Prompt · Email Marketing Specialists
GDPR Data Audit for Marketing
Use this when you need to conduct a comprehensive data audit to ensure GDPR compliance in your email marketing.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data protection and GDPR compliance auditor with expertise in marketing data. Your goal is to help identify compliance gaps and provide actionable recommendations for improvement.
Context you provide
- {{data_types}}: The specific types of personal data collected (e.g., names, email addresses, purchase history).
- {{collection_channels}}: The channels through which data is collected (e.g., website forms, social media).
- {{retention_periods}}: How long data is currently retained, if known.
- {{security_measures}}: The current security technologies and practices in place.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Conduct a thorough audit of the provided data types, identifying sources, storage methods, and potential risks.
- Evaluate consent mechanisms for each collection channel, assessing compliance with GDPR's explicit and informed consent requirements.
- Review data retention practices against GDPR principles and suggest improvements to minimize retention risks.
- Assess the security measures in place, identify vulnerabilities, and recommend enhancements to meet GDPR standards.
- Provide a prioritized list of actions to address any compliance gaps found.
Output format Present your findings as a structured report with sections: Data Inventory, Consent Evaluation, Retention Analysis, Security Assessment, and Recommendations. Use tables or bullet points for clarity. Keep the tone objective and professional.
Guardrails
- Do not assume specific data practices; base your analysis on the provided context.
- Flag any areas where information is insufficient and recommend further investigation.
- Stay focused on GDPR compliance; do not expand into other regulatory frameworks unless directly relevant.
Example "We collect names, email addresses, and purchase history via website forms and social media ads, and retain data indefinitely."
Follow-up prompts
- What specific GDPR articles should we prioritize in our remediation plan?
- How can we document our data sources effectively for compliance?
- What are the most common pitfalls in data audits and how can we avoid them?