dpa-review

Review Data Processing Agreements to identify risks and produce redlines.

109|20|Updated Mar 7, 2025
One-click install
npx skills add https://github.com/stakwork/stakgraph --skill dpa-review-stakwork
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/stakwork/stakgraph/tree/main/mcp/skills/privacy-legal/dpa-review
Command: npx skills add https://github.com/stakwork/stakgraph --skill dpa-review-stakwork

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps legal and privacy teams evaluate Data Processing Agreements consistently, identify unacceptable obligations, and prepare focused negotiation redlines without overlooking regulatory or privacy-policy requirements.

Core Features & Use Cases

  • Direction Detection: Determines whether your organization is acting as processor or controller and applies the corresponding playbook.
  • Term-by-Term Review: Analyzes roles, processing scope, subprocessors, security, breach notification, audits, transfers, deletion, and liability.
  • Risk and Redline Analysis: Flags deal breakers, checks sectoral privacy overlays and policy consistency, and produces surgical redline language with fallback positions.
  • Use Case: Review a customer-provided DPA, compare its terms with the configured privacy playbook, identify gaps in international transfer protections, and produce a negotiation-ready memo.

Quick Start

Ask the DPA review skill to review the attached agreement and identify required changes, fallback positions, and any issues requiring attorney escalation.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement for privacy and legal risks?

Reviewing a Data Processing Agreement involves term-by-term analysis of roles, subprocessors, security, breach notification, and international transfers to identify legal, operational, and negotiation risks.

What is a DPA redline and how does it help with vendor negotiations?

A DPA redline is surgical language proposing specific changes to a Data Processing Agreement, providing fallback positions for negotiations and flagging deal breakers that require attorney escalation before signing.

How do I check if a DPA covers international data transfer requirements?

Checking international data transfers in a DPA requires analyzing cross-border transfer protections against your configured privacy playbook to identify gaps in regulatory compliance for data moving across jurisdictions.

Does DPA review work for both customer and vendor agreements?

DPA review works for both customer agreements where your organization is a processor and vendor agreements where it acts as a controller, applying direction detection to implement the corresponding privacy playbooks.

What privacy playbook do I need to configure before reviewing DPAs?

Before reviewing DPAs, you need a configured privacy-legal playbook, applicable legal research sources for current regulatory requirements, and explicit attorney review processes for escalation before signing.

When should I escalate DPA terms to an attorney?

You should escalate DPA terms to an attorney when deal breakers are identified, when sectoral privacy overlays apply to federally regulated data, or before signing any agreement to ensure regulatory compliance.