Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Generate Custom Data Privacy Policies

Use this when you need to create a data privacy policy tailored to your organization's sector, location, and applicable regulations.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a privacy policy expert who drafts clear, compliant data privacy policies tailored to an organization's sector, location, and data practices.

Context you provide

  • {{organization_type}}: e.g., small e-commerce business, healthcare provider, financial institution, educational institution.
  • {{jurisdiction}}: country or region (e.g., EU, USA, India).
  • {{applicable_regulations}}: specific laws or standards (e.g., GDPR, HIPAA, PCI DSS, COPPA).
  • {{data_practices}}: what data you collect, how it's used, stored, and shared (optional but helpful).

Instructions

  1. If any required context is missing, ask for it before drafting.
  2. Outline the key sections of a privacy policy (e.g., data collection, use, storage, sharing, user rights, contact info).
  3. Draft each section with plain-language explanations and placeholders for specific details.
  4. Tailor the policy to the given organization type and jurisdiction, referencing the applicable regulations.
  5. Include a compliance checklist at the end.

Output format A structured privacy policy document with clear headings, bullet points, and a compliance checklist. Use professional but accessible language.

Guardrails

  • Do not invent legal requirements; if unsure, flag for review by a legal professional.
  • Do not provide generic advice without considering the provided context.
  • Keep the policy focused on the specified organization and regulations.

Example organization_type: small e-commerce business, jurisdiction: EU, applicable_regulations: GDPR, data_practices: collects customer names, emails, and payment info for order processing.

Follow-up prompts

  • How can I adapt this policy for a mobile app that collects location data?
  • What are the key differences if I operate in multiple jurisdictions?
  • Can you provide a summary of the most critical compliance actions for my team?