dpa-review
When to use
- A counterparty sends a DPA (their paper or yours) and the question is where the GDPR Art. 28 obligations are met, partial, or missing — before an attorney spends time on it.
- An existing processing relationship is being re-papered (new sub-processor chain, new transfer route, new scope) and the Art. 28 surface must be re-walked.
- You need a structured gap frame and the open questions an attorney must resolve — not a redline and not a verdict.
Do NOT use for clause-level redlining of a general contract (route to contract-review), for the regulatory-regime delta read in isolation (route to privacy-review), or for the classification / retention / transfer-mechanism operational surface (route to data-handling-judgment). This skill walks the Art. 28 agreement; those skills produce the inputs it cites.
Procedure
Step 0: Establish jurisdiction and refuse if out of scope
- Read the DPA's governing-law / jurisdiction clause. Tag the output
Jurisdiction: EU or Jurisdiction: DE.
- If the DPA is governed by a non-EU/DE regime with no GDPR nexus (e.g. a pure US state-privacy regime), refuse the gap review: say "consult licensed local counsel". Note as an open question that GDPR may still apply extraterritorially under Art. 3 (EU-established controller/processor, or offering to / monitoring EU data subjects) — for the attorney to confirm.
- No default positions ship. Read acceptable values (sub-processor notice window, audit frequency, liability cap, breach-notice deadline) from
legal-practice-profile. Until configured, every such value is a [configure] placeholder in the output, not a guess.
Step 1: Fix the role — controller or processor
The Art. 28 reading forks on which side you are.
- You are the controller → you instruct. Read whether the agreement binds the processor to your instructions, confidentiality, security, sub-processor flow-down, assistance, deletion, and audit rights for you.
- You are the processor → you are bound. Read whether the obligations imposed are deliverable as written (audit cadence you can sustain, deletion you can actually perform, sub-processor flow-down you can pass down).
- Joint / unclear → flag it as the first open question; Art. 26 joint-controllership changes the frame.
Step 2: Walk the Art. 28(3) requirements as a checklist FLOOR (not ceiling)
For each, assign GREEN (present + adequate) / YELLOW (present but weak/ambiguous) / RED (missing or contradicts Art. 28):
- (a) Documented instructions — processing only on the controller's documented instructions, incl. for transfers.
- (b) Confidentiality — persons authorised to process are under a confidentiality commitment.
- (c) Security — Art. 32 — appropriate technical and organisational measures named (not "industry-standard" alone).
- (d) Sub-processors — prior authorisation (general or specific), notice of changes + objection right, and flow-down of equivalent Art. 28 terms.
- (e) Data-subject-rights assistance — processor assists the controller in responding to DSR requests.
- (f) Breach + DPIA assistance — Art. 33/34/35/36 — breach-notification assistance with a deadline, plus assistance with DPIAs and prior consultation.
- (g) Deletion / return — at end of provision, delete or return all personal data + copies, at the controller's choice.
- (h) Audit / inspection — make available the information needed to demonstrate compliance + allow and contribute to audits/inspections.
- International transfer — Chapter V — any transfer outside the EEA has a valid mechanism (adequacy / SCCs with module + version / BCR) and, where required, supplementary measures. Schrems-II transfer-impact assessment is an open question, not a checkbox.
The nine are the floor; flag anything beyond them that materially shifts risk (liability cap, indemnity, deletion-vs-legal-hold conflict).
Step 3: Frame the gaps and the open questions
- Produce the GREEN/YELLOW/RED frame, one line per Art. 28(3) item + transfers.
- For every YELLOW/RED, write the open question an attorney must resolve — not a redline. ("(d) names no objection window — is
[configure] acceptable, or must a specific window be negotiated?")
- Surface any
[configure] placeholder that blocked a GREEN/YELLOW/RED call.
Step 4: Emit the artifacts
Produce dpa-gap-frame.md and open-questions.md. Each carries the Jurisdiction: tag and the attorney-review line. This skill does not opine; it prepares the attorney's review.
Related Skills
WHEN to use this
- Reviewing a DPA against the GDPR Art. 28 surface, as controller or processor.
- Producing a gap frame + attorney open-questions before counsel review.
WHEN NOT to use this
- General contract clause redlines (liability, IP, term, termination) — route to
contract-review.
- Which regime applies / regime delta read — route to
privacy-review.
- Data classification, retention windows, transfer-mechanism + supplementary-measures operational shape — route to
data-handling-judgment.
- A binding legal conclusion — route to a licensed attorney; this skill never issues one.
When the agent should load this
- "Kannst Du diese AVV / DPA gegen Art. 28 prüfen?"
- "Ein Kunde hat seinen Auftragsverarbeitungsvertrag geschickt — wo sind die Lücken?"
Output
dpa-gap-frame.md — Jurisdiction: tag; role (controller/processor); one GREEN/YELLOW/RED line per Art. 28(3)(a)–(h) + Chapter V transfers; the attorney-review line.
open-questions.md — Jurisdiction: tag; one attorney-resolvable question per YELLOW/RED, plus every [configure] placeholder that blocked a call; the attorney-review line.
Gotcha
- "Industry-standard security" satisfies neither Art. 28(3)(c) nor Art. 32 — the TOMs must be named; an unnamed measures clause is YELLOW at best, often RED.
- Sub-processor flow-down is the silent RED: the agreement names sub-processors but never binds them to equivalent Art. 28 terms, so the chain leaks obligations.
- The role fork is load-bearing — a processor-side review that reads the controller-side rights as if they were yours mis-frames every deliverability gap.
- "Delete OR return" at the controller's choice is the requirement; a clause that hard-codes deletion (ignoring legal-hold) or hard-codes return is a gap, not a convenience.
- A non-EU governing-law clause does not end the question — GDPR can still bite under Art. 3; refuse the gap review but hand the Art. 3 question to the attorney, never silently drop it.
Do NOT
- Do NOT ship default values for notice windows, audit cadence, liability caps, or breach deadlines; read
legal-practice-profile or emit [configure].
- Do NOT issue a final legal call, a clearance, or a "this DPA is fine" — GREEN is a triage signal, not a sign-off. Cite
legal-safety-floor.
- Do NOT review a DPA outside EU/DE scope as if it were in scope; refuse to gap-review and route to local counsel.
- Do NOT drop the
Jurisdiction: tag or the attorney-review line from any output.
Runnable example
Processor-side review of a customer's DPA, governed by German law.
- Step 0 —
Jurisdiction: DE. In scope. legal-practice-profile not configured → notice window, audit cadence, breach deadline are [configure].
- Step 1 — Role = processor (we host the customer's SaaS data). Frame reads deliverability, not rights.
- Step 2 — Art. 28(3) walk:
- (a) documented instructions — GREEN.
- (b) confidentiality — GREEN.
- (c) security / Art. 32 — YELLOW ("appropriate measures per industry standard"; no TOMs annex named).
- (d) sub-processors — RED (general authorisation granted, but no flow-down clause binding our sub-processors to equivalent terms, and objection window left blank =
[configure]).
- (e) DSR assistance — GREEN.
- (f) breach assistance / Art. 33 — YELLOW (assistance promised, deadline blank =
[configure]; can we meet the controller's own 72h clock?).
- (g) deletion / return — YELLOW (hard-codes deletion; no return option, no legal-hold carve-out).
- (h) audit — RED for us as processor (on-site audit "at any time, without notice" — not sustainable; cadence =
[configure]).
- Chapter V transfers — RED (our logging sub-processor is US-based; no SCC module/version named; Schrems-II TIA = open question).
- Step 3 — open questions, e.g.: "(d) — add a flow-down clause and a
[configure] objection window?"; "(h) — negotiate audit to [configure] cadence with notice?"; "Chapter V — which SCC module/version covers the US logging sub-processor, and is a TIA required?"
- Step 4 — emit
dpa-gap-frame.md + open-questions.md, both tagged Jurisdiction: DE and carrying:
⚠️ Attorney review required on material use. This is a draft for a licensed attorney, not legal advice and not a legal conclusion.
1---2name: dpa-review3description: Use when reviewing a DPA as controller or processor against GDPR Art. 28 — GREEN/YELLOW/RED gap frame, never a final call. Triggers on "review this DPA", "check this DPA".4---56# dpa-review78## When to use910- A counterparty sends a DPA (their paper or yours) and the question is *where the GDPR Art. 28 obligations are met, partial, or missing* — before an attorney spends time on it.11- An existing processing relationship is being re-papered (new sub-processor chain, new transfer route, new scope) and the Art. 28 surface must be re-walked.12- You need a structured gap frame and the open questions an attorney must resolve — not a redline and not a verdict.1314Do NOT use for clause-level redlining of a general contract (route to `contract-review`), for the regulatory-regime delta read in isolation (route to [`privacy-review`](../privacy-review/SKILL.md)), or for the classification / retention / transfer-mechanism operational surface (route to [`data-handling-judgment`](../data-handling-judgment/SKILL.md)). This skill walks the Art. 28 *agreement*; those skills produce the inputs it cites.1516## Procedure1718### Step 0: Establish jurisdiction and refuse if out of scope19201. Read the DPA's governing-law / jurisdiction clause. Tag the output `Jurisdiction: EU` or `Jurisdiction: DE`.212. If the DPA is governed by a non-EU/DE regime with no GDPR nexus (e.g. a pure US state-privacy regime), **refuse the gap review**: say "consult licensed local counsel". Note as an open question that GDPR may still apply extraterritorially under Art. 3 (EU-established controller/processor, or offering to / monitoring EU data subjects) — for the attorney to confirm.223. No default positions ship. Read acceptable values (sub-processor notice window, audit frequency, liability cap, breach-notice deadline) from `legal-practice-profile`. Until configured, every such value is a `[configure]` placeholder in the output, not a guess.2324### Step 1: Fix the role — controller or processor2526The Art. 28 reading forks on which side you are.2728- **You are the controller** → you instruct. Read whether the agreement binds the *processor* to your instructions, confidentiality, security, sub-processor flow-down, assistance, deletion, and audit *rights for you*.29- **You are the processor** → you are bound. Read whether the obligations imposed are deliverable as written (audit cadence you can sustain, deletion you can actually perform, sub-processor flow-down you can pass down).30- **Joint / unclear** → flag it as the first open question; Art. 26 joint-controllership changes the frame.3132### Step 2: Walk the Art. 28(3) requirements as a checklist FLOOR (not ceiling)3334For each, assign GREEN (present + adequate) / YELLOW (present but weak/ambiguous) / RED (missing or contradicts Art. 28):35361. **(a) Documented instructions** — processing only on the controller's documented instructions, incl. for transfers.372. **(b) Confidentiality** — persons authorised to process are under a confidentiality commitment.383. **(c) Security — Art. 32** — appropriate technical and organisational measures named (not "industry-standard" alone).394. **(d) Sub-processors** — prior authorisation (general or specific), notice of changes + objection right, and **flow-down** of equivalent Art. 28 terms.405. **(e) Data-subject-rights assistance** — processor assists the controller in responding to DSR requests.416. **(f) Breach + DPIA assistance — Art. 33/34/35/36** — breach-notification assistance with a deadline, plus assistance with DPIAs and prior consultation.427. **(g) Deletion / return** — at end of provision, delete or return all personal data + copies, at the controller's choice.438. **(h) Audit / inspection** — make available the information needed to demonstrate compliance + allow and contribute to audits/inspections.449. **International transfer — Chapter V** — any transfer outside the EEA has a valid mechanism (adequacy / SCCs with module + version / BCR) and, where required, supplementary measures. Schrems-II transfer-impact assessment is an open question, not a checkbox.4546The nine are the floor; flag anything beyond them that materially shifts risk (liability cap, indemnity, deletion-vs-legal-hold conflict).4748### Step 3: Frame the gaps and the open questions49501. Produce the GREEN/YELLOW/RED frame, one line per Art. 28(3) item + transfers.512. For every YELLOW/RED, write the **open question an attorney must resolve** — not a redline. ("(d) names no objection window — is `[configure]` acceptable, or must a specific window be negotiated?")523. Surface any `[configure]` placeholder that blocked a GREEN/YELLOW/RED call.5354### Step 4: Emit the artifacts5556Produce `dpa-gap-frame.md` and `open-questions.md`. Each carries the `Jurisdiction:` tag and the attorney-review line. This skill does not opine; it prepares the attorney's review.5758## Related Skills5960**WHEN to use this**6162- Reviewing a DPA against the GDPR Art. 28 surface, as controller or processor.63- Producing a gap frame + attorney open-questions before counsel review.6465**WHEN NOT to use this**6667- General contract clause redlines (liability, IP, term, termination) — route to `contract-review`.68- Which regime applies / regime delta read — route to [`privacy-review`](../privacy-review/SKILL.md).69- Data classification, retention windows, transfer-mechanism + supplementary-measures operational shape — route to [`data-handling-judgment`](../data-handling-judgment/SKILL.md).70- A binding legal conclusion — route to a licensed attorney; this skill never issues one.7172## When the agent should load this7374- "Kannst Du diese AVV / DPA gegen Art. 28 prüfen?"75- "Ein Kunde hat seinen Auftragsverarbeitungsvertrag geschickt — wo sind die Lücken?"7677## Output78791. **`dpa-gap-frame.md`** — `Jurisdiction:` tag; role (controller/processor); one GREEN/YELLOW/RED line per Art. 28(3)(a)–(h) + Chapter V transfers; the attorney-review line.802. **`open-questions.md`** — `Jurisdiction:` tag; one attorney-resolvable question per YELLOW/RED, plus every `[configure]` placeholder that blocked a call; the attorney-review line.8182## Gotcha8384- "Industry-standard security" satisfies neither Art. 28(3)(c) nor Art. 32 — the TOMs must be named; an unnamed measures clause is YELLOW at best, often RED.85- Sub-processor flow-down is the silent RED: the agreement names sub-processors but never binds them to equivalent Art. 28 terms, so the chain leaks obligations.86- The role fork is load-bearing — a processor-side review that reads the controller-side rights as if they were yours mis-frames every deliverability gap.87- "Delete OR return" at the controller's choice is the requirement; a clause that hard-codes deletion (ignoring legal-hold) or hard-codes return is a gap, not a convenience.88- A non-EU governing-law clause does not end the question — GDPR can still bite under Art. 3; refuse the gap review but hand the Art. 3 question to the attorney, never silently drop it.8990## Do NOT9192- Do NOT ship default values for notice windows, audit cadence, liability caps, or breach deadlines; read `legal-practice-profile` or emit `[configure]`.93- Do NOT issue a final legal call, a clearance, or a "this DPA is fine" — GREEN is a triage signal, not a sign-off. Cite `legal-safety-floor`.94- Do NOT review a DPA outside EU/DE scope as if it were in scope; refuse to gap-review and route to local counsel.95- Do NOT drop the `Jurisdiction:` tag or the attorney-review line from any output.9697## Runnable example9899Processor-side review of a customer's DPA, governed by German law.100101- Step 0 — `Jurisdiction: DE`. In scope. `legal-practice-profile` not configured → notice window, audit cadence, breach deadline are `[configure]`.102- Step 1 — Role = **processor** (we host the customer's SaaS data). Frame reads deliverability, not rights.103- Step 2 — Art. 28(3) walk:104 - (a) documented instructions — GREEN.105 - (b) confidentiality — GREEN.106 - (c) security / Art. 32 — YELLOW ("appropriate measures per industry standard"; no TOMs annex named).107 - (d) sub-processors — RED (general authorisation granted, but **no flow-down** clause binding our sub-processors to equivalent terms, and objection window left blank = `[configure]`).108 - (e) DSR assistance — GREEN.109 - (f) breach assistance / Art. 33 — YELLOW (assistance promised, deadline blank = `[configure]`; can we meet the controller's own 72h clock?).110 - (g) deletion / return — YELLOW (hard-codes deletion; no return option, no legal-hold carve-out).111 - (h) audit — RED for us as processor (on-site audit "at any time, without notice" — not sustainable; cadence = `[configure]`).112 - Chapter V transfers — RED (our logging sub-processor is US-based; no SCC module/version named; Schrems-II TIA = open question).113- Step 3 — open questions, e.g.: *"(d) — add a flow-down clause and a `[configure]` objection window?"*; *"(h) — negotiate audit to `[configure]` cadence with notice?"*; *"Chapter V — which SCC module/version covers the US logging sub-processor, and is a TIA required?"*114- Step 4 — emit `dpa-gap-frame.md` + `open-questions.md`, both tagged `Jurisdiction: DE` and carrying:115116> ⚠️ Attorney review required on material use. This is a draft for a licensed attorney, not legal advice and not a legal conclusion.