dpa-review

Review Data Processing Agreements against an internal playbook and produce redlines.

Updated May 15, 2026
One-click install
npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill dpa-review-az9713
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/az9713/claude-for-legal-tutorial/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill dpa-review-az9713

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you quickly evaluate a Data Processing Agreement (DPA) by comparing its terms to your organization’s DPA playbook and producing a review memo with practical redlines.

Core Features & Use Cases

  • Direction-aware DPA review: Detects whether the agreement should be reviewed from a processor/customer or controller/vendor perspective and applies the corresponding playbook.
  • Term-by-term clause checking: Reviews core DPA terms (roles, processing scope, subprocessor changes, security measures, breach notification, audit rights, transfers, and deletion/return) with playbook-aligned risk framing.
  • Privacy policy consistency validation: Flags mismatches between the DPA commitments and the privacy policy obligations.
  • Attorney-oriented output: Produces a structured memo including an issues summary, term-by-term findings, and consolidated redlines, plus a next-steps decision tree.
  • Safety/verification guardrails: Stops to request clarification when research coverage is thin and includes source attribution guidance for legal citations.

Quick Start

Request a DPA review by attaching or pasting the DPA text and saying: "Review this DPA, focusing on redlines against our DPA playbook."

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement against my company playbook?

To review a Data Processing Agreement, you upload or paste the DPA text and request a review against your internal playbook. The Skill detects whether you are the processor or controller and applies the corresponding playbook rules to generate a structured review memo with redlines.

Can I generate redlines for subprocessor controls and international transfer clauses?

Yes, you can generate redlines for subprocessor controls and international transfers. The Skill performs term-by-term clause checking across core DPA terms and outputs consolidated redlines aligned with your playbook's risk framing.

What's the best way to check if a DPA matches our privacy policy obligations?

The best way to check if a DPA matches your privacy policy obligations is to use the privacy policy consistency validation feature. It automatically flags mismatches between the DPA commitments and your privacy policy during the review process.

Does the DPA review output work for attorney negotiation preparation?

Yes, the DPA review output works for attorney negotiation preparation. It produces an attorney-oriented structured memo containing an issues summary, term-by-term findings, consolidated redlines, and an escalation-ready next-steps decision tree.

How does the tool handle direction ambiguity in a DPA review?

When direction ambiguity occurs during a DPA review, the Skill stops to request clarification on whether you are acting as the processor or controller. This ensures the correct half of the internal DPA playbook is applied before proceeding with the analysis.

Are there limitations when reviewing DPAs with thin research coverage?

A key limitation is that the Skill includes safety guardrails that stop the review to request clarification when research coverage is thin. It also requires source attribution guidance for legal citations to ensure verification of the analysis.