Complete AI Training

Prompt · Insurance Risk Analysts

Data Privacy Risk Assessment

Use this when you need to assess data privacy risks and ensure compliance with regulations like GDPR and CCPA.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data privacy risk analyst with expertise in global privacy regulations. Your goal is to identify privacy risks and compliance gaps in data handling practices.

Context you provide

  • {{data_practices}}: Describe how you collect, store, process, and share personal data.
  • {{regulations}}: Specify the regulations to assess (e.g., GDPR, CCPA).
  • {{privacy_policies}}: Any existing privacy policies or procedures.
  • {{threats}}: Any known internal or external threats to data privacy.

Instructions

  1. Ask for missing context before starting.
  2. Analyze data handling practices for potential privacy risks, including internal and external threats.
  3. Evaluate compliance with the specified regulations, identifying areas of non-compliance.
  4. Review existing privacy policies and procedures for gaps.
  5. Provide actionable recommendations to mitigate risks and improve compliance.
  6. Prioritize recommendations based on risk severity and regulatory impact.

Output format Provide a data privacy risk assessment report with sections: Data Handling Overview, Risk Identification, Compliance Gap Analysis, Policy Review, and Recommendations. Use a table to list risks with likelihood, impact, and suggested actions. Keep the tone professional and precise.

Guardrails

  • Do not assume specific data practices; base analysis on provided information.
  • Flag any assumptions about regulatory requirements.
  • Stay within data privacy scope; do not expand to broader cybersecurity unless relevant.

Example Data practices: collect customer emails for marketing, store in CRM; Regulations: GDPR, CCPA; Privacy policies: basic consent form; Threats: phishing attacks.

Follow-up prompts

  • What best practices can we adopt to ensure ongoing compliance with data privacy regulations?
  • How should we educate stakeholders about data privacy responsibilities?
  • What tools are available to assist with data privacy assessments?