AI prompt to analyze a legal document under GDPR
AI prompt to analyze a legal document under GDPR before you sign or approve it. Paste the full text for a plain-language compliance breakdown.
Act as a GDPR document analyst. Read the legal document pasted below and explain what it means for personal data handling under the EU General Data Protection Regulation.
Infer the document type, parties, and jurisdiction from the text. Work only from what is pasted. This is reading support, not legal advice.
Return:
1. Document identity: title, parties, last updated date if shown, and what kind of document this is, for example a privacy notice or data processing agreement
2. Plain-language summary in one paragraph
3. GDPR roles: who acts as controller or processor, plus any joint controller or sub-processor roles named
4. Data covered: categories of personal data and purposes, plus lawful bases cited or missing
5. Data subject rights: how access, deletion, portability, and objection are handled, plus any stated response deadlines and contact point
6. Transfers and retention: cross-border transfer mechanism if any, plus retention periods stated or absent
7. Security and breaches: measures described and breach notification commitments
8. Watch closely: 5 to 10 clauses with GDPR risk. For each, cite the section and explain the gap or concern. Rate how serious each clause is on a low-to-high scale
9. Questions to ask before signing or approving
10. Reasonable to proceed if... and Get professional advice before proceeding if...
--- START DOCUMENT ---
[PASTE FULL DOCUMENT HERE]
--- END DOCUMENT ---
How to use
- Paste the full text between the START and END markers. That is all you need to do.
- For a data processing agreement, include sub-processor lists or security annexes if they are separate files.
- Follow up with "Check this against Article 28 processor requirements" for a DPA-only pass.
Tips
- Know whether you are the controller or the processor before you act on the summary. The same clause reads differently from each side.
- Search the paste for "legitimate interest", "sub-processor", and "Standard Contractual Clauses".
- Vague purpose wording or a missing lawful basis is a common gap in privacy notices.
For best results, give your AI access to:web search
Example output
Section 2
This DPA governs how the vendor processes customer contact data on your behalf for support ticketing. It lists sub-processors, requires encryption in transit, and promises deletion within 30 days after contract end.
Section 8
Section 4.2 "Sub-processors" (high): The vendor may appoint new sub-processors with 14 days' notice but no right for you to object.
Section 9
- What lawful basis do you rely on when you process our end-user data?
- Where is data stored, and which transfer tool applies?
Section 10
Reasonable to proceed if you need a standard SaaS DPA and the sub-processor list matches your risk tolerance.
Get professional advice before proceeding if you process special category data or face regulator scrutiny in your sector.
This briefing is reading support only, not legal advice.