1---2name: draft-data-processing-addendum3description: Controller-protective data processing addendum as an exhibit to an MSA, with complete annexes and a negotiation issues memo, for a healthcare analytics vendor onboarding.4---56# Skill: Draft Data Processing Addendum78## 1. Subject-matter triage (only if applicable)910- Treat the MSA as the governing commercial contract and the DPA as a controller-protective exhibit that must integrate cleanly with it, not conflict with it.11- Identify whether the processing includes regulated health data, protected health information, or other sensitive categories; if so, preserve consistency with any separate healthcare privacy, confidentiality, or security regime that also applies.12- Confirm which data roles apply to each party and which services actually involve personal data processing; do not draft to hypothetical processing outside the deal scope.13- If multiple data categories, jurisdictions, or service lines appear, enumerate them first and then draft the operative provisions and annexes against that full set.14- Build the annexes from the deal documents and security materials, not from generic boilerplate.1516## 2. Failure modes the skill is correcting1718- Drafting from the vendor’s template with surface edits instead of resetting to a controller-protective baseline.19- Preserving vendor-favorable positions on sub-processor control, audit limitations, assistance obligations, retention, and liability allocation.20- Addressing general privacy concepts while missing the healthcare-specific overlay and any required consistency with parallel health privacy obligations.21- Treating sub-processors as a notice-only issue rather than a meaningful approval-and-flow-down control.22- Omitting or under-specifying the processing annexes that make the DPA operational.23- Failing to translate security documents into contractual minimums, resulting in an exhibit that is aspirational rather than enforceable.24- Producing a memo that describes issues without naming the governing rule, the affected contract interaction, and the practical consequence.2526## 3. Legal frameworks / domain conventions that apply2728- Controller-processor / service-provider structure: require processing only on documented instructions, confidentiality, security appropriate to risk, assistance with rights and incidents, deletion or return, audit cooperation, and compliance demonstration.29- Healthcare privacy overlay: if regulated health data is in scope, align the DPA with any separate healthcare privacy framework and avoid internal inconsistencies between exhibits.30- Sub-processor control: require prior approval or a tightly controlled notice-and-objection process, plus equivalent flow-down obligations and responsibility for subcontracted performance.31- Security contracting: translate the company’s information-security standard into contractual requirements that cover access controls, encryption, incident response, vulnerability management, logging, training, and segregation where relevant.32- Data subject rights and incident obligations: specify response timing, cooperation duties, and content requirements sufficient for the controller to meet downstream legal deadlines.33- Retention and deletion: require return or deletion at end of services, certify completion where appropriate, and preserve only limited legally required copies under controlled safeguards.34- Audit and compliance evidence: third-party reports may supplement but do not replace contractual inspection rights or meaningful compliance demonstrations.35- Liability and remedy alignment: ensure the DPA remedies, indemnity posture, and liability carve-outs do not undercut the MSA’s risk allocation.3637## 4. Analytical scaffolds3839- Start from the company’s required position, then compare the vendor template clause by clause and rewrite the DPA to the more protective position where the documents support it.40- For each core provision, test whether it answers four questions: what data, what purpose, what controls, and what remedy if the processor deviates.41- For each annex, use source-document extraction: processing description, categories, durations, transfer geography if relevant, security controls, and subprocessors.42- For healthcare-related scope, check whether the processing description, confidentiality language, and incident obligations need a parallel reference to the applicable health-data regime.43- For sub-processors, draft the control mechanism in sequence: disclosure, approval, objection, onboarding conditions, onward flow-down, and liability for failure.44- For the negotiation memo, identify only material departures from the company baseline; for each, state the company position, the vendor position, the risk, and a practical fallback.45- When a source document is silent, draft conservatively and flag the gap in the memo rather than assuming vendor-favorable silence.46- Use a clause-level consistency check so the DPA, MSA, security exhibit, and annexes do not conflict on definitions, precedence, term, or breach notice mechanics.4748## 5. Vertical / structural / temporal relationships (only if applicable)4950- Make the DPA an exhibit that expressly incorporates the MSA, but preserve the DPA as the controlling privacy-specific addendum where its subject matter is more specific.51- Resolve vertical hierarchy expressly: MSA general terms, then DPA-specific processing terms, then annexes describing the operational details.52- Align temporal obligations: commencement of processing, onboarding of any sub-processor, security implementation timing, incident notice timing, deletion/return timing, and post-termination survival.53- If multiple affiliated entities, service modules, or data environments are in scope, map each to the applicable processing description and security controls before drafting obligations.54- Where a healthcare overlay exists, make the interaction rule explicit so one framework does not dilute the other by implication.5556## 6. Output structure conventions5758- Draft the DPA as a complete, controller-protective exhibit ready to attach to the MSA, with operative clauses plus complete annexes.59- Include all core privacy provisions in integrated contract form rather than in a checklist or commentary style.60- Ensure annexes are populated with deal-specific content and not placeholder text.61- Prepare the negotiation issues memo as a concise issue-by-issue advisory comparing the vendor template against the company’s required position.62- For each memo issue, state the governing rule or contractual convention, the disagreement, the company position, the likely fallback, and the practical consequence of compromise.63- Use an ordinal severity label for each memo issue and keep the scale consistent throughout the memo.64- End the memo with concrete recommended actions directed to the appropriate internal role and tied to the deal timeline.65- Keep the drafting deliverable and the memo distinct; do not let the memo substitute for the operative DPA.66- Before finishing, confirm the DPA file exists and is non-empty, and then confirm the memo file exists and is non-empty.