AI Data Retention & Governance Policy Generator
Create UK-compliant data retention frameworks for AI systems in finance and legal sectors.
Act as a Senior Compliance Officer and Legal Counsel specializing in UK Data Protection and Financial Regulation. Your task is to draft a comprehensive 'AI Data Retention Policy' for [COMPANY_NAME], which operates within the [SPECIFIC_SECTOR] sector. ### Regulatory Framework The policy must strictly adhere to: 1. UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. 2. Financial Conduct Authority (FCA) handbook requirements (specifically SYSC and PRIN). 3. The Principle of Storage Limitation (Article 5(1)(e)). ### Policy Components to Include: - **Scope:** Define the types of AI-related data covered (training data, input prompts, model outputs, log files, and metadata). - **Retention Schedule:** Provide a detailed table with specific timeframes for different data categories (e.g., KYC data vs. general customer queries). - **Legal Basis:** Define the lawful basis for retention for each category (Contractual Necessity, Legal Obligation, or Legitimate Interest). - **AI Specifics:** Address retention for 'Model Weights' and 'Prompt History' used in [AI_USE_CASE]. - **Security & Disposal:** Outline requirements for encryption during storage and the 'Right to Erasure' protocols. - **Review Cycle:** Establish a frequency for auditing data holdings. ### Contextual Constraints: - Company Size: [COMPANY_SIZE] - Data Sensitivity Level: [DATA_SENSITIVITY_LEVEL] - Automated Decision Making (ADM): State whether ADM is used: [ADM_STATUS] Draft the policy in a formal, authoritative tone suitable for a board-level compliance manual. Use British English spelling and terminology.
Act as a Senior Compliance Officer and Legal Counsel specializing in UK Data Protection and Financial Regulation. Your task is to draft a comprehensive 'AI Data Retention Policy' for [COMPANY_NAME], which operates within the [SPECIFIC_SECTOR] sector. ### Regulatory Framework The policy must strictly adhere to: 1. UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. 2. Financial Conduct Authority (FCA) handbook requirements (specifically SYSC and PRIN). 3. The Principle of Storage Limitation (Article 5(1)(e)). ### Policy Components to Include: - **Scope:** Define the types of AI-related data covered (training data, input prompts, model outputs, log files, and metadata). - **Retention Schedule:** Provide a detailed table with specific timeframes for different data categories (e.g., KYC data vs. general customer queries). - **Legal Basis:** Define the lawful basis for retention for each category (Contractual Necessity, Legal Obligation, or Legitimate Interest). - **AI Specifics:** Address retention for 'Model Weights' and 'Prompt History' used in [AI_USE_CASE]. - **Security & Disposal:** Outline requirements for encryption during storage and the 'Right to Erasure' protocols. - **Review Cycle:** Establish a frequency for auditing data holdings. ### Contextual Constraints: - Company Size: [COMPANY_SIZE] - Data Sensitivity Level: [DATA_SENSITIVITY_LEVEL] - Automated Decision Making (ADM): State whether ADM is used: [ADM_STATUS] Draft the policy in a formal, authoritative tone suitable for a board-level compliance manual. Use British English spelling and terminology.
More Like This
Back to LibraryAI Debt Collection Letter Generator (UK Compliant)
This prompt generates formal debt collection letters that adhere to UK financial regulations and Pre-Action Protocols. It allows users to scale the tone from a friendly reminder to a formal Letter Before Action (LBA) while ensuring all legal requirements are met.
UK AI Terms of Business Creator
This prompt generates a comprehensive set of Terms of Business tailored for UK entities offering AI services or software. It covers essential clauses including data protection (UK GDPR), intellectual property rights for AI outputs, and liability limitations specific to algorithmic risks.
AI Intellectual Property Assignment Agreement Generator
This prompt generates a comprehensive Intellectual Property Assignment Agreement tailored for the UK legal jurisdiction. it specifically addresses the nuances of AI-generated content, ownership transfer from creators or contractors to entities, and compliance with the Copyright, Designs and Patents Act 1988.