Find sensitive-data exposure and design least-privilege controls across a data platform.
#pii
#governance
#privacy
#access-control
Prompt
Perform a privacy and access-control design review for this data platform. Treat inferred and quasi-identifying attributes as sensitive, not just obvious PII.
Jurisdictions and obligations: [GDPR / CCPA / HIPAA / PCI / internal policy]
Data sources and subject types: [customers, employees, merchants]
Schemas or catalog export:
[Paste fields, types, and descriptions]
Storage, transformation, and BI systems: [stack]
Roles and current grants: [details]
Retention and deletion requirements: [details]
Non-production data practices: [details]
Produce:
1. Field-level classification: direct identifier, quasi-identifier, sensitive, confidential, public
2. Data-flow and exposure map from collection through downstream exports
3. Least-privilege RBAC/ABAC model with row- and column-level controls
4. Masking, tokenization, encryption, and key-management recommendations
5. Safe non-production data strategy
6. Retention, legal hold, and verified deletion workflow across derived datasets
7. Access-review, break-glass, and audit-log controls
8. Detection queries for overbroad grants and unauthorized copies
9. Prioritized remediation plan by likelihood and impact
10. Tests proving policies remain enforced after schema and role changes
Distinguish policy requirements from technical recommendations. Flag places where de-identification can be reversed through joins.
Customize
Fill Variables
Details
Model
Claude 3
Category
Data Engineering
Added On
Jul 12, 2026
Prompts are starting points. Review outputs before using them in production.