dpa-review

Review Data Processing Agreements against a configured privacy-legal playbook.

Updated Dec 4, 2025
One-click install
npx skills add https://github.com/PolliticalSolutions/political-portal --skill dpa-review-polliticalsolutions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/PolliticalSolutions/political-portal/tree/main/.claude/skills/privacy-legal/dpa-review
Command: npx skills add https://github.com/PolliticalSolutions/political-portal --skill dpa-review-polliticalsolutions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you evaluate a Data Processing Agreement (DPA) against a predefined privacy playbook, ensuring the review matches whether you act as a processor or a controller.

Core Features & Use Cases

  • Role-aware DPA direction: Detects whether you are reviewing a customer-issued DPA (processor posture) or a vendor-issued/your-issued DPA (controller posture), and applies the corresponding playbook rules.
  • Term-by-term contract scrutiny: Checks key clauses such as subprocessors, security measures, breach notification, audit rights, international transfers, deletion/return, and liability against the playbook and (where required) primary-law floors.
  • Consistency and negotiation-ready outputs: Performs a privacy policy consistency check and produces a structured review memo with prioritized issues and recommended redlines, including escalation guidance if fallback positions are insufficient.

Quick Start

Review an attached DPA by running the dpa-review skill on the file you received.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate GDPR DPA redlines for subprocessor and international transfer clauses?

Data Processing Agreement redlining evaluates DPA clauses against a privacy playbook to generate negotiation-ready risk redlines. It scans subprocessor, security, breach notification, audit, and international transfer terms using direction detection for processor or controller posture.

Can I review a Data Processing Agreement differently as a controller versus a processor?

Yes, role-aware DPA review detects whether you received a customer-issued or vendor-issued contract and applies the matching processor or controller playbook rules. This direction detection ensures protective scrutiny or defensive positioning aligns with your actual compliance posture.

What is the best way to check DPA compliance with privacy policy consistency requirements?

Performing a privacy policy consistency check during DPA review compares the contract's data processing terms against your stated privacy policies. The analysis produces a structured memo with prioritized issues, recommended redlines, and escalation guidance for insufficient fallback positions.

Do I need a configured privacy playbook to review DPA clauses for GDPR compliance?

Yes, you must load a configured CLAUDE.md privacy playbook to evaluate Data Processing Agreement terms. The playbook provides the rule set for term-by-term clause analysis across subprocessors, security measures, breach notification, deletion, and liability.

What DPA clauses are checked during a data protection agreement risk review?

A DPA risk review checks subprocessors, security measures, breach notification, audit rights, international transfers, deletion and return of data, and liability clauses. Each term is evaluated against the configured playbook and primary-law floors to generate prioritized, negotiation-ready redlines.

Why does my DPA review flag insufficient fallback positions for international transfers?

Data Processing Agreement review flags fallback positions when recommended redlines for clauses like international transfers fall below primary-law GDPR floors. The analysis includes escalation guidance to ensure your contract negotiation maintains required data protection standards.