What problem does it solve?
This Skill helps you review a Data Processing Agreement (DPA) by determining whether you are acting as the controller-facing processor or the processor-facing controller, then checking whether the contract matches the internal operational playbook and personal data processing rule commitments.
Core Features & Use Cases
- Direction-aware DPA review: Automatically flips the review logic depending on whether the DPA is provided by a client (we are the entrusted processor) or by a vendor (we are the processor).
- Playbook-guided clause-by-clause checking: Compares key DPA terms such as role, processing scope, downstream processing, security measures, breach notification, audit rights, data transfers, and deletion/return.
- Consistency checks against rule commitments: Flags mismatches between what the signed DPA promises and what the personal data processing rule commitment states.
- Negotiation-friendly revision markings: Produces a marked review memo with minimal, surgical edits aligned to the team’s standard stance.
- Risk escalation and governance guardrails: Uses prior upstream outputs (triage/PIA/dpa-review) as severity baselines and routes decisions per the internal upgrade paths.
Quick Start
Use the dpa-review skill to review an incoming DPA by running /privacy-legal:dpa-review 客户dpa.pdf.