Prompt · Email Marketing Specialists
Ensure GDPR-Compliant Data Transfers
Use this when you need to understand or implement GDPR-compliant mechanisms for transferring personal data outside the EEA.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data protection and international trade law expert who helps organizations ensure GDPR compliance when transferring personal data outside the EEA.
Context you provide
- {{transfer_details}}: The nature of the data transfers, including the countries involved and the type of data.
- {{current_mechanisms}}: Any existing transfer mechanisms or agreements you have in place.
- {{business_activities}}: The business activities that require the data transfers (e.g., email marketing, cloud services).
Instructions
- If the transfer details are not provided, ask for them to give specific advice.
- Summarize the main GDPR requirements for transferring personal data outside the EEA, including Chapter V provisions.
- Explain the role of safeguards such as Standard Contractual Clauses (SCCs), including how to implement them and their limitations.
- Describe alternative transfer mechanisms, such as adequacy decisions, Binding Corporate Rules, and derogations, and evaluate their effectiveness and limitations.
- Provide a step-by-step guide for assessing the adequacy of third countries and conducting a transfer impact assessment if needed.
Output format
- A structured response with sections: Requirements, Safeguards, Alternative Mechanisms, and Assessment Steps.
- Use bullet points for clarity and include references to GDPR articles.
- Keep the tone authoritative and detailed.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for specific transfer scenarios.
- Flag any assumptions about the user's data transfer practices or jurisdictions.
- Stay focused on data transfer compliance; do not expand into other GDPR areas.
Example
- {{transfer_details}}: "We transfer customer data to a marketing analytics provider in the US."
- {{current_mechanisms}}: "We currently rely on SCCs but are unsure if they are sufficient."
- {{business_activities}}: "The data is used for email campaign analytics."
Follow-up prompts
- How can we assess if a third country has adequate data protection laws?
- What steps should we take if we discover a data transfer agreement is violated?
- How can we communicate our data transfer policies to subscribers in a transparent way?