playbook-dpa

Reviews GDPR data processing agreements against firm-approved clause positions and fallback text.

72|19|Updated Jun 6, 2026
One-click install
npx skills add https://github.com/sure-scale/doc-haus --skill playbook-dpa-sure-scale
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: playbook-dpa
Source: https://github.com/sure-scale/doc-haus/tree/main/dochaus/playbooks/playbook-dpa
Command: npx skills add https://github.com/sure-scale/doc-haus --skill playbook-dpa-sure-scale

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Negotiating data processing agreements clause by clause is slow and inconsistent without a documented firm position. This playbook gives reviewers approved replacement language, fallback positions, and unacceptable-clause criteria for every standard DPA section under the GDPR and UK GDPR. ## Core Features & Use Cases - Clause-by-clause positions: Covers documented instructions, confidentiality, security measures, subprocessors, data subject requests, breach notification, deletion/return, audit rights, international transfers, and liability allocation. - Approved and fallback text: Provides byte-exact firm-approved replacement clauses plus conditional fallback language for common vendor pushback scenarios. - Jurisdiction guard: Restricts application to processing subject to the GDPR or UK GDPR and flags DPAs whose governing law or scope falls outside the EU/EEA and UK. - Use Case: A vendor returns a DPA with a five-day breach notice window and unrestricted subprocessor rights. The reviewer applies the playbook to redline both clauses with the approved 72-hour backstop and notice-and-objection subprocessor language. ## Quick Start Review this vendor DPA against the playbook and redline any clauses that fall below the firm's approved positions.

Frequently Asked Questions about playbook-dpa

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I redline a data processing agreement under GDPR?

Compare each DPA clause against the playbook's preferred position for that clause type. Where the vendor text is unacceptable, replace it with the approved clause text copied byte-exact into the redline tool's replacement argument.

What clauses should a GDPR Article 28 DPA contain?

Article 28 requires documented-instructions processing, confidentiality commitments, security measures, subprocessor authorization and flow-down, data subject request assistance, breach notification, deletion or return of data, and audit rights. The playbook provides approved text for each.

When should I use the fallback clause text instead of the approved text?

Use fallback text only when its stated condition is met, such as a subscription-based subprocessor notice mechanism or a multi-tenant environment restricting on-site audits. Each fallback fence specifies its triggering circumstance.

Does this playbook apply to DPAs governed by non-EU law?

No. The playbook applies only to processing subject to the GDPR or UK GDPR. DPAs whose governing law or processing scope falls outside the EU/EEA and UK should be flagged to the user rather than redlined with these positions.

Is a 72-hour breach notification window a legal requirement for processors?

No. The statutory processor duty under Article 33(2) GDPR is notification without undue delay; the 72-hour backstop is contractual market practice. The playbook distinguishes statutory requirements from market positions in each Rationale section.