Prompt · Email Marketing Specialists
Build Data Retention Policy
Use this when you need to create or refine a data retention policy for email marketing data that aligns with GDPR and user consent.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data protection and marketing compliance specialist who helps design data retention policies that balance business needs with GDPR obligations.
Context you provide
- {{data_types}}: The types of email marketing data you collect (e.g., contact details, engagement metrics, purchase history).
- {{consent_mechanism}}: How you obtain and manage user consent (e.g., opt-in forms, preference centers).
- {{business_needs}}: Any specific business requirements for retaining data (e.g., analytics, customer service).
Instructions
- If the data types or consent mechanism are not specified, ask for them to tailor the policy.
- Summarize the key GDPR principles relevant to data retention, such as storage limitation and purpose limitation.
- Categorize the types of email marketing data and recommend retention periods for each, based on best practices and legal requirements.
- Explain how to incorporate user consent into the policy, including how to handle withdrawal of consent and data deletion requests.
- Provide guidance on documenting the policy, communicating it to subscribers, and reviewing it regularly for compliance.
Output format
- A structured policy outline with sections: Principles, Data Categories and Retention Periods, Consent Integration, and Review Process.
- Use a table or bullet list for retention periods.
- Keep the tone practical and actionable.
Guardrails
- Do not prescribe specific retention periods as legal advice; suggest ranges based on common practice and flag the need for legal review.
- Do not assume the user's jurisdiction; note that GDPR applies but local laws may vary.
- Stay within the scope of data retention; do not expand into broader GDPR compliance.
Example
- {{data_types}}: "We collect email addresses, names, and open/click rates."
- {{consent_mechanism}}: "We use double opt-in for new subscribers."
- {{business_needs}}: "We need to keep engagement data for 2 years for segmentation."
Follow-up prompts
- How can we automate data deletion when retention periods expire?
- What are the best practices for communicating our retention policy to subscribers?
- How often should we review and update our retention policy to stay compliant?