mohitagw15856/pm-claude-skills

dpa-review

Read a Data Processing Agreement before you sign it β€” sub-processors, transfer mechanism, breach-notice window, deletion, audit rights β€” in plain language with πŸ”΄πŸŸ‘πŸŸ’ risk.

First seen Aug 13, 2026

Installation

$ npx skills add mohitagw15856/pm-claude-skills --skill dpa-review

Summary

  • Read a Data Processing Agreement before you sign it β€” sub-processors, transfer mechanism, breach-notice window, deletion, audit rights β€” in plain language with πŸ”΄πŸŸ‘πŸŸ’ risk.
  • Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data.
  • Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.

Similar popular skills

Related neighbors and high-traction skills in the same topics β€” useful to compare before installing.

Also in this package

Other skills from mohitagw15856/pm-claude-skills Β· top by installs.

npx skills add mohitagw15856/pm-claude-skills

Browse all from mohitagw15856/pm-claude-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed β€” the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1.3K
License LICENSE
Default branch main
Open issues 7
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 4,033 B
  • docs SUMMARY.md 468 B

History

  1. First seen on skills.sh
  2. First recorded snapshot Β· 2 installs

SKILL.md

DPA Review

Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread β€” which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's missing β€” ranked by how much it can hurt.

Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement.

What This Skill Produces

  • The plain-English summary β€” what this DPA actually commits each side to
  • Risk-ranked findings β€” πŸ”΄ sign-blockers, 🟑 negotiate, 🟒 standard β€” each with the clause and why it matters
  • The missing-clause checklist β€” the protections a good DPA has that this one lacks
  • The redline questions β€” what to send back to the vendor before signing

Required Inputs

Ask for these if not provided:

  • The DPA text β€” the document, or its key clauses pasted
  • Your role β€” are you the controller (your data) or the processor (you're the vendor)? The risks flip
  • The data β€” what personal/sensitive data is involved, and any regime that applies (GDPR, CCPA, HIPAA)
  • Deal context β€” how critical the vendor is; leverage shapes what's worth fighting

Framework: What a DPA Must Get Right

  1. Scope & roles β€” controller vs processor, and the processing purpose; a mismatch here voids the rest.
  2. Sub-processors β€” who else gets the data, notice of new ones, and a right to object.
  3. International transfers β€” the mechanism (SCCs, adequacy, DPF) for data leaving its region.
  4. Security & breach β€” the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
  5. Deletion & return β€” what happens to your data at termination, and by when.
  6. Audit & liability β€” your right to verify, and whether liability is capped below the data risk.

Output Format

DPA Review β€” [vendor] Β· you are the [controller/processor]

Verdict: Safe to sign / Negotiate first / Do not sign β€” one line why

Risk-ranked findings

Risk Clause What it says Why it matters
πŸ”΄ … … …

Missing protections

  • [clause a good DPA has that this lacks]

Send back before signing

  1. [redline question / requested change]

Quality Checks

  • Controller/processor role identified β€” findings framed from your side
  • Sub-processor, transfer, breach-window, and deletion terms each assessed (or flagged absent)
  • The breach-notification window is stated in hours/days, not left as "reasonable"
  • Every πŸ”΄ names the exact clause and the concrete exposure
  • Missing-clause list distinguishes "unusual gap" from "standard omission"
  • Flagged for counsel review on anything material

Anti-Patterns

  • Summarising without ranking β€” a wall of clauses helps no one; rank by damage.
  • Ignoring who you are β€” a processor and a controller face opposite risks in the same document.
  • Treating "reasonable security" as fine β€” undefined standards are the finding.
  • Inventing a clause number or requirement not in the text β€” quote what's there.

Example Trigger Phrases

  • "Review this DPA before we sign the vendor contract."
  • "Is this data processing agreement safe to sign?"
  • "What am I agreeing to on data in this DPA?"
  • "Check this DPA β€” we're the controller, it's a GDPR deal."