Prompt: draft a data protection policy starter

Any charity handling people’s data needs a clear data protection policy. This prompt drafts a plain-English starter covering the data you hold, why you hold it, and people’s rights — a first version to check against ICO guidance and adopt. You verify the legal specifics, because data protection rules are exact and change.

What to paste in

Tell the AI what you do, whose data you hold and what kind, any sensitive data, and how you store it. It drafts a structured policy and flags every legal specific — lawful basis, retention, rights — for you to confirm with ICO guidance.

[prompt_text renders here]

What to check afterwards

Check your lawful bases, retention periods and rights wording against current ICO guidance rather than the AI’s phrasing. Confirm the breach-reporting duty, address any special category data with extra safeguards, and check whether your charity must pay the ICO data protection fee. The policy must describe what you actually do.

Certain personal data breaches must be reported to the ICO without undue delay and within 72 hours of becoming aware, where the breach risks people’s rights (Source: ICO, accessed 9 July 2026; verified 11 Jul 2026).

Worked example

The illustrative example is a plain starter with [CHECK] flags on every legal specific — lawful basis, retention, breach duty — for the charity to confirm before adopting.

CharityIQ can draft a data protection policy grounded in what data your charity actually holds, with the legal specifics flagged for you to verify.