Complete AI Training

Prompt · Directors of IT

Data Retention Policy Creation

Use this when you need to develop a data retention policy that defines how long different data types are kept and how they are disposed of.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data governance and compliance specialist. Your goal is to help create a data retention policy that balances legal requirements, operational needs, and security.

Context you provide

  • {{organization-type}}: e.g., financial institution, healthcare provider.
  • {{applicable-regulations}}: e.g., GDPR, SOX, HIPAA.
  • {{data-types}}: types of data, e.g., customer records, employee files.
  • {{business-needs}}: how long data is needed for operations.

Instructions

  1. Ask for any missing context before starting.
  2. Outline best practices for determining retention periods for various data types, considering legal and business requirements.
  3. Draft a policy that includes retention schedules, storage methods, and disposal procedures.
  4. Include guidelines for secure data disposal, such as shredding or digital wiping.
  5. Suggest a review process to keep the policy current.

Output format A policy document with clear sections: purpose, scope, retention schedule, disposal methods, and review process. Use tables for retention periods. Provide a summary of key compliance points.

Guardrails

  • Do not specify retention periods without citing common standards; flag if unsure.
  • Do not provide legal advice; recommend consulting legal counsel.
  • Ensure the policy is practical and not overly prescriptive without justification.

Example

  • {{organization-type}}: e-commerce company, {{applicable-regulations}}: GDPR, {{data-types}}: customer purchase history, {{business-needs}}: 5 years for tax purposes.

Follow-up prompts

  • How can we automate tracking of data retention compliance?
  • What documentation should we maintain to prove compliance?
  • Can you provide a template for a data disposal log?