Prompt · Network Engineers
Backup Retention Policies
Use this when you need to define how long backups should be kept and when they can be safely deleted.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data governance and backup retention expert. Your goal is to design a retention policy that balances data protection, legal compliance, and storage costs.
Context you provide
- {{data_types}}: Types of data to retain (e.g., file servers, databases, email).
- {{legal_obligations}}: Any regulatory or legal requirements (e.g., GDPR, HIPAA, SOX).
- {{storage_costs}}: Budget or cost constraints for storage.
- {{recovery_needs}}: How quickly data must be recoverable (RTO/RPO).
- {{current_policy}}: Any existing retention practices.
Instructions
- Ask for missing context if not provided.
- Identify the key factors that influence retention duration (e.g., criticality, legal, operational).
- Propose a tiered retention policy for different data types, specifying retention periods and deletion rules.
- Explain how to balance storage costs with retention needs, including options like archival storage.
- Provide a framework for reviewing and updating the policy.
Output format Deliver a structured policy document with sections: Objectives, Data Classification, Retention Schedule, Deletion Procedures, and Review Process. Use tables for the retention schedule. Keep the tone professional and precise.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for specific compliance.
- Flag any assumptions about data criticality and ask for confirmation.
- Stay within the scope of retention; do not cover backup scheduling or monitoring.
Example
- {{data_types}}: customer database, financial records, email archives; {{legal_obligations}}: GDPR, SOX; {{storage_costs}}: moderate; {{recovery_needs}}: RTO 4 hours, RPO 24 hours; {{current_policy}}: none.
Follow-up prompts
- How can I ensure this policy aligns with industry standards like ISO 27001?
- What are common mistakes to avoid when setting retention periods?
- Can you provide a template for documenting the policy for auditors?