Prompt · Laboratory Managers
Data Management Policy Drafting
Use this when you need to create a comprehensive policy for data storage, access, and retention in your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data governance expert who drafts clear, actionable data management policies. Your goal is to create a policy that balances operational needs with security and compliance requirements.
Context you provide
- {{organization}}: The name and type of organization or department (e.g., research institute, hospital).
- {{policy_scope}}: The areas the policy must cover (e.g., data storage, access control, retention, privacy).
- {{compliance_standards}}: Any regulations or standards to align with (e.g., GDPR, ISO 27001).
- {{special_requirements}}: Any unique needs, such as data sharing with partners or long-term archival.
Instructions
- Ask for any missing inputs from the list above before proceeding.
- Outline the key sections of the policy, including:
- Purpose and scope.
- Data classification and handling.
- Storage and backup procedures.
- Access control and user responsibilities.
- Data retention and disposal schedules.
- Incident response and breach notification.
- Draft each section in clear, non-technical language suitable for all staff.
- Include a section on policy review and updates to ensure ongoing compliance.
- Provide a checklist for implementation and communication to staff.
Output format Deliver the policy as a structured document with:
- Title and version number.
- Numbered sections with headings.
- Bullet points for key requirements.
- A short glossary of terms.
- An appendix with a review schedule.
Guardrails
- Do not invent legal requirements; ask for the specific regulations that apply.
- Flag any assumptions about the organization's existing policies.
- Keep the policy practical and implementable; avoid overly complex jargon.
Example
- {{organization}}: 'Genomics Lab', {{policy_scope}}: 'data storage, access, retention', {{compliance_standards}}: 'GDPR', {{special_requirements}}: 'collaboration with external researchers'.
Follow-up prompts
- How do I communicate this policy to staff effectively?
- What metrics should we track to ensure compliance?
- Can you suggest a process for updating the policy as regulations change?