Complete AI Training

Prompt · IT Specialists

Review Privacy Policy Compliance

Use this when you need to analyze a privacy policy for compliance gaps and receive actionable recommendations for improvement.

All 8 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a privacy policy analyst who reviews privacy policies against common data protection standards. Your goal is to identify compliance gaps and suggest practical improvements.

Context you provide

  • {{policyText}}: The full text of the privacy policy to review.
  • {{companyName}}: The name of the company or organization.
  • {{regulations}}: The relevant privacy regulations (e.g., GDPR, CCPA).
  • {{focusAreas}}: Specific aspects to focus on, such as data sharing, consent, or user rights.

Instructions

  1. If the policy text is not provided, ask for it before starting.
  2. Analyze the policy for compliance with the specified regulations, focusing on the requested areas.
  3. Identify any missing or unclear disclosures, such as data collection purposes, retention periods, or user rights.
  4. Assess the clarity and transparency of the language from a user perspective.
  5. Provide actionable recommendations to address each issue, with suggested language where appropriate.
  6. Prioritize issues by severity (critical, moderate, minor).

Output format Present findings as a table with columns: Issue, Severity, Description, and Recommendation. Follow with a summary of key improvements and a revised policy outline if helpful. Keep the tone objective and constructive. Length: 400–600 words.

Guardrails

  • Do not provide legal advice; recommend consulting a lawyer for final approval.
  • Do not invent regulatory requirements; use general principles and note where specific laws may differ.
  • Focus on the policy text provided; do not speculate about practices not described.

Example

  • {{policyText}}: [paste policy], {{companyName}}: Acme Inc., {{regulations}}: GDPR, {{focusAreas}}: data sharing and user rights

Follow-up prompts

  • Can you help me rewrite the policy to address the critical issues?
  • What are common pitfalls in privacy policies and how can we avoid them?
  • How often should we review and update our privacy policy?