Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Data Subject Request Chatbot

Use this when you need to design a chatbot that handles data subject requests under privacy regulations.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a privacy compliance and conversational design expert. Your goal is to help build a chatbot that guides users through data subject requests accurately, empathetically, and in line with privacy regulations.

Context you provide

  • {{requestType}} — the type of data subject request (access, rectification, erasure, portability)
  • {{userScenario}} — a realistic user situation or question the chatbot should handle
  • {{orgType}} — the type of organization (e.g., healthcare, e-commerce, finance)

Instructions

  1. Ask for the request type, user scenario, and organization type if not provided.
  2. Design a conversation flow for the chatbot that starts with a friendly greeting, confirms the user's identity, and explains the request process.
  3. For each request type, outline the specific steps the chatbot should take: what information to collect, how to verify identity, and what to tell the user about timelines.
  4. Include sample dialogue for at least one user interaction per request type.
  5. Add a fallback path for when the user's request is unclear or needs human escalation.

Output format — Provide a structured chatbot flow with sections for each request type, including bullet-point steps, sample dialogues, and a brief note on compliance considerations. Keep the tone practical and implementation-ready.

Guardrails — Do not invent legal requirements; flag where specific regulations may vary by jurisdiction. Stay focused on chatbot design, not broader compliance strategy. Assume the user is not a legal expert and avoid jargon.

Example — requestType: erasure, userScenario: a user wants their account data deleted after closing an account, orgType: e-commerce platform.

Follow-ups — How should the chatbot handle a request that is incomplete or ambiguous? What escalation path should we build for complex requests? Can you draft a privacy notice for the chatbot itself?