P
⚖️LegalAdvancedAll AIs

Create a Complete DPO Checklist for GDPR Compliance

This prompt generates a complete, structured DPO checklist to manage an organization GDPR compliance, with priority actions, audit frequencies and regulatory references.

Paste in your AI

Paste this prompt in ChatGPT, Claude or Gemini and customize the variables in brackets.

Agis en tant que Data Protection Officer (DPO) certifié avec 10 ans d'expérience en conformité RGPD. Génère une checklist DPO exhaustive et opérationnelle pour une organisation de type [TYPE D'ORGANISATION : ex. PME de 200 salariés, startup SaaS B2B, hôpital public, collectivité territoriale] opérant dans le secteur [SECTEUR D'ACTIVITÉ : ex. e-commerce, santé, éducation, fintech, industrie].

La checklist doit couvrir les axes suivants :

  1. Gouvernance des données personnelles : nomination du DPO, rattachement hiérarchique, moyens alloués, comité de pilotage privacy, politique de protection des données.

  2. Registre des traitements (article 30 RGPD) : inventaire des traitements, bases légales, finalités, catégories de données et de personnes concernées, durées de conservation, transferts hors UE.

  3. Droits des personnes concernées : procédures pour les droits d'accès, rectification, effacement, portabilité, opposition, limitation, profilage. Délais de réponse et traçabilité.

  4. Analyse d'impact (DPIA) : critères de déclenchement, méthodologie, consultation préalable de la CNIL, suivi des mesures correctives.

  5. Sécurité des données : mesures techniques (chiffrement, pseudonymisation, contrôle d'accès), mesures organisationnelles (sensibilisation, charte informatique), gestion des sous-traitants (article 28).

  6. Gestion des violations de données : procédure de détection, notification à la CNIL sous 72h, communication aux personnes concernées, registre des violations.

  7. Privacy by Design & by Default : intégration dans les projets IT, minimisation des données, paramètres par défaut respectueux de la vie privée.

  8. Formation et sensibilisation : plan de formation annuel, sessions par métier, indicateurs de suivi.

  9. Relations avec la CNIL : veille réglementaire, gestion des contrôles, coopération.

  10. Indicateurs et reporting : tableau de bord DPO, KPIs de conformité, rapport annuel.

Pour chaque axe, fournis :

  • Les actions concrètes à mener (formulées comme des items cochables)
  • Le niveau de priorité (critique / important / recommandé)
  • La fréquence de vérification (ponctuel / trimestriel / annuel / continu)
  • Les articles du RGPD et lignes directrices CNIL/EDPB associés

Termine par un calendrier de mise en conformité sur 12 mois avec les jalons clés.

Personalize this prompt with Léa

Answer 3 questions and Léa tailors the prompt to your situation.

Why this prompt works

<p>This prompt is designed to produce a working tool directly usable by a DPO or compliance officer. By specifying the <strong>organization type</strong> and <strong>industry</strong>, the AI adapts the checklist to the operational realities and specific risks of your structure: a fintech does not have the same challenges as a hospital or a local authority.</p><p>The 10-axis structure covers the fundamental GDPR obligations and CNIL recommendations. Each item is formulated as a checkable action with a priority level and audit frequency, making it a genuine <strong>operational dashboard</strong> rather than a mere theoretical document. References to GDPR articles and EDPB guidelines justify each action to management.</p><p>To get the most from this prompt, supplement it with contextual information: number of existing processing activities, presence of non-EU subcontractors, processing of sensitive data. You can then iterate by asking the AI to elaborate on a specific axis or generate <strong>associated document templates</strong> (processing register, breach management procedure, DPIA form).</p>

Use Cases

New DPO onboarding who needs to audit existing practices and establish a roadmapPreparing for a CNIL inspection with systematic verification of all compliance pointsInitial GDPR compliance for a company that has never formalized its obligations

Expected Output

A checklist structured in 10 axes with dozens of checkable actions, each accompanied by its priority level, audit frequency and regulatory references. The whole concludes with a 12-month deployment calendar with key milestones.

Improve this prompt

Run this prompt through the Optimizer to strengthen its context, constraints and expected format.

Improve this prompt with the Optimizer

Comments

Be the first to comment on this prompt.

📬 Get new prompts every week

Join our newsletter and never miss a prompt.

Related Agents

⚖️LegalAdvanced

Sector Regulatory Watch

This agent structures and automates your regulatory watch by analyzing laws, directives and regulations applicable to your industry. It identifies current obligations, upcoming changes (bills, EU directives), assesses their impact on your business and generates a prioritized compliance plan.

4 steps
veilleréglementationconformité+4
⚖️LegalIntermediate

Contract Clause Analysis

This agent deeply analyzes clauses in your commercial contracts, leases, employment contracts or partnership agreements. It identifies legal risks, unbalanced clauses, potential ambiguities and proposes protective rewording. Ideal before signing a contract or preparing a negotiation.

3 steps
contratclauseanalyse juridique+3
⚖️LegalBeginner

Terms of Service / Terms of Use Drafting

This agent generates Terms of Service (ToS) and Terms of Use (ToU) compliant with French law and GDPR. It adapts to your business type (e-commerce, SaaS, marketplace, services) and produces structured legal documents covering all mandatory and recommended clauses.

3 steps
CGVCGUjuridique+4

Go further

Similar Prompts

⚖️LegalIntermediateAll AIs

Analyze a Contract and Identify All Legal Risks with AI

A comprehensive prompt to analyze a contract clause by clause, identify legal risks, imbalances and missing clauses, with concrete recommendations before signing.

0337
⚖️LegalAdvancedAll AIs

Jurisdiction Comparison Summary

Multi-jurisdiction analysis and forum selection

0132
⚖️LegalAdvancedAll AIs

Compliance Audit Framework

Conducting internal compliance audits

0105
⚖️LegalBeginnerAll AIs

GDPR and Email Compliance

Ensure GDPR compliance

0167