dpa-review

Review DPAs against a privacy playbook with direction-aware clause analysis.

Updated May 19, 2026
One-click install
npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dpa-review-jrhueiueng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/jrhueiueng/codex-for-legal/tree/main/plugins/jrhueiueng/codex-for-legal/skills/privacy-legal__dpa-review
Command: npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dpa-review-jrhueiueng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you quickly identify whether a Data Processing Agreement (DPA) is acceptable by benchmarking each term against your organization’s privacy playbook, including the correct direction (we are processor vs. we are controller).

Core Features & Use Cases

  • Direction-aware review (processor vs. controller): Automatically selects the correct side of the playbook based on whether the counterparty is sending you their DPA or you are reviewing/sending one to a vendor.
  • Clause-by-clause term assessment: Evaluates roles, processing scope, subprocessors, security measures, breach notification, audit rights, international transfers, deletion/return, and liability.
  • Privacy policy consistency checks: Flags mismatches between what the DPA promises and what the privacy policy commits to.
  • Attorney-ready outputs with redlines: Produces an issues list and consolidated recommended redlines formatted for legal review and negotiation.

Quick Start

Use the dpa-review skill to review the attached document 'customer-dpa.pdf' by running: /privacy-legal:dpa-review customer-dpa.pdf

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement against my organization's privacy playbook?

To review a Data Processing Agreement, the skill performs term-by-term clause analysis against your configured DPA playbook, identifying gaps, risks, and outputting an attorney-ready review memo with recommended redlines.

What is a processor vs controller direction check in a DPA review?

A processor vs controller direction check in DPA review automatically detects your organization's role based on the counterparty context, ensuring the legal playbook applies the correct side's obligations to the agreement.

Can I automatically generate redlines for subprocessor and international transfer clauses?

Yes, you can automatically generate redlines for subprocessor and international transfer clauses by benchmarking the DPA text against your privacy playbook, producing consolidated attorney-ready negotiation edits.

Does DPA review check for privacy policy consistency with the data processing addendum?

Yes, DPA review includes privacy policy consistency checks that flag mismatches between what the Data Processing Agreement promises and what your organization's public privacy policy commits to.

What is the best way to identify risks in breach notification and audit rights clauses?

The best way to identify risks in breach notification and audit rights clauses is through a term-by-term assessment that benchmarks these specific provisions against a configured privacy-legal playbook to highlight gaps.

When do I need an attorney-ready review memo for a data processing agreement?

You need an attorney-ready review memo for a data processing agreement when you require a structured issues list, consolidated recommended redlines, and a next-steps decision tree to guide legal negotiation.