dpa-review

Review a DPA document against a configured privacy playbook and generate a redline memo.

9.1k|1.8k|Updated Apr 21, 2026
One-click install
npx skills add https://github.com/anthropics/claude-for-legal --skill dpa-review-anthropics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/anthropics/claude-for-legal/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/anthropics/claude-for-legal --skill dpa-review-anthropics

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

dpa-review helps you quickly evaluate a data processing agreement (DPA) against your organization’s established privacy playbook by identifying mismatches, gaps, and risky terms and turning them into a review memo with targeted redlines.

Core Features & Use Cases

  • Processor vs. controller review mode: Detects whether you’re acting as the processor (customer’s DPA to you) or the controller (you to a vendor) and applies the correct half of the playbook.
  • Term-by-term DPA gap analysis: Checks core clauses such as roles, processing scope, subprocessor changes, security measures, breach notice timing, audit rights, international transfers, deletion/return, and liability.
  • Privacy policy consistency check: Flags conflicts between what the DPA promises and what your privacy policy commits to.
  • Redline-ready negotiation output: Produces a structured memo with a clear bottom line, issue ratings, consolidated recommended redlines, and fallback/escalation guidance.

Quick Start

Use the command shown in the skill to review the attached file customer-dpa.pdf.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a data processing agreement against my organization's privacy playbook?

To review a data processing agreement (DPA), you load your privacy playbook into the local CLAUDE.md configuration, then the skill analyzes the DPA term-by-term to detect your role as processor or controller and generates a redline-ready memo with targeted corrections.

Can I automate DPA redlining for subprocessor management and breach notification clauses?

Yes, DPA redlining is automated by checking specific clauses such as subprocessor changes and breach notice timing against your configured playbook, then outputting consolidated recommended redlines and fallback guidance for negotiation.

What is the difference between processor and controller review mode for DPA gap analysis?

Processor review mode evaluates a customer's DPA sent to you, while controller review mode evaluates a DPA you send to a vendor. The skill detects your role and applies the correct half of your privacy playbook for accurate clause expectations.

How do I check if a DPA's international transfer terms conflict with my privacy policy?

Checking DPA consistency involves flagging conflicts between what the DPA promises and what your privacy policy commits to. The skill performs a privacy policy consistency check alongside international transfer and deletion clause analysis.

What do I need to configure before running a DPA clause analysis?

Before running DPA clause analysis, you need your organization's privacy playbook loaded into the local CLAUDE.md configuration file. This provides the clause expectations for roles, scope, security, audit rights, and liability that the skill enforces.

Does DPA review enforce safety gates before allowing contract signing decisions?

Yes, DPA review enforces safety gates for signing decisions by generating a structured memo with a clear bottom line, issue ratings, and escalation guidance, ensuring risky terms are flagged before any agreement is finalized.