AI Tools for Work

Draft a personal data processing policy with Claude

Updated: 2026-09-26

A personal data processing policy is only as good as its description of your actual processes. Claude is well suited to drafting one: it holds your process notes, internal procedures and the text of the law in a single context and writes a structured document without padding. The draft and a compliance checklist take about 45 minutes. The legal references are the part to treat with suspicion, and the prompt tells the model to leave them as markers.

Map the processes before you write

List every process that touches personal data: hiring, payroll, the CRM, the website, video surveillance, and anything specific to your business. For each, write which data it collects, where it is stored and who receives it outside the company. This map does most of the work. A policy written without it describes a generic company, and a regulator or an employee reading it will notice.

Then decide which regime applies: GDPR, local data protection law, or both. The model mixes requirements across regimes if you leave this open.

Give Claude the sources

Create a Project for the policy and load the current text of the applicable law and your internal procedures. Claude reads large documents in full, so the whole statute can sit next to your notes. Replace names of responsible people and details of your access scheme with roles before uploading if you use a personal plan.

Role: you are a data protection lawyer working under {{GDPR, local law, or both}}. Context: the company {{what it does, number of employees}}. Processes with personal data: {{process 1 and list of data}}, {{process 2}}, {{process 3}}. Storage systems: {{list}}. Transfers to third parties: {{to whom and why}}. Task: draft a personal data processing policy and a compliance checklist. For each process: list of data, purpose, legal basis, retention period, who has access, to whom it is transferred, data subject rights and how they exercise them. Where a legal provision is needed, write [PROVISION, verify] instead of quoting from memory. Separately, give a short plain-language guide for employees. Format: a structured document with numbered sections, no long dashes, up to 1,200 words. The checklist as a table requirement | present or missing | what to do.

The transfers field is often incomplete on the first pass. Payroll providers, cloud storage, accountants and delivery services all receive personal data, and each one belongs in the list.

Working with the checklist

The checklist is where the draft becomes a plan. Each "missing" row is a gap between what the law requires and what the company does: no retention period for CCTV footage, no procedure for a data subject request, no agreement with a processor. Some of these are paperwork; some need a decision from management. Separate them before the approval meeting.

What to do

  1. List every process that handles personal data, with the data, storage and recipients.
  2. State which law applies: GDPR, local law or both.
  3. Load the current law and your internal procedures into a Claude Project, anonymized where needed.
  4. Run the prompt and get the draft policy, the checklist and the employee guide.
  5. Check every [PROVISION, verify] marker in the current version of the law and replace it.
  6. Get approval from management and HR, adopt the policy by internal order and collect employee signatures.

When it is done

The policy describes each process with its data list, legal basis, retention period and owner; every provision is verified; the policy is approved; and employees have been briefed. The plain-language guide helps with the last step, since few people read a full policy.

Plans

A 45-minute drafting session with a statute in context uses quota fast, because Claude's limit depends on conversation size. Pro at 20 USD per month (17 with annual billing) gives five times the free plan's messages and Projects; Team at 25 USD per seat with annual billing keeps team data out of training by default. See Claude pricing. On personal plans, check Settings, Privacy before uploading. The lawyer's version of this task is on the privacy policy page for lawyers, and Claude vs ChatGPT covers the difference for long legal documents.

FAQ

Can Claude write a GDPR privacy policy for my company?

It drafts a policy process by process: data list, purpose, legal basis, retention, access, transfers and data subject rights, plus a compliance checklist. Every legal provision is left as [PROVISION, verify] for you to check.

Why does the AI mix up GDPR and local law?

The model blends requirements from different regimes unless told which applies. State GDPR, local law or both in the prompt and check every provision in the current text.

How long does it take to draft a data processing policy?

About 45 minutes for the draft and checklist, if you arrive with a description of each process that handles personal data. Approval, the internal order and employee sign-off take longer.

Sources

Useful pages

AI tools weekly for your role

One email a week: new tools, price changes and one tested prompt for your job. Free, unsubscribe in one click.

Need an AI agent for your task?

An agent built around your workflow: we pick the models and tools and connect them to your systems.

Describe your task