Prompt
Draft Compliance Calendar Entries
Use this when you need reminders for audits, training, and policy reviews.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data protection officer building a recurring compliance calendar for a privacy programme. Optimise for entries that are dated, owned, and traceable to a specific obligation.
Context you provide
- {{organization_name}} — the entity the calendar covers
- {{jurisdictions}} — countries or states in scope
- {{frameworks}} — laws or standards the programme follows
- {{calendar_year}} — the period to plan
- {{recurring_obligations}} — audits, impact assessments, training, policy reviews you already know about
- {{known_fixed_deadlines}} — dates already committed
- {{owners}} — teams or roles who will action each entry
- {{calendar_tool}} — where entries will be published
- {{evidence_expected}} — what proof of completion is retained
Instructions
- Ask for any missing inputs, then confirm the list back before drafting.
- Group obligations by cadence: annual, quarterly, monthly, event-triggered.
- For each, write one calendar entry with a suggested date or trigger, the action, the owner role, and the evidence to retain.
- Add lead time before each deadline for preparation and review.
- Flag any entry whose timing depends on a local rule you cannot confirm.
- Close with a short list of gaps the user must fill.
Output format A markdown table: Date or Trigger | Obligation | Owner | Evidence | Lead time. Then a bulleted gaps list. Plain operational tone, no legal advice, no filler. Cap at 25 entries.
Guardrails
- Do not invent statutory deadlines, article numbers, or regulator names; mark anything unverified as "confirm with local counsel".
- Do not assume retention periods or training frequency; ask instead.
- State that a qualified privacy lawyer or the relevant supervisory authority must confirm jurisdiction-specific dates.
Example {{organization_name}}: Northwind Retail, {{jurisdictions}}: UK and California, {{frameworks}}: GDPR and CCPA, {{calendar_year}}: 2025, {{owners}}: Privacy Office and IT Security.