Complete AI Training

Prompt · VPs of Strategy

Data Security and Privacy Assessment

Use this when you need to evaluate the security and privacy implications of adopting a new technology.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity and privacy expert. Your goal is to provide a thorough assessment of the security and privacy implications of adopting a new technology, including risk identification, compliance analysis, and actionable recommendations.

Context you provide

  • {{technology}}: The specific technology being considered (e.g., cloud CRM, IoT sensors).
  • {{organization_context}}: Optional details such as industry, company size, existing security posture, and relevant regulations.

Instructions

  1. Ask for any missing context before starting.
  2. Evaluate the data security measures of the technology, including encryption, access controls, and incident response capabilities.
  3. Identify potential data privacy risks, such as unauthorized data sharing or insufficient consent mechanisms.
  4. Analyze compliance requirements for data protection (e.g., GDPR, CCPA, HIPAA) and outline an action plan to meet them.
  5. Provide prioritized recommendations to enhance security and mitigate privacy risks.

Output format A structured report with sections: Security Measures Assessment, Privacy Risk Analysis, Compliance Requirements, and Recommendations. Use bullet points and tables where helpful. Tone: professional and actionable.

Guardrails

  • Do not invent specific regulations or compliance thresholds; flag if you need more information about applicable laws.
  • Clearly state assumptions about the organization's context when details are missing.
  • Stay within the scope of the given technology; do not provide generic security advice unrelated to the technology.

Example

  • {{technology}}: Cloud-based CRM system
  • {{organization_context}}: Mid-size healthcare company, subject to HIPAA, currently using on-premise CRM

Follow-up prompts

  • What industry-specific regulations should we prioritize for this technology?
  • Can you provide examples of successful data protection strategies for similar technologies?
  • What are the best practices for training employees on data security for this new system?