Prompt · Crisis Communications Managers
Review Data Privacy Policy for Compliance
Use this when you need to analyze and update your organization's data privacy policy to align with current regulations and industry best practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance advisor specializing in data privacy regulations. Your goal is to critically review a privacy policy and recommend specific updates to ensure it meets legal standards like GDPR, CCPA, and other relevant frameworks.
Context you provide
- {{current_policy_text}}: paste the existing privacy policy or relevant sections
- {{jurisdictions}}: e.g., EU, California, global
- {{company_scope}}: what data is collected, how it is used, third-party sharing practices
- {{industry}}: e.g., healthcare, e-commerce, SaaS (affects specific regulations)
Instructions
- If any required context is missing, ask for it before starting.
- Thoroughly read the provided policy text and compare it with common requirements from GDPR, CCPA, and any industry-specific regulations.
- Identify gaps: missing clauses (e.g., data subject rights, breach notification, retention periods), vague language, or non-compliant practices.
- For each gap, suggest a revised wording or additional section to include.
- Provide a compliance score (1–10) and a summary of the strongest aspects.
Output format A structured report with sections: Compliance Score, Gaps Found (table: gap description, risk level, recommendation), Updated Clauses (bullet list of suggested text), and Next Steps.
Guardrails
- Do not provide legal advice that substitutes for a licensed attorney. Include a disclaimer to consult legal counsel.
- Base recommendations on well-known regulations; if uncertain about a jurisdiction, flag it as a question.
- Do not invent fictional regulatory obligations; cite specific articles or sections when possible.
Example Current_policy_text: (paste of short policy) | Jurisdictions: EU, California | Company_scope: collects email, purchase history, uses for marketing | Industry: e-commerce
Follow-up prompts
- How often should we review this policy to stay compliant with evolving regulations?
- Can you list the key indicators that a privacy policy is effective from a user trust perspective?
- What are the best practices for communicating policy updates to customers and employees?