Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Gdpr Dpa

ASecurity

Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendum, controller-processor agreement, or data protection addendum involving sub-processors, breach notification, audits, international transfers, or SCCs.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
securitygoawstestingsecurity

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill gdpr-dpa --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gdpr Dpa?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Gdpr Dpa
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-gdpr-dpa/badge)](https://www.skillsdirectory.com/skills/lev-os-gdpr-dpa)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: gdpr-dpa
description: >-
  Drafts GDPR Article 28-compliant Data Processing Addenda with schedules
  ready for execution. Use when drafting or updating a DPA, vendor GDPR
  addendum, controller-processor agreement, or data protection addendum
  involving sub-processors, breach notification, audits, international
  transfers, or SCCs.
---

# GDPR Data Processing Addendum (DPA)

Produces an Article 28-compliant DPA aligned with the governing service agreement, covering processing details, security, sub-processor controls, breach notice, audits, and deletion terms.

## Quick Start

Gather before drafting:

- [ ] Party details: legal names, addresses, registration numbers (Controller + Processor)
- [ ] Underlying agreement reference (name, date, SOWs/order forms)
- [ ] Processing description: subject matter, duration, nature, purpose, operations
- [ ] Data inventory: data subject categories, personal data types, special categories (Art 9), criminal data (Art 10)
- [ ] Transfer map: processing locations, transfer mechanism (adequacy, SCCs, BCRs, Art 49)
- [ ] Security baseline: certifications, TOMs
- [ ] Sub-processor list + approval model (general vs specific) with objection window
- [ ] Incident response SLAs and audit preferences
- [ ] Termination: return/deletion formats, timelines, retention constraints

## Drafting Workflow

1. Draft header, recitals, effective date, and order-of-precedence clause with the main agreement.
2. Define GDPR terms: Controller, Processor, Personal Data, Processing, Sub-processor, Data Protection Laws, Personal Data Breach, Services.
3. Insert Article 28(3) mandatory clauses (see checklist below).
4. Add security (Art 32), breach notification (Arts 33-34), and assistance (Arts 32-36) clauses.
5. Add sub-processor governance (Art 28(2), 28(4)) with flow-down obligations.
6. Add audit and compliance evidence provisions (Arts 28(3)(h), 40, 42).
7. If data leaves the EEA, add international transfer terms (Art 46 SCCs, Art 47 BCRs, Art 49 derogations).
8. Add termination, return/deletion obligations, and backup handling.
9. Populate Schedules A-D from inputs; mark gaps as `[REQUIRED]`.

## Article 28(3) Mandatory Clause Checklist

| GDPR basis | Clause | Required content |
|---|---|---|
| Art 28(3)(a) | Instructions | Process only on documented Controller instructions; notify if instruction violates law |
| Art 28(3)(b) | Confidentiality | Authorized personnel bound by confidentiality |
| Art 28(3)(c) | Security | Appropriate TOMs per Art 32 |
| Art 28(3)(d) | Sub-processors | No sub-processing without authorization; flow-down equivalent obligations |
| Art 28(3)(e) | Data subject rights | Assist Controller with Chapter III requests |
| Art 28(3)(f) | Assistance | Assist with Art 32-36 obligations including DPIA and prior consultation |
| Art 28(3)(g) | Return/Deletion | Return or delete personal data at end of services; certify |
| Art 28(3)(h) | Audits/Info | Make information available; allow and contribute to audits |

## Key Decision Points

| Decision | Options | Input needed |
|---|---|---|
| Sub-processor authorization | General / Specific | Controller policy, objection window |
| Audit model | On-site / Remote / Third-party / Certification | Vendor policy, existing reports |
| Breach notice SLA | 24h / 48h / Other | Risk tolerance, incident playbooks |
| Data return format | CSV / JSON / Native export | System compatibility |
| Transfer mechanism | Adequacy / SCCs / BCRs / Art 49 | Data flows and locations |

## Schedule Templates

**Schedule A — Approved Sub-processors**

| Name | Location | Processing Activity | Authorization Type | Notice Period |
|---|---|---|---|---|
| TBD | TBD | TBD | General/Specific | 30 days |

**Schedule B — Description of Processing**

| Field | Details |
|---|---|
| Subject matter | |
| Duration | |
| Nature of processing | |
| Purpose | |
| Processing operations | |
| Categories of data subjects | |
| Categories of personal data | |
| Special categories (Art 9) | |
| Criminal data (Art 10) | |
| Processing locations | |

**Schedule C — Technical and Organizational Measures**

| Domain | Measures |
|---|---|
| Access control | |
| Encryption/pseudonymization | |
| Logging/monitoring | |
| Availability/resilience | |
| Incident response | |
| Testing/evaluation | |
| Physical security | |

**Schedule D — Audit/Certification Evidence**

| Evidence | Date | Scope | Reference |
|---|---|---|---|
| ISO 27001 | | | |
| SOC 2 Type II | | | |

## Pitfalls

- **No absolute security promises.** Use "appropriate" measures per Art 32; tie to risk profile.
- **Special categories / children's data** require heightened safeguards and stricter access controls.
- **Missing transfer basis is a blocker.** If any non-EEA transfer occurs, specify the mechanism and attach SCCs or equivalent before finalizing.
- **Schedule consistency.** Keep schedules aligned with DPA body text; ensure sub-processor lists are current.
- **Order of precedence.** Data protection terms must prevail over conflicting service agreement terms.
- Mark uncertain legal citations with `[VERIFY]`.

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

805540 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

805540 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

805540 votes
View all in security →