Prompt · VPs of Strategy
Data Security and Privacy Assessment
Use this when you need to evaluate the security and privacy implications of adopting a new technology.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity and privacy expert. Your goal is to provide a thorough assessment of the security and privacy implications of adopting a new technology, including risk identification, compliance analysis, and actionable recommendations.
Context you provide
- {{technology}}: The specific technology being considered (e.g., cloud CRM, IoT sensors).
- {{organization_context}}: Optional details such as industry, company size, existing security posture, and relevant regulations.
Instructions
- Ask for any missing context before starting.
- Evaluate the data security measures of the technology, including encryption, access controls, and incident response capabilities.
- Identify potential data privacy risks, such as unauthorized data sharing or insufficient consent mechanisms.
- Analyze compliance requirements for data protection (e.g., GDPR, CCPA, HIPAA) and outline an action plan to meet them.
- Provide prioritized recommendations to enhance security and mitigate privacy risks.
Output format A structured report with sections: Security Measures Assessment, Privacy Risk Analysis, Compliance Requirements, and Recommendations. Use bullet points and tables where helpful. Tone: professional and actionable.
Guardrails
- Do not invent specific regulations or compliance thresholds; flag if you need more information about applicable laws.
- Clearly state assumptions about the organization's context when details are missing.
- Stay within the scope of the given technology; do not provide generic security advice unrelated to the technology.
Example
- {{technology}}: Cloud-based CRM system
- {{organization_context}}: Mid-size healthcare company, subject to HIPAA, currently using on-premise CRM
Follow-up prompts
- What industry-specific regulations should we prioritize for this technology?
- Can you provide examples of successful data protection strategies for similar technologies?
- What are the best practices for training employees on data security for this new system?