What problem does it solve?
It reduces the time and risk of reviewing a Data Processing Agreement by systematically checking each key privacy-control term against your DPA playbook, including the required direction-specific posture (processor vs. controller).
Core Features & Use Cases
- Processor vs. controller detection: Automatically treats the review as defensive or protective depending on whether you are the processor (customer-sent DPA) or the controller (vendor/vendor-sent or you sent the DPA), and asks for clarification if direction is ambiguous.
- Playbook-driven term-by-term review: Compares the agreement clause by clause to the configured DPA playbook positions and flags gaps in areas like roles, scope, subprocessing, security measures, breach notice, audit rights, international transfers, deletion/return, and liability.
- Privacy policy consistency check: Flags mismatches between the DPA commitments and the privacy policy commitments so you don’t promise contradictory terms.
- Negotiation-ready output: Produces a review memo with prioritized issues and consolidated redlines suitable for attorney review.
Quick Start
Use the dpa-review skill on an attached document like customer-dpa.pdf by asking it to review this DPA.