dpa-review

Reviews Data Processing Agreements against a configurable playbook and produces redline memos.

Updated Jun 17, 2026
One-click install
npx skills add https://github.com/tk1cntt/PhapChe --skill dpa-review-tk1cntt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/tk1cntt/PhapChe/tree/main/docs/claude-for-legal-main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/tk1cntt/PhapChe --skill dpa-review-tk1cntt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Reviewing a Data Processing Agreement term-by-term is slow and error-prone, and the right negotiating position flips depending on whether you are the processor or the controller. This Skill walks a DPA clause by clause against your configured playbook, detects your role automatically, and produces a review memo with surgical redlines. ## Core Features & Use Cases - Direction-aware review: Auto-detects whether you are the processor (customer's DPA) or controller (vendor's DPA) and applies the correct half of the playbook. - Term-by-term analysis: Checks roles, subprocessors, security measures, breach notification, audit rights, international transfers, deletion, and liability against playbook positions and regulatory floors. - Federal sectoral overlay: Flags GLBA, HIPAA, FERPA, COPPA, and other sectoral regimes that a generic GDPR-style review would miss. - Use Case: A customer sends their DPA attached to an MSA. Run the review to get a memo rating each issue 🟢🟡🟠🔴, consolidated redlines, fallback positions, and a privacy-policy consistency check. ## Quick Start Review the attached customer DPA against our playbook and produce a redline memo.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement against my playbook?

Provide the DPA as a file, Drive link, or pasted text. The Skill loads your configured DPA playbook, determines whether you are processor or controller, walks each core term against playbook positions, and outputs a review memo with recommended redlines.

What terms does a DPA review check?

The review covers roles, processing scope, subprocessors, security measures, breach notification timelines, audit rights, international transfer mechanisms, deletion and return, and liability. Each term is compared to your playbook position and the applicable regulatory floor.

Does DPA review handle GDPR and US state privacy laws?

Yes, the review assumes the jurisdictional scope set in your configuration and checks GDPR, state consumer privacy laws, and federal sectoral regimes like GLBA, HIPAA, FERPA, and COPPA. It flags when a counterparty or data subjects fall outside the configured jurisdiction.

Can the DPA review draft a new agreement from scratch?

No, the Skill only reviews existing DPAs and produces redlines; it does not draft one from scratch. If a template is needed, it directs you to the template path in your configuration, and it flags rather than performs Transfer Impact Assessments.

Why does the DPA review ask whether we are processor or controller?

The negotiating posture is nearly opposite for each role: as processor you defend operational flexibility, while as controller you demand protective commitments. Getting the direction wrong inverts every recommendation, so the Skill asks when it is ambiguous.