dpa-review

Review data processing agreements for Turkish KVKK compliance and operational completeness.

100|16|Updated May 13, 2026
One-click install
npx skills add https://github.com/ZekaiSuni/claude-for-legal-turkish --skill dpa-review-zekaisuni
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/ZekaiSuni/claude-for-legal-turkish/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/ZekaiSuni/claude-for-legal-turkish --skill dpa-review-zekaisuni

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill removes uncertainty in supplier/customer data processing agreements by checking whether your DPA and related annexes align with Turkish KVKK requirements and operational realities.

Core Features & Use Cases

  • KVKK-focused contract review: Verifies roles, permitted purposes, data categories, and the contract basis for processing.
  • Operational controls coverage: Checks security measures (KVKK m.12), sub-processor handling, incident notification timing, deletion/return/improper retention clauses, and audit rights.
  • Cross-border transfer alignment: Assesses whether international data transfers follow KVKK m.9 mechanisms, including standard commitments, notifications, and signature/process requirements.
  • Negotiation-ready redlines: Produces actionable gaps and targeted redline suggestions instead of generic text generation.

Quick Start

Provide the DPA text (or attach the supplier/customer DPA annex) and ask for a KVKK role- and clause-based review with specific redline recommendations.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a data processing agreement for KVKK compliance?

To review a data processing agreement for KVKK compliance, provide the contract text to check roles, permitted purposes, KVKK m.12 security measures, sub-processor controls, incident notification timing, and deletion or return clauses.

What is a cross-border data transfer mechanism under KVKK m.9?

A cross-border data transfer mechanism under KVKK m.9 regulates international data sharing by requiring standard commitments and specific notifications. The review verifies your DPA aligns with these signature and process requirements.

Can I generate negotiation redlines for a supplier DPA annex?

Yes, you can generate negotiation-oriented redlines for a supplier or customer DPA annex. The review identifies actionable gaps and outputs targeted redline suggestions requiring human approval before finalization.

Does DPA review work for unclear controller and processor roles?

DPA review works for unclear controller and processor roles by performing a role-triage. It evaluates mixed or uncertain operational scenarios to determine the correct KVKK obligations and apply the appropriate contract basis.

What security measures must a KVKK compliant contract include?

A KVKK compliant contract must include security measures under KVKK m.12, covering sub-processor handling, incident notification timing, audit rights, and improper retention clauses. The review verifies operational completeness against these requirements.