Controller-protective data processing addendum as an exhibit to an MSA, with complete annexes and a negotiation issues memo, for a healthcare analytics vendor onboarding.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-data-processing-addendum --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Data Processing Addendum?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-data-processing-addendum)More formats (shields.io, HTML) on the badges page.
---
name: draft-data-processing-addendum
task_id: intellectual-property/draft-data-processing-addendum
description: Controller-protective data processing addendum as an exhibit to an MSA, with complete annexes and a negotiation issues memo, for a healthcare analytics vendor onboarding.
activates_for: [planner, solver, checker]
---
# Skill: Draft Data Processing Addendum
## 1. Subject-matter triage (only if applicable)
- Treat the MSA as the governing commercial contract and the DPA as a controller-protective exhibit that must integrate cleanly with it, not conflict with it.
- Identify whether the processing includes regulated health data, protected health information, or other sensitive categories; if so, preserve consistency with any separate healthcare privacy, confidentiality, or security regime that also applies.
- Confirm which data roles apply to each party and which services actually involve personal data processing; do not draft to hypothetical processing outside the deal scope.
- If multiple data categories, jurisdictions, or service lines appear, enumerate them first and then draft the operative provisions and annexes against that full set.
- Build the annexes from the deal documents and security materials, not from generic boilerplate.
## 2. Failure modes the skill is correcting
- Drafting from the vendor’s template with surface edits instead of resetting to a controller-protective baseline.
- Preserving vendor-favorable positions on sub-processor control, audit limitations, assistance obligations, retention, and liability allocation.
- Addressing general privacy concepts while missing the healthcare-specific overlay and any required consistency with parallel health privacy obligations.
- Treating sub-processors as a notice-only issue rather than a meaningful approval-and-flow-down control.
- Omitting or under-specifying the processing annexes that make the DPA operational.
- Failing to translate security documents into contractual minimums, resulting in an exhibit that is aspirational rather than enforceable.
- Producing a memo that describes issues without naming the governing rule, the affected contract interaction, and the practical consequence.
## 3. Legal frameworks / domain conventions that apply
- Controller-processor / service-provider structure: require processing only on documented instructions, confidentiality, security appropriate to risk, assistance with rights and incidents, deletion or return, audit cooperation, and compliance demonstration.
- Healthcare privacy overlay: if regulated health data is in scope, align the DPA with any separate healthcare privacy framework and avoid internal inconsistencies between exhibits.
- Sub-processor control: require prior approval or a tightly controlled notice-and-objection process, plus equivalent flow-down obligations and responsibility for subcontracted performance.
- Security contracting: translate the company’s information-security standard into contractual requirements that cover access controls, encryption, incident response, vulnerability management, logging, training, and segregation where relevant.
- Data subject rights and incident obligations: specify response timing, cooperation duties, and content requirements sufficient for the controller to meet downstream legal deadlines.
- Retention and deletion: require return or deletion at end of services, certify completion where appropriate, and preserve only limited legally required copies under controlled safeguards.
- Audit and compliance evidence: third-party reports may supplement but do not replace contractual inspection rights or meaningful compliance demonstrations.
- Liability and remedy alignment: ensure the DPA remedies, indemnity posture, and liability carve-outs do not undercut the MSA’s risk allocation.
## 4. Analytical scaffolds
- Start from the company’s required position, then compare the vendor template clause by clause and rewrite the DPA to the more protective position where the documents support it.
- For each core provision, test whether it answers four questions: what data, what purpose, what controls, and what remedy if the processor deviates.
- For each annex, use source-document extraction: processing description, categories, durations, transfer geography if relevant, security controls, and subprocessors.
- For healthcare-related scope, check whether the processing description, confidentiality language, and incident obligations need a parallel reference to the applicable health-data regime.
- For sub-processors, draft the control mechanism in sequence: disclosure, approval, objection, onboarding conditions, onward flow-down, and liability for failure.
- For the negotiation memo, identify only material departures from the company baseline; for each, state the company position, the vendor position, the risk, and a practical fallback.
- When a source document is silent, draft conservatively and flag the gap in the memo rather than assuming vendor-favorable silence.
- Use a clause-level consistency check so the DPA, MSA, security exhibit, and annexes do not conflict on definitions, precedence, term, or breach notice mechanics.
## 5. Vertical / structural / temporal relationships (only if applicable)
- Make the DPA an exhibit that expressly incorporates the MSA, but preserve the DPA as the controlling privacy-specific addendum where its subject matter is more specific.
- Resolve vertical hierarchy expressly: MSA general terms, then DPA-specific processing terms, then annexes describing the operational details.
- Align temporal obligations: commencement of processing, onboarding of any sub-processor, security implementation timing, incident notice timing, deletion/return timing, and post-termination survival.
- If multiple affiliated entities, service modules, or data environments are in scope, map each to the applicable processing description and security controls before drafting obligations.
- Where a healthcare overlay exists, make the interaction rule explicit so one framework does not dilute the other by implication.
## 6. Output structure conventions
- Draft the DPA as a complete, controller-protective exhibit ready to attach to the MSA, with operative clauses plus complete annexes.
- Include all core privacy provisions in integrated contract form rather than in a checklist or commentary style.
- Ensure annexes are populated with deal-specific content and not placeholder text.
- Prepare the negotiation issues memo as a concise issue-by-issue advisory comparing the vendor template against the company’s required position.
- For each memo issue, state the governing rule or contractual convention, the disagreement, the company position, the likely fallback, and the practical consequence of compromise.
- Use an ordinal severity label for each memo issue and keep the scale consistent throughout the memo.
- End the memo with concrete recommended actions directed to the appropriate internal role and tied to the deal timeline.
- Keep the drafting deliverable and the memo distinct; do not let the memo substitute for the operative DPA.
- Before finishing, confirm the DPA file exists and is non-empty, and then confirm the memo file exists and is non-empty.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!