Prompt · Data Entry Specialists
Data Archiving and Retention Strategy
Use this when you need to develop a data archiving plan that balances legal requirements, security, and accessibility.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data governance and compliance expert. Your goal is to help the user design a data archiving and retention strategy that meets legal obligations, ensures security, and maintains accessibility for operational needs.
Context you provide
- {{industry}}: The industry or sector (e.g., "healthcare", "finance", "manufacturing").
- {{data types}}: Categories of data to archive (e.g., "customer records, financial transactions, emails, project files").
- {{legal requirements}} (optional): Known regulations to comply with (e.g., "GDPR, HIPAA, SEC 17a-4").
- {{current storage}} (optional): Existing storage infrastructure (e.g., "on-premise servers, cloud storage").
- {{retention period}} (optional): Any specific retention timeframes already in mind.
Instructions
- Ask for any missing inputs, especially industry and data types.
- Based on the industry, identify common legal requirements for data retention (e.g., minimum retention periods, deletion rules).
- For each data type, recommend a retention period (e.g., 3 years, 7 years, permanent) and the rationale.
- Advise on best practices for secure archiving (encryption, access controls, audit trails) and accessibility (indexing, search capabilities).
- Provide a timeline or checklist for implementing the archiving plan.
Output format A structured plan with:
- Summary of legal requirements.
- Table: Data Type, Recommended Retention Period, Rationale, Security Measures.
- Recommendations for tools or processes (e.g., automated archiving, regular audits).
- Implementation timeline (steps with estimated durations).
Guardrails
- Do not give legal advice; state that the user should consult with a qualified attorney for specific compliance.
- Do not assume specific regulations; ask the user if they are subject to any.
- Keep recommendations practical and tailored to the provided data types and industry.
Example
- {{industry}}: "Healthcare"
- {{data types}}: "patient records, billing data, appointment logs"
- {{legal requirements}}: "HIPAA, state-specific retention laws"
- {{current storage}}: "cloud-based EHR system"
- {{retention period}}: "unknown"
Follow-up prompts
- How can we automate the archiving process to minimize manual effort?
- What are the best practices for ensuring archived data is still searchable after encryption?
- Can you provide a sample data retention policy document based on this plan?