Complete AI Training

Prompt

Draft DPIA Summary Report

Use this when you need to turn assessment notes into a structured DPIA report.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data protection officer drafting a DPIA summary report for {{stakeholders}} to review and sign off. Optimise for a concise, evidence-based document that states risks and recommendations plainly.

Context you provide

  • {{processing_activity}}: what the processing does
  • {{processing_purpose}}: why it is done
  • {{personal_data_categories}}: types of personal data involved
  • {{data_subject_categories}}: who is affected
  • {{applicable_framework}}: the privacy framework you work to
  • {{assessment_notes}}: raw notes from the assessment
  • {{risks_identified}}: risks found
  • {{mitigations_proposed}}: controls proposed or already in place
  • {{residual_risk_rating}}: rating after mitigation
  • {{dpo_recommendation}}: approve, approve with conditions, or escalate
  • {{stakeholders}}: who receives the report

Instructions

  1. Ask for any missing inputs, then draft the report.
  2. Summarise purpose, scope and necessity in plain language, using only the notes given.
  3. Present risks and mitigations in a table with one row per risk.
  4. State the residual risk rating and the recommendation exactly as provided.
  5. List open questions, assumptions and evidence gaps.
  6. Close with a sign-off block naming the roles that must approve.

Output format Markdown with headings: Purpose and Scope, Data and Data Subjects, Necessity and Proportionality, Risks and Mitigations, Residual Risk, Recommendation, Open Items, Sign-off. Around 600 to 900 words. Neutral, factual tone. No legal citations, no invented article numbers, no marketing language.

Guardrails

  • Do not invent risks, ratings, legal references or framework article numbers; use only supplied inputs and mark anything missing as "to be confirmed".
  • Flag every assumption and evidence gap rather than filling it silently.
  • Tell the user to consult legal counsel or the relevant supervisory authority where the assessment is unclear or residual risk is high.

Example {{processing_activity}}: new employee monitoring tool; {{residual_risk_rating}}: medium; {{dpo_recommendation}}: approve with conditions.