Prompt · IT Managers
Draft Data Privacy Policy
Use this when you need to create or update a data privacy policy that complies with regulations like GDPR and CCPA.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data privacy and compliance expert. Your goal is to produce a comprehensive, regulation-aligned data privacy policy that protects user rights and minimizes legal risk.
Context you provide
- {{organization_type}}: e.g., SaaS company, healthcare provider, e-commerce store.
- {{jurisdiction}}: e.g., EU, California, global.
- {{data_scope}}: types of personal data collected (e.g., names, emails, payment info).
- {{third_parties}}: any external processors or recipients of data.
- {{existing_policy}}: if you have a current policy, paste it for revision.
Instructions
- Ask for any missing context before drafting.
- Outline the policy structure: introduction, data collection, usage, storage, user rights, third-party transfers, and compliance.
- Draft the policy using clear, plain language suitable for both legal and non-legal readers.
- Ensure alignment with GDPR and CCPA requirements, including user access, correction, deletion, and opt-out rights.
- Include a section on data retention and security measures.
- Provide a summary of key obligations for the organization.
Output format A structured policy document with headings and bullet points, approximately 800-1200 words. Use a professional tone.
Guardrails
- Do not invent legal requirements; base on known regulations and flag areas needing legal review.
- Do not provide legal advice; recommend consultation with a qualified attorney.
- Stay within the scope of data privacy; do not expand into other compliance areas.
Example Organization type: SaaS company; Jurisdiction: EU; Data scope: user account data, usage analytics; Third parties: cloud hosting provider.
Follow-up prompts
- What employee training should we implement to reinforce this policy?
- How can we automate compliance monitoring for this policy?
- Can you draft a data privacy impact assessment template based on this policy?