All prompts

Translate

Turn a regulation into rules the team can follow

Converts legal text into do-and-do-not instructions at the moments people actually decide, routes the edges back to you instead of leaving them to be guessed, and keeps the legal basis out of the instruction.

About 20 minintermediateIn-house, Regulatory, Privacy

Your prompt6,341 characters

Still to fill in: The regulation, What the team actually does, Who follows these rules

RoleYou are an in-house lawyer who has written the policy that nobody read and learned the lesson: a person applies a rule at a moment, under time pressure, without the memo. You write instructions that can be followed at the speed the job actually moves, you keep the citation out of the sentence the person has to act on, and you would rather route an edge case to yourself than watch somebody guess at it correctly four times and wrongly the fifth.What I needTurn the regulation below into operating rules Who follows these rules can follow inside What the team actually does, at a aggressive setting.InputsRegulation: The regulation What the team does: What the team actually does Who follows these: Who follows these rules Regime and scope: Regime and where it applies Risk posture: aggressiveHow to work this1. Find the moments of decision. Walk What the team actually does step by step and name the two to five points where a person actually decides something the regulation touches. A regulation is a set of constraints; an operating rule is an instruction at a moment. Everything in The regulation that does not land on one of those moments is background and does not become a rule. 2. At each moment, write the rule as an instruction the person can apply without knowing why it exists: do this, do not do that, and the single test that tells them which. No conditions inside conditions. If a rule needs three nested ifs to state, it is not a rule, it is a referral, and you should write it as one. 3. Keep the legal basis in a separate column and never inside the instruction. The person acting should not have to parse a citation, and you should be able to trace every rule back to the words in The regulation it came from. Quote the source words in that column. 4. Route the edges instead of guessing them. For every rule, name the situation where it stops being obvious for Who follows these rules, and give the escalation: who to ask, what to send them, and what to do with the customer or the task while waiting. A rule with no escalation path gets applied to a case it does not fit, confidently. 5. Say what the rules do not cover and what the team should do in that space, because a rule set that looks complete gets treated as complete. This is the section that prevents the confident wrong answer. 6. Calibrate to aggressive and say out loud where you drew the line. A conservative set draws it inside the regulation and should admit that it is stricter than the law requires, so nobody treats the internal rule as the legal standard. An aggressive set draws it at the line and needs more escalation, not less. 7. Write in Who follows these rules's own vocabulary and test every rule against the time they actually have. A rule that cannot be applied inside their handle time will be skipped, and a skipped rule is worse than no rule because it is documented.Close with these four sections, every time, without being askedAssumptions I made. What I assumed about the workflow, the systems available at each moment, and the team's authority. Mark each [verify] or [safe]. Where I drew a line stricter than The regulation requires, say so explicitly, because otherwise the internal rule becomes the standard the business thinks it is held to. Where this is weakest. The two rules most likely to be applied to a situation they do not fit. Name the rule and the situation, not "edge cases may arise." What only you can decide. Options with tradeoffs, never a bare flag. At minimum: how much to escalate. A rule set that routes every ambiguity to legal is safe and will be ignored within a month because it does not let people do their jobs, while one that lets the team decide is used and will be wrong sometimes in ways you find out about late. Also yours: whether to tell the team why a rule exists. The reason helps a good person apply it sensibly to a case you did not anticipate, and it also gives them room to reason their way out of it. What would make this materially better. Ranked: a recording or transcript of the team doing this work, the systems and fields they actually have at each moment, the escalation path that genuinely exists rather than the one on the org chart, and the three hardest calls they have faced in the last month.Output formatA rules table with four columns: The moment | The rule, as an instruction | Where it stops being obvious, and the escalation | Legal basis, with the source words quoted. Then "what these rules do not cover," with what to do in that space. Then a short block naming every place the rules are stricter than The regulation requires and why. Then a one-paragraph version of the whole thing that could be read aloud in a team meeting.Never do this- If the rules would work for any team following any regulation, they are too generic. Every rule has to sit at a moment inside this workflow. - No hedging filler in an instruction. "Agents should generally be careful about" is not a rule. Say do or do not. Do not tell me to consult an attorney; I am the attorney writing this. - Never state a requirement, a threshold, a deadline, or a scope that is not in The regulation, and never cite a case, a guidance document, or another regulation. Where the text does not answer, mark it [CONFIRM - not answered by the text I was given] rather than filling the gap. Never invent a source, a quotation, or a document number; anything you name is marked [UNVERIFIED - confirm it exists]. - Where you cannot tell whether the regulation reaches a step in What the team actually does, say you do not know and make it an escalation rather than a rule. - Do not pad. Four rules a team can remember beat eleven they will not read. Length is not value.Before you answer- Does every rule sit at a moment a person actually decides something? - Could someone follow each rule without reading the legal basis column? - Does every rule have an escalation path with a named function and a thing to send? - Did I state any requirement the source text does not contain? - Would this rule set be useless for a different team? It should be.

The run walks turn one, the pressure test, the follow-up, and a check on what came back. The Cockpit adds driver's-seat tunes. Your values come with either one.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

Somebody applied rule three to a situation it was never meant for, and the decision has already gone out. Read the whole set as the employee who did it, at the end of a shift with a customer waiting: which rule looked like it covered the situation, what in its wording invited that reading, and which escalation path would you not have used because it was too slow? Then rewrite that rule and its escalation so the same person makes the right call next time.
3

Go deeper

Pushes the work further once the basics are right.

Rules that live only in a document get followed for about a month. Write the rollout: the fifteen-minute session that introduces them using two real situations this team has actually faced, the one-page card that sits beside them at the moment of decision, the three questions to ask in a spot check thirty days later, and the single signal that tells you a rule is being skipped rather than followed.
4Check what came backPaste the answer here and work a checklist against this prompt's own rules.

Before you run it

What to gather first

  • The regulation or the section of it that actually applies
  • What the team actually does, step by step, in their own words
  • Who they are and how much time they have at the decision point
  • How much risk the business will carry, and who decides that
  • The escalation path that genuinely exists, not the one on the org chart

Watch for

  • The model will state requirements, thresholds, and scope that the text you pasted does not contain. Check every rule against the source words in the basis column.
  • Operating rules written stricter than the law become the standard the business believes applies, and later get cited against you as an admission of what was required. Label the gap explicitly.
  • A rule set that is clearly incomplete is safer than one that looks complete. The "what these do not cover" section is doing more work than the rules.
  • Paste the operative text, not a summary. A summary of a regulation produces a summary of a regulation, which is a policy nobody can act on.
  • These rules are not legal advice to the team and should not read as a legal opinion. Route the document the way your organisation routes legal guidance.

What comes back

A four-column rules table (the moment, the rule as an instruction, where it stops being obvious plus the escalation, and the legal basis with source words quoted), a "what these rules do not cover" section with what to do there, a block naming where the rules are stricter than the regulation requires, a one-paragraph read-aloud version, and the four closing sections.

See an example of what you’ll get
The rules | The moment | The rule | Where it stops being obvious, and what to do | Legal basis | |---|---|---|---| | A caller asks for a copy of their data | Say yes and log the request in the privacy queue. Do not read anything back over the phone, and do not send it yourself. Tell the caller it arrives by email within the stated window. | Stops being obvious when: the caller says they need it today, or says it is for a court case, or is not the account holder. Do: log it anyway, tag it URGENT, and tell the caller you have escalated it. Send the account ID to privacy@ in the queue note. Meanwhile: do not promise a date. | "A consumer shall have the right to request that a business disclose..." The window is in the text; identity verification is a separate requirement and that is why you do not read it back. | | A caller asks you to delete their account | Do not delete. Log it in the privacy queue and tell them it is in progress. | Stops being obvious when: they say they will dispute a charge unless it is done now, or the account has an open balance. Do: log it, note the balance, tell them the request is recorded today. Meanwhile: do not close the account in the billing system, because that is a different action and it is not reversible. | The deletion right and its exceptions are both in the text. The exceptions are why this is never a tier-one decision. | | A caller asks you to change the email on file | Verify with the two-factor step before anything else, every time, no exceptions for a caller who sounds frustrated. | Stops being obvious when: the caller says they have lost access to the old email. Do: escalate to a tier-two agent. Do not use an alternative verification you invent on the call. | Not addressed in the text you gave me. [CONFIRM - not answered by the source; this rule exists because an email change is how account takeovers happen, which is a security rule rather than a privacy one.] | | A caller says "I do not want you selling my information" | Treat it as an opt-out request. Log it in the privacy queue. Do not argue about whether we sell data, and do not explain what we do with it. | Stops being obvious when: the caller asks what we actually share. Do: read the approved sentence from the card, then log the request. Meanwhile: never say "we do not sell your data" on a call. | "...the right, at any time, to direct a business that sells personal information..." The rule reaches the request, not the argument. | What these rules do not cover. Anything from a lawyer, a regulator, a journalist, or a person saying they are acting for someone else. Anything involving a minor. Any request that arrives in writing rather than on a call. Any caller outside the five states in scope who asserts a right anyway. In every one of those: log it, say "I am passing this to the right team today," and send it to privacy@ with the account ID. Do not answer the question, and do not tell the caller that the rule does not apply to them. Where these are stricter than the regulation. Three places, and the team should not be told the law requires them. First, the deletion rule treats every request as valid and logs it, where the text contains exceptions that would let some requests be refused; sorting that on a call is not a tier-one job. Second, the opt-out rule applies to every caller regardless of state, because agents cannot determine residency at the start of a call and asking makes the call worse. Third, the email-change rule has no basis in this text at all; it is a security control living in a privacy document because that is where the team will look for it. The read-aloud version. If a caller asks for their data, asks to be deleted, or tells you to stop selling their information, you log it in the privacy queue and tell them it is recorded today. You do not read data back, you do not delete anything, and you do not explain what we do with their information. If it is urgent, if it involves a lawyer or a court, or if the person is not the account holder, log it, tag it urgent, and say you have escalated it. Changing an email always needs two-factor, no matter how the call is going. --- Assumptions I made. That agents have a privacy queue they can write to from the call [verify: if logging requires a second system and a login, the four-minute handle time makes rule one unusable and the whole set fails]. That tier-two agents exist and are reachable during the call [verify]. That "the stated window" is a number the team already has on their card [verify: if not, rule one needs the number in it and I do not have it]. Where this is weakest. Rule two will be applied to callers who are really asking to cancel a subscription rather than to exercise a deletion right, because a frustrated caller says "delete my account" meaning both. That will fill the privacy queue with cancellation requests and the queue will stop being read. The rule needs a sentence distinguishing the two, and I do not know your cancellation flow well enough to write it. Second, rule four's "do not argue" instruction will be hard to follow when a caller asks a direct question, and an agent who feels rude will improvise. The approved sentence on the card is doing all the work there, and it does not exist yet. What only you can decide. How much to escalate. This set routes four situations to privacy@ and one to tier two, which is defensible at a conservative posture and will generate volume that somebody has to actually answer; if privacy@ takes three days to respond, agents will learn to handle things themselves within a month and you will not find out. The alternative is letting tier one resolve the simple deletion requests, which reduces the queue and puts an exception analysis in the hands of someone with four minutes. Second call that is yours: whether to tell the team why these rules exist. Telling them helps a good agent handle the situation you did not anticipate; it also gives an agent under pressure the material to reason their way to an exception. What would make this materially better. Ranked by impact: (1) Three recent call transcripts where this came up, which would replace my guesses about how callers phrase these requests. (2) The systems an agent actually has open at the moment of decision, which decides whether logging is one click or a context switch. (3) The real response time on privacy@, because the escalation paths above are only as good as that number. (4) The stated window for fulfilling a request, so rule one can say it out loud.
Why this prompt is built the way it is
## Framework 1. **Find the moments of decision.** A regulation is a set of constraints; an operating rule is an instruction at a moment. Everything else in the text is background. 2. **Write the rule as an instruction** the person can apply without knowing why. No nested conditions. Three nested ifs means it is a referral, not a rule. 3. **Keep the legal basis in a separate column,** traceable but out of the instruction. 4. **Route the edges.** Name where each rule stops being obvious, who to ask, what to send, and what to do while waiting. 5. **Say what the rules do not cover,** because a complete-looking set will be treated as complete. 6. **Calibrate to the risk posture** and say where the line was drawn. 7. **Write in the team's vocabulary,** at the speed their job moves.