Read a Data Processing Agreement before you sign it β sub-processors, transfer mechanism, breach-notice window, deletion, audit rights β in plain language with π΄π‘π’ risk.
Read a Data Processing Agreement before you sign it β sub-processors, transfer mechanism, breach-notice window, deletion, audit rights β in plain language with π΄π‘π’ risk.
Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data.
Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.
Similar popular skills
Related neighbors and high-traction skills in the same topics β useful to compare before installing.
Declared targets from SKILL.md / docs. Unmarked agents are not listed β the skill may still install via the CLI.
Claude CodeNot declared
CursorNot declared
CodexNot declared
GitHub CopilotNot declared
WindsurfNot declared
Gemini CLINot declared
ClineNot declared
OpenCodeNot declared
Repository health
Stars1.3K
LicenseLICENSE
Default branchmain
Open issues7
Status
Active
Package contents
Files included with this skill beyond the listing page.
skill mdSKILL.md4,033 B
docsSUMMARY.md468 B
History
First seen on skills.sh
First recorded snapshot Β· 2 installs
SKILL.md
DPA Review
Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread β which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's missing β ranked by how much it can hurt.
Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement.
What This Skill Produces
The plain-English summary β what this DPA actually commits each side to
Risk-ranked findings β π΄ sign-blockers, π‘ negotiate, π’ standard β each with the clause and why it matters
The missing-clause checklist β the protections a good DPA has that this one lacks
The redline questions β what to send back to the vendor before signing
Required Inputs
Ask for these if not provided:
The DPA text β the document, or its key clauses pasted
Your role β are you the controller (your data) or the processor (you're the vendor)? The risks flip
The data β what personal/sensitive data is involved, and any regime that applies (GDPR, CCPA, HIPAA)
Deal context β how critical the vendor is; leverage shapes what's worth fighting
Framework: What a DPA Must Get Right
Scope & roles β controller vs processor, and the processing purpose; a mismatch here voids the rest.
Sub-processors β who else gets the data, notice of new ones, and a right to object.
International transfers β the mechanism (SCCs, adequacy, DPF) for data leaving its region.
Security & breach β the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
Deletion & return β what happens to your data at termination, and by when.
Audit & liability β your right to verify, and whether liability is capped below the data risk.
Output Format
DPA Review β [vendor] Β· you are the [controller/processor]
Verdict: Safe to sign / Negotiate first / Do not sign β one line why
Risk-ranked findings
Risk
Clause
What it says
Why it matters
π΄
β¦
β¦
β¦
Missing protections
[clause a good DPA has that this lacks]
Send back before signing
[redline question / requested change]
Quality Checks
Controller/processor role identified β findings framed from your side
Sub-processor, transfer, breach-window, and deletion terms each assessed (or flagged absent)
The breach-notification window is stated in hours/days, not left as "reasonable"
Every π΄ names the exact clause and the concrete exposure
Missing-clause list distinguishes "unusual gap" from "standard omission"
Flagged for counsel review on anything material
Anti-Patterns
Summarising without ranking β a wall of clauses helps no one; rank by damage.
Ignoring who you are β a processor and a controller face opposite risks in the same document.
Treating "reasonable security" as fine β undefined standards are the finding.
Inventing a clause number or requirement not in the text β quote what's there.
Example Trigger Phrases
"Review this DPA before we sign the vendor contract."
"Is this data processing agreement safe to sign?"
"What am I agreeing to on data in this DPA?"
"Check this DPA β we're the controller, it's a GDPR deal."