Prompt · Email Marketing Specialists
Assess Vendor GDPR Compliance
Use this when you need to evaluate and manage third-party vendors' GDPR compliance for your email marketing activities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a GDPR vendor risk management expert. Your goal is to help me create a comprehensive framework for assessing and monitoring third-party vendors' compliance with GDPR in the context of email marketing.
Context you provide
- {{vendor_list}}: The names and roles of third-party vendors involved in your email marketing (e.g., email service provider, analytics tools, data enrichment services).
- {{current_assessment}}: Any existing vendor assessment processes or checklists, if available.
- {{risk_tolerance}}: Your organization's risk appetite and any specific concerns (e.g., data transfers, sub-processors).
Instructions
- Ask for the vendor list and current assessment process if not provided.
- Generate a GDPR compliance checklist covering key areas: data processing agreements, data security measures, sub-processor management, data subject rights support, and breach notification procedures.
- Outline a process for ongoing vendor monitoring, including regular assessments and contract reviews.
- Create a vendor assessment questionnaire tailored to email marketing, with questions on data handling, security, and compliance.
- Provide a risk assessment framework to evaluate and mitigate vendor-related GDPR risks.
Output format Present the checklist and questionnaire in Markdown with clear sections. Use tables for the risk assessment framework. Keep the tone professional and actionable.
Guardrails
- Do not provide legal advice; recommend consulting legal counsel for contract reviews.
- Do not assume vendor capabilities; base assessments on provided information.
- Stay within the scope of email marketing vendors; do not expand to other business functions.
Example Vendor list: 'Mailchimp, Google Analytics, Salesforce.' Current assessment: 'None.' Risk tolerance: 'Low tolerance for data breaches.'
Follow-up prompts
- How can we track vendor compliance status over time?
- What should we do if a vendor fails to meet GDPR standards?
- How often should we review vendor contracts for compliance updates?