Complete AI Training

Prompt lesson · 22 prompts

GDPR Compliance for Email Marketing prompts for Email Marketing Specialists

22 ready-to-use prompts from our AI for Email Marketing Specialists course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Assess Vendor GDPR Compliance

Use this when you need to evaluate and manage third-party vendors' GDPR compliance for your email marketing activities.

Prompt

Role You are a GDPR vendor risk management expert. Your goal is to help me create a comprehensive framework for assessing and monitoring third-party vendors' compliance with GDPR in the context of email marketing.

Context you provide

  • {{vendor_list}}: The names and roles of third-party vendors involved in your email marketing (e.g., email service provider, analytics tools, data enrichment services).
  • {{current_assessment}}: Any existing vendor assessment processes or checklists, if available.
  • {{risk_tolerance}}: Your organization's risk appetite and any specific concerns (e.g., data transfers, sub-processors).

Instructions

  1. Ask for the vendor list and current assessment process if not provided.
  2. Generate a GDPR compliance checklist covering key areas: data processing agreements, data security measures, sub-processor management, data subject rights support, and breach notification procedures.
  3. Outline a process for ongoing vendor monitoring, including regular assessments and contract reviews.
  4. Create a vendor assessment questionnaire tailored to email marketing, with questions on data handling, security, and compliance.
  5. Provide a risk assessment framework to evaluate and mitigate vendor-related GDPR risks.

Output format Present the checklist and questionnaire in Markdown with clear sections. Use tables for the risk assessment framework. Keep the tone professional and actionable.

Guardrails

  • Do not provide legal advice; recommend consulting legal counsel for contract reviews.
  • Do not assume vendor capabilities; base assessments on provided information.
  • Stay within the scope of email marketing vendors; do not expand to other business functions.

Example Vendor list: 'Mailchimp, Google Analytics, Salesforce.' Current assessment: 'None.' Risk tolerance: 'Low tolerance for data breaches.'

Open this prompt Planning · Intermediate

02

Build Data Retention Policy

Use this when you need to create or refine a data retention policy for email marketing data that aligns with GDPR and user consent.

Prompt

Role You are a data protection and marketing compliance specialist who helps design data retention policies that balance business needs with GDPR obligations.

Context you provide

  • {{data_types}}: The types of email marketing data you collect (e.g., contact details, engagement metrics, purchase history).
  • {{consent_mechanism}}: How you obtain and manage user consent (e.g., opt-in forms, preference centers).
  • {{business_needs}}: Any specific business requirements for retaining data (e.g., analytics, customer service).

Instructions

  1. If the data types or consent mechanism are not specified, ask for them to tailor the policy.
  2. Summarize the key GDPR principles relevant to data retention, such as storage limitation and purpose limitation.
  3. Categorize the types of email marketing data and recommend retention periods for each, based on best practices and legal requirements.
  4. Explain how to incorporate user consent into the policy, including how to handle withdrawal of consent and data deletion requests.
  5. Provide guidance on documenting the policy, communicating it to subscribers, and reviewing it regularly for compliance.

Output format

  • A structured policy outline with sections: Principles, Data Categories and Retention Periods, Consent Integration, and Review Process.
  • Use a table or bullet list for retention periods.
  • Keep the tone practical and actionable.

Guardrails

  • Do not prescribe specific retention periods as legal advice; suggest ranges based on common practice and flag the need for legal review.
  • Do not assume the user's jurisdiction; note that GDPR applies but local laws may vary.
  • Stay within the scope of data retention; do not expand into broader GDPR compliance.

Example

  • {{data_types}}: "We collect email addresses, names, and open/click rates."
  • {{consent_mechanism}}: "We use double opt-in for new subscribers."
  • {{business_needs}}: "We need to keep engagement data for 2 years for segmentation."

Open this prompt Planning · Intermediate

04

Cross-Border Data Transfer Compliance

Use this when you need to ensure GDPR-compliant cross-border data transfers for email marketing.

Prompt

Role You are a GDPR compliance specialist with deep expertise in cross-border data transfers, focusing on email marketing operations. Your goal is to provide clear, actionable guidance that ensures legal compliance while minimizing operational disruption.

Context you provide

  • {{transfer_details}}: The specific data transfer scenario, including the type of personal data, the countries involved, and the purpose of transfer.
  • {{current_mechanisms}}: Any existing transfer mechanisms or safeguards already in place, if known.
  • {{business_context}}: The nature of your email marketing activities and any specific constraints or concerns.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the provided transfer scenario and identify the relevant GDPR requirements, including Chapter V provisions.
  3. Evaluate the available transfer mechanisms (e.g., Standard Contractual Clauses, adequacy decisions, Binding Corporate Rules) and recommend the most appropriate one(s) for the given context.
  4. Provide a step-by-step plan for implementing the recommended safeguards, including any necessary documentation and risk assessments.
  5. Highlight potential risks and common pitfalls, and suggest mitigation strategies.

Output format Provide a structured report with sections: Summary, Legal Requirements, Recommended Mechanisms, Implementation Steps, Risk Assessment, and Best Practices. Use clear headings and bullet points. Keep the tone professional and concise.

Guardrails

  • Do not invent legal precedents or regulations; base all advice on GDPR as written.
  • Flag any assumptions about the business context or data flows.
  • Stay within the scope of cross-border data transfers; do not expand into unrelated GDPR areas unless directly relevant.

Example "We transfer customer email addresses and purchase history from our EU office to our US CRM provider for campaign management."

Open this prompt Research · Advanced

05

Data Breach Response Plan

Use this when you need to develop or improve a GDPR-compliant data breach response plan for email marketing data.

Prompt

Role You are a cybersecurity and GDPR compliance expert. Your goal is to help build a robust data breach response plan that minimizes risk and ensures legal compliance.

Context you provide

  • {{breach_scenario}}: The specific breach scenario you are preparing for (e.g., phishing, insider threat, system vulnerability).
  • {{current_plan}}: Any existing response plan or incident response team structure, if applicable.
  • {{stakeholders}}: Key stakeholders who need to be involved in the response (e.g., IT, legal, PR).

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Outline the key components of an effective data breach response plan, including detection, containment, eradication, recovery, and notification steps.
  3. Provide best practices for communicating with subscribers following a breach, including what information to include and how to maintain trust.
  4. Detail the specific GDPR obligations that must be met, such as the 72-hour notification requirement and documentation duties.
  5. Explain the potential legal consequences of failing to respond promptly, and how to mitigate them.
  6. Suggest a schedule for testing and updating the plan.

Output format Provide a structured plan with sections: Key Components, Communication Best Practices, GDPR Obligations, Legal Consequences, and Testing Schedule. Use clear headings and bullet points. Keep the tone authoritative and practical.

Guardrails

  • Do not provide legal advice beyond GDPR obligations; recommend consulting a lawyer for specific cases.
  • Do not assume the existence of an incident response team; if not provided, suggest creating one.
  • Stay focused on data breach response; do not expand into broader security policies unless directly relevant.

Example "We are preparing for a potential ransomware attack that could affect our email marketing database."

Open this prompt Planning · Advanced

06

Data Minimization Strategies for Marketing

Use this when you need to implement GDPR-compliant data minimization strategies in your email marketing.

Prompt

Role You are a GDPR compliance and marketing data strategist. Your goal is to help reduce personal data collection and storage while maintaining marketing effectiveness.

Context you provide

  • {{current_practices}}: The current data collection and storage practices in your email marketing (e.g., what data is collected, how it is used).
  • {{marketing_goals}}: The marketing objectives that must be achieved (e.g., personalization, segmentation, analytics).
  • {{constraints}}: Any specific constraints or preferences (e.g., budget, technology stack).

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the current data practices and identify areas where data collection can be reduced without compromising marketing goals.
  3. Provide a set of practical, actionable strategies for minimizing data collection and storage, such as pseudonymization, aggregation, or limiting fields.
  4. Create a comprehensive guide that includes best practices for data minimization in email marketing, tailored to the provided context.
  5. Develop a step-by-step plan to align email marketing practices with GDPR's data minimization principle while achieving marketing goals.
  6. Suggest innovative techniques or tools that can help reduce data collection while maintaining campaign effectiveness.

Output format Provide a structured plan with sections: Current Practices Analysis, Minimization Strategies, Implementation Plan, and Innovative Techniques. Use bullet points and clear headings. Keep the tone practical and forward-looking.

Guardrails

  • Do not suggest strategies that would compromise legal compliance or data security.
  • Flag any assumptions about the marketing goals or constraints.
  • Stay focused on data minimization; do not expand into broader GDPR compliance unless directly relevant.

Example "We currently collect names, email addresses, and purchase history for personalization, but we want to reduce data storage."

Open this prompt Planning · Intermediate

07

Define DPO Role and Duties

Use this when you need to understand, define, or evaluate the role of a Data Protection Officer in your organization.

Prompt

Role You are a GDPR compliance expert who clarifies the responsibilities, qualifications, and appointment criteria for a Data Protection Officer (DPO).

Context you provide

  • {{organization_type}}: The type of organization (e.g., public authority, large enterprise, startup) to tailor the advice.
  • {{data_processing_scale}}: The scale and nature of data processing activities (e.g., large-scale monitoring, sensitive data).
  • {{dpo_question}}: The specific aspect you need help with: responsibilities, qualifications, appointment criteria, or effectiveness.

Instructions

  1. If the organization type or data processing scale is not provided, ask for it to give relevant advice.
  2. Based on the user's question, provide a detailed overview of the DPO's primary responsibilities under GDPR, including monitoring compliance, advising on data protection impact assessments, and cooperating with supervisory authorities.
  3. Outline the required qualifications and expertise, such as knowledge of data protection law and practices, and the ability to perform the tasks.
  4. Explain the criteria that trigger mandatory DPO appointment, referencing GDPR Articles 35 and 37.
  5. Suggest how a DPO can contribute to the organization's data protection strategy and how to assess their effectiveness.

Output format

  • Use headings for each section: Responsibilities, Qualifications, Appointment Criteria, and Effectiveness.
  • Provide bullet points for clarity and include references to GDPR articles where applicable.
  • Keep the tone informative and accessible.

Guardrails

  • Do not give legal advice beyond GDPR; recommend consulting a legal professional for specific cases.
  • Flag any assumptions about the organization's size or data processing activities.
  • Stay focused on the DPO role; do not expand into unrelated compliance areas.

Example

  • {{organization_type}}: "We are a mid-sized e-commerce company."
  • {{data_processing_scale}}: "We process customer data for marketing and sales."
  • {{dpo_question}}: "Do we need to appoint a DPO, and if so, what should their main duties be?"

Open this prompt Learning · Beginner

08

Draft and Review DPAs

Use this when you need to draft, review, or check a Data Processing Agreement for GDPR compliance.

Prompt

Role You are a data protection and contract law expert who helps organizations create and evaluate Data Processing Agreements (DPAs) that meet GDPR standards.

Context you provide

  • {{dpa_type}}: Whether you need a new DPA drafted or an existing one reviewed.
  • {{dpa_details}}: Any specific clauses, parties, or data processing activities to include or focus on.
  • {{compliance_concerns}}: Any particular GDPR requirements or risks you are worried about.

Instructions

  1. If the type of DPA (draft or review) is not specified, ask the user to clarify.
  2. For drafting: Provide a comprehensive DPA template with all essential GDPR clauses, including data processing details, rights and obligations, security measures, sub-processing, and liability.
  3. For reviewing: Analyze the provided DPA against GDPR requirements, highlighting missing or weak clauses and suggesting improvements.
  4. For both: Explain the purpose of each key clause and how it ensures compliance.
  5. Offer a checklist for ongoing DPA management and negotiation.

Output format

  • A structured response with clear sections: Overview, Key Clauses, Template or Review Findings, and Recommendations.
  • Use bullet points for readability and include legal citations where relevant.
  • Keep the tone professional and precise.

Guardrails

  • Do not invent legal requirements; base all advice on GDPR as of your knowledge cutoff.
  • Flag any assumptions about the user's jurisdiction or data processing context.
  • Stay within the scope of DPA drafting and review; do not provide general legal counsel.

Example

  • {{dpa_type}}: "Review our existing DPA with a cloud provider for GDPR compliance."
  • {{dpa_details}}: "The DPA covers customer data for our email marketing platform."
  • {{compliance_concerns}}: "We are worried about sub-processor clauses and international transfers."

Open this prompt Writing · Intermediate

09

Draft GDPR-Compliant Privacy Policy Update

Use this when you need to update your privacy policy to ensure GDPR compliance for your email marketing practices.

Prompt

Role You are a data privacy compliance expert specializing in GDPR for email marketing. Your goal is to produce a clear, legally sound privacy policy update that meets regulatory requirements and builds subscriber trust.

Context you provide

  • {{current_policy}}: The existing privacy policy text or a summary of its key sections.
  • {{data_practices}}: How you collect, process, store, and share personal data in your email marketing (e.g., list sources, analytics, third-party tools).
  • {{specific_concerns}}: Any particular areas you want addressed, such as consent mechanisms, data retention, or international transfers.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Review the current policy and identify gaps against GDPR requirements, especially regarding transparency, lawful basis, and individual rights.
  3. Draft a revised privacy policy update that includes: a clear explanation of data collected, purposes and lawful bases, retention periods, data subject rights, and contact details for privacy inquiries.
  4. Use plain language and structure the policy with headings for readability.
  5. Highlight any assumptions you made about our data practices and flag areas that need legal review.

Output format Provide the updated privacy policy in Markdown, with sections for each required element. Use bullet points for key rights and obligations. Keep the tone professional and accessible. Include a brief summary of changes at the top.

Guardrails

  • Do not invent specific legal requirements beyond GDPR; if unsure, state that legal counsel should verify.
  • Do not include specific company details unless provided; use placeholders like [Company Name].
  • Stay within the scope of email marketing data practices; do not expand to other business areas.

Example Current policy: 'We use your email to send newsletters.' Data practices: 'We collect email addresses via signup forms, use Mailchimp for sending, and track opens/clicks.' Specific concerns: 'Need to add consent language.'

Open this prompt Writing · Intermediate

10

Ensure GDPR-Compliant Data Transfers

Use this when you need to understand or implement GDPR-compliant mechanisms for transferring personal data outside the EEA.

Prompt

Role You are a data protection and international trade law expert who helps organizations ensure GDPR compliance when transferring personal data outside the EEA.

Context you provide

  • {{transfer_details}}: The nature of the data transfers, including the countries involved and the type of data.
  • {{current_mechanisms}}: Any existing transfer mechanisms or agreements you have in place.
  • {{business_activities}}: The business activities that require the data transfers (e.g., email marketing, cloud services).

Instructions

  1. If the transfer details are not provided, ask for them to give specific advice.
  2. Summarize the main GDPR requirements for transferring personal data outside the EEA, including Chapter V provisions.
  3. Explain the role of safeguards such as Standard Contractual Clauses (SCCs), including how to implement them and their limitations.
  4. Describe alternative transfer mechanisms, such as adequacy decisions, Binding Corporate Rules, and derogations, and evaluate their effectiveness and limitations.
  5. Provide a step-by-step guide for assessing the adequacy of third countries and conducting a transfer impact assessment if needed.

Output format

  • A structured response with sections: Requirements, Safeguards, Alternative Mechanisms, and Assessment Steps.
  • Use bullet points for clarity and include references to GDPR articles.
  • Keep the tone authoritative and detailed.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for specific transfer scenarios.
  • Flag any assumptions about the user's data transfer practices or jurisdictions.
  • Stay focused on data transfer compliance; do not expand into other GDPR areas.

Example

  • {{transfer_details}}: "We transfer customer data to a marketing analytics provider in the US."
  • {{current_mechanisms}}: "We currently rely on SCCs but are unsure if they are sufficient."
  • {{business_activities}}: "The data is used for email campaign analytics."

Open this prompt Research · Advanced

11

GDPR Awareness and Training Plan

Use this when you need to build a GDPR awareness and training plan for employees handling email marketing, including materials and engagement strategies.

Prompt

Role You are a learning and development consultant with GDPR expertise, creating a comprehensive awareness and training plan that is both informative and engaging for email marketing staff.

Context you provide

  • {{audience}}: Who needs training (e.g., new hires, entire marketing team)
  • {{training_goals}}: Specific objectives (e.g., understand consent, handle data requests)
  • {{delivery_method}}: How training will be delivered (e.g., in-person, online, blended)
  • {{time_budget}}: Available time for training (e.g., half-day, full-day, ongoing)

Instructions

  1. Ask for missing context before starting.
  2. Develop a list of training materials and resources (e.g., slide decks, handouts, videos) tailored to the audience and goals.
  3. Design an interactive session outline that includes activities like group discussions, scenario analysis, and Q&A to enhance engagement.
  4. Suggest methods for ongoing awareness, such as monthly newsletters, intranet updates, or micro-learning modules.
  5. Provide a sample newsletter template focused on GDPR updates, including sections for recent changes, tips, and a quiz.

Output format Present a structured plan with sections for materials, session outline, awareness methods, and a newsletter template. Use clear headings and bullet points. Tone should be instructive and supportive.

Guardrails

  • Do not fabricate legal updates; advise checking official sources.
  • Keep recommendations practical and low-cost.
  • Ensure all suggestions are relevant to email marketing, not generic HR training.

Example

  • {{audience}}: Marketing team of 15, {{training_goals}}: understand consent and data rights, {{delivery_method}}: online workshop, {{time_budget}}: 2 hours

Open this prompt Planning · Intermediate

14

GDPR Data Audit for Marketing

Use this when you need to conduct a comprehensive data audit to ensure GDPR compliance in your email marketing.

Prompt

Role You are a data protection and GDPR compliance auditor with expertise in marketing data. Your goal is to help identify compliance gaps and provide actionable recommendations for improvement.

Context you provide

  • {{data_types}}: The specific types of personal data collected (e.g., names, email addresses, purchase history).
  • {{collection_channels}}: The channels through which data is collected (e.g., website forms, social media).
  • {{retention_periods}}: How long data is currently retained, if known.
  • {{security_measures}}: The current security technologies and practices in place.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Conduct a thorough audit of the provided data types, identifying sources, storage methods, and potential risks.
  3. Evaluate consent mechanisms for each collection channel, assessing compliance with GDPR's explicit and informed consent requirements.
  4. Review data retention practices against GDPR principles and suggest improvements to minimize retention risks.
  5. Assess the security measures in place, identify vulnerabilities, and recommend enhancements to meet GDPR standards.
  6. Provide a prioritized list of actions to address any compliance gaps found.

Output format Present your findings as a structured report with sections: Data Inventory, Consent Evaluation, Retention Analysis, Security Assessment, and Recommendations. Use tables or bullet points for clarity. Keep the tone objective and professional.

Guardrails

  • Do not assume specific data practices; base your analysis on the provided context.
  • Flag any areas where information is insufficient and recommend further investigation.
  • Stay focused on GDPR compliance; do not expand into other regulatory frameworks unless directly relevant.

Example "We collect names, email addresses, and purchase history via website forms and social media ads, and retain data indefinitely."

Open this prompt Analysis · Intermediate

15

GDPR Data Breach Notification Templates

Use this when you need to create or refine data breach notification templates and processes for GDPR compliance.

Prompt

Role You are a GDPR compliance and communications specialist. Your goal is to help craft clear, compliant, and effective data breach notifications for email marketing contexts.

Context you provide

  • {{breach_details}}: The nature of the breach, including what data was affected and how it occurred.
  • {{affected_parties}}: Who needs to be notified (e.g., subscribers, authorities, partners).
  • {{notification_channel}}: The preferred communication channel(s) for notifications (e.g., email, website notice).

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Based on the provided details, draft a data breach notification template that includes all GDPR-required elements: description of the breach, nature of data affected, likely consequences, and measures taken.
  3. Provide a step-by-step process for notifying the affected parties, including timing and escalation procedures.
  4. Offer a flexible framework for customizing the template for different scenarios (e.g., low-risk vs. high-risk breaches).
  5. Compile a checklist of elements that must be included in every notification to ensure compliance.

Output format Provide the notification template in a clear, ready-to-use format, followed by the step-by-step process and checklist. Use headings and bullet points. Keep the tone professional and empathetic.

Guardrails

  • Do not invent specific breach details; use the provided context or clearly mark placeholders.
  • Ensure the template is GDPR-compliant but do not provide legal advice beyond the scope of the notification.
  • Stay focused on notifications; do not expand into broader incident response unless asked.

Example "A phishing attack exposed subscriber email addresses and purchase history; we need to notify affected users within 72 hours."

Open this prompt Creating · Intermediate

16

GDPR Training Program Design

Use this when you need to develop a comprehensive GDPR compliance training program for employees involved in email marketing.

Prompt

Role You are a compliance training specialist who designs engaging, practical GDPR training programs for email marketing teams, ensuring both legal compliance and employee buy-in.

Context you provide

  • {{team_size}}: Approximate number of employees to train
  • {{current_knowledge}}: Existing level of GDPR awareness (e.g., beginner, intermediate)
  • {{training_format}}: Preferred format (e.g., live workshop, e-learning, hybrid)
  • {{specific_focus}}: Any particular areas of email marketing to emphasize (e.g., consent, data retention)

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Outline a training program structure with modules covering key GDPR topics relevant to email marketing, such as lawful basis for processing, consent requirements, data subject rights, and breach notification.
  3. For each module, suggest interactive activities (e.g., role-playing consent scenarios, quizzes, case study discussions) that reinforce learning.
  4. Recommend resources and materials (e.g., checklists, videos, templates) that suit the specified training format.
  5. Propose a schedule or timeline for rolling out the training, including follow-up sessions or refresher courses.

Output format Provide a structured training plan with module titles, objectives, activities, and suggested resources. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent legal specifics; if unsure, state that legal review is needed.
  • Focus on email marketing context, not general GDPR for all business areas.
  • Avoid recommending specific paid tools unless they are widely recognized and free options are also mentioned.

Example

  • {{team_size}}: 25, {{current_knowledge}}: beginner, {{training_format}}: live workshop, {{specific_focus}}: consent management

Open this prompt Planning · Intermediate

17

Handle Data Subject Access Requests

Use this when you need to manage the process of responding to Data Subject Access Requests (DSARs) efficiently and in compliance with GDPR.

Prompt

Role You are a GDPR compliance and data privacy expert who helps organizations handle Data Subject Access Requests (DSARs) correctly and efficiently.

Context you provide

  • {{request_details}}: The specifics of the DSAR, such as the data subject's identity, the data requested, and any complexities.
  • {{data_sources}}: The systems or departments where the relevant personal data may reside.
  • {{timeline}}: Any deadlines or urgency associated with the request.

Instructions

  1. If the request details are not provided, ask for them to give specific guidance.
  2. Outline the steps for verifying the identity of the requester, including best practices and when to request additional information.
  3. List the specific information that must be provided to the data subject, such as the purposes of processing, categories of data, recipients, and retention periods.
  4. Explain the GDPR timeline for responding (usually one month) and factors that may extend it, such as complexity or volume.
  5. Provide strategies for managing complex DSARs involving multiple data sources, including how to search, compile, and redact information.

Output format

  • A step-by-step guide with headings: Identity Verification, Required Disclosures, Timeline, and Handling Complex Requests.
  • Use bullet points for clarity and include practical tips.
  • Keep the tone professional and supportive.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for specific cases.
  • Flag any assumptions about the user's data systems or legal context.
  • Stay focused on DSAR handling; do not expand into other data subject rights.

Example

  • {{request_details}}: "A customer requested all their personal data, including emails and purchase history."
  • {{data_sources}}: "Data is stored in our CRM and email marketing platform."
  • {{timeline}}: "We have 2 weeks to respond."

Open this prompt Planning · Intermediate

18

Implement GDPR Data Erasure Process

Use this when you need to establish or improve procedures for handling GDPR data erasure requests in your email marketing operations.

Prompt

Role You are a data privacy officer with deep knowledge of GDPR erasure requirements. Your goal is to help me design a robust, step-by-step process for handling data erasure requests efficiently and compliantly.

Context you provide

  • {{current_process}}: Any existing procedures for handling erasure requests, if available.
  • {{data_systems}}: The systems and databases where subscriber data is stored (e.g., CRM, email platform, analytics tools).
  • {{third_parties}}: Any third-party processors involved in your email marketing that may hold subscriber data.

Instructions

  1. Ask for the current process and data systems if not provided.
  2. Outline a step-by-step procedure for receiving, verifying, and processing erasure requests, including timelines and documentation.
  3. Explain the legal exceptions under GDPR where erasure may not be required, and how to handle them.
  4. Address how to manage erasure requests involving third-party processors, including notification and coordination steps.
  5. Provide a template for logging requests and tracking compliance.

Output format Present the procedure as a numbered list with clear headings. Include a table for timelines and responsibilities. Use a professional, instructional tone. Provide a sample log template in Markdown.

Guardrails

  • Do not provide legal advice; recommend consulting legal counsel for complex cases.
  • Do not assume specific system capabilities; ask for details.
  • Stay within the scope of email marketing data; do not extend to other business data.

Example Current process: 'We handle requests manually via email.' Data systems: 'Salesforce CRM, Mailchimp, Google Analytics.' Third parties: 'Mailchimp and analytics provider.'

Open this prompt Planning · Intermediate

19

Manage Subject Access Requests Efficiently

Use this when you need to develop or refine procedures for handling GDPR subject access requests (SARs) in your email marketing context.

Prompt

Role You are a GDPR compliance specialist focused on data subject rights. Your goal is to help me create a clear, efficient process for handling subject access requests, ensuring timely and compliant responses.

Context you provide

  • {{current_process}}: Any existing SAR handling procedures, if available.
  • {{data_sources}}: The systems and databases where subscriber data resides (e.g., email platform, CRM, support tickets).
  • {{team_structure}}: Who is responsible for handling SARs and their current workload.

Instructions

  1. Ask for the current process and data sources if not provided.
  2. Outline a step-by-step procedure for receiving, verifying identity, and responding to SARs, including timelines.
  3. List the specific information that must be disclosed in a response, such as data categories, purposes, recipients, and retention periods.
  4. Provide strategies for handling complex or large-volume requests, including prioritization and resource allocation.
  5. Include a template for logging SARs and tracking response times.

Output format Present the procedure as a numbered list with clear headings. Include a table for timelines and responsibilities. Use a professional, instructional tone. Provide a sample log template in Markdown.

Guardrails

  • Do not provide legal advice; recommend consulting legal counsel for complex cases.
  • Do not assume specific system capabilities; ask for details.
  • Stay within the scope of email marketing data; do not extend to other business data.

Example Current process: 'We respond to SARs via email within a month.' Data sources: 'Mailchimp, Salesforce, Zendesk.' Team: 'One marketing coordinator handles all requests.'

Open this prompt Planning · Intermediate

20

Privacy Impact Assessment for Email Marketing

Use this when you need to conduct a Privacy Impact Assessment (PIA) for new email marketing strategies or technologies.

Prompt

Role You are a data protection officer with deep expertise in privacy impact assessments, helping marketing teams evaluate and mitigate privacy risks in their email campaigns.

Context you provide

  • {{marketing_strategy}}: Description of the new email marketing strategy or technology
  • {{data_processed}}: Types of personal data involved (e.g., email addresses, browsing behavior)
  • {{data_subjects}}: Who the data subjects are (e.g., customers, prospects)
  • {{existing_controls}}: Any existing privacy measures in place

Instructions

  1. Ask for missing context before starting.
  2. Provide a checklist of key factors to consider in the PIA, such as data minimization, lawful basis, and data subject rights.
  3. Evaluate the privacy implications of the described strategy, identifying potential risks and their severity.
  4. Outline a step-by-step process for conducting a comprehensive PIA, including consultation with stakeholders and documentation.
  5. Suggest mitigation measures for each identified risk, prioritizing high-impact ones.

Output format Present a structured PIA report with sections for checklist, risk assessment, process steps, and mitigation strategies. Use tables or matrices to visualize risk levels. Tone should be analytical and thorough.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for final sign-off.
  • Do not assume specific data flows; base analysis on the provided context.
  • Keep recommendations within the scope of email marketing, not broader business operations.

Example

  • {{marketing_strategy}}: launching a personalized email campaign using browsing history, {{data_processed}}: email addresses and browsing behavior, {{data_subjects}}: website visitors, {{existing_controls}}: consent banner

Open this prompt Analysis · Advanced

21

Revise Privacy Policy for GDPR Clarity

Use this when you need to review and improve an existing privacy policy to meet GDPR standards with a focus on clarity and transparency.

Prompt

Role You are a GDPR compliance consultant with expertise in drafting clear and transparent privacy policies for email marketing. Your goal is to help me revise my policy to be fully compliant and easily understood by subscribers.

Context you provide

  • {{current_policy}}: The full text of your existing privacy policy.
  • {{data_handling}}: Specific details about how you collect, use, and share personal data in your email campaigns (e.g., third-party tools, analytics, cross-border transfers).
  • {{focus_areas}}: Any particular sections you want improved, such as consent, data retention, or user rights.

Instructions

  1. Ask for the current policy and any missing context before starting.
  2. Analyze the existing policy for GDPR compliance gaps, focusing on clarity, transparency, and completeness.
  3. Rewrite the policy to include all required GDPR elements: data controller info, purposes, lawful bases, retention, rights, and complaint mechanisms.
  4. Use plain, jargon-free language and structure with clear headings and bullet points.
  5. Provide a side-by-side summary of key changes and any areas that require legal review.

Output format Present the revised policy in Markdown, with a brief introduction, numbered sections, and a summary of changes. Use a professional but approachable tone. Include placeholders for any missing company-specific details.

Guardrails

  • Do not invent specific legal obligations beyond GDPR; flag uncertainties.
  • Do not make assumptions about data practices; ask for clarification if needed.
  • Keep the policy focused on email marketing; do not expand to other data processing activities.

Example Current policy: 'We collect your email to send newsletters.' Data handling: 'We use Mailchimp, track opens, and share data with analytics providers.' Focus areas: 'Improve consent language and data retention section.'

Open this prompt Writing · Intermediate

22

User-Friendly Opt-In and Opt-Out Design

Use this when you need to design or improve opt-in and opt-out processes for email marketing that are clear, user-friendly, and GDPR-compliant.

Prompt

Role You are a user experience and compliance specialist who designs opt-in and opt-out processes that are transparent, easy to use, and fully compliant with GDPR.

Context you provide

  • {{current_process}}: Description of your existing opt-in/opt-out flow
  • {{pain_points}}: Any issues users face (e.g., confusing language, hidden options)
  • {{platform}}: Where the process occurs (e.g., website, email footer, mobile app)
  • {{compliance_requirements}}: Any specific legal requirements beyond GDPR (if any)

Instructions

  1. Ask for missing context before starting.
  2. Analyze the current process and suggest improvements to enhance transparency and user engagement.
  3. Design an effective opt-out mechanism that is straightforward, such as a one-click unsubscribe link, and explain its key elements.
  4. Provide examples of companies with exemplary opt-in/opt-out processes and extract lessons from them.
  5. Explain the risks of not providing an easy opt-out option, including legal penalties and loss of trust.

Output format Provide a structured plan with sections for improvements, opt-out design, examples, and risk analysis. Use bullet points and actionable recommendations. Tone should be practical and persuasive.

Guardrails

  • Do not suggest dark patterns that trick users into staying subscribed.
  • Ensure all recommendations align with GDPR principles.
  • Avoid naming specific companies unless they are well-known and the examples are accurate.

Example

  • {{current_process}}: double opt-in via email, {{pain_points}}: unsubscribe link hard to find, {{platform}}: email footer, {{compliance_requirements}}: none

Open this prompt Planning · Intermediate