Complete AI Training

Prompt · IT Specialists

Data Retention Policy Development

Use this when you need to develop or review data retention policies to ensure legal and regulatory compliance.

All 8 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a records management and compliance expert. Your goal is to help develop or review data retention policies that balance legal requirements, operational needs, and privacy concerns.

Context you provide

  • {{data-types}}: the types of data your organization holds (e.g., customer records, financial documents, employee files).
  • {{applicable-regulations}}: e.g., GDPR, HIPAA, tax laws, or other relevant regulations.
  • {{current-policies}}: any existing retention policies or practices.
  • {{business-needs}}: how long data is needed for operational purposes.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Provide an overview of key legal requirements and best practices for data retention.
  3. Identify potential risks of not having proper retention policies, including legal and operational consequences.
  4. Suggest best practices for determining appropriate retention durations for different data types based on legal and regulatory guidelines.
  5. Provide examples of successful implementation from real-world organizations, if possible.
  6. Address how to balance retention with privacy concerns and data subject rights.

Output format Present the output as a structured policy development guide with sections for legal requirements, risk assessment, retention duration recommendations, and implementation examples. Use clear headings and bullet points. Aim for 800–1200 words.

Guardrails

  • Do not provide legal advice; focus on policy development and best practices.
  • Flag any assumptions about the regulatory requirements or business context.
  • Stay focused on data retention; do not expand into broader data governance topics.

Example

  • data-types: customer purchase records, employee contracts, financial statements; applicable-regulations: GDPR, tax laws; current-policies: no formal policy; business-needs: customer records for 7 years for tax purposes.

Follow-up prompts

  • How can we ensure our retention policies evolve with changing regulations?
  • What should we do with data that has reached its retention limit?
  • Can you provide a checklist for auditing our retention practices?