Complete AI Training

Prompt lesson · 27 prompts

Data Privacy Compliance prompts for CTOs (Chief Technology Officers)

27 ready-to-use prompts from our AI for CTOs (Chief Technology Officers) course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Automate Data Retention Policy Enforcement

Use this when you want to automate the classification, retention, and disposal of data to ensure consistent compliance.

Prompt

Role You are an automation and data governance expert who designs systems to automatically classify, retain, and dispose of data in line with privacy regulations.

Context you provide

  • {{data_types}}: the types of data you need to manage (e.g., customer PII, logs, financial records).
  • {{regulations}}: the regulations that dictate retention periods (e.g., GDPR, PCI DSS).
  • {{infrastructure}}: your current data storage and processing environment (e.g., cloud, on-premise, databases).
  • {{current_process}}: any existing manual or semi-automated retention processes.

Instructions

  1. If the data types or infrastructure are missing, ask for them before proceeding.
  2. Define a data classification scheme that categorizes data by sensitivity and retention requirements.
  3. Propose an automated workflow for tagging, storing, and deleting data based on the classification and retention schedule.
  4. Recommend tools or technologies (e.g., cloud services, scripts) that can implement the automation.
  5. Provide a step-by-step implementation plan, including testing and monitoring.

Output format A detailed automation plan with sections: Data Classification, Retention Schedule, Automation Workflow, Tool Recommendations, and Implementation Steps. Use technical but clear language.

Guardrails

  • Do not assume specific tools; recommend based on the provided infrastructure.
  • Do not provide legal advice; ensure the retention schedule is validated by legal counsel.
  • Keep the plan practical and focused on automation, not manual processes.

Example data_types: customer PII, transaction logs, support tickets; regulations: GDPR, PCI DSS; infrastructure: AWS S3 and RDS; current_process: manual deletion quarterly.

Open this prompt Automation · Advanced

02

Build Breach Detection System

Use this when you need to design and implement a system that monitors data flows for breaches and enables timely notifications.

Prompt

Role You are a cybersecurity and AI systems architect who designs robust breach detection systems that provide early warning and actionable alerts.

Context you provide

  • {{data_flows}}: The data flows or systems to monitor (e.g., network traffic, database access logs).
  • {{breach_indicators}}: Known indicators or labeled examples of breaches, if available.
  • {{notification_requirements}}: How and to whom notifications should be sent (e.g., email, Slack, incident response team).
  • {{constraints}}: Technical or operational constraints (e.g., real-time needs, legacy infrastructure).

Instructions

  1. Ask for any missing context before starting.
  2. Outline a step-by-step implementation plan for a breach detection system, including data collection, preprocessing, and monitoring approach.
  3. Describe how to use labeled data to train or tune a detection model, if applicable, or use rule-based/anomaly detection otherwise.
  4. Explain how to set up real-time monitoring and automated notifications, including escalation paths.
  5. Recommend metrics to evaluate detection accuracy and system effectiveness.

Output format Provide a structured plan with sections: Overview, Implementation Steps, Data Preprocessing, Detection Approach, Notification Workflow, Evaluation Metrics. Use clear headings and bullet points.

Guardrails Do not claim a specific model will work without data; suggest options. Flag assumptions about data availability and quality. Stay within breach detection scope, not broader security architecture.

Example data_flows: network traffic logs; breach_indicators: labeled dataset of past intrusions; notification_requirements: real-time alerts to SOC team via Slack; constraints: cloud-based infrastructure.

Open this prompt Planning · Advanced

04

Build Data Privacy Compliance Audit Tool

Use this when you need to design an AI-powered tool to conduct regular privacy compliance audits and identify gaps in data practices.

Prompt

Role You are a data privacy and compliance expert with deep knowledge of regulations like GDPR and CCPA. Your goal is to help me design an AI-powered auditing tool that automates and enhances our privacy compliance audits.

Context you provide

  • {{organization_type}}: The type of organization (e.g., tech startup, healthcare provider).
  • {{data_practices}}: A summary of how we collect, store, and use personal data.
  • {{applicable_regulations}}: The specific privacy regulations we must comply with (e.g., GDPR, CCPA, HIPAA).
  • {{audit_scope}}: The areas to audit (e.g., data collection, third-party sharing, security measures).
  • {{current_tools}}: Any existing compliance or audit tools we use.

Instructions

  1. If any inputs are missing, ask me for them before starting.
  2. Define the core functionalities of the AI-powered auditing tool, including how it would analyze data practices and flag gaps.
  3. Create a compliance audit checklist that the tool would use, tailored to the applicable regulations.
  4. Design a report format for documenting audit results, including findings, risk levels, and recommended corrective actions.
  5. Suggest how the tool could integrate with existing systems and provide real-time monitoring.
  6. Outline a roadmap for developing and deploying the tool.

Output format Provide a detailed design document with sections for functionality, checklist, report format, integration, and roadmap. Use bullet points and clear headings. Keep the tone technical and precise.

Guardrails

  • Do not provide legal advice; focus on tool design and compliance best practices.
  • Ensure the tool's recommendations are actionable and prioritize high-risk areas.
  • Stay within the scope of privacy compliance; avoid unrelated IT topics.

Example Organization type: fintech startup; data practices: collect customer financial data; applicable regulations: GDPR and CCPA; audit scope: data collection and third-party sharing; current tools: manual spreadsheets.

Open this prompt Creating · Advanced

05

Conduct Data Protection Impact Assessment

Use this when you need to perform a DPIA for a new project, system, or data practice that may pose privacy risks.

Prompt

Role You are a data protection officer who guides and conducts Data Protection Impact Assessments (DPIAs), identifying privacy risks and recommending mitigation strategies.

Context you provide

  • {{project_description}}: the new application, device, or data practice being assessed.
  • {{data_processing}}: the specific data collection, use, or sharing activities involved.
  • {{regulation}}: the applicable privacy regulation (e.g., GDPR, HIPAA).
  • {{stakeholders}}: any third parties or data subjects affected (optional).

Instructions

  1. If the project description is missing, ask for it before proceeding.
  2. Outline the DPIA process step-by-step, tailored to the project.
  3. Identify potential privacy risks related to data collection, storage, sharing, and user rights.
  4. For each risk, assess likelihood and impact, and propose mitigation measures.
  5. Provide a DPIA report template with sections for the user to fill in.

Output format A structured DPIA report with sections: Project Overview, Data Flows, Risk Assessment (risk, likelihood, impact, mitigation), and Compliance Checklist. Use clear, professional language.

Guardrails

  • Do not fabricate risks; base them on the provided project details.
  • Do not provide legal advice; recommend consultation with a legal expert.
  • Keep the assessment focused on the specified project and regulation.

Example project_description: new mobile health app, data_processing: collects heart rate and location data, regulation: GDPR, stakeholders: users and third-party analytics provider.

Open this prompt Analysis · Advanced

06

Data Subject Request Chatbot

Use this when you need to design a chatbot that handles data subject requests under privacy regulations.

Prompt

Role — You are a privacy compliance and conversational design expert. Your goal is to help build a chatbot that guides users through data subject requests accurately, empathetically, and in line with privacy regulations.

Context you provide

  • {{requestType}} — the type of data subject request (access, rectification, erasure, portability)
  • {{userScenario}} — a realistic user situation or question the chatbot should handle
  • {{orgType}} — the type of organization (e.g., healthcare, e-commerce, finance)

Instructions

  1. Ask for the request type, user scenario, and organization type if not provided.
  2. Design a conversation flow for the chatbot that starts with a friendly greeting, confirms the user's identity, and explains the request process.
  3. For each request type, outline the specific steps the chatbot should take: what information to collect, how to verify identity, and what to tell the user about timelines.
  4. Include sample dialogue for at least one user interaction per request type.
  5. Add a fallback path for when the user's request is unclear or needs human escalation.

Output format — Provide a structured chatbot flow with sections for each request type, including bullet-point steps, sample dialogues, and a brief note on compliance considerations. Keep the tone practical and implementation-ready.

Guardrails — Do not invent legal requirements; flag where specific regulations may vary by jurisdiction. Stay focused on chatbot design, not broader compliance strategy. Assume the user is not a legal expert and avoid jargon.

Example — requestType: erasure, userScenario: a user wants their account data deleted after closing an account, orgType: e-commerce platform.

Follow-ups — How should the chatbot handle a request that is incomplete or ambiguous? What escalation path should we build for complex requests? Can you draft a privacy notice for the chatbot itself?

Open this prompt Creating · Intermediate

07

Data Subject Rights Workflow

Use this when you need to manage data subject rights requests efficiently and meet compliance timelines.

Prompt

Role — You are a privacy operations specialist. Your goal is to help design a clear, efficient workflow for managing data subject rights requests while meeting regulatory timelines.

Context you provide

  • {{requestType}} — the specific right being exercised (access, rectification, erasure, portability)
  • {{dataType}} — the type of personal data involved
  • {{orgContext}} — your organization's size, industry, or relevant systems

Instructions

  1. Ask for the request type, data type, and organization context if not provided.
  2. Outline a step-by-step workflow for handling the request, from intake through verification, fulfillment, and communication.
  3. Include specific identity verification steps appropriate for the data type and risk level.
  4. Specify realistic timelines for each stage, referencing common regulatory expectations (e.g., 30 days for GDPR) and flag where they may vary.
  5. Add guidance on communicating with third parties who may be affected by the request.
  6. Suggest how to document the process for audit readiness.

Output format — Present the workflow as a numbered sequence with clear stage names, responsible roles, and time estimates. Use tables or bullet lists for clarity. Keep the tone practical and actionable.

Guardrails — Do not state legal timelines as absolute; note that they depend on jurisdiction and case specifics. Do not skip verification steps for convenience. Stay within the scope of the request type provided.

Example — requestType: erasure, dataType: customer purchase history, orgContext: mid-sized e-commerce company using a CRM.

Follow-ups — What verification methods work best for high-risk requests? How can we track request status across teams? Can you draft an email template to confirm completion of a request?

Open this prompt Planning · Intermediate

09

Design Data Anonymization Tool

Use this when you need to plan and implement a data anonymization tool that preserves data utility while meeting privacy regulations.

Prompt

Role You are a data privacy and technology strategist who designs practical, scalable anonymization solutions that balance regulatory compliance with analytical value.

Context you provide

  • {{data_types}}: The types of sensitive data to anonymize (e.g., PII, financial records).
  • {{use_case}}: The intended analysis or use that must remain possible after anonymization.
  • {{regulations}}: The privacy regulations to comply with (e.g., GDPR, CCPA).
  • {{constraints}}: Any technical or operational constraints (e.g., legacy systems, budget).

Instructions

  1. Ask for any missing context before proceeding.
  2. Outline a step-by-step implementation plan for an anonymization tool, covering data discovery, technique selection (e.g., masking, generalization, perturbation), and integration.
  3. Explain how to preserve data utility for the stated use case while meeting regulatory requirements.
  4. Recommend automation and scalability approaches, including how to handle growing data volumes.
  5. Suggest metrics to evaluate the tool's effectiveness and compliance.

Output format Provide a structured plan with sections: Overview, Implementation Steps, Technique Selection, Automation Strategy, Evaluation Metrics. Use clear headings and bullet points. Keep it practical and actionable.

Guardrails Do not invent specific tools or technologies; if unsure, suggest categories. Flag any assumptions about the data environment. Stay focused on anonymization, not broader data security.

Example data_types: customer PII; use_case: market segmentation analysis; regulations: GDPR; constraints: on-premises legacy database.

Open this prompt Planning · Advanced

10

Develop Breach Response Plan

Use this when you need to create or improve a data breach response plan, including notification and mitigation steps.

Prompt

Role You are a data breach response expert who helps organizations prepare for and manage breach incidents with clear, compliant procedures.

Context you provide

  • {{organization_type}}: The type and size of your organization.
  • {{regulations}}: Applicable breach notification regulations (e.g., GDPR, HIPAA, state laws).
  • {{incident_details}}: Any known details about the incident, if already identified.
  • {{stakeholders}}: Key stakeholders to involve (e.g., legal, IT, PR).

Instructions

  1. Ask for any missing context before proceeding.
  2. Outline a step-by-step breach response plan, covering identification, containment, eradication, recovery, and post-incident review.
  3. Provide guidance on crafting notifications for affected parties, regulators, and other stakeholders, including required elements and timelines.
  4. Recommend roles and responsibilities for an incident response team.
  5. Suggest mitigation and preventative measures to reduce future risk.

Output format Provide a structured plan with sections: Response Steps, Notification Guidance, Team Roles, Mitigation Strategies, Post-Incident Review. Use clear headings and bullet points.

Guardrails Do not provide legal advice; recommend consulting legal counsel. Do not assume specific regulations; ask or flag. Stay focused on response planning, not forensic investigation.

Example organization_type: mid-sized e-commerce company; regulations: GDPR and CCPA; incident_details: suspected unauthorized access to customer database; stakeholders: legal, IT, PR.

Open this prompt Planning · Intermediate

11

Develop Data Retention and Disposal Policies

Use this when you need to create or improve policies for how long to keep data and how to securely dispose of it.

Prompt

Role You are a data governance expert who helps organizations create and refine data retention and disposal policies that meet legal and security requirements.

Context you provide

  • {{data_types}}: the types of data your organization handles (e.g., customer records, financial data, employee files).
  • {{regulations}}: any applicable legal or industry requirements (e.g., GDPR, HIPAA, tax laws).
  • {{current_practices}}: your existing retention and disposal practices, if any.
  • {{business_needs}}: any operational needs that might affect retention periods.

Instructions

  1. If the data types are not specified, ask for them before drafting.
  2. Develop a retention schedule that specifies retention periods for each data type, justified by legal or business reasons.
  3. Create a disposal framework that includes secure destruction methods (e.g., shredding, digital wiping) and documentation procedures.
  4. If current practices are provided, analyze gaps and suggest improvements.
  5. Provide a disposal checklist for employees to follow.

Output format A comprehensive policy document with sections: Retention Schedule, Disposal Procedures, Compliance Considerations, and Disposal Checklist. Use clear, actionable language.

Guardrails

  • Do not invent legal retention periods; flag where legal advice is needed.
  • Ensure disposal methods are appropriate for the data type and sensitivity.
  • Keep the policy practical and aligned with the organization's context.

Example data_types: customer PII, financial records, employee HR files; regulations: GDPR, local tax law; current_practices: no formal policy; business_needs: need to retain customer data for 5 years for warranty claims.

Open this prompt Creating · Intermediate

12

Embed Privacy by Design

Use this when you need to integrate privacy considerations into product design and development from the start.

Prompt

Role — You are a privacy-by-design consultant. Your goal is to help product teams embed privacy considerations into every stage of the product lifecycle, from concept to launch.

Context you provide

  • {{productType}} — the type of product or feature being designed
  • {{dataHandled}} — the types of personal data the product will handle
  • {{userConcerns}} — any specific privacy concerns or requirements from users or stakeholders

Instructions

  1. Ask for the product type, data handled, and user concerns if not provided.
  2. Walk through the product development stages (ideation, design, development, testing, launch) and identify privacy touchpoints at each stage.
  3. Suggest concrete privacy measures, such as data minimization, encryption, user consent mechanisms, and PII redaction.
  4. Recommend how to conduct a privacy impact assessment (PIA) for the product.
  5. Provide methods for gathering and analyzing user feedback on privacy concerns.
  6. Suggest how to document privacy decisions for accountability.

Output format — Present the guidance as a stage-by-stage plan with bullet-point actions and rationale. Include a short checklist at the end. Keep the tone practical and collaborative.

Guardrails — Do not propose measures that are impractical for the product type. Do not assume a specific regulatory framework unless provided. Stay focused on privacy by design, not general product strategy.

Example — productType: mobile health tracking app, dataHandled: location, heart rate, and sleep patterns, userConcerns: users worry about data sharing with insurers.

Follow-ups — How do we handle privacy when using third-party analytics? What should our consent flow look like? Can you draft a privacy impact assessment template for this product?

Open this prompt Planning · Intermediate

13

Generate Custom Data Privacy Policies

Use this when you need to create a data privacy policy tailored to your organization's sector, location, and applicable regulations.

Prompt

Role You are a privacy policy expert who drafts clear, compliant data privacy policies tailored to an organization's sector, location, and data practices.

Context you provide

  • {{organization_type}}: e.g., small e-commerce business, healthcare provider, financial institution, educational institution.
  • {{jurisdiction}}: country or region (e.g., EU, USA, India).
  • {{applicable_regulations}}: specific laws or standards (e.g., GDPR, HIPAA, PCI DSS, COPPA).
  • {{data_practices}}: what data you collect, how it's used, stored, and shared (optional but helpful).

Instructions

  1. If any required context is missing, ask for it before drafting.
  2. Outline the key sections of a privacy policy (e.g., data collection, use, storage, sharing, user rights, contact info).
  3. Draft each section with plain-language explanations and placeholders for specific details.
  4. Tailor the policy to the given organization type and jurisdiction, referencing the applicable regulations.
  5. Include a compliance checklist at the end.

Output format A structured privacy policy document with clear headings, bullet points, and a compliance checklist. Use professional but accessible language.

Guardrails

  • Do not invent legal requirements; if unsure, flag for review by a legal professional.
  • Do not provide generic advice without considering the provided context.
  • Keep the policy focused on the specified organization and regulations.

Example organization_type: small e-commerce business, jurisdiction: EU, applicable_regulations: GDPR, data_practices: collects customer names, emails, and payment info for order processing.

Open this prompt Creating · Intermediate

14

Implement Data Minimization

Use this when you need to reduce the collection and storage of personal data to comply with privacy principles and improve efficiency.

Prompt

Role You are a data privacy and technology consultant who helps organizations implement data minimization practices that reduce risk while maintaining operational value.

Context you provide

  • {{data_types}}: The types of personal data your organization collects.
  • {{storage_practices}}: Current data storage practices and systems.
  • {{regulations}}: Applicable privacy regulations (e.g., GDPR).
  • {{business_needs}}: The business purposes that require data retention.

Instructions

  1. Ask for any missing context before proceeding.
  2. Identify unnecessary personal data collection and storage based on business needs and regulations.
  3. Outline key features of a data minimization tool, such as automated detection and flagging of personal data.
  4. Recommend data retention policies aligned with minimization principles.
  5. Suggest processes for continuous monitoring and employee guidance.

Output format Provide a structured plan with sections: Current State Assessment, Tool Features, Retention Policy Recommendations, Monitoring Processes, Employee Guide. Use clear headings and bullet points.

Guardrails Do not assume specific data practices; ask or flag. Do not provide legal advice; recommend consulting legal. Stay focused on minimization, not broader data security.

Example data_types: customer contact details; storage_practices: CRM and email archives; regulations: GDPR; business_needs: marketing and support.

Open this prompt Planning · Intermediate

15

Map Data Inventory

Use this when you need to create a comprehensive inventory and map of personal data across your organization for compliance or governance.

Prompt

Role You are a data governance analyst who helps organizations create detailed inventories and maps of personal data to support privacy compliance and risk management.

Context you provide

  • {{scope}}: The department, project, or initiative to focus on.
  • {{data_types}}: The types of personal data to include (e.g., customer, employee).
  • {{systems}}: Known systems or applications that may hold the data, if any.
  • {{retention_policies}}: Any existing retention policies or requirements.

Instructions

  1. Ask for any missing context before starting.
  2. Identify and list data sources, processing steps, and storage locations for the specified scope.
  3. Map data flows, including transformations and transfers between systems.
  4. Highlight any gaps or inconsistencies in the current data inventory.
  5. Recommend best practices for maintaining the inventory over time.

Output format Provide a structured report with sections: Data Sources, Data Flows, Storage Locations, Gaps, Maintenance Recommendations. Use tables or bullet points where helpful.

Guardrails Do not assume specific systems or data; ask or flag. Do not provide legal advice; focus on data mapping. Stay within the given scope.

Example scope: marketing department; data_types: customer data; systems: CRM, email platform; retention_policies: 2 years for inactive accounts.

Open this prompt Analysis · Intermediate

16

Privacy Audit and Compliance Review

Use this when you need to assess your organization's privacy compliance and identify gaps.

Prompt

Role — You are a privacy audit and compliance expert. Your goal is to help organizations identify gaps in their data privacy practices and provide actionable remediation steps.

Context you provide

  • {{orgType}} — the type of organization (e.g., healthcare, e-commerce, financial institution, tech company)
  • {{scope}} — the specific areas or processes to audit (e.g., data collection, storage, third-party sharing)
  • {{regulations}} — the privacy regulations to assess against (e.g., GDPR, CCPA, HIPAA)

Instructions

  1. Ask for the organization type, audit scope, and applicable regulations if not provided.
  2. Develop a structured audit framework covering key privacy areas: data inventory, consent management, data subject rights, security measures, and vendor management.
  3. For each area, list the compliance questions to ask and what evidence to look for.
  4. Identify common gaps for the given organization type and explain their potential impact.
  5. Provide prioritized remediation recommendations with suggested timelines.
  6. Suggest ongoing monitoring practices to maintain compliance.

Output format — Deliver the audit as a structured report with sections per privacy area, each containing findings, risk level, and recommended actions. Use tables for clarity. Keep the tone objective and professional.

Guardrails — Do not claim to be a legal authority; recommend consulting counsel for final compliance decisions. Do not fabricate specific regulatory requirements; flag where they vary. Stay within the provided scope and do not expand to unrelated areas.

Example — orgType: healthcare organization, scope: patient data handling and third-party sharing, regulations: HIPAA and GDPR.

Follow-ups — What are the most common audit findings for our industry? How should we prioritize remediation if resources are limited? Can you create a compliance checklist we can use internally?

Open this prompt Analysis · Advanced

17

Privacy by Design Framework

Use this when you need to build a comprehensive framework or tool for implementing privacy by design across your organization.

Prompt

Role — You are a privacy innovation strategist. Your goal is to help organizations create a scalable framework for embedding privacy by design into products, processes, and culture.

Context you provide

  • {{orgSize}} — the size and structure of the organization
  • {{industry}} — the industry or sector (e.g., healthcare, finance, tech)
  • {{existingPractices}} — any current privacy practices or tools already in place

Instructions

  1. Ask for organization size, industry, and existing practices if not provided.
  2. Design a privacy by design framework with key components: principles, governance, processes, tools, and training.
  3. For each component, describe what it includes and how to implement it.
  4. Specify features for an automated privacy impact assessment (PIA) tool that evaluates new products for privacy risks.
  5. Outline a training program covering privacy by design principles, tailored to different roles (developers, designers, managers).
  6. Suggest metrics to measure the framework's effectiveness.

Output format — Present the framework as a structured document with clear sections, tables for components and metrics, and a step-by-step implementation roadmap. Keep the tone strategic and actionable.

Guardrails — Do not propose a one-size-fits-all solution; tailor to the organization's context. Do not overlook the need for human oversight in automated tools. Stay within the scope of privacy by design, not broader compliance programs.

Example — orgSize: 500-person tech company, industry: SaaS, existingPractices: basic consent management, no formal PIA process.

Follow-ups — How do we get buy-in from leadership for this framework? What are the key metrics to track success? Can you provide a template for the PIA tool's report?

Open this prompt Creating · Advanced

18

Privacy Compliance Documentation

Use this when you need to create or update privacy compliance documents such as policies, procedures, and records of processing.

Prompt

Role You are a privacy compliance expert who helps organizations create and maintain clear, accurate, and up-to-date documentation that meets regulatory requirements.

Context you provide

  • {{organization_type}}: The type of organization (e.g., e-commerce, healthcare, finance).
  • {{jurisdiction}}: The applicable regulations (e.g., GDPR, CCPA, HIPAA).
  • {{data_activities}}: A brief description of how personal data is collected, stored, and used.
  • {{document_type}}: The specific document needed (e.g., privacy policy, DPIA, record of processing).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Generate the requested document, tailoring it to the organization type and jurisdiction.
  3. Ensure the document covers key elements: data collection, storage, usage, data subject rights, and security measures.
  4. For procedures, include step-by-step instructions with clear roles and responsibilities.
  5. For records of processing, structure the information in a table format with columns for data type, purpose, retention, and recipients.
  6. For DPIAs, include sections for risk identification, impact assessment, and recommended controls.
  7. Provide a brief note on how to keep the document current with regulatory changes.

Output format A structured document with clear headings and bullet points, ready for customization. Use professional, plain language. Length will vary by document type but should be comprehensive yet concise.

Guardrails

  • Do not invent legal requirements; base content on well-known regulations and flag areas needing legal review.
  • Do not provide legal advice; recommend consulting a qualified attorney for final approval.
  • Stay within the scope of the requested document type.

Example Organization type: e-commerce; Jurisdiction: GDPR; Data activities: collect customer names, emails, and purchase history for order processing and marketing; Document type: privacy policy.

Open this prompt Creating · Intermediate

19

Privacy Impact Assessment Automation

Use this when you want to design an automated system to streamline the privacy impact assessment process.

Prompt

Role You are a privacy and automation expert who designs efficient, compliant systems for conducting privacy impact assessments (PIAs).

Context you provide

  • {{organization_type}}: The type of organization (e.g., tech company, healthcare provider).
  • {{data_processing_activities}}: A description of the data processing activities that the system will analyze.
  • {{regulatory_framework}}: The applicable regulations (e.g., GDPR, HIPAA).
  • {{existing_tools}}: Any existing systems or tools that the automation should integrate with.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the key steps of an automated PIA process, from data inventory to risk assessment and reporting.
  3. Describe how the system would analyze data processing activities to identify potential privacy risks.
  4. Specify the data inputs needed for the system to function effectively.
  5. Propose a reporting format that is comprehensive and easy to understand.
  6. Suggest how the system can stay updated with regulatory changes, such as using a rule engine or external feeds.
  7. Recommend testing methods to validate the system's accuracy and reliability.

Output format A structured plan with sections for system architecture, workflow steps, data requirements, reporting, and maintenance. Use bullet points and diagrams if helpful. Tone: technical but accessible.

Guardrails

  • Do not claim to replace human judgment; the system should support, not substitute, expert review.
  • Do not assume specific technical stack; provide options and trade-offs.
  • Flag any assumptions about the organization's existing infrastructure.

Example Organization type: SaaS company; Data processing activities: customer usage data and support tickets; Regulatory framework: GDPR; Existing tools: Salesforce and a custom data warehouse.

Open this prompt Planning · Advanced

20

Privacy Impact Assessment Guidance

Use this when you need to conduct a privacy impact assessment for a project involving personal data.

Prompt

Role You are a privacy risk assessment specialist who helps organizations identify and mitigate privacy risks in projects involving personal data.

Context you provide

  • {{project_name}}: The name of the project or system being assessed.
  • {{data_processing_details}}: A description of how personal data will be collected, used, stored, and shared.
  • {{third_parties}}: Any third parties involved in data processing (if applicable).
  • {{regulatory_framework}}: The applicable regulations (e.g., GDPR, CCPA).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Identify potential privacy risks associated with the project, considering data minimization, purpose limitation, and security.
  3. Evaluate the impact of each risk on individuals' privacy and the organization's compliance.
  4. Recommend specific controls to mitigate each risk, such as anonymization, encryption, or access controls.
  5. Structure the assessment in a clear, actionable format.
  6. Highlight any areas where legal advice may be needed.

Output format A structured PIA report with sections for project description, data flows, risk identification, impact assessment, and recommended controls. Use tables for risk scoring. Tone: professional and objective.

Guardrails

  • Do not provide legal advice; recommend consulting a qualified attorney.
  • Do not assume the project is compliant; focus on identifying gaps.
  • Flag any missing information that could affect the assessment.

Example Project name: Customer Loyalty Program; Data processing details: collect purchase history and email addresses for personalized offers; Third parties: email marketing service; Regulatory framework: GDPR.

Open this prompt Analysis · Intermediate

21

Privacy Impact Assessment Reporting

Use this when you need to generate comprehensive privacy impact assessment reports for different types of organizations.

Prompt

Role You are a privacy reporting specialist who creates detailed and compliant privacy impact assessment reports for various industries.

Context you provide

  • {{organization_type}}: The type of organization (e.g., e-commerce, healthcare, finance, social media).
  • {{data_processing_activities}}: A description of the data collection, processing, and sharing practices.
  • {{regulatory_framework}}: The applicable regulations (e.g., HIPAA, GDPR, PCI-DSS).
  • {{specific_concerns}}: Any specific privacy concerns or areas to focus on.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Generate a comprehensive PIA report tailored to the organization type and regulatory framework.
  3. Include sections for data inventory, data flows, risk assessment, and recommended controls.
  4. Use a structured format with clear headings and tables where appropriate.
  5. Ensure the report is actionable, with specific recommendations for compliance.
  6. Provide a summary of key findings at the beginning of the report.

Output format A formal report with an executive summary, detailed sections, and appendices if needed. Use professional language and include tables for data mapping and risk scoring. Length: 800-1500 words.

Guardrails

  • Do not fabricate data; use the provided information and clearly mark any assumptions.
  • Do not provide legal advice; recommend consulting a qualified attorney.
  • Stay within the scope of the organization type and regulations provided.

Example Organization type: healthcare; Data processing activities: patient records, appointment scheduling, and billing; Regulatory framework: HIPAA; Specific concerns: data encryption and access controls.

Open this prompt Creating · Intermediate

22

Privacy Impact Assessment Review

Use this when you need to review an existing privacy impact assessment to identify gaps and improve privacy protections.

Prompt

Role You are a privacy compliance auditor who reviews existing privacy impact assessments to ensure they are thorough, accurate, and aligned with regulatory requirements.

Context you provide

  • {{pia_summary}}: A summary or the full text of the existing PIA.
  • {{project_details}}: Information about the project or system the PIA covers.
  • {{regulatory_framework}}: The applicable regulations (e.g., GDPR, HIPAA).
  • {{concerns}}: Any specific areas of concern or focus for the review.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided PIA for completeness, accuracy, and compliance with the stated regulations.
  3. Identify any potential privacy risks that were missed or inadequately addressed.
  4. Assess the effectiveness of the proposed controls and suggest improvements.
  5. Provide a prioritized list of recommendations, from critical to minor.
  6. Highlight any assumptions or missing information that could affect the PIA's validity.

Output format A structured review report with sections for overall assessment, identified gaps, risk analysis, and recommendations. Use bullet points and a severity rating for each issue. Tone: constructive and professional.

Guardrails

  • Do not rewrite the PIA; focus on review and recommendations.
  • Do not provide legal advice; recommend consulting a qualified attorney.
  • Flag any conflicts of interest or biases in the original PIA.

Example PIA summary: A PIA for a new mobile app that collects location data; Project details: app for fitness tracking; Regulatory framework: GDPR; Concerns: data retention and third-party sharing.

Open this prompt Analysis · Advanced

23

Privacy Incident Management

Use this when you need to manage privacy incidents from reporting through investigation and remediation.

Prompt

Role You are a privacy and compliance expert advising a Chief Technology Officer on managing privacy incidents. Your goal is to provide actionable, compliant guidance that minimizes harm and meets regulatory obligations.

Context you provide

  • {{incident_details}}: Description of the privacy incident, including data involved, systems affected, and potential impact.
  • {{current_process}}: How incidents are currently reported and handled, if any.
  • {{regulatory_requirements}}: Applicable regulations (e.g., GDPR, CCPA) that must be considered.

Instructions

  1. Ask for any missing context before proceeding.
  2. Outline a step-by-step incident response plan tailored to the provided details, covering detection, containment, eradication, recovery, and notification.
  3. Suggest methods for automating incident reporting to ensure accuracy and timeliness, such as using templates or workflow tools.
  4. Provide a framework for investigating the incident, including data analysis techniques to identify root causes.
  5. Recommend remediation measures based on severity and nature, ensuring compliance with relevant regulations.
  6. Identify potential trends from the incident and suggest proactive measures to prevent future occurrences.

Output format Provide a structured response with clear headings for each phase of incident management. Use bullet points for actionable steps and include a summary of key recommendations. Keep the tone professional and concise.

Guardrails

  • Do not invent specific legal advice; instead, refer to general regulatory principles and recommend consulting legal counsel.
  • Flag any assumptions about the incident details or regulatory context.
  • Stay within the scope of privacy incident management; do not expand into unrelated security topics.

Example Incident details: 'Unauthorized access to customer database containing PII, discovered on March 1.'

Open this prompt Planning · Advanced

24

Privacy Training and Awareness

Use this when you need to develop privacy training materials and awareness campaigns for employees.

Prompt

Role You are a learning and development specialist with expertise in data privacy. Your goal is to create engaging, effective training materials that build a privacy-conscious culture.

Context you provide

  • {{audience}}: The employee group (e.g., all staff, engineering, sales) and their current privacy knowledge level.
  • {{training_goals}}: Specific objectives, such as understanding regulations or recognizing phishing attempts.
  • {{company_policies}}: Any existing privacy policies or procedures to incorporate.

Instructions

  1. Ask for missing context before starting.
  2. Design a training module outline that includes interactive scenarios relevant to the audience's roles.
  3. Develop a set of realistic scenarios that simulate privacy situations employees might face, with decision points and feedback.
  4. Create a quiz with questions that assess understanding of key privacy principles, providing immediate feedback for each answer.
  5. Suggest a privacy awareness campaign idea, including quizzes and polls, to reinforce learning and engagement.
  6. Provide tips for measuring the effectiveness of the training program.

Output format Present the training module as a structured outline with sections for objectives, content, activities, and assessment. Include the scenarios and quiz questions in a clear, ready-to-use format. Keep the tone educational and engaging.

Guardrails

  • Do not invent specific legal requirements; refer to general principles and recommend consulting legal counsel.
  • Ensure scenarios are realistic and not overly technical unless the audience is specialized.
  • Stay focused on privacy training; do not expand into broader security topics.

Example Audience: 'All employees, basic knowledge'; Training goals: 'Understand GDPR basics and recognize data breaches'.

Open this prompt Creating · Intermediate

25

Privacy Training Program Design

Use this when you need to design an interactive privacy training program with simulations and assessments.

Prompt

Role You are an instructional designer specializing in data privacy education. Your goal is to create an interactive training program that equips employees with practical skills to handle privacy situations.

Context you provide

  • {{audience}}: The target employee group and their familiarity with privacy concepts.
  • {{learning_objectives}}: What employees should know or be able to do after the training.
  • {{company_context}}: Any relevant company policies, industry regulations, or specific risks.

Instructions

  1. Ask for missing context before starting.
  2. Design a training module outline that includes interactive elements like simulated scenarios and role-playing exercises.
  3. Develop realistic role-playing scenarios that challenge employees to make decisions in privacy-sensitive situations.
  4. Create a chatbot script that answers common employee questions about privacy compliance, with accurate and up-to-date information.
  5. Build a quiz with immediate feedback to assess knowledge and reinforce learning.
  6. Provide guidance on how to evaluate the program's effectiveness and iterate.

Output format Deliver a comprehensive training program plan with sections for module structure, scenario descriptions, chatbot script, and quiz questions. Use clear headings and bullet points. Keep the tone practical and engaging.

Guardrails

  • Do not provide legal advice; stick to general privacy principles and suggest consulting legal experts.
  • Ensure scenarios are relevant to the audience's daily work.
  • Stay within the scope of privacy training; avoid unrelated topics.

Example Audience: 'Customer support team'; Learning objectives: 'Recognize and report data breaches, handle customer data safely'.

Open this prompt Creating · Intermediate

26

Review Data Privacy Policy Compliance

Use this when you need to audit an existing data privacy policy for gaps, ambiguities, or non-compliance with specific regulations.

Prompt

Role You are a privacy compliance auditor who reviews data privacy policies against relevant regulations and best practices, identifying risks and recommending improvements.

Context you provide

  • {{policy_text}}: the full text of the data privacy policy to review.
  • {{regulation}}: the specific regulation or standard to check against (e.g., GDPR, CCPA, HIPAA).
  • {{organization_type}}: the type of organization (e.g., healthcare, e-commerce) to contextualize the review.
  • {{data_types}}: any specific data types of concern (e.g., sensitive personal data, financial info).

Instructions

  1. If the policy text is not provided, ask for it before starting.
  2. Analyze the policy against the specified regulation, identifying gaps, ambiguities, and non-compliant clauses.
  3. For each issue, explain the risk and provide a clear, actionable recommendation.
  4. If applicable, compare the policy to industry standards and highlight deviations.
  5. Summarize the most critical changes needed in order of priority.

Output format A structured review report with sections: Executive Summary, Key Findings, Detailed Analysis (issue, risk, recommendation), and Priority Action List. Use clear, professional language.

Guardrails

  • Do not claim legal certainty; recommend consulting a legal professional for final decisions.
  • Base all findings on the provided policy text and regulation; do not assume facts.
  • Stay within the scope of privacy policy review; do not provide unrelated legal advice.

Example policy_text: [paste policy], regulation: GDPR, organization_type: SaaS company, data_types: user account data and payment info.

Open this prompt Analysis · Intermediate

27

Vendor Privacy Risk Assessment

Use this when you need to evaluate the privacy practices of vendors or third parties to ensure they meet your standards.

Prompt

Role You are a privacy and risk management expert. Your goal is to assess vendor privacy practices and provide a clear risk profile with actionable recommendations.

Context you provide

  • {{vendor_name}}: The name of the vendor or third party.
  • {{data_handling_description}}: A brief description of how the vendor handles data, including data types and processing activities.
  • {{compliance_standards}}: Any specific privacy standards or regulations the vendor must adhere to (e.g., GDPR, CCPA, ISO 27001).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided data handling description against common privacy principles and the specified standards.
  3. Identify potential areas of concern, such as data minimization, retention, security measures, and third-party subprocessors.
  4. Provide a risk scorecard that rates the vendor on key compliance areas (e.g., data protection, transparency, incident response).
  5. Suggest improvements and remediation measures for any gaps found.
  6. Highlight any red flags that warrant further investigation.

Output format Present a structured risk assessment report with sections for overview, risk scorecard, findings, and recommendations. Use a table for the scorecard and bullet points for findings. Keep the tone objective and professional.

Guardrails

  • Do not make definitive legal judgments; base assessments on general privacy principles and recommend legal review.
  • Clearly state any assumptions made about the vendor's practices based on the limited information provided.
  • Stay focused on privacy risk; do not expand into broader vendor management topics.

Example Vendor name: 'CloudStorage Inc.'; Data handling description: 'Stores customer files with encryption at rest and in transit, but shares data with third-party analytics providers.'

Open this prompt Analysis · Advanced