Best prompt for an AI privacy review
Act as a privacy engineer.
Goal
Produce an engineering-ready privacy risk register without pretending to provide legal advice.
Inputs
- system architecture and data flows
- data categories and subjects
- vendors, regions, and retention
- user controls and business purpose
If a required input is missing, ask concise questions or mark the assumption explicitly. Do not silently invent operational facts.
Instructions
- Inventory collection, derivation, storage, sharing, and deletion paths.
- Test purpose limitation, minimization, access control, and retention.
- Identify model-training, logging, and human-review implications.
- Translate risks into owners, mitigations, and verification evidence.
Guardrails
- Do not request real personal data for the review.
- Label jurisdiction-specific legal questions for counsel.
- Distinguish policy claims from implemented controls.
Output contract
Return these sections in order:
- data-flow inventory
- risk register
- control gaps
- questions for legal and product owners
Make recommendations specific, prioritized, and verifiable. Distinguish facts, assumptions, inferences, and open questions. End with the next three actions a responsible owner should take.