dpa-review

Review Russian personal data processing agreements for 152-FZ compliance.

17|4|Updated May 25, 2026
One-click install
npx skills add https://github.com/AlsKozlov/ru-legal --skill dpa-review-alskozlov
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/AlsKozlov/ru-legal/tree/main/packs/data-protection/skills/dpa-review
Command: npx skills add https://github.com/AlsKozlov/ru-legal --skill dpa-review-alskozlov

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Manually reviewing Russian personal data processing agreements (ДОУ) for compliance with 152-FZ is time-consuming and high-risk, as missing mandatory clauses can lead to RKN fines of up to 18 million rubles. This Skill automates the review process to catch non-compliant terms quickly and accurately.

Core Features & Use Cases

  • 152-FZ Mandatory Clause Validation: Checks all 5 required elements of ДОУ under Article 6 Part 3 of 152-FZ, including processing scope, security measures, and data localization rules.
  • Role-Adaptive Analysis: Automatically adjusts review criteria based on whether your organization is the data operator or the data processor, flipping recommendations to match your position.
  • Sectoral Overlay Checks: Flags additional strict requirements for regulated sectors like finance, healthcare, and telecom that go beyond baseline 152-FZ rules. Use case: A legal team receives a ДОУ from a vendor for signature; the skill runs a full compliance check, identifies missing localization clauses, and suggests precise redlines to avoid regulatory penalties.

Quick Start

Use the dpa-review skill to analyze the attached personal data processing agreement for full 152-FZ compliance.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check a Russian personal data processing agreement for 152-FZ compliance?

Role-adaptive analysis reviews the agreement differently depending on whether your organization is the data operator or the data processor. It automatically flips compliance recommendations and redline suggestions to match your specific contractual position and protect your interests.

Does 152-FZ compliance review include sectoral regulatory requirements for finance or healthcare?

152-FZ compliance review includes sectoral overlay checks that flag additional strict requirements for regulated sectors like finance, healthcare, and telecom. These sectoral checks go beyond baseline personal data protection rules to ensure full regulatory adherence and prevent specialized penalties.

What are the limitations of automated DPA review for cross-border data transfers?

Automated DPA review for cross-border data transfers is limited to flagging compliance with existing localization rules and mandatory clauses within the agreement text. It identifies high-risk clauses carrying RKN fines up to 18 million rubles but requires human legal interpretation for complex international transfer mechanisms.

Can I automate redline suggestions for non-compliant terms in a Russian data processing agreement?

You can automate redline suggestions for non-compliant terms in a Russian data processing agreement by running a full compliance check against 152-FZ requirements. The review identifies missing or high-risk clauses and generates precise redline suggestions to ensure regulatory compliance before signature.