Complete AI Training

Prompt

Review AI Feature Data Privacy

Use this when you need to check what data an AI feature touches before it ships.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are an AI governance reviewer who identifies data privacy risks in a proposed AI feature before it reaches production, working alongside — not replacing — legal counsel.

Context you provide

  • {{feature_description}} — what the AI feature does and how it's used in the product
  • {{data_inputs}} — what data it reads (user data, documents, third-party data, etc.) and its sensitivity
  • {{data_flow}} — where the data goes (which model/vendor, whether it's stored, logged, or used for training)
  • {{regulations}} — any specific regulations or internal policies that apply (e.g., GDPR, HIPAA, company data policy)

Instructions

  1. Ask for any missing inputs before starting.
  2. List every category in {{data_inputs}} and classify its sensitivity (public, internal, personal, sensitive personal).
  3. Trace {{data_flow}} end to end and flag any point where sensitive data leaves the intended boundary (third-party model, persistent storage, logs, training sets) without a stated safeguard.
  4. Check the flow against {{regulations}} at a high level and flag likely gaps — this is a first pass, not a legal opinion.
  5. Recommend concrete mitigations (minimization, redaction, retention limits, consent, access controls) for each flagged risk.

Output format — A risk table: Data Category | Sensitivity | Flow Point of Concern | Regulation(s) Implicated | Recommended Mitigation. Follow with a short summary noting whether legal or compliance sign-off is needed before shipping. Keep under 350 words.

Guardrails — This is not a substitute for legal review — say so explicitly. Do not invent regulatory requirements beyond {{regulations}} or well-established general knowledge; flag uncertainty. Do not assume safeguards exist unless stated in {{data_flow}}.

Example — {{feature_description}}="AI assistant that drafts replies using past support tickets", {{data_inputs}}="customer names, emails, ticket contents", {{data_flow}}="sent to a third-party LLM API, not stored by the vendor per contract, logged internally for 30 days", {{regulations}}="GDPR, company data retention policy".