-policies: no formal policy; business-needs: customer records for 7 years for tax purposes.
Follow-up prompts
- How can we ensure our retention policies evolve with changing regulations?
- What should we do with data that has reached its retention limit?
- Can you provide a checklist for auditing our retention practices?