These prompts help legal professionals draft compliance policy documents fast. Each prompt produces a complete policy section you can refine and approve, not another template to fill out.
These prompts pair well with Jasper AI for Legal-specific tone control, or Copy.ai for fast iteration.
Data Protection and Privacy Policies
You are a compliance officer drafting a data breach notification policy for employee communications.
Company: {company_name} Industry: {industry_sector} Employee count: {number_of_employees} Previous incidents: {yes_no_brief_description} Notification timeline: {hours_or_days} Key stakeholders: {list_three_key_roles} Tone: {formal / accessible / urgent} Regulatory framework: {GDPR / CCPA / HIPAA / other}
Write a 400-500 word internal data breach notification policy. Structure it with clear trigger events, notification timelines, and escalation procedures. Include specific language employees can use when reporting incidents. End with a decision tree for severity classification.
When to use it: When your CISO flags gaps in incident response after a security audit or near-miss event.
Pro tip: Replace generic “immediately notify” language with specific timeframes like “within 2 hours of discovery” to avoid confusion during actual incidents.
You are a privacy counsel writing a cookie consent policy update for the company website.
Company: {company_name} Website type: {ecommerce / saas / corporate / other} Current cookies: {analytics_marketing_functional} Third-party tools: {list_main_tracking_tools} User base location: {primary_geographic_regions} Business impact concern: {conversion_rates / user_experience / analytics} Legal jurisdiction: {EU / US / Canada / other} Implementation deadline: {date_or_timeframe}
Write a 300-400 word cookie policy section that explains cookie categories, user choices, and opt-out procedures. Use plain English that non-lawyers understand. Include specific instructions for users who want to withdraw consent after initial acceptance.
When to use it: When marketing reports dropping conversion rates after privacy law changes or competitor policy updates.
Pro tip: Test your policy language with actual users before publishing—legal precision often conflicts with user comprehension, especially around “legitimate interest” categories.
You are an employment lawyer drafting a workplace surveillance policy for hybrid teams.
Company: {company_name} Remote work percentage: {percentage_remote_hybrid} Monitoring tools used: {productivity_software_list} Employee concerns raised: {privacy_productivity_trust_other} Industry requirements: {financial_healthcare_none} Union presence: {yes_no_collective_bargaining} Jurisdiction: {state_country_employment_law} Policy tone: {transparent / reassuring / compliance_focused}
Write a 500-600 word workplace surveillance policy. Open with business justification and employee benefits. Detail what is monitored, when, and who has access to data. Include employee rights and dispute procedures. Structure with clear headers for easy reference during onboarding.
When to use it: When HR reports employee pushback on productivity monitoring tools or before implementing new remote work software.
Pro tip: Specify data retention periods for monitoring records—indefinite retention creates unnecessary legal liability and employee distrust.
You are a chief privacy officer updating the company’s third-party data sharing policy after a vendor audit.
Company: {company_name} Audit findings: {data_sharing_gaps_found} Key vendors: {list_top_five_data_processors} Data types shared: {customer_employee_financial_other} Regulatory requirements: {gdpr_ccpa_hipaa_sox_other} Risk tolerance: {conservative / balanced / aggressive} Vendor management maturity: {basic / intermediate / advanced} Contract renewal cycle: {annual_biannual_ongoing}
Write a 450-550 word third-party data sharing policy. Include vendor vetting requirements, data processing agreements, and ongoing monitoring procedures. Add specific criteria for high-risk vendors and data types. End with clear approval workflows for new vendor relationships.
When to use it: When procurement brings vendor contracts that involve customer data but lack proper privacy safeguards.
Pro tip: Create different approval thresholds based on data sensitivity—not all vendor relationships need C-suite approval, but payment processors and analytics tools should.
You are a compliance manager writing a records retention policy for financial services client communications.
Company: {company_name} Client communication channels: {email_chat_calls_meetings} Regulatory body: {sec_finra_cftc_other} Retention requirements: {specific_timeframes_by_record_type} Storage systems: {cloud_onpremise_hybrid} Destruction procedures: {automatic_manual_certified} Audit history: {recent_findings_or_clean} Team size: {number_handling_records}
Write a 400-500 word records retention policy focused on client communications. Organize by communication type with specific retention periods and destruction schedules. Include procedures for litigation holds and regulatory requests. Add a simple reference table for quick lookups during busy periods.
When to use it: When regulators request communication records and your team struggles to locate or verify retention compliance.
Pro tip: Automate retention schedules wherever possible—manual tracking fails during staff turnover and high-volume periods.
Anti-Corruption and Ethics Policies
You are a chief compliance officer drafting a gift and entertainment policy for client-facing employees.
Company: {company_name} Client types: {government_private_healthcare_other} Geographic operations: {countries_or_regions} Previous violations: {none_minor_significant} Industry norms: {conservative_moderate_liberal} Approval levels needed: {manager_compliance_clevel} Monetary thresholds: {dollar_amounts_by_category} Reporting requirements: {quarterly_annual_incident_based}
Write a 500-600 word gift and entertainment policy. Start with clear monetary limits by category and recipient type. Include pre-approval procedures and documentation requirements. Add practical examples of acceptable and prohibited activities. End with reporting procedures for borderline situations.
When to use it: When sales teams ask about client entertainment limits before major conferences or deal closings.
Pro tip: Set different limits for government versus private sector clients—what’s acceptable for corporate clients often violates government ethics rules.
You are a general counsel writing a conflicts of interest policy for senior executives.
Company: {company_name} Executive level coverage: {c_suite_vp_director_all} Business relationships concern: {vendor_customer_competitor_investment} Disclosure frequency: {annual_quarterly_transaction_based} Review process: {board_audit_committee_hr} Industry conflicts: {common_sector_specific_issues} Family member scope: {spouse_children_extended_family} Remediation options: {recusal_divestiture_resignation}
Write a 450-550 word conflicts of interest policy for executives. Define covered relationships and financial interests clearly. Include disclosure timelines and review procedures. Add specific guidance for board positions, investments, and family business interests. Structure with decision trees for common scenarios.
When to use it: When board members raise questions about executive outside activities or before annual disclosure cycles.
Pro tip: Require disclosure of potential conflicts, not just actual ones—perception matters as much as reality in regulatory and reputational contexts.
You are an employment attorney drafting a whistleblower protection policy after a recent incident.
Company: {company_name} Incident type: {financial_safety_discrimination_other} Reporting channels: {hotline_email_manager_external} Investigation team: {hr_legal_external_counsel} Protection scope: {employees_contractors_customers} Anonymous options: {yes_no_limited_circumstances} Retaliation concerns: {performance_reviews_assignments_termination} Legal requirements: {sox_dodd_frank_state_law}
Write a 400-500 word whistleblower protection policy. Open with strong anti-retaliation commitment and reporting encouragement. Detail multiple reporting channels and investigation procedures. Include specific examples of protected activities and prohibited retaliation. End with clear consequences for retaliation violations.
When to use it: When employees express fear about reporting misconduct or after settlement of retaliation claims.
Pro tip: Train managers separately on retaliation recognition—most violations happen through subtle changes in assignments or performance evaluations, not obvious terminations.
You are a compliance director writing an anti-bribery policy for international operations.
Company: {company_name} Operating countries: {list_key_international_markets} High-risk activities: {government_contracts_permits_customs} Local practices concern: {facilitation_payments_gift_customs} Due diligence scope: {agents_distributors_joint_ventures} Training requirements: {annual_role_based_country_specific} Monitoring procedures: {audits_reporting_red_flags} Enforcement history: {clean_warnings_violations}
Write a 550-650 word international anti-bribery policy. Address facilitation payments, third-party relationships, and government interactions. Include country-specific guidance for high-risk markets. Add red flag indicators and escalation procedures. Structure with clear prohibitions and limited exceptions with approval requirements.
When to use it: When entering new international markets or after due diligence reveals questionable third-party practices.
Pro tip: Address facilitation payments explicitly—many employees assume small “grease payments” are acceptable if they’re culturally normal, but they’re still illegal under most anti-bribery laws.
You are a chief ethics officer updating the company code of conduct after employee feedback surveys.
Company: {company_name} Survey feedback themes: {unclear_guidance_fear_reporting_inconsistent_enforcement} Employee demographics: {remote_onsite_generational_mix} Recent ethics issues: {conflicts_harassment_financial_other} Communication preferences: {email_video_interactive_written} Management support level: {strong_moderate_needs_improvement} Training format: {online_inperson_peer_led} Accountability measures: {performance_reviews_discipline_recognition}
Write a 500-600 word code of conduct introduction and framework. Address employee concerns directly with specific behavioral expectations. Include clear reporting procedures and protection assurances. Add practical scenarios relevant to daily work situations. End with leadership commitment statement and accountability measures.
When to use it: When annual ethics surveys show declining confidence or confusion about company standards.
Pro tip: Include positive examples of ethical behavior, not just prohibitions—employees respond better to aspirational guidance than fear-based compliance.
Financial Compliance and Reporting
You are a controller writing an expense policy for remote employees with corporate credit cards.
Company: {company_name} Remote employee percentage: {percentage_workforce} Expense categories: {travel_meals_office_equipment_other} Approval thresholds: {dollar_amounts_by_level} Receipt requirements: {digital_physical_exception_rules} Reimbursement timeline: {days_or_weeks} Card misuse concerns: {personal_use_overages_lost_cards} Audit frequency: {monthly_quarterly_random}
Write a 400-500 word expense policy for remote workers. Specify allowable expenses, documentation requirements, and approval workflows. Include home office equipment guidelines and travel expense procedures. Add clear consequences for policy violations and dispute resolution procedures.
When to use it: When finance reports increasing expense violations or unclear remote work expense claims.
Pro tip: Define “reasonable” expenses with specific examples and dollar ranges—“reasonable business meal” means different things to different people and income levels.
You are a chief financial officer drafting a financial disclosure policy for quarterly earnings calls.
Company: {company_name} Public status: {public_preparing_ipo_private_regulated} Disclosure triggers: {material_changes_forward_guidance_metrics} Review process: {legal_audit_committee_board} Communication channels: {earnings_calls_press_releases_sec_filings} Materiality threshold: {percentage_dollar_amount} Forward guidance: {provided_avoided_limited_circumstances} Quiet period procedures: {duration_restrictions_exceptions}
Write a 450-550 word financial disclosure policy. Define materiality standards and disclosure timing requirements. Include pre-clearance procedures for public statements and social media. Add specific guidance for forward-looking statements and quiet periods. Structure with approval workflows and escalation procedures.
When to use it: When investor relations schedules earnings calls or after SEC comments on previous disclosure practices.
Pro tip: Create standard disclosure templates for common scenarios—having pre-approved language for acquisitions, restructuring, and guidance changes speeds up review during time-sensitive situations.
You are a compliance manager writing a purchasing policy for vendor contracts over the approval threshold.
Company: {company_name} Approval threshold: {dollar_amount} Vendor categories: {technology_professional_services_supplies_other} Procurement team size: {centralized_distributed_hybrid} Contract terms concern: {liability_data_security_performance} Budget authority levels: {department_division_corporate} Competitive bidding requirements: {always_threshold_based_exceptions} Emergency procedures: {business_continuity_urgent_needs}
Write a 400-500 word purchasing policy for high-value vendor contracts. Include competitive bidding requirements, approval workflows, and contract term standards. Add emergency procurement procedures and budget authority guidelines. End with vendor performance monitoring and renewal procedures.
When to use it: When department heads bypass procurement for large software purchases or consulting agreements.
Pro tip: Build in emergency procurement procedures with retroactive approval requirements—business emergencies happen, but they shouldn’t bypass all controls.
You are a tax director writing a transfer pricing documentation policy for international subsidiaries.
Company: {company_name} International structure: {subsidiaries_branches_joint_ventures} Intercompany transactions: {services_royalties_goods_loans} Documentation requirements: {local_country_master_file} Economic analysis: {comparable_profits_cost_plus_market} Update frequency: {annual_transaction_based_regulatory_changes} Audit history: {clean_adjustments_penalties} Professional support: {internal_external_advisors}
Write a 500-600 word transfer pricing documentation policy. Specify documentation requirements by transaction type and jurisdiction. Include economic analysis standards and benchmarking procedures. Add update triggers and audit preparation procedures. Structure with clear responsibilities and deadlines.
When to use it: When tax authorities request transfer pricing documentation or before establishing new intercompany arrangements.
Pro tip: Maintain contemporaneous documentation—retroactive transfer pricing studies are more expensive and less defensible during audits.
You are a treasury manager writing a cash management policy for multiple bank accounts and subsidiaries.
Company: {company_name} Banking relationships: {number_banks_domestic_international} Cash sweep arrangements: {automated_manual_concentration_accounts} Investment guidelines: {short_term_restrictions_risk_limits} Signatory authorities: {single_dual_threshold_based} Foreign exchange: {hedging_natural_speculation_prohibited} Liquidity requirements: {minimum_cash_credit_facilities} Reporting frequency: {daily_weekly_monthly}
Write a 450-550 word cash management policy covering bank account management, investment guidelines, and authorization procedures. Include foreign exchange risk management and liquidity maintenance requirements. Add specific procedures for cash forecasting and variance reporting.
When to use it: When auditors question cash management controls or before implementing new treasury management systems.
Pro tip: Set different authorization levels for routine versus non-routine transactions—payroll and vendor payments need efficiency, but investment decisions need additional oversight.
Industry-Specific Compliance
You are a healthcare compliance officer writing a patient data