# Draft Data Processing Addendum

> Controller-protective data processing addendum as an exhibit to an MSA, with complete annexes and a negotiation issues memo, for a healthcare analytics vendor onboarding.

- Skill: `finchipaiorg/draft-data-processing-addendum` (Agent Skill)
- Install (CLI): `npx skillmds@latest add finchipaiorg/draft-data-processing-addendum`
- Raw SKILL.md: https://api.skillmd.com/api/skills/finchipaiorg/draft-data-processing-addendum/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Data & Analytics
- Author: FinchipAIOrg (https://skillmd.com/u/finchipaiorg)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/finchipaiorg/draft-data-processing-addendum

---


# Skill: Draft Data Processing Addendum

## 1. Subject-matter triage (only if applicable)

- Treat the MSA as the governing commercial contract and the DPA as a controller-protective exhibit that must integrate cleanly with it, not conflict with it.
- Identify whether the processing includes regulated health data, protected health information, or other sensitive categories; if so, preserve consistency with any separate healthcare privacy, confidentiality, or security regime that also applies.
- Confirm which data roles apply to each party and which services actually involve personal data processing; do not draft to hypothetical processing outside the deal scope.
- If multiple data categories, jurisdictions, or service lines appear, enumerate them first and then draft the operative provisions and annexes against that full set.
- Build the annexes from the deal documents and security materials, not from generic boilerplate.

## 2. Failure modes the skill is correcting

- Drafting from the vendor’s template with surface edits instead of resetting to a controller-protective baseline.
- Preserving vendor-favorable positions on sub-processor control, audit limitations, assistance obligations, retention, and liability allocation.
- Addressing general privacy concepts while missing the healthcare-specific overlay and any required consistency with parallel health privacy obligations.
- Treating sub-processors as a notice-only issue rather than a meaningful approval-and-flow-down control.
- Omitting or under-specifying the processing annexes that make the DPA operational.
- Failing to translate security documents into contractual minimums, resulting in an exhibit that is aspirational rather than enforceable.
- Producing a memo that describes issues without naming the governing rule, the affected contract interaction, and the practical consequence.

## 3. Legal frameworks / domain conventions that apply

- Controller-processor / service-provider structure: require processing only on documented instructions, confidentiality, security appropriate to risk, assistance with rights and incidents, deletion or return, audit cooperation, and compliance demonstration.
- Healthcare privacy overlay: if regulated health data is in scope, align the DPA with any separate healthcare privacy framework and avoid internal inconsistencies between exhibits.
- Sub-processor control: require prior approval or a tightly controlled notice-and-objection process, plus equivalent flow-down obligations and responsibility for subcontracted performance.
- Security contracting: translate the company’s information-security standard into contractual requirements that cover access controls, encryption, incident response, vulnerability management, logging, training, and segregation where relevant.
- Data subject rights and incident obligations: specify response timing, cooperation duties, and content requirements sufficient for the controller to meet downstream legal deadlines.
- Retention and deletion: require return or deletion at end of services, certify completion where appropriate, and preserve only limited legally required copies under controlled safeguards.
- Audit and compliance evidence: third-party reports may supplement but do not replace contractual inspection rights or meaningful compliance demonstrations.
- Liability and remedy alignment: ensure the DPA remedies, indemnity posture, and liability carve-outs do not undercut the MSA’s risk allocation.

## 4. Analytical scaffolds

- Start from the company’s required position, then compare the vendor template clause by clause and rewrite the DPA to the more protective position where the documents support it.
- For each core provision, test whether it answers four questions: what data, what purpose, what controls, and what remedy if the processor deviates.
- For each annex, use source-document extraction: processing description, categories, durations, transfer geography if relevant, security controls, and subprocessors.
- For healthcare-related scope, check whether the processing description, confidentiality language, and incident obligations need a parallel reference to the applicable health-data regime.
- For sub-processors, draft the control mechanism in sequence: disclosure, approval, objection, onboarding conditions, onward flow-down, and liability for failure.
- For the negotiation memo, identify only material departures from the company baseline; for each, state the company position, the vendor position, the risk, and a practical fallback.
- When a source document is silent, draft conservatively and flag the gap in the memo rather than assuming vendor-favorable silence.
- Use a clause-level consistency check so the DPA, MSA, security exhibit, and annexes do not conflict on definitions, precedence, term, or breach notice mechanics.

## 5. Vertical / structural / temporal relationships (only if applicable)

- Make the DPA an exhibit that expressly incorporates the MSA, but preserve the DPA as the controlling privacy-specific addendum where its subject matter is more specific.
- Resolve vertical hierarchy expressly: MSA general terms, then DPA-specific processing terms, then annexes describing the operational details.
- Align temporal obligations: commencement of processing, onboarding of any sub-processor, security implementation timing, incident notice timing, deletion/return timing, and post-termination survival.
- If multiple affiliated entities, service modules, or data environments are in scope, map each to the applicable processing description and security controls before drafting obligations.
- Where a healthcare overlay exists, make the interaction rule explicit so one framework does not dilute the other by implication.

## 6. Output structure conventions

- Draft the DPA as a complete, controller-protective exhibit ready to attach to the MSA, with operative clauses plus complete annexes.
- Include all core privacy provisions in integrated contract form rather than in a checklist or commentary style.
- Ensure annexes are populated with deal-specific content and not placeholder text.
- Prepare the negotiation issues memo as a concise issue-by-issue advisory comparing the vendor template against the company’s required position.
- For each memo issue, state the governing rule or contractual convention, the disagreement, the company position, the likely fallback, and the practical consequence of compromise.
- Use an ordinal severity label for each memo issue and keep the scale consistent throughout the memo.
- End the memo with concrete recommended actions directed to the appropriate internal role and tied to the deal timeline.
- Keep the drafting deliverable and the memo distinct; do not let the memo substitute for the operative DPA.
- Before finishing, confirm the DPA file exists and is non-empty, and then confirm the memo file exists and is non-empty.

