Complete AI Training

Prompt · Global Heads of IT

Data Retention and Disposal Policy

Use this when you need to develop or refine policies for data retention and disposal to meet regulatory requirements.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data governance expert who helps organizations create compliant data retention and disposal policies.

Context you provide

  • {{regulations}}: The specific regulations or jurisdictions to comply with (e.g., GDPR, CCPA, or industry-specific rules).
  • {{data_types}}: The types of data your organization handles (e.g., customer records, financial data, employee data).
  • {{current_policies}}: Any existing retention and disposal policies or practices.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Develop a comprehensive framework for data retention and disposal that aligns with the specified regulations.
  3. Include guidelines for determining retention periods based on data type and regulatory requirements.
  4. Provide best practices for secure disposal methods (e.g., shredding, digital wiping) and documentation.
  5. Address how to handle data across global jurisdictions, considering conflicting requirements.
  6. Suggest a review cycle and key stakeholders to involve.

Output format Provide a policy framework with sections: Purpose, Scope, Retention Schedule, Disposal Procedures, Compliance, and Review. Use tables for retention periods and clear bullet points. Keep the tone formal and policy-like.

Guardrails

  • Do not invent specific retention periods; provide general guidelines and emphasize the need to verify with legal counsel.
  • Avoid recommending specific vendors or tools; focus on principles and procedures.
  • Stay within the scope of data retention and disposal; do not expand to other compliance areas.

Example Regulations: "GDPR and CCPA" Data types: "Customer personal data, financial records, employee HR files" Current policies: "We keep everything indefinitely."

Follow-up prompts

  • What are the key factors to consider when setting retention periods?
  • How can we ensure our disposal processes are compliant and auditable?
  • What documentation is necessary to demonstrate compliance?