dpa-review

Review UK GDPR Data Processing Agreements for Article 28 compliance.

9|Updated May 18, 2026
One-click install
npx skills add https://github.com/uk-agents/uk-legal-plugins --skill dpa-review-uk-agents
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/uk-agents/uk-legal-plugins/tree/main/privacy-legal-uk/skills/dpa-review
Command: npx skills add https://github.com/uk-agents/uk-legal-plugins --skill dpa-review-uk-agents

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you review a Data Processing Agreement to confirm it meets UK GDPR Article 28 mandatory processor/controller terms and that key clauses (sub-processors, security, breaches, international transfers, and notice alignment) are fit for purpose.

Core Features & Use Cases

  • Detects DPA direction (processor vs controller) and applies the correct Art.28 playbook path, so recommendations match the real legal posture.
  • Validates the Art.28(3) mandatory provisions and flags any missing items as a non-negotiable compliance failure.
  • Checks critical commercial/privacy terms including sub-processor change rules, breach notification obligations, security measures, audit rights, deletion/return, liability, assistance obligations, and international transfer mechanisms.
  • Ensures privacy notice consistency so the DPA does not promise data uses or transfer positions that the privacy notice does not support.

Quick Start

Run the review on the attached DPA file by asking the assistant to execute /privacy-legal-uk:dpa-review with your document.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check a Data Processing Agreement for UK GDPR Article 28 compliance?

A UK GDPR DPA review validates mandatory Art.28(3) provisions, sub-processor chain rules, breach notification obligations, and international transfer mechanisms. It detects whether the agreement establishes a controller or processor posture and flags missing clauses as compliance failures.

What mandatory provisions must a UK GDPR DPA include under Article 28(3)?

Mandatory provisions under UK GDPR Article 28(3) include details on processing purpose, data nature, subject categories, duration, and processor obligations. The review checks the DPA for these mandatory items and flags any missing elements as a non-negotiable compliance failure.

How do I verify international transfer mechanisms and privacy notice consistency in a DPA?

Verifying international transfer mechanisms requires checking the agreed transfer positions against your privacy notice. The review ensures the DPA does not promise data uses or transfer positions that the privacy notice does not support, outputting redline-ready corrections.

Does the DPA review work for both controller and processor agreements?

The DPA review works for both controller and processor agreements by detecting the DPA direction. It applies the correct Article 28 playbook path based on the detected legal posture, ensuring recommendations match the actual position.

What is the best way to evaluate sub-processor and breach notification clauses in a vendor DPA?

Evaluating sub-processor and breach notification clauses requires checking change rules and security measures. The review validates these critical commercial terms alongside deletion, return, liability, and assistance obligations to generate redline-ready output.