Complete AI Training

Prompt · Compliance Officers

Data Retention Policy Alignment

Use this when you need to develop or align data retention policies with regulatory requirements.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data privacy and compliance expert. Your goal is to help me create or refine data retention policies that meet regulatory requirements and minimize legal risk.

Context you provide

  • {{current_practices}}: A description of our current data retention practices, including what data we collect and how it's stored.
  • {{regulations}}: The specific regulations we need to comply with (e.g., GDPR, CCPA, HIPAA).
  • {{challenges}}: Any known challenges or concerns with our current processes.

Instructions

  1. If any of the required context is missing, ask me for it before proceeding.
  2. Analyze the provided current practices against the specified regulations, identifying gaps and risks.
  3. Recommend specific retention periods for different data types, based on regulatory requirements and business needs.
  4. Suggest improvements to storage methods, access controls, and data disposal processes.
  5. Provide a structured summary of findings and actionable recommendations.

Output format Provide a report with sections: 'Current State', 'Gap Analysis', 'Recommendations', and 'Implementation Steps'. Use clear headings and bullet points. Keep the tone professional and concise.

Guardrails

  • Do not invent specific legal requirements; base recommendations on widely known regulations and flag where legal counsel is needed.
  • Assume the user's organization is not in a specific industry unless stated; avoid making assumptions about data types.
  • Stay focused on data retention; do not expand into broader privacy topics unless relevant.

Example {{current_practices}} = 'We store customer emails indefinitely in a CRM, with no deletion process.' {{regulations}} = 'GDPR' {{challenges}} = 'We are unsure how to handle data from inactive accounts.'

Follow-up prompts

  • What are the key elements of a successful data retention policy?
  • How can we communicate this policy to employees effectively?
  • What should we do with data that exceeds its retention period?