dpa-checklist-review

Score DPA, addendum, or BAA clauses as present, partial, missing, or unclear.

46|25|Updated May 7, 2026
One-click install
npx skills add https://github.com/LegalQuants/lq-skills --skill dpa-checklist-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-checklist-review
Source: https://github.com/LegalQuants/lq-skills/tree/main/skills/dpa-checklist-review
Command: npx skills add https://github.com/LegalQuants/lq-skills --skill dpa-checklist-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill turns a messy contract review into a structured, clause-referenced compliance checklist so you can quickly see what is present, partial, missing, or unclear in a Data Processing Agreement (DPA), DPA addendum, or HIPAA Business Associate Agreement (BAA).

Core Features & Use Cases

  • Regime-based checklist scoring: Reviews against one of four selectable scopes—GDPR (Art. 28 + Art. 32 + transfers), US state privacy laws (CCPA/CPRA and the convergent set), HIPAA BAAs, or general commercial DPA baseline.
  • Clause-referenced gap analysis: Produces a table where each required term is mapped to a clause reference and a severity level (High/Medium/Low) for compliance triage.
  • Operationally actionable remediation: Includes recommended language for gaps (for Partial/Missing/Unclear items) to speed up negotiation and redlining.
  • Role-aware scrutiny: Uses party_role (controller vs processor, or equivalent) to calibrate what to scrutinize most heavily.
  • Structured handling of edge cases: Flags when the document type/regime selection looks mismatched and calls out transfer-mechanism issues for GDPR scenarios.

Quick Start

Use the dpa-checklist-review skill to review the attached DPA document for GDPR compliance using the regulatory_regime value "gdpr".

Frequently Asked Questions about dpa-checklist-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement for GDPR Article 28 compliance?

Review a DPA for GDPR compliance by scoring each Article 28 and 32 required term as present, partial, missing, or unclear with clause references. This structured checklist approach maps required terms to severity levels for compliance triage.

Can I check a HIPAA Business Associate Agreement for required safeguards?

Check a HIPAA BAA by scoring required terms against 45 CFR §164.504(e)(2) safeguards. The review flags terms as present, partial, missing, or unclear, and generates recommended clause language to remediate detected gaps.

What is the best way to identify missing clauses in a CCPA DPA?

Identify missing clauses in a CCPA DPA using a regime-based checklist scoring method. This approach maps each convergent US state privacy law provision to a clause reference and assigns a severity level for compliance triage.

How do I generate recommended redline language for partial DPA terms?

Generate recommended redline language for partial or missing DPA terms through an operationally actionable remediation checklist. This provides suggested clause language mapped to detected gaps to speed up contract negotiation.

Does DPA review vary if my role is a controller versus a processor?

DPA review varies by role using role-aware scrutiny to calibrate what to scrutinize most heavily. Setting the party role as controller versus processor adjusts the checklist focus based on your specific compliance obligations.

How does a checklist review handle GDPR data transfer mechanism issues?

A checklist review handles GDPR data transfer mechanisms by specifically flagging transfer-mechanism issues when reviewing against GDPR Article 28 and transfer requirements. It also flags when the document type or regime selection looks mismatched.