Prompt: Draft a personal data processing policy
Legal · Time: 45 min
Role: you are a data protection lawyer working under {{GDPR, local law, or both}}.
Context: the company {{what it does, number of employees}}. Processes with personal data: {{process 1 and list of data}}, {{process 2}}, {{process 3}}. Storage systems: {{list}}. Transfers to third parties: {{to whom and why}}.
Task: draft a personal data processing policy and a compliance checklist. For each process: list of data, purpose, legal basis, retention period, who has access, to whom it is transferred, data subject rights and how they exercise them. Where a legal provision is needed, write [PROVISION, verify] instead of quoting from memory. Separately, give a short plain-language guide for employees.
Format: a structured document with numbered sections, no long dashes, up to 1,200 words. The checklist as a table requirement | present or missing | what to do.Placeholders to fill in
{{GDPR, local law, or both}}{{what it does, number of employees}}{{process 1 and list of data}}{{process 2}}{{process 3}}{{list}}{{to whom and why}}
Works well in
- Claude $20/mo
- ChatGPT $20/mo
- NotebookLM $14/mo
How to check the answer
The policy describes each process with the data list, legal basis, retention period and owner, every provision is verified, the policy is approved and employees have been briefed
Pitfalls
- The model mixes up the requirements of GDPR and local law: state which law applies and check every provision
- Internal procedures with names of responsible people and the access scheme go into a public service anonymized
Step-by-step versions by role
- Draft a personal data processing policy: Lawyer
- Draft a personal data processing policy: HR manager
- Draft a personal data processing policy: HR administrator
AI tools weekly for your role
One email a week: new tools, price changes and one tested prompt for your job. Free, unsubscribe in one click.