All prompts
Workflow/Featured
Run a GDPR and CCPA gap analysis
Scores your privacy program topic by topic against GDPR and CCPA, ranks the gaps by what regulators actually pursue rather than by article number, and outputs a 30/60/90 plan with named owners and a budget ask.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
Executive summary. Fanstop is YELLOW overall with five RED topics: international transfers, request handling, vendor data processing terms, retention, and the missing Article 30 record, and one that cannot be scored at all because no data inventory exists. The fastest-moving risks are the 61-day request response, which is a documented miss a complainant can point to, and the vendor paperwork, where 60% have no data processing terms at all and the rest sit on SCCs of unknown vintage. Ship the notice rewrite, the opt-out signal, and a request workflow with SLA tracking in the first thirty days; the vendor and transfer work is a full quarter.
GDPR scorecard (abridged)
| Topic | Score | Current state | Gap | Provision |
|---|---|---|---|---|
| Lawful basis | YELLOW | Implied across activities | No documented basis mapping per activity | Art. 6 |
| Records of processing | RED | None | No Article 30 record exists in any form | Art. 30 |
| Notices | YELLOW | Last updated June 2023 | Stale; missing rights detail, retention, and recipients | Arts. 13–14 |
| Data subject rights | RED | Manual, GC-handled | One response took 61 days; no SLA tracking, no way to prove timeliness | Arts. 15–22 |
| Processor contracts | RED | ~40% coverage | 60% of vendors have no data processing terms | Art. 28 |
| International transfers | RED | Some SCCs, vintage unknown | No transfer assessments; no UK addendum | Chapter V |
| Risk assessments | UNKNOWN | Cannot assess | No inventory, so high-risk processing cannot be identified | Art. 35 |
| Security | YELLOW | SOC 2 in progress | Controls exist but are undocumented for privacy purposes | Art. 32 |
| Breach response | YELLOW | IR plan exists | Never tested against the notification clock | Art. 33 |
| Retention | RED | None defined | No schedule by data category | Art. 5(1)(e) |
CCPA/CPRA scorecard (abridged)
| Topic | Score | Current state | Gap |
|---|---|---|---|
| Notice at collection | YELLOW | Generic | Missing categories, purposes, retention |
| Right to correct | RED | Not offered | Not implemented at all |
| Opt out of sale/sharing | RED | No link | No mechanism for cross-context behavioral advertising |
| Global opt-out signal | RED | Not honored | Site does not detect or act on browser signals |
| Retention disclosure | RED | Absent | Not stated in the notice |
| Service-provider terms | YELLOW | Inconsistent | No standard clause set across vendors |
| Employee and B2B | YELLOW | No notice provided | Workforce notice missing |
*(Provision citations for the CCPA table are [UNVERIFIED - confirm current section numbers before this document leaves legal].)*
Top five, ranked by enforcement risk
1. The 61-day request response. Documented, provable, and exactly what a single complaint turns into a file. Nothing else on this list is as easy for a caseworker to confirm.
2. Transfer paperwork of unknown vintage. Verifiable from your own contracts in an afternoon, and it reaches every EU customer relationship.
3. No global opt-out signal. Publicly testable from outside the company by anyone with a browser.
4. Vendor processing terms at 40% coverage. Low visibility until a vendor has an incident, at which point it is the first thing anyone asks for.
5. No Article 30 record. Rarely the opening question, but it is the first document requested once a file is open, and its absence colors everything after.
Remediation plan
*Days 1–30: ships without engineering*
1. Name the privacy owner and give them written authority. (CEO + GC, day 1)
2. Rewrite the privacy notice for GDPR, UK GDPR, and current US state requirements. (Privacy lead + outside counsel, day 21)
3. Stand up request intake with SLA tracking and an auditable log. (Privacy lead, day 30)
4. Freeze deletion of anything within scope until a retention schedule exists. (Privacy lead, day 7)
5. Inventory every vendor with a contract date and current terms status. (Privacy lead + Procurement, day 30)
*Days 31–60: operational*
6. Build the Article 30 record across all processing activities. (Privacy lead, day 60)
7. Replace or paper vendor terms; standardize the SCC module set and UK addendum. (Privacy lead + Procurement, day 60)
8. Transfer assessments for the top ten destinations. (Privacy lead + outside counsel, day 60)
9. Publish the opt-out link and implement global opt-out signal detection. (Privacy lead + Eng, day 45)
10. Retention schedule by data category. (Privacy lead + Eng, day 60)
*Days 61–90: structural*
11. Risk-assessment process, run against the three highest-risk activities. (Privacy lead, day 90)
12. Tabletop the breach-notification clock end to end. (Privacy lead + CISO, day 90)
13. Workforce notice and internal request process. (Privacy lead + HR, day 80)
14. Right-to-correct workflow. (Privacy lead + Eng, day 85)
15. Quarterly privacy dashboard for the CEO and audit committee. (Privacy lead, day 90)
Accountability artifacts. Article 30 record; risk-assessment template; request SOP with the log; vendor terms library; transfer assessment template; retention schedule; workforce notice; vendor onboarding checklist.
Budget and headcount ask. A director-level privacy lead (or a fractional lead plus outside counsel retainer at roughly $250K a year), request tooling at about $60K a year, and one-time outside counsel work on transfers and vendor terms at roughly $75K. Year one, approximately $385K. Without the named owner, items 6 through 10 will not ship. They need someone whose full-time job is chasing 120 vendors.
---
Assumptions I made. That Fanstop is a processor for retailer purchase data and a controller for its own marketing and HR data [verify - this drives half the scorecard]. That the Irish DPC would be lead because Dublin is the main establishment [verify - depends on where decisions are actually made, not where the entity sits]. That no sensitive categories are processed; you told me there is no inventory, so this is genuinely unknown and I have scored it UNKNOWN rather than GREEN [verify].
Where this is weakest. The security score. YELLOW rests on "SOC 2 in progress," which tells me about a control framework, not about whether the measures are appropriate to the processing. A caseworker would ask a different question than an auditor does. Second: items 9 and 14 both depend on engineering capacity nobody has committed, and they are the two most likely to slip past ninety days.
What only you can decide. Hire a dedicated privacy lead: someone owns this, it survives turnover, and it takes twelve weeks to hire plus a visible headcount line, or run the program through outside counsel and a fractional consultant, which starts Monday and costs more per hour, and leaves nobody inside the company owning it when the engagement ends. Separately: fix the public-facing layer first (notice, opt-out link, request workflow), which is what a regulator and a plaintiff's firm see first, or fix the contractual layer first (vendor terms, transfer paperwork), which is what actually breaks when a vendor has an incident.
What would make this materially better. (1) The vendor list with contract dates and terms status: items 7 and 8 are unschedulable without it. (2) Whatever passes for a data map, even an engineering diagram, so the risk-assessment topic can be scored at all. (3) Confirmation of whether any request has been missed besides the 61-day one, since that changes the first item on the risk list from a single incident to a pattern.
Why this prompt is built the way it is
## Framework
1. **Score by topic, never overall.** A single grade is a number nobody can act on. Each requirement gets its own score.
2. **GDPR coverage.** Lawful basis, records of processing, notices, data subject rights, consent quality, processor contracts, international transfers, risk assessments, security, breach response, representative and DPO thresholds, retention.
3. **CCPA/CPRA coverage.** Notice at collection, know, delete, correct, opt out of sale and sharing, global opt-out signals, sensitive personal information, retention disclosure, service-provider terms, and employee and B2B coverage.
4. **GREEN / YELLOW / RED, with the specific gap.** "Partially compliant" is not a score. Name what is missing and what provision it maps to.
5. **Score only what you were told.** A topic you cannot assess is UNKNOWN, with a note on what you would need. Guessing produces a scorecard nobody can defend.
6. **Rank by enforcement risk.** Likelihood times consequence, using what authorities are actually pursuing, not the order of the articles.
7. **Three waves, named owners.** Days 1–30 for what ships without engineering, 31–60 for operational work, 61–90 for structural program work. "The privacy team" owns nothing.
8. **Documented, or it did not happen.** Both regimes reward demonstrable compliance; the plan should produce artifacts, not intentions.