1---2name: analyze-counterparty-markup-of-data-processing-agreement3description: DPA redline reviews lose rigour when the agent treats playbook positions as optional and fails to cross-reference the broader commercial agreement when assessing risk of counterparty changes.4---56# Skill: Analyze Counterparty Markup of Data Processing Agreement — Deviation Report78## 1. Subject-matter triage (only if applicable)910- This task is a markup-analysis workflow, not a clean drafting exercise: read the template, the redline, the negotiation playbook, the cover email, and the MSA together before drawing conclusions.11- Treat the DPA as a control document that must be reconciled with the commercial agreement; do not let the redline analysis drift into a standalone privacy commentary.12- If the source set includes multiple DPAs, amendments, schedules, jurisdictions, or processing scopes, enumerate them first and analyze each separately rather than blending them into one pass.1314## 2. Failure modes the skill is correcting1516- Reviewing the redlined DPA in isolation instead of triangulating against the original template, the playbook, and the MSA, which hides removals or dilution of baseline privacy protections.17- Missing where the counterparty’s edits conflict with the commercial deal architecture on scope, liability, indemnity, audit, or assistance obligations.18- Treating negotiable preferences as if they were mandatory privacy terms, or vice versa, and therefore mis-prioritizing the report.19- Describing deviations without tying each one to a concrete response, which leaves the output non-actionable.20- Relying on styling alone to show changes; the output must remain readable and reviewable even if exported or flattened.2122## 3. Legal frameworks / domain conventions that apply2324- Mandatory DPA baseline: processor obligations, instructions, security measures, sub-processor controls, deletion or return on termination, audit/inspection rights, breach notice, and assistance with data-subject requests and compliance.25- Security standard: technical and organizational measures appropriate to the risk, assessed in context rather than by slogan language.26- Sub-processor regime: written authorization mechanics, flow-down obligations, notice of changes where required, and preservation of controller oversight.27- Agreement hierarchy: the DPA must fit within the MSA’s commercial envelope on scope, liability, and indemnity, while preserving non-waivable privacy obligations.28- Playbook discipline: each clause should be measured against the company’s stated position category, then escalated or accepted accordingly.29- Where a legal proposition is stated, anchor it to the controlling authority named in the source materials or to the applicable privacy regulation, standard form, or internal playbook rule that supports it.3031## 4. Analytical scaffolds3233- Start with the baseline: original template, then playbook, then cover email, then the counterparty redline.34- For each changed clause, identify: what the template said, what the counterparty changed, what the playbook position is, whether the MSA already addresses the point, and whether the change affects privacy risk or deal consistency.35- Classify every issue by clause type: mandatory privacy term, negotiated company position, or flexible commercial term.36- For every issue, close the analysis with three moves:37 - anchor the concern to a concrete source-document figure, trigger, term, scope, or procedural threshold where one exists;38 - cross-reference the clause, schedule, or related agreement provision that interacts with the change;39 - state the downstream consequence for the client in practical terms, including regulatory, operational, litigation, or transaction risk.40- Do not stop at “this is better/worse”; provide the reason the deviation matters and the exact bargaining move that follows from that reason.41- If the playbook or cover email indicates a deal-specific concession, note it explicitly and adjust the recommendation rather than treating the template as immutable.4243## 5. Vertical / structural / temporal relationships (only if applicable)4445- The MSA governs the commercial frame; the DPA should not create inconsistent allocations of liability, indemnity, limitation of liability, or scope.46- Priority and sequencing matter: later amendments, side letters, or negotiated exceptions may override a template position only if the source documents clearly do so.47- Operational timing matters for privacy obligations: notice, objection, deletion, return, and assistance commitments should be checked against any stated response windows or go-live milestones in the source set.48- If a clause depends on another instrument or schedule, report the dependency rather than analyzing the clause as self-contained.4950## 6. Output structure conventions5152- Use a prioritized deviation report in table form, with an explicit ordinal severity scale defined once at the top of the report and applied uniformly to every row.53- For each row, include the operative clause reference, the template baseline, the counterparty change, the playbook position, the MSA cross-check, the severity, the legal/commercial impact, and the recommended response.54- Mark every substantive change in a way that survives plain-text export; do not rely only on formatting.55- Keep recommendations concrete and action-oriented: state whether to accept, reject, narrow, clarify, or escalate, and explain why in one line.56- End with a short recommended actions section that sequences the next negotiation steps and identifies the role that should take each step.57- If a deliverable filename is specified, the deviation report should be prepared for that filename and not displaced by a summary-only response.