What problem does it solve?
This Skill turns a messy contract review into a structured, clause-referenced compliance checklist so you can quickly see what is present, partial, missing, or unclear in a Data Processing Agreement (DPA), DPA addendum, or HIPAA Business Associate Agreement (BAA).
Core Features & Use Cases
- Regime-based checklist scoring: Reviews against one of four selectable scopes—GDPR (Art. 28 + Art. 32 + transfers), US state privacy laws (CCPA/CPRA and the convergent set), HIPAA BAAs, or general commercial DPA baseline.
- Clause-referenced gap analysis: Produces a table where each required term is mapped to a clause reference and a severity level (High/Medium/Low) for compliance triage.
- Operationally actionable remediation: Includes recommended language for gaps (for Partial/Missing/Unclear items) to speed up negotiation and redlining.
- Role-aware scrutiny: Uses
party_role (controller vs processor, or equivalent) to calibrate what to scrutinize most heavily.
- Structured handling of edge cases: Flags when the document type/regime selection looks mismatched and calls out transfer-mechanism issues for GDPR scenarios.
Quick Start
Use the dpa-checklist-review skill to review the attached DPA document for GDPR compliance using the regulatory_regime value "gdpr".