Prompts / Legal Drafting & Compliance

ChatGPT prompt for a privacy policy

This prompt creates a fact-based first draft of a website or app privacy policy and highlights missing disclosures. Use it after documenting your actual data practices and before legal review.

PromptOpen ChatGPTOpen Claude
Draft a plain-language privacy policy first draft for [BUSINESS AND PRODUCT], which operates in [JURISDICTIONS AND AUDIENCE]. Base it only on these documented practices: [DATA PRACTICES AND VENDORS]. Our contact and rights-request details are [CONTACT AND REQUEST PROCESS]. Relevant legal or contractual requirements we already know are [KNOWN REQUIREMENTS].

Produce a policy in clear sections: effective date; scope; categories of personal information collected; sources; purposes; retention; sharing and service providers; cookies and similar technologies; analytics and advertising; international transfers; security; children; user choices and privacy-rights requests; changes; and contact information. For each category of data, state the purpose, recipient category, and retention period only if supplied. Describe technical or organizational measures at a high level without claiming certification, encryption, deletion, or compliance that I did not provide.

Use conditional language and a clearly marked “information needed before publication” list for missing facts. Do not copy another company’s policy, invent legal bases, consent mechanisms, opt-out links, data-sale/sharing practices, response timelines, or jurisdiction-specific rights. This is an informational draft, not legal advice; state that qualified counsel should review it for applicable law and the live product behavior.

After the policy, create a one-page disclosure checklist mapping every policy statement to the supplied practice or vendor. Ask up to 3 clarifying questions only if a required input is missing.

Before answering, check that the policy never promises a practice absent from my documentation and that every vendor disclosure matches the stated data flow.

Fill in

PlaceholderWhat to enterExample
[BUSINESS AND PRODUCT]Enter the legal or trading name and a concise description of the website, app, or service.Maple Ledger LLC, a web app that helps independent consultants create invoices
[JURISDICTIONS AND AUDIENCE]Enter where you operate, where users are located, and whether you knowingly serve children.US and Canada; adults only; no intended use by children under 13
[DATA PRACTICES AND VENDORS]List collected data, collection points, purposes, retention, sharing, cookies, and each relevant vendor.account name, email, invoice data, and support emails; Stripe for payments, PostHog analytics, AWS hosting; account data retained while active plus 30 days
[CONTACT AND REQUEST PROCESS]Enter the privacy contact method and the documented process for access, deletion, correction, or opt-out requests.[email protected]; verified email requests are handled by the operations lead
[KNOWN REQUIREMENTS]List applicable laws, contractual commitments, or prior legal guidance you already have.California users may request access or deletion; customer contracts require notice of material policy changes

How to use

  1. Inventory the live product first, including forms, logs, support tools, payment providers, analytics, advertising pixels, and data exports.
  2. Replace every placeholder with documented practices; leave an item marked unknown rather than guessing.
  3. Have product, security, and marketing owners compare the draft to what the service actually does, then send it to qualified counsel.
  4. Follow up with: “Convert the information-needed list into questions for our engineering, marketing, and support owners.”

Variations

Vendor inventory

Use this before drafting a policy when your data flow is not documented.

Variation
Turn these tools and workflows into a privacy data inventory: [SYSTEMS AND WORKFLOWS]. For each system, produce a table with data categories, data subjects, collection source, purpose, storage location if known, vendor, onward sharing, retention, owner, and unknowns. Separate confirmed facts from assumptions. Include common overlooked flows such as error logs, support attachments, backups, email marketing, payment processors, and analytics cookies, but do not claim they are used unless I confirm them. End with questions for each owner. Ask up to 3 clarifying questions only if required inputs are missing.

Cookie notice

Use this for a concise notice after you know which technologies are deployed.

Variation
Draft a website cookie notice for [SITE] based only on [COOKIE AND TRACKING INVENTORY] and [USER CHOICE MECHANISM]. Explain essential, analytics, functional, and advertising technologies that are actually present; name providers and purposes where supplied. State how visitors can change choices and link to [PRIVACY POLICY URL] if provided. Do not claim consent, opt-out, or preference controls exist unless documented. Flag gaps that counsel or the consent-platform owner should resolve for [JURISDICTIONS]. Ask up to 3 questions only if required input is missing.

Policy audit

Use this when a current policy may not match the product anymore.

Variation
Compare this current privacy policy: [CURRENT POLICY] against these actual data practices: [CURRENT PRACTICES]. Create a discrepancy table with policy statement, observed practice, risk of mismatch, owner to confirm, and recommended draft change. Then write only the revised sections, marking unresolved facts in brackets. Do not make legal conclusions or claim compliance; identify matters for qualified privacy counsel, especially children, sensitive data, advertising, international transfers, and rights requests. Ask up to 3 questions only if a required input is missing.

Tips

  • A privacy policy should describe the product that exists, including support, analytics, and deletion workflows—not the product team’s intent.
  • Ask each vendor owner for data categories, purposes, locations, retention, and subprocessors; a vendor name alone is not a disclosure inventory.
  • Avoid absolute promises such as “we never share data” unless your contracts, logs, and workflows make that literally true.
  • A lawyer can review the draft efficiently when every open item is marked with the product owner who can answer it.

FAQ

Can AI generate a legally compliant privacy policy?

It can create a useful fact-based draft, but it cannot determine your obligations from incomplete inputs. Have qualified counsel review it for your jurisdictions and live data practices.

Do I need to list every software vendor?

The required level of detail depends on applicable law and your facts. At minimum, maintain a complete internal inventory so counsel can decide what the public policy should disclose.

What is the most common policy mistake?

Publishing language copied from another business that does not match your own tracking, sharing, retention, or user-rights process. The mismatch can be worse than an incomplete first draft.

Related prompts

All Legal Drafting & Compliance prompts →

Get a few prompts like this every week

Something Big is a free AI newsletter read by 50,000+ professionals. One email a week with prompts and tools that work, plus what changed in AI and what to do about it.