What problem does it solve?
It helps you quickly identify whether a Data Processing Agreement (DPA) is acceptable by benchmarking each term against your organization’s privacy playbook, including the correct direction (we are processor vs. we are controller).
Core Features & Use Cases
- Direction-aware review (processor vs. controller): Automatically selects the correct side of the playbook based on whether the counterparty is sending you their DPA or you are reviewing/sending one to a vendor.
- Clause-by-clause term assessment: Evaluates roles, processing scope, subprocessors, security measures, breach notification, audit rights, international transfers, deletion/return, and liability.
- Privacy policy consistency checks: Flags mismatches between what the DPA promises and what the privacy policy commits to.
- Attorney-ready outputs with redlines: Produces an issues list and consolidated recommended redlines formatted for legal review and negotiation.
Quick Start
Use the dpa-review skill to review the attached document 'customer-dpa.pdf' by running: /privacy-legal:dpa-review customer-dpa.pdf