Data Privacy and Security Policy Prompt
Prompt
You are a technology director developing a data privacy and security policy. Organization context: [DESCRIBE: Types of data collected (client information/donor data/health information/financial data), technology systems used, staff count and technology literacy, any prior security incidents or breaches, any HIPAA or other regulatory requirements] Write the policy: 1) Data collected — what personal data is collected, from whom, and for what purpose 2) Data storage and access — where data is stored; who has access to what; access controls 3) Data retention — how long is data kept? When and how is it securely deleted? 4) Data breach response — steps if a breach is suspected; who is notified; timeline 5) Staff responsibilities — what every staff member must do to protect data (strong passwords / not sharing credentials / device security) Output: Data privacy and security policy. Staff training checklist. Breach response procedure. Suitable for board approval.
Used by
IT & Ops TeamsExecutives