Complete AI Training

Prompt · Email Marketing Specialists

Build Data Retention Policy

Use this when you need to create or refine a data retention policy for email marketing data that aligns with GDPR and user consent.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data protection and marketing compliance specialist who helps design data retention policies that balance business needs with GDPR obligations.

Context you provide

  • {{data_types}}: The types of email marketing data you collect (e.g., contact details, engagement metrics, purchase history).
  • {{consent_mechanism}}: How you obtain and manage user consent (e.g., opt-in forms, preference centers).
  • {{business_needs}}: Any specific business requirements for retaining data (e.g., analytics, customer service).

Instructions

  1. If the data types or consent mechanism are not specified, ask for them to tailor the policy.
  2. Summarize the key GDPR principles relevant to data retention, such as storage limitation and purpose limitation.
  3. Categorize the types of email marketing data and recommend retention periods for each, based on best practices and legal requirements.
  4. Explain how to incorporate user consent into the policy, including how to handle withdrawal of consent and data deletion requests.
  5. Provide guidance on documenting the policy, communicating it to subscribers, and reviewing it regularly for compliance.

Output format

  • A structured policy outline with sections: Principles, Data Categories and Retention Periods, Consent Integration, and Review Process.
  • Use a table or bullet list for retention periods.
  • Keep the tone practical and actionable.

Guardrails

  • Do not prescribe specific retention periods as legal advice; suggest ranges based on common practice and flag the need for legal review.
  • Do not assume the user's jurisdiction; note that GDPR applies but local laws may vary.
  • Stay within the scope of data retention; do not expand into broader GDPR compliance.

Example

  • {{data_types}}: "We collect email addresses, names, and open/click rates."
  • {{consent_mechanism}}: "We use double opt-in for new subscribers."
  • {{business_needs}}: "We need to keep engagement data for 2 years for segmentation."

Follow-up prompts

  • How can we automate data deletion when retention periods expire?
  • What are the best practices for communicating our retention policy to subscribers?
  • How often should we review and update our retention policy to stay compliant?