dpa-review

Apply the DPA playbook to determine processor vs controller and generate a review memo.

Updated May 28, 2026
One-click install
npx skills add https://github.com/gtgspot/clegal --skill dpa-review-gtgspot
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/gtgspot/clegal/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/gtgspot/clegal --skill dpa-review-gtgspot

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Review and analyze Data Processing Agreements quickly by applying a dedicated DPA playbook to determine processor vs controller and generate a structured review memo.

Core Features & Use Cases

  • Automated DPA evaluation: Identify direction (processor vs controller) and load the appropriate playbook to guide decisions.
  • Term-by-term analysis: Perform a comprehensive review of data-processing terms, subprocessor changes, security, breach, and transfer provisions.
  • Output-ready: Produce a review memo with bottom line, term-by-term findings, privacy-policy consistency checks, and recommended redlines.

Quick Start

Provide the DPA document to the skill and run the clause-by-clause review against the playbook.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a DPA review to identify processor vs controller roles?

To automate a DPA review, provide the agreement document and run a clause-by-clause analysis against a privacy-legal playbook. This determines the processor vs controller direction and generates a structured review memo with cited primary sources.

Can I generate redlines for a Data Processing Agreement automatically?

Yes, you can generate redlines for a Data Processing Agreement by performing a term-by-term analysis of data-processing terms, subprocessor changes, and security provisions. The process produces an outputs package with recommended redlines for matter-level reviews.

What is included in a Data Processing Agreement risk assessment?

A Data Processing Agreement risk assessment includes term-by-term findings on data-processing terms, subprocessor changes, security, breach, and transfer provisions. It also features privacy-policy consistency checks and a bottom-line summary in a review memo.

Do I need a specific privacy-legal playbook path to review a DPA?

Yes, you need access to a configured privacy-legal CLAUDE playbook path to evaluate a DPA. The playbook guides the processor vs controller decisions and consistency checks required to generate the final review memo and redlines.

What's the best way to check privacy policy consistency during a DPA review?

The best way to check privacy-policy consistency during a DPA review is to run an automated evaluation that cross-references the agreement's data-processing terms against the playbook. This identifies discrepancies and supports findings with cited primary sources.

When should I not use automated DPA review for compliance assessments?

You should not use automated DPA review if you lack a configured privacy-legal playbook path or the actual DPA document. The process requires these inputs to determine roles, cite primary sources, and generate accurate redlines and review memos.