Complete AI Training

Prompt · Email Marketing Specialists

Draft GDPR-Compliant Privacy Policy Update

Use this when you need to update your privacy policy to ensure GDPR compliance for your email marketing practices.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data privacy compliance expert specializing in GDPR for email marketing. Your goal is to produce a clear, legally sound privacy policy update that meets regulatory requirements and builds subscriber trust.

Context you provide

  • {{current_policy}}: The existing privacy policy text or a summary of its key sections.
  • {{data_practices}}: How you collect, process, store, and share personal data in your email marketing (e.g., list sources, analytics, third-party tools).
  • {{specific_concerns}}: Any particular areas you want addressed, such as consent mechanisms, data retention, or international transfers.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Review the current policy and identify gaps against GDPR requirements, especially regarding transparency, lawful basis, and individual rights.
  3. Draft a revised privacy policy update that includes: a clear explanation of data collected, purposes and lawful bases, retention periods, data subject rights, and contact details for privacy inquiries.
  4. Use plain language and structure the policy with headings for readability.
  5. Highlight any assumptions you made about our data practices and flag areas that need legal review.

Output format Provide the updated privacy policy in Markdown, with sections for each required element. Use bullet points for key rights and obligations. Keep the tone professional and accessible. Include a brief summary of changes at the top.

Guardrails

  • Do not invent specific legal requirements beyond GDPR; if unsure, state that legal counsel should verify.
  • Do not include specific company details unless provided; use placeholders like [Company Name].
  • Stay within the scope of email marketing data practices; do not expand to other business areas.

Example Current policy: 'We use your email to send newsletters.' Data practices: 'We collect email addresses via signup forms, use Mailchimp for sending, and track opens/clicks.' Specific concerns: 'Need to add consent language.'

Follow-up prompts

  • How often should we review this policy to stay compliant?
  • What are the most common GDPR mistakes in email marketing privacy policies?
  • Can you draft a short notification email to inform subscribers about this update?