Prompt Details
Model
Chat - (gpt-5.6)
Token size
4,854
Example input
[REGULATORY MATERIAL]: Regulation (EU) 2016/679 (GDPR), Article 30 — Records of Processing Activities. For the organization’s processing activities, the record should cover information including the purposes of processing, categories of data subjects and personal data, recipients, applicable international transfers and safeguards, retention periods where possible, and a general description of technical and organisational security measures where possible. ((Eur-Lex)(1))
[INTERNAL POLICY PROCEDURE CONTROL MATERIAL]: **Data Governance Policy v3.2** Section 4.2 — Records of Processing Activities “Each business unit must maintain an up-to-date record of processing activities describing the purpose of each processing activity, the categories of personal data involved, and the relevant business owner.” Section 4.4 — Review “Business units must review their records annually and update them when material changes occur.” **Privacy Operations Procedure v2.1** Section 5 — International Transfers “International data transfers must be reviewed by Privacy Legal before implementation.” Section 6 — Retention “Business units should follow approved retention schedules applicable to their data category.”
[REVIEW FOCUS]: Assess whether the supplied internal policy and procedure language adequately covers the GDPR Article 30 record-of-processing requirements, with particular attention to recipients, international transfers, retention, and security-measure documentation.
[OUTPUT LANGUAGE]: English
Example output
### Requirement-to-Policy Matrix
The supplied materials are sufficient for a targeted comparison of the stated Article 30 elements against the supplied policy/procedure excerpts. The analysis is limited to those excerpts; no underlying ROPA, retention schedule, transfer-safeguard documentation, or security-measure register was supplied.
| Requirement | Source | Corresponding Policy Language | Coverage Status | Gap | Uncertainty | Evidence Reference |
| ---------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| The record of processing activities should describe the **purpose of each processing activity**. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | “Each business unit must maintain an up-to-date record of processing activities describing the purpose of each processing activity…” | **COVERED** | No apparent gap identified for the stated purpose element. | No material uncertainty identified from the supplied evidence. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Data Governance Policy v3.2, §4.2**. |
| The record should identify the **categories of data subjects** covered by the processing activities. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | Section 4.2 requires the record to describe “the categories of personal data involved,” but does not state that categories of data subjects must be recorded. | **NOT IDENTIFIED** | No corresponding internal language was identified requiring categories of data subjects to be included in the record. | The supplied internal excerpts do not include a ROPA template or other record specification that could establish additional required fields. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Data Governance Policy v3.2, §4.2**. |
| The record should identify the **categories of personal data** involved in the processing activities. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | “Each business unit must maintain an up-to-date record of processing activities describing … the categories of personal data involved…” | **COVERED** | No apparent gap identified for this element. | No material uncertainty identified from the supplied evidence. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Data Governance Policy v3.2, §4.2**. |
| The record should identify **recipients** of the personal data. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | No supplied policy, procedure, or control language expressly addresses recording recipients in the record of processing activities. | **NOT IDENTIFIED** | No corresponding internal requirement was identified requiring recipients to be documented in the record. | The comparison is limited to the supplied excerpts; no ROPA specification or other internal record-control document was supplied. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: no corresponding evidence identified in supplied materials. |
| The record should identify **applicable international transfers**. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | “International data transfers must be reviewed by Privacy Legal before implementation.” | **PARTIALLY COVERED** | The supplied procedure establishes review of international transfers, but does not state that applicable transfers must be recorded in the record of processing activities. | No ROPA field requirement or transfer-recording mechanism was supplied, so the extent to which the review process results in ROPA documentation cannot be established. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Privacy Operations Procedure v2.1, §5**. |
| The record should identify the **safeguards applicable to international transfers**, as applicable. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | Section 5 requires international transfers to be reviewed by Privacy Legal before implementation, but does not specify documentation of transfer safeguards. | **NOT IDENTIFIED** | No internal language was identified requiring applicable transfer safeguards to be recorded in the record. | The supplied material does not identify what safeguard documentation exists or whether safeguards are captured elsewhere. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Privacy Operations Procedure v2.1, §5**. |
| The record should include **retention periods**, where possible. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | “Business units should follow approved retention schedules applicable to their data category.” | **PARTIALLY COVERED** | The procedure addresses adherence to retention schedules but does not expressly require retention periods to be documented in the record of processing activities. | The referenced approved retention schedules were not supplied, and no ROPA documentation requirement for retention periods was provided. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: **Privacy Operations Procedure v2.1, §6**. |
| The record should contain a **general description of technical and organisational security measures**, where possible. | Regulation (EU) 2016/679, Article 30 — supplied regulatory material | No supplied policy, procedure, or control language expressly requires security measures to be described in the record of processing activities. | **NOT IDENTIFIED** | No corresponding internal requirement was identified for documenting technical and organisational security measures in the record. | The supplied material does not identify a security-control inventory, standard, or ROPA specification that could establish such coverage. | Regulatory: GDPR Art. 30, supplied regulatory material. Internal: no corresponding evidence identified in supplied materials. |
### Source / Conflict Review
No **CONFLICTING** classification is supported by the supplied internal materials. Data Governance Policy v3.2 §4.4 requires annual review and updating when material changes occur, which supports maintenance of the records but does not itself supply an additional Article 30 content element stated in the supplied regulatory material.
The principal apparent coverage limitations are therefore concentrated in **data-subject categories, recipients, transfer safeguards, and security-measure documentation**, while **international transfers and retention** have related internal controls but not an express requirement that the corresponding information be captured in the record itself.
Get this prompt + 9 more with Select$14 first month, then $19/mo · Cancel anytime$14 first month · then $19/mo
View SelectBy purchasing this prompt, you agree to our terms of service
GPT-5.6
A structured AI prompt for comparing supplied regulatory requirements with internal privacy policies, procedures, and controls. It extracts requirements, maps evidence, classifies coverage, flags apparent gaps, uncertainty, and internal conflicts, and produces a traceable requirement-to-policy matrix for professional review. Designed for privacy counsel, DPOs, compliance teams, and corporate legal.
...more
Added 5 days ago
