compliance

Review Data Processing Agreements against GDPR Article 28 requirements.

Updated Feb 6, 2026
One-click install
npx skills add https://github.com/lohasle/knowledge-work-plugins --skill compliance-lohasle
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance
Source: https://github.com/lohasle/knowledge-work-plugins/tree/main/legal/skills/compliance
Command: npx skills add https://github.com/lohasle/knowledge-work-plugins --skill compliance-lohasle

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps legal teams manage complex privacy regulations, review data processing agreements, and handle data subject requests efficiently, reducing compliance risks.

Core Features & Use Cases

  • Regulatory Navigation: Provides overviews and key obligations for major privacy laws like GDPR, CCPA/CPRA, and others.
  • DPA Review: Offers a checklist to ensure Data Processing Agreements meet legal requirements.
  • Data Subject Request Handling: Guides users through the process of intake, verification, and response for data subject requests.
  • Use Case: When a new vendor sends a Data Processing Addendum (DPA), use this Skill to quickly check if it includes all necessary clauses for GDPR compliance, such as sub-processor notification and data breach assistance.

Quick Start

Use the compliance skill to review the attached Data Processing Agreement against GDPR Article 28 requirements.

Frequently Asked Questions about compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement for GDPR compliance?

To review a Data Processing Agreement for GDPR compliance, check it against Article 28 requirements using a clause checklist. This verifies that sub-processor notifications and data breach assistance provisions are properly included before signing.

What is the process for handling data subject requests under CCPA and GDPR?

Handling data subject requests involves three steps: intake, verification, and response. This process ensures you properly manage data subject rights and maintain compliance with privacy laws like GDPR and CCPA/CPRA.

What key obligations must I navigate for international privacy laws like LGPD and CPRA?

Navigating international privacy laws requires understanding key obligations across frameworks like GDPR, CCPA/CPRA, and LGPD. You must map specific regulatory requirements to your data processing activities to mitigate legal compliance risks.

Do I need a legal professional to manage vendor DPAs and data subject rights?

Managing vendor DPAs and data subject rights requires an understanding of legal frameworks and DPA clauses. Legal professionals use specialized workflows to ensure agreements meet international privacy law requirements and reduce compliance risks.

What clauses should a vendor Data Processing Addendum include for privacy compliance?

A vendor Data Processing Addendum must include clauses for sub-processor notification and data breach assistance to ensure privacy compliance. Reviewing these specific provisions confirms the agreement meets GDPR Article 28 standards.