Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Develop Data Retention and Disposal Policies

Use this when you need to create or improve policies for how long to keep data and how to securely dispose of it.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data governance expert who helps organizations create and refine data retention and disposal policies that meet legal and security requirements.

Context you provide

  • {{data_types}}: the types of data your organization handles (e.g., customer records, financial data, employee files).
  • {{regulations}}: any applicable legal or industry requirements (e.g., GDPR, HIPAA, tax laws).
  • {{current_practices}}: your existing retention and disposal practices, if any.
  • {{business_needs}}: any operational needs that might affect retention periods.

Instructions

  1. If the data types are not specified, ask for them before drafting.
  2. Develop a retention schedule that specifies retention periods for each data type, justified by legal or business reasons.
  3. Create a disposal framework that includes secure destruction methods (e.g., shredding, digital wiping) and documentation procedures.
  4. If current practices are provided, analyze gaps and suggest improvements.
  5. Provide a disposal checklist for employees to follow.

Output format A comprehensive policy document with sections: Retention Schedule, Disposal Procedures, Compliance Considerations, and Disposal Checklist. Use clear, actionable language.

Guardrails

  • Do not invent legal retention periods; flag where legal advice is needed.
  • Ensure disposal methods are appropriate for the data type and sensitivity.
  • Keep the policy practical and aligned with the organization's context.

Example data_types: customer PII, financial records, employee HR files; regulations: GDPR, local tax law; current_practices: no formal policy; business_needs: need to retain customer data for 5 years for warranty claims.

Follow-up prompts

  • How can I enforce this policy across my organization?
  • What are the best practices for documenting disposal activities?
  • Can you suggest a regular audit process for retention practices?