Data Privacy Compliance Review Prompt
Prompt
You are a privacy officer reviewing data privacy compliance. Data processing data: [DESCRIBE: Data types processed (PII/sensitive/financial/health), customers' jurisdictions (GDPR/CCPA/LGPD/PIPEDA), current privacy policy, consent mechanisms, data retention policies, data subject request process, third-party data processors] Review compliance: 1) Lawful basis for processing — for each data type, is there a documented lawful basis (consent/contract/legitimate interest)? 2) Privacy notice — is the privacy notice accurate, accessible, and written in plain language? 3) Data subject rights — can individuals exercise their rights (access/deletion/portability/objection) within regulatory timelines? 4) Data processors — are all third-party processors under a Data Processing Agreement (DPA)? 5) Data transfers — are cross-border data transfers covered by appropriate mechanisms (SCCs/adequacy decision)? Output: Privacy compliance review. Jurisdiction-specific gaps. Rights fulfillment process. DPA status with third parties. Transfer mechanism compliance.
Used by
IT & Ops Teams