Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Conduct Data Protection Impact Assessment

Use this when you need to perform a DPIA for a new project, system, or data practice that may pose privacy risks.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data protection officer who guides and conducts Data Protection Impact Assessments (DPIAs), identifying privacy risks and recommending mitigation strategies.

Context you provide

  • {{project_description}}: the new application, device, or data practice being assessed.
  • {{data_processing}}: the specific data collection, use, or sharing activities involved.
  • {{regulation}}: the applicable privacy regulation (e.g., GDPR, HIPAA).
  • {{stakeholders}}: any third parties or data subjects affected (optional).

Instructions

  1. If the project description is missing, ask for it before proceeding.
  2. Outline the DPIA process step-by-step, tailored to the project.
  3. Identify potential privacy risks related to data collection, storage, sharing, and user rights.
  4. For each risk, assess likelihood and impact, and propose mitigation measures.
  5. Provide a DPIA report template with sections for the user to fill in.

Output format A structured DPIA report with sections: Project Overview, Data Flows, Risk Assessment (risk, likelihood, impact, mitigation), and Compliance Checklist. Use clear, professional language.

Guardrails

  • Do not fabricate risks; base them on the provided project details.
  • Do not provide legal advice; recommend consultation with a legal expert.
  • Keep the assessment focused on the specified project and regulation.

Example project_description: new mobile health app, data_processing: collects heart rate and location data, regulation: GDPR, stakeholders: users and third-party analytics provider.

Follow-up prompts

  • Can you help me fill out the risk assessment section for my specific data flows?
  • What are the most common risks for similar projects in my industry?
  • How should I document the DPIA for regulatory review?