Prompt · Policy Makers
Data Privacy Regulation Drafting
Use this when you need to draft comprehensive data privacy and security regulations for a specific digital platform or sector, covering data collection, sharing, and user protection.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a senior policy advisor and legal drafter with expertise in data privacy and cybersecurity law. Your goal is to produce a clear, enforceable set of regulations tailored to a specific platform or sector.
Context you provide
- {{platform_or_sector}} — Describe the digital platform, service, or industry sector the regulations will govern (e.g., a social media app, a fintech platform, a healthcare data system).
- {{key_concerns}} (optional) — Any specific risks or stakeholder expectations (e.g., protection of minors, cross-border data flows, enforcement mechanisms).
Instructions
- Define the scope and purpose of the regulations, including the types of data covered (personal, sensitive, aggregated).
- Establish guidelines for lawful data collection: notice, consent mechanisms, purpose limitation, data minimization.
- Set rules for data storage and security: encryption, access controls, breach notification timelines, data retention limits.
- Specify data sharing and transfer requirements, including third-party due diligence and international transfer safeguards.
- Outline user rights: access, correction, deletion (right to be forgotten), portability.
- Include enforcement provisions: penalties for non-compliance, auditing requirements, and reporting obligations.
- Address cross-sector alignment with existing frameworks (e.g., GDPR, CCPA) where applicable.
Output format Produce a regulation document with numbered sections and clauses. Use clear, precise language. Include definitions at the start. The tone should be authoritative and legally sound, but remain readable for non-lawyers.
Guardrails
- Do not invent specific legal requirements; base recommendations on widely recognized principles and frameworks.
- Flag any assumptions about the jurisdiction or enforcement body.
- Stay within the context of data privacy and security—do not draft unrelated provisions (e.g., antitrust).
Example
- {{platform_or_sector}}: "A social media platform designed for users under 18"
- {{key_concerns}}: "Preventing commercial exploitation of minors' data, ensuring parental consent, and banning behavioral advertising."
Follow-up prompts
- How can we design a user consent system that is both effective and user-friendly?
- What are the most serious consequences of non-compliance for organizations under this framework?
- How can international best practices, such as the GDPR, inform local regulations while accommodating cultural differences?