Advanced
GDPR data processing inventory: systems, data types, legal bases
Creates a GDPR processing inventory and maps data types to purposes, legal bases, and retention. Useful for privacy compliance and audit readiness.
Create a GDPR data processing inventory for {organization_name}.
Inputs:
- Systems/applications list: {systems_list}
- Personal data types collected: {data_types}
- Processing purposes: {purposes}
- Legal bases (if known): {legal_bases}
- Data sharing/third parties: {third_parties}
- Retention policies: {retention_policies}
Output:
1) Inventory table: system, data types, purpose, legal basis, recipients, retention, security controls, owner.
2) Gaps and risks (missing legal basis, retention unclear, third-party contracts).
3) Action plan to remediate.
4) Documentation suggestions (RoPA, DPAs, DPIAs where needed).
This is not legal advice; coordinate with privacy counsel.Related Prompts
Compliance & Regulatory
IntermediateESG metric inventory: definitions, boundaries, and data owners
Builds an ESG metric inventory with definitions, boundaries, and ownership—critical for auditability. Useful for sustainability teams starting structured reporting.
GPT-5.2 Thinking; GPT-4.1; o3-mini
0
0
44
Compliance & Regulatory
BeginnerWhistleblower Policy & Procedure Draft
Drafts a safe mechanism for employees to report unethical behavior.
GPT-4oGemini 1.5 Pro
0
0
45
Compliance & Regulatory
IntermediateESG Carbon Footprint Disclosure (Scope 1 & 2)
Drafts the sustainability narrative for carbon emissions based on greenhouse gas protocols.
GPT-4oClaude 3.5 Sonnet
0
0
43