What problem does it solve?
It helps you review a Data Processing Agreement to confirm it meets UK GDPR Article 28 mandatory processor/controller terms and that key clauses (sub-processors, security, breaches, international transfers, and notice alignment) are fit for purpose.
Core Features & Use Cases
- Detects DPA direction (processor vs controller) and applies the correct Art.28 playbook path, so recommendations match the real legal posture.
- Validates the Art.28(3) mandatory provisions and flags any missing items as a non-negotiable compliance failure.
- Checks critical commercial/privacy terms including sub-processor change rules, breach notification obligations, security measures, audit rights, deletion/return, liability, assistance obligations, and international transfer mechanisms.
- Ensures privacy notice consistency so the DPA does not promise data uses or transfer positions that the privacy notice does not support.
Quick Start
Run the review on the attached DPA file by asking the assistant to execute /privacy-legal-uk:dpa-review with your document.