dpa-review

Review Data Processing Agreements clause by clause against operational playbooks.

183|37|Updated May 15, 2026
One-click install
npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill dpa-review-zhou210712
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpa-review
Source: https://github.com/zhou210712/claude-for-legal-ZH/tree/main/privacy-legal/skills/dpa-review
Command: npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill dpa-review-zhou210712

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you review a Data Processing Agreement (DPA) by determining whether you are acting as the controller-facing processor or the processor-facing controller, then checking whether the contract matches the internal operational playbook and personal data processing rule commitments.

Core Features & Use Cases

  • Direction-aware DPA review: Automatically flips the review logic depending on whether the DPA is provided by a client (we are the entrusted processor) or by a vendor (we are the processor).
  • Playbook-guided clause-by-clause checking: Compares key DPA terms such as role, processing scope, downstream processing, security measures, breach notification, audit rights, data transfers, and deletion/return.
  • Consistency checks against rule commitments: Flags mismatches between what the signed DPA promises and what the personal data processing rule commitment states.
  • Negotiation-friendly revision markings: Produces a marked review memo with minimal, surgical edits aligned to the team’s standard stance.
  • Risk escalation and governance guardrails: Uses prior upstream outputs (triage/PIA/dpa-review) as severity baselines and routes decisions per the internal upgrade paths.

Quick Start

Use the dpa-review skill to review an incoming DPA by running /privacy-legal:dpa-review 客户dpa.pdf.

Frequently Asked Questions about dpa-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a Data Processing Agreement to check for privacy compliance risks?

To review a Data Processing Agreement for privacy compliance, upload the contract file or paste the DPA text, and the system automatically determines your role as controller or processor, then checks each clause against operational playbook baselines to produce a marked revision memo.

What DPA clauses should I check when reviewing a data processing contract?

When reviewing a data processing contract, key DPA clauses to check include processing scope, downstream processing, security measures, breach notification timelines, audit rights, data transfer mechanisms, and data deletion or return obligations.

How does direction-aware DPA review work for controller versus processor roles?

Direction-aware DPA review works by automatically flipping the assessment logic depending on whether the DPA is provided by a client, meaning you are the entrusted processor, or by a vendor, meaning you are the controller, ensuring role-specific compliance checks.

Can I check if a signed DPA matches my personal data processing rule commitments?

Yes, you can check if a signed DPA matches your personal data processing rule commitments through built-in consistency checks that flag mismatches between what the contract promises and what your internal rules state.

How do I generate a negotiation-friendly legal memo for DPA contract revisions?

You generate a negotiation-friendly legal memo for DPA revisions by running the review process, which produces a structured, clause-by-clause marked document with minimal, surgical edits aligned to your team's standard negotiation stance.

What happens when a DPA review identifies high-risk data transfer or breach notification terms?

When a DPA review identifies high-risk data transfer or breach notification terms, the system uses prior upstream triage or PIA outputs as severity baselines and routes the decision per internal upgrade paths for risk escalation and governance.