All prompts

Workflow/Featured

Run a GDPR and CCPA gap analysis

Scores your privacy program topic by topic against GDPR and CCPA, ranks the gaps by what regulators actually pursue rather than by article number, and outputs a 30/60/90 plan with named owners and a budget ask.

About 25 minadvancedIn-house, Privacy, Regulatory

Your prompt4,882 characters

Still to fill in: Company profile, What is in place today, Establishments and data subjects

RoleYou are a senior privacy counsel who has built programs at three SaaS companies and sat through two supervisory-authority inquiries. You score honestly (a YELLOW you can defend beats a GREEN nobody believes), you rank gaps by what regulators actually pursue, and you never write a remediation item without a named role and a date on it.What I needScore the privacy program below against GDPR and CCPA only, rank the gaps by enforcement risk, and give me a 30/60/90 plan I can take to the CEO.InputsCompany profile: Company profile In place today: What is in place today Scope: GDPR and CCPA only Establishments and data subjects: Establishments and data subjects Sensitive categories: None that we know ofHow to work this1. Score each topic separately; refuse a single overall grade. GDPR: lawful basis, records of processing, notices, rights handling, consent, processor contracts, transfers, risk assessments, security, breach response, retention. CCPA: notice at collection, the four consumer rights, opt-out signals, sensitive personal information, retention disclosure, service-provider terms, workforce. 2. Give each topic GREEN, YELLOW, or RED with a one-sentence reason, the specific gap, and the provision it maps to. "Partially compliant" is not a score. 3. Score only what What is in place today tells you. Anything you cannot assess is UNKNOWN, with a note on what you would need. 4. Rank the top five gaps by enforcement risk under Establishments and data subjects: likelihood times consequence, weighted toward what a caseworker can verify quickly, and say why each made it. 5. Build the plan in three waves: 1–30 for what ships without engineering, 31–60 operational, 61–90 structural, every item carrying a named role, a deliverable, and a date. "The privacy team" owns nothing. Close with the artifacts produced and a budget ask naming which items die unfunded.Close with these four sections, every time, without being askedAssumptions I made. Every assumption about controller and processor roles, which regimes reach this company, which authority would lead, and whether sensitive categories are processed. Mark each [verify] or [safe]; flag any score based on inference. Where this is weakest. The two or three scores most likely to be wrong, and the plan item most likely to slip, usually the one depending on a vendor answering or on engineering nobody committed. Name the topic and the item. What only you can decide. The calls I left to you, as options with tradeoffs. Hire a dedicated privacy lead: someone owns this and it survives turnover, at twelve weeks to hire and a visible headcount line, or run it through outside counsel plus a fractional consultant, which starts Monday and leaves nobody inside owning it. And: fix the public-facing layer first (notice, opt-out, requests), which a regulator sees first, or the contractual layer, which breaks in an incident. What would make this materially better. The input that would most improve the next pass: the vendor list with contract dates, any data map at all, committed engineering capacity, or whether a request deadline has been missed. Rank by impact.Output formatExecutive summary in three sentences: posture, top three risks, sequence. Two scorecards, GDPR and CCPA/CPRA, each a table of topic, score, current state, gap, provision. Top five by enforcement risk. Remediation plan in three waves, numbered, each with role, deliverable, date. Accountability artifacts. Budget ask. Then the four closing sections.Never do this- If this analysis would fit any SaaS company anywhere, it is too generic. It should read like someone looked at this company. - No hedging filler. Cut "arguably," "it should be noted," and "consider implementing": every plan item is an instruction with an owner. Do not tell me to consult an attorney; I am the privacy counsel. - Every article, section, deadline, and enforcement example must come from my inputs or carry [UNVERIFIED - confirm current text]. Never invent a citation, a fine figure, or a compliance deadline; this area moves faster than you do. - Where you do not have enough to score a topic, mark it UNKNOWN and say what you need. Do not smooth over the gap with a confident YELLOW. - Do not pad. A program with four real problems gets four. Length is not value; a scorecard padded with GREENs hides the RED.Before you answer- Did I score every topic separately, with no overall grade standing in for the detail? - Does every score trace to the inputs, or is it marked UNKNOWN? - Does every plan item carry a named role, a deliverable, and a date? - Are the top five ranked by enforcement risk, not article order, and would this be useless at a company with a different data map?

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

Assume one data subject complains and a supervisory authority caseworker opens a file on this company tomorrow. Working as the caseworker who drew it: which two findings do you ask about first, and what document do you request to prove or disprove each? Which finding converts from inquiry to enforcement fastest, and what would the company need to have in hand today to stop that? Reorder the priority list if the answer differs, and add a seven-day mitigation for the top item.
3

Go deeper

Pushes the work further once the basics are right.

Someone has to own this program before any of the findings close. Draft the one-page privacy program charter the CEO signs on day one: the named program owner and their authority, the steering group and its cadence, the approved budget, four success metrics that are measurable in ninety days, the escalation path for an incident or a regulator contact, and the quarterly reporting line to the board. Written to be handed to the audit committee without edits.

Before you run it

What to gather first

  • What data you hold, for whom, and whether you are controller or processor for each activity
  • Where your establishments are and where your data subjects sit
  • Vendor count and how many have current data processing terms
  • Whether you have ever missed a data subject request deadline
  • Engineering capacity actually committed to privacy work this quarter

Watch for

  • Privacy law and enforcement priorities change faster than any model's training. Treat every article number, deadline, fine figure, and enforcement example as a lead to verify against the current text, not as authority.
  • Cookie and tracking-technology consent is enforced under member-state rules that sit alongside GDPR, and it is one of the most active areas. Assess it separately or you will miss the thing most likely to generate a complaint.
  • Cross-border transfer paperwork is where programs quietly fail. Unknown SCC vintage and missing transfer assessments are findings a caseworker can confirm in an afternoon.
  • A scorecard with a missed request deadline in it is an admission. Think about privilege and framing before this document circulates outside legal, and about who receives it.
  • The model will score topics you never described. Any GREEN that does not trace to something you actually said should be treated as UNKNOWN until you check it.

What comes back

An executive summary in three sentences: posture, top three risks, recommended sequence. A GDPR scorecard and a CCPA/CPRA scorecard, each with topic, score, current state, specific gap, and the provision it maps to. The top five gaps ranked by enforcement risk with the reason each is on the list. A remediation plan in three waves, every item numbered with a named role, a deliverable, and a date. The accountability artifacts the plan produces. A budget and headcount ask stating what fails if it is not funded. Then assumptions, the shakiest scores, the calls left to you, and what would improve the next pass.

See an example of what you’ll get
Executive summary. Fanstop is YELLOW overall with five RED topics: international transfers, request handling, vendor data processing terms, retention, and the missing Article 30 record, and one that cannot be scored at all because no data inventory exists. The fastest-moving risks are the 61-day request response, which is a documented miss a complainant can point to, and the vendor paperwork, where 60% have no data processing terms at all and the rest sit on SCCs of unknown vintage. Ship the notice rewrite, the opt-out signal, and a request workflow with SLA tracking in the first thirty days; the vendor and transfer work is a full quarter. GDPR scorecard (abridged) | Topic | Score | Current state | Gap | Provision | |---|---|---|---|---| | Lawful basis | YELLOW | Implied across activities | No documented basis mapping per activity | Art. 6 | | Records of processing | RED | None | No Article 30 record exists in any form | Art. 30 | | Notices | YELLOW | Last updated June 2023 | Stale; missing rights detail, retention, and recipients | Arts. 13–14 | | Data subject rights | RED | Manual, GC-handled | One response took 61 days; no SLA tracking, no way to prove timeliness | Arts. 15–22 | | Processor contracts | RED | ~40% coverage | 60% of vendors have no data processing terms | Art. 28 | | International transfers | RED | Some SCCs, vintage unknown | No transfer assessments; no UK addendum | Chapter V | | Risk assessments | UNKNOWN | Cannot assess | No inventory, so high-risk processing cannot be identified | Art. 35 | | Security | YELLOW | SOC 2 in progress | Controls exist but are undocumented for privacy purposes | Art. 32 | | Breach response | YELLOW | IR plan exists | Never tested against the notification clock | Art. 33 | | Retention | RED | None defined | No schedule by data category | Art. 5(1)(e) | CCPA/CPRA scorecard (abridged) | Topic | Score | Current state | Gap | |---|---|---|---| | Notice at collection | YELLOW | Generic | Missing categories, purposes, retention | | Right to correct | RED | Not offered | Not implemented at all | | Opt out of sale/sharing | RED | No link | No mechanism for cross-context behavioral advertising | | Global opt-out signal | RED | Not honored | Site does not detect or act on browser signals | | Retention disclosure | RED | Absent | Not stated in the notice | | Service-provider terms | YELLOW | Inconsistent | No standard clause set across vendors | | Employee and B2B | YELLOW | No notice provided | Workforce notice missing | *(Provision citations for the CCPA table are [UNVERIFIED - confirm current section numbers before this document leaves legal].)* Top five, ranked by enforcement risk 1. The 61-day request response. Documented, provable, and exactly what a single complaint turns into a file. Nothing else on this list is as easy for a caseworker to confirm. 2. Transfer paperwork of unknown vintage. Verifiable from your own contracts in an afternoon, and it reaches every EU customer relationship. 3. No global opt-out signal. Publicly testable from outside the company by anyone with a browser. 4. Vendor processing terms at 40% coverage. Low visibility until a vendor has an incident, at which point it is the first thing anyone asks for. 5. No Article 30 record. Rarely the opening question, but it is the first document requested once a file is open, and its absence colors everything after. Remediation plan *Days 1–30: ships without engineering* 1. Name the privacy owner and give them written authority. (CEO + GC, day 1) 2. Rewrite the privacy notice for GDPR, UK GDPR, and current US state requirements. (Privacy lead + outside counsel, day 21) 3. Stand up request intake with SLA tracking and an auditable log. (Privacy lead, day 30) 4. Freeze deletion of anything within scope until a retention schedule exists. (Privacy lead, day 7) 5. Inventory every vendor with a contract date and current terms status. (Privacy lead + Procurement, day 30) *Days 31–60: operational* 6. Build the Article 30 record across all processing activities. (Privacy lead, day 60) 7. Replace or paper vendor terms; standardize the SCC module set and UK addendum. (Privacy lead + Procurement, day 60) 8. Transfer assessments for the top ten destinations. (Privacy lead + outside counsel, day 60) 9. Publish the opt-out link and implement global opt-out signal detection. (Privacy lead + Eng, day 45) 10. Retention schedule by data category. (Privacy lead + Eng, day 60) *Days 61–90: structural* 11. Risk-assessment process, run against the three highest-risk activities. (Privacy lead, day 90) 12. Tabletop the breach-notification clock end to end. (Privacy lead + CISO, day 90) 13. Workforce notice and internal request process. (Privacy lead + HR, day 80) 14. Right-to-correct workflow. (Privacy lead + Eng, day 85) 15. Quarterly privacy dashboard for the CEO and audit committee. (Privacy lead, day 90) Accountability artifacts. Article 30 record; risk-assessment template; request SOP with the log; vendor terms library; transfer assessment template; retention schedule; workforce notice; vendor onboarding checklist. Budget and headcount ask. A director-level privacy lead (or a fractional lead plus outside counsel retainer at roughly $250K a year), request tooling at about $60K a year, and one-time outside counsel work on transfers and vendor terms at roughly $75K. Year one, approximately $385K. Without the named owner, items 6 through 10 will not ship. They need someone whose full-time job is chasing 120 vendors. --- Assumptions I made. That Fanstop is a processor for retailer purchase data and a controller for its own marketing and HR data [verify - this drives half the scorecard]. That the Irish DPC would be lead because Dublin is the main establishment [verify - depends on where decisions are actually made, not where the entity sits]. That no sensitive categories are processed; you told me there is no inventory, so this is genuinely unknown and I have scored it UNKNOWN rather than GREEN [verify]. Where this is weakest. The security score. YELLOW rests on "SOC 2 in progress," which tells me about a control framework, not about whether the measures are appropriate to the processing. A caseworker would ask a different question than an auditor does. Second: items 9 and 14 both depend on engineering capacity nobody has committed, and they are the two most likely to slip past ninety days. What only you can decide. Hire a dedicated privacy lead: someone owns this, it survives turnover, and it takes twelve weeks to hire plus a visible headcount line, or run the program through outside counsel and a fractional consultant, which starts Monday and costs more per hour, and leaves nobody inside the company owning it when the engagement ends. Separately: fix the public-facing layer first (notice, opt-out link, request workflow), which is what a regulator and a plaintiff's firm see first, or fix the contractual layer first (vendor terms, transfer paperwork), which is what actually breaks when a vendor has an incident. What would make this materially better. (1) The vendor list with contract dates and terms status: items 7 and 8 are unschedulable without it. (2) Whatever passes for a data map, even an engineering diagram, so the risk-assessment topic can be scored at all. (3) Confirmation of whether any request has been missed besides the 61-day one, since that changes the first item on the risk list from a single incident to a pattern.
Why this prompt is built the way it is
## Framework 1. **Score by topic, never overall.** A single grade is a number nobody can act on. Each requirement gets its own score. 2. **GDPR coverage.** Lawful basis, records of processing, notices, data subject rights, consent quality, processor contracts, international transfers, risk assessments, security, breach response, representative and DPO thresholds, retention. 3. **CCPA/CPRA coverage.** Notice at collection, know, delete, correct, opt out of sale and sharing, global opt-out signals, sensitive personal information, retention disclosure, service-provider terms, and employee and B2B coverage. 4. **GREEN / YELLOW / RED, with the specific gap.** "Partially compliant" is not a score. Name what is missing and what provision it maps to. 5. **Score only what you were told.** A topic you cannot assess is UNKNOWN, with a note on what you would need. Guessing produces a scorecard nobody can defend. 6. **Rank by enforcement risk.** Likelihood times consequence, using what authorities are actually pursuing, not the order of the articles. 7. **Three waves, named owners.** Days 1–30 for what ships without engineering, 31–60 for operational work, 61–90 for structural program work. "The privacy team" owns nothing. 8. **Documented, or it did not happen.** Both regimes reward demonstrable compliance; the plan should produce artifacts, not intentions.