Review and draft data-processing agreements and privacy schedules for controller-processor, fiduciary-processor, joint-controller, service-provider, or independent-controller relationships. Use for instructions, security, breaches, subprocessors, assistance, transfers, audits, deletion, and liability.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add Cancellationperiplocagraeca503/legal-ai-skills --skill data-processing-agreement-reviewer --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Data Processing Agreement Reviewer?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cancellationperiplocagraeca503-data-processing-agreement-reviewer)More formats (shields.io, HTML) on the badges page.
---
name: data-processing-agreement-reviewer
description: >-
Review and draft data-processing agreements and privacy schedules for
controller-processor, fiduciary-processor, joint-controller, service-provider,
or independent-controller relationships. Use for instructions, security,
breaches, subprocessors, assistance, transfers, audits, deletion, and liability.
---
# Data Processing Agreement Reviewer
Test the agreement against the actual service and data flow. Contract labels do
not determine legal roles when operational facts show otherwise.
## Intake
Obtain the main agreement, proposed DPA, parties and affiliates, service
description, data-flow and system diagrams, data and subject categories, purposes,
instructions, jurisdictions, hosting and access locations, subprocessors,
security materials, retention, incident process, audits, transfer mechanisms,
sector rules, insurance, and liability terms.
## Review method
1. Determine each party's role per processing purpose and identify independent,
joint, processor, subprocessor, fiduciary, or other regulated activities.
2. Verify the processing schedule: subject, duration, nature, purpose, data,
people, frequency, locations, retention, and controller instructions.
3. Test limits on use, sale, sharing, combination, profiling, advertising,
product improvement, AI training, de-identification, re-identification, and
independent purposes.
4. Review confidentiality, personnel access, training, screening, security
measures, testing, certifications, evidence, and change controls.
5. Align incident definitions, immediate escalation, investigation cooperation,
evidence, notice content, notification control, costs, and remediation.
6. Review subprocessor authorisation, current list, change notice, objection,
equivalent obligations, location, flow-down, and primary responsibility.
7. Require proportionate assistance with rights requests, notices, DPIAs,
consultations, records, audits, regulators, litigation holds, and complaints.
8. Map international transfers, onward transfers, approved mechanisms, annexes,
government requests, supplementary safeguards, suspension, and updates.
9. Review retention, return, deletion, backups, legal holds, certification,
transition, portability, and post-termination access.
10. Make audit and assurance rights operational, risk-based, non-duplicative,
confidentiality-protected, and capable of escalating material gaps.
11. Reconcile privacy indemnities, liability caps, exclusions, insurance,
precedence, termination, change control, and survival with the main agreement.
## Output
Provide a role and data-flow matrix, clause-by-clause issue list, operational-gap
schedule, proposed language, processing annex, security and subprocessor checklist,
transfer map, and negotiation priorities.
## Guardrails
Do not accept inaccurate roles, empty processing schedules, security promises
unsupported by evidence, blanket secondary use, or unworkable audit language.
Do not assume a DPA supplies lawful basis, notice, consent, or transfer compliance.
Verify current mandatory terms in every relevant jurisdiction.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!