What problem does it solve?
Privacy counsels and legal ops leads spend hours manually reviewing vendor Data Processing Addendums (DPAs) for GDPR and CCPA-CPRA compliance, often missing vague clauses, red-flag anti-patterns, and inconsistent obligation scoring across vendors.
Core Features & Use Cases
- Structured first-pass review: Scores every DPA obligation against a customizable firm checklist covering GDPR Article 28 and CCPA-CPRA default requirements, with per-section citations for every finding.
- Red-flag detection: Automatically flags common anti-patterns like vague breach notification windows, uncapped privacy liability, and broad sub-processor consent waivers that pose compliance risk.
- Actionable redlines: Generates recommended replacement language sourced from the firm's checklist, prior accepted vendor terms, or standard regulatory text, with clear source attribution for counsel to weight.
- Use case: A privacy counsel can use this skill to reduce first-pass DPA review time from 2+ hours per document to 10 minutes, ensuring no critical compliance gaps are missed before escalation to review.
Quick Start
Use the dpa-reviewer skill to review the vendor DPA file at '/path/to/vendor-dpa.md' against your firm's checklist at '/path/to/firm-dpa-checklist.md' to generate a structured compliance report with per-section findings and recommended redlines.