Prompts
Prompts de IA jurídica para Privacy & Data Protection
15 prompts you can paste straight into HAQQ or any other assistant. Every one is written out in full - open it, copy it, change the bracketed parts.
Privacy PolicyPolicyAdvancedDraft / Generate
Draft a comprehensive privacy policy for [Company] that operates [describe business] in [jurisdictions]. Address data collection practices, legal bases for processing, retention periods, individual rights, international transfers, cookies, and contact information for privacy inquiries.
Data Processing AgreementAgreementAdvancedDraft / Generate
Draft a data processing agreement where [Processor] will process personal data on behalf of [Controller] for [describe processing activities]. Include GDPR Article 28 requirements, security measures, sub-processor approval process, audit rights, and data breach notification obligations.
Cookie PolicyPolicyAdvancedDraft / Generate
Draft a cookie policy for [Company's] website explaining the types of cookies used (essential, analytics, marketing), their purposes, duration, third-party cookies, and how users can manage cookie preferences in compliance with [jurisdiction] requirements.
Data Subject Access Request ProcedurePolicyAdvancedDraft / Generate
Draft an internal procedure for [Company] to handle data subject access requests under GDPR/[applicable law]. Include identity verification steps, search protocols, response timelines, exemptions assessment, format of response, and escalation procedures.
Data Breach Response PlanPolicyAdvancedDraft / Generate
Draft a data breach response plan for [Company]. Include incident detection and reporting, initial assessment, containment measures, notification requirements to regulators and affected individuals, documentation, post-incident review, and assigned responsibilities.
Employee Privacy NoticePolicyAdvancedDraft / Generate
Draft an employee privacy notice for [Company] explaining what personal data is collected from employees, purposes of processing, legal bases, retention periods, employee rights, monitoring practices, and international data transfers within the corporate group.
Vendor Data Protection AddendumAgreementAdvancedDraft / Generate
Draft a data protection addendum to attach to vendor agreements where [Vendor] may access or process personal data controlled by [Company]. Include processor obligations, security requirements, sub-processing restrictions, audit rights, and cross-border transfer mechanisms.
Data Retention PolicyPolicyAdvancedDraft / Generate
Draft a data retention policy for [Company] covering all categories of personal and business data. Specify retention periods based on legal requirements and business needs, secure deletion procedures, litigation hold protocols, and responsibilities for policy compliance.
Privacy Impact AssessmentReportAdvancedCompliance / Due Diligence
Conduct a privacy impact assessment for [Company's] proposed [project/system/product] that will process [describe personal data]. Identify privacy risks, assess necessity and proportionality, evaluate safeguards, and recommend mitigating measures per GDPR Article 35.
Cross-Border Data Transfer AssessmentMemoAdvancedCompliance / Due Diligence
Assess the lawfulness of transferring personal data from [origin country/region] to [destination country]. Analyze adequacy decisions, appropriate safeguards (SCCs, BCRs), supplementary measures needed, and risks per Schrems II requirements.
AI System Data Governance FrameworkPolicyAdvancedDraft / Generate
Draft a data governance framework for [Company's] AI/ML systems addressing training data requirements, bias mitigation, data minimization, purpose limitation, transparency obligations, individual rights in automated decision-making, and compliance with emerging AI regulations.
Third-Party Data Sharing AgreementAgreementAdvancedDraft / Generate
Draft a data sharing agreement between [Company A] and [Company B] for sharing [describe data] for [describe purposes]. Address controller-to-controller responsibilities, legal bases, data subject notification, security standards, limitation on further sharing, and liability allocation.
AI Governance PolicyPolicyExpertDraft / Generate
Draft an AI governance policy for [organization] that addresses responsible AI use, risk assessment framework, bias detection and mitigation, transparency requirements, human oversight mechanisms, data handling for AI training, vendor evaluation criteria, and incident response procedures.
Regulatory Research Memo (Verify-Before-Cite)MemoAdvancedResearch / Authorities
Research the current requirements under [name the regulation or framework] as they apply to [describe the company's activity] in [jurisdiction]. Structure the answer as: the specific obligation, the statutory or regulatory section it comes from, the deadline or trigger event, and the penalty for non-compliance. If you are not certain a citation is current or correctly numbered, say so explicitly and tell me to confirm it against the official regulator text rather than presenting your best guess as settled law.
Obligation Calendar Under a Named MENA Data Protection LawChecklistExpertCompliance / Due Diligence
Act as privacy counsel building an obligation calendar for [ORGANISATION], a [SECTOR] business processing personal data of individuals in [COUNTRY], under [NAMED LAW — for example the Saudi Personal Data Protection Law (Royal Decree M/19) and its Implementing Regulations, UAE Federal Decree-Law No. 45 of 2021, DIFC Data Protection Law No. 5 of 2020, Bahrain Law No. 30 of 2018, or Qatar Law No. 13 of 2016]. Work only from that named law and its implementing regulations. Cite the article for every obligation; where a deadline, threshold, fee or retention period is not stated in the text you are working from, write "not specified in source — confirm" rather than supplying a number. Return: (1) Applicability — whether and why the law reaches this organisation, including any extraterritorial hook, sector carve-out or free-zone regime that displaces it; (2) Registration and Filings — any registration, licence, appointment or regulator notification, with the article and the event that triggers it; (3) Recurring Obligations — a calendar of what must be done and on what cadence (records of processing, impact assessments, reviews, training, audits), each with article, internal owner and frequency; (4) Event-Driven Deadlines — the clock that starts on a personal-data breach, a data-subject request, a cross-border transfer or a change of processor, with the article and how the period is counted; (5) Cross-Border Transfer Conditions — the permitted grounds, any approval or adequacy step, and any localisation requirement, each cited; (6) Roles and Contract Terms — whether a data protection officer or local representative is required and on what trigger, the controller-processor split, and the clauses the law requires in processor agreements; (7) Enforcement Exposure — the sanctions the law itself provides for, quoted from the text, with no estimate of likelihood; (8) Gap List and Evidence — measured against [CURRENT PRACTICE], what is missing and what artefact [ORGANISATION] must be able to produce to demonstrate compliance, plus the open questions for local counsel. Current practice: [DESCRIBE].