dpa-review

Review a Data Processing Agreement against a configured DPA playbook.

Updated May 26, 2026
One-click install
npx skills add https://github.com/yachela/claude-for-legal-ar --skill dpa-review-yachela
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/yachela/claude-for-legal-ar/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/yachela/claude-for-legal-ar --skill dpa-review-yachela

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It reduces the time and risk of reviewing a Data Processing Agreement by systematically checking each key privacy-control term against your DPA playbook, including the required direction-specific posture (processor vs. controller).

Core Features & Use Cases

  • Processor vs. controller detection: Automatically treats the review as defensive or protective depending on whether you are the processor (customer-sent DPA) or the controller (vendor/vendor-sent or you sent the DPA), and asks for clarification if direction is ambiguous.
  • Playbook-driven term-by-term review: Compares the agreement clause by clause to the configured DPA playbook positions and flags gaps in areas like roles, scope, subprocessing, security measures, breach notice, audit rights, international transfers, deletion/return, and liability.
  • Privacy policy consistency check: Flags mismatches between the DPA commitments and the privacy policy commitments so you don’t promise contradictory terms.
  • Negotiation-ready output: Produces a review memo with prioritized issues and consolidated redlines suitable for attorney review.

Quick Start

Use the dpa-review skill on an attached document like customer-dpa.pdf by asking it to review this DPA.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement against my privacy playbook?

To review a Data Processing Agreement against your playbook, attach the DPA document and trigger the review. The Skill loads your configured playbook positions and runs a term-by-term consistency check to identify clause gaps.

How does a DPA review detect processor versus controller stance?

DPA review detects processor versus controller stance by evaluating the document direction. It treats the review as defensive if you are the processor or protective if you are the controller, and prompts for clarification if the direction is ambiguous.

Can I check if my DPA clauses contradict my privacy policy commitments?

Yes, you can check if your DPA contradicts your privacy policy commitments. The review runs a privacy policy consistency check to flag mismatches between the DPA commitments and your configured privacy policy to prevent contradictory terms.

What is the best way to generate negotiation-ready redlines for a DPA?

The best way to generate negotiation-ready redlines is running a playbook-driven term-by-term review. The process compares clauses in areas like subprocessing, security, and international transfers, outputting consolidated redlines and a prioritized risk summary.

Does DPA review cover international data transfer clauses?

Yes, DPA review covers international data transfer clauses. The term-by-term consistency check specifically flags gaps in international transfers alongside other key privacy-control areas like audit rights, breach notice, and liability.

When do I need to clarify the direction of a data processing addendum?

You need to clarify the direction of a data processing addendum when the processor versus controller relationship is ambiguous. Without clarification, the Skill cannot accurately determine whether to apply a defensive or protective review posture.