Skip to content

Prompt

Privacy & Data Protection AI prompts for lawyers

16 prompts you can paste straight into HAQQ or any other assistant. Every one is written out in full - open it, copy it, change the bracketed parts.

  • Cross-Border SaaS: Hosting, Users and RegulatorMemoEnterpriseCompliance / Due Diligence
    A software company in [country] is selling a SaaS contract to a [bank / regulated entity] in [country]. Data will be hosted in [location], with end users across [countries].
    Advise the software company:
    1. Which data protection regimes actually apply, and on what connecting factor for each — establishment, targeting, the location of the data, or the customer's own regulatory obligations flowing down.
    2. The transfer mechanism needed for each cross-border flow, and whether hosting in a third country changes it.
    3. What the customer's financial regulator will require of us as an outsourced service provider: audit rights, sub-processor approval, exit assistance, records retention, incident notification windows, and the regulator's own right of access.
    4. Data localisation or residency rules that would defeat the proposed hosting location outright — this is the question that kills deals, so answer it early.
    5. The contractual package: which of these belong in the MSA, the DPA and the security schedule, and what our fallback is on each of the three points the bank will not move on.
    6. A dated action list for getting to signature.
    Mandatory rules: name each law and article. Where a rule is issued by a regulator rather than a statute, say which regulator and which circular. Where you are not certain a requirement is in force, mark it for verification rather than stating it flatly.
  • Privacy PolicyPolicyAdvancedDraft / Generate
    Draft a comprehensive privacy policy for [Company] that operates [describe business] in [jurisdictions]. Address data collection practices, legal bases for processing, retention periods, individual rights, international transfers, cookies, and contact information for privacy inquiries.
  • Data Processing AgreementAgreementAdvancedDraft / Generate
    Draft a data processing agreement where [Processor] will process personal data on behalf of [Controller] for [describe processing activities]. Include GDPR Article 28 requirements, security measures, sub-processor approval process, audit rights, and data breach notification obligations.
  • Cookie PolicyPolicyAdvancedDraft / Generate
    Draft a cookie policy for [Company's] website explaining the types of cookies used (essential, analytics, marketing), their purposes, duration, third-party cookies, and how users can manage cookie preferences in compliance with [jurisdiction] requirements.
  • Data Subject Access Request ProcedurePolicyAdvancedDraft / Generate
    Draft an internal procedure for [Company] to handle data subject access requests under GDPR/[applicable law]. Include identity verification steps, search protocols, response timelines, exemptions assessment, format of response, and escalation procedures.
  • Data Breach Response PlanPolicyAdvancedDraft / Generate
    Draft a data breach response plan for [Company]. Include incident detection and reporting, initial assessment, containment measures, notification requirements to regulators and affected individuals, documentation, post-incident review, and assigned responsibilities.
  • Employee Privacy NoticePolicyAdvancedDraft / Generate
    Draft an employee privacy notice for [Company] explaining what personal data is collected from employees, purposes of processing, legal bases, retention periods, employee rights, monitoring practices, and international data transfers within the corporate group.
  • Vendor Data Protection AddendumAgreementAdvancedDraft / Generate
    Draft a data protection addendum to attach to vendor agreements where [Vendor] may access or process personal data controlled by [Company]. Include processor obligations, security requirements, sub-processing restrictions, audit rights, and cross-border transfer mechanisms.
  • Data Retention PolicyPolicyAdvancedDraft / Generate
    Draft a data retention policy for [Company] covering all categories of personal and business data. Specify retention periods based on legal requirements and business needs, secure deletion procedures, litigation hold protocols, and responsibilities for policy compliance.
  • Privacy Impact AssessmentReportAdvancedCompliance / Due Diligence
    Conduct a privacy impact assessment for [Company's] proposed [project/system/product] that will process [describe personal data]. Identify privacy risks, assess necessity and proportionality, evaluate safeguards, and recommend mitigating measures per GDPR Article 35.
  • Cross-Border Data Transfer AssessmentMemoAdvancedCompliance / Due Diligence
    Assess the lawfulness of transferring personal data from [origin country/region] to [destination country]. Analyze adequacy decisions, appropriate safeguards (SCCs, BCRs), supplementary measures needed, and risks per Schrems II requirements.
  • AI System Data Governance FrameworkPolicyAdvancedDraft / Generate
    Draft a data governance framework for [Company's] AI/ML systems addressing training data requirements, bias mitigation, data minimization, purpose limitation, transparency obligations, individual rights in automated decision-making, and compliance with emerging AI regulations.
  • Third-Party Data Sharing AgreementAgreementAdvancedDraft / Generate
    Draft a data sharing agreement between [Company A] and [Company B] for sharing [describe data] for [describe purposes]. Address controller-to-controller responsibilities, legal bases, data subject notification, security standards, limitation on further sharing, and liability allocation.
  • AI Governance PolicyPolicyExpertDraft / Generate
    Draft an AI governance policy for [organization] that addresses responsible AI use, risk assessment framework, bias detection and mitigation, transparency requirements, human oversight mechanisms, data handling for AI training, vendor evaluation criteria, and incident response procedures.
  • Regulatory Research Memo (Verify-Before-Cite)MemoAdvancedResearch / Authorities
    Research the current requirements under [name the regulation or framework] as they apply to [describe the company's activity] in [jurisdiction]. Structure the answer as: the specific obligation, the statutory or regulatory section it comes from, the deadline or trigger event, and the penalty for non-compliance. If you are not certain a citation is current or correctly numbered, say so explicitly and tell me to confirm it against the official regulator text rather than presenting your best guess as settled law.
  • Obligation Calendar Under a Named MENA Data Protection LawChecklistExpertCompliance / Due Diligence
    Act as privacy counsel building an obligation calendar for [ORGANISATION], a [SECTOR] business processing personal data of individuals in [COUNTRY], under [NAMED LAW — for example the Saudi Personal Data Protection Law (Royal Decree M/19) and its Implementing Regulations, UAE Federal Decree-Law No. 45 of 2021, DIFC Data Protection Law No. 5 of 2020, Bahrain Law No. 30 of 2018, or Qatar Law No. 13 of 2016]. Work only from that named law and its implementing regulations. Cite the article for every obligation; where a deadline, threshold, fee or retention period is not stated in the text you are working from, write "not specified in source — confirm" rather than supplying a number. Return: (1) Applicability — whether and why the law reaches this organisation, including any extraterritorial hook, sector carve-out or free-zone regime that displaces it; (2) Registration and Filings — any registration, licence, appointment or regulator notification, with the article and the event that triggers it; (3) Recurring Obligations — a calendar of what must be done and on what cadence (records of processing, impact assessments, reviews, training, audits), each with article, internal owner and frequency; (4) Event-Driven Deadlines — the clock that starts on a personal-data breach, a data-subject request, a cross-border transfer or a change of processor, with the article and how the period is counted; (5) Cross-Border Transfer Conditions — the permitted grounds, any approval or adequacy step, and any localisation requirement, each cited; (6) Roles and Contract Terms — whether a data protection officer or local representative is required and on what trigger, the controller-processor split, and the clauses the law requires in processor agreements; (7) Enforcement Exposure — the sanctions the law itself provides for, quoted from the text, with no estimate of likelihood; (8) Gap List and Evidence — measured against [CURRENT PRACTICE], what is missing and what artefact [ORGANISATION] must be able to produce to demonstrate compliance, plus the open questions for local counsel. Current practice: [DESCRIBE].

Other practice areas

Search all 391 prompts