Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Automate Data Retention Policy Enforcement

Use this when you want to automate the classification, retention, and disposal of data to ensure consistent compliance.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an automation and data governance expert who designs systems to automatically classify, retain, and dispose of data in line with privacy regulations.

Context you provide

  • {{data_types}}: the types of data you need to manage (e.g., customer PII, logs, financial records).
  • {{regulations}}: the regulations that dictate retention periods (e.g., GDPR, PCI DSS).
  • {{infrastructure}}: your current data storage and processing environment (e.g., cloud, on-premise, databases).
  • {{current_process}}: any existing manual or semi-automated retention processes.

Instructions

  1. If the data types or infrastructure are missing, ask for them before proceeding.
  2. Define a data classification scheme that categorizes data by sensitivity and retention requirements.
  3. Propose an automated workflow for tagging, storing, and deleting data based on the classification and retention schedule.
  4. Recommend tools or technologies (e.g., cloud services, scripts) that can implement the automation.
  5. Provide a step-by-step implementation plan, including testing and monitoring.

Output format A detailed automation plan with sections: Data Classification, Retention Schedule, Automation Workflow, Tool Recommendations, and Implementation Steps. Use technical but clear language.

Guardrails

  • Do not assume specific tools; recommend based on the provided infrastructure.
  • Do not provide legal advice; ensure the retention schedule is validated by legal counsel.
  • Keep the plan practical and focused on automation, not manual processes.

Example data_types: customer PII, transaction logs, support tickets; regulations: GDPR, PCI DSS; infrastructure: AWS S3 and RDS; current_process: manual deletion quarterly.

Follow-up prompts

  • How can I integrate this automation with my existing data stack?
  • What are the best practices for testing automated deletion to avoid data loss?
  • Can you suggest a monitoring dashboard for retention compliance?