1---2name: draft-markup-counterparty-dpa3description: Redlined DPA with bracketed commentary organized against the applicable negotiation playbook, with a risk-prioritized commentary memo covering negotiation strategy.4---56# Skill: Draft Markup of Counterparty Data Processing Addendum78## 1. Subject-matter triage9- Treat the DPA as the primary deliverable and the commentary memo as secondary.10- If there is more than one source document set, map the operative positions first: the DPA text, the negotiation playbook, deal context, and any security or sub-processor materials.11- Identify whether the DPA is being used as a controller-processor addendum, a standalone privacy exhibit, or a negotiated supplement; do not assume a generic form fits the deal.12- Confirm whether cross-border transfer language is implicated by the actual data flows or hosting structure before adding transfer mechanics.1314## 2. Failure modes the skill is correcting15- Marking up against generic privacy principles instead of the deal-specific negotiation playbook positions.16- Failing to integrate the sub-processor schedule and security materials into the markup, leaving internal inconsistencies between the DPA and supporting exhibits.17- Treating certifications, audit reports, or external attestations as substitutes for substantive contractual security obligations.18- Omitting bracketed commentary and leaving the deal team without an explanation of why a clause was changed.19- Drafting a redline that cannot be recovered from plain text because the changes are only visual.20- Producing commentary that lists concerns without a severity ranking, recommended strategy, and next step.21- Making legal assertions about processor duties, transfers, or audit rights without tying them to the controlling contractual framework or cited authority.2223## 3. Legal frameworks / domain conventions that apply24- The playbook is the operative negotiating standard; the markup should meet or exceed the playbook floor on each clause the playbook addresses.25- The DPA must preserve baseline processor obligations for notice, confidentiality, security, subprocessors, assistance, deletion/return, and compliance support, with deal-specific refinements layered on top.26- Sub-processor terms should address approval or objection rights, flow-down obligations, and a meaningful mechanism for updating the list.27- Security terms should be substantive and operational, not merely referential to a certificate or high-level policy statement.28- Audit and assessment rights should be workable in practice, including scope, cadence, access, and substitute reporting where appropriate.29- Assistance obligations should cover data subject requests, incident response, DPIAs or equivalent assessments, and regulatory inquiries where the deal calls for them.30- Transfer language should use the applicable legal mechanism for the jurisdictional pathway actually implicated by the transaction.31- Where legal propositions are stated in the memo, cite the controlling authority by name and section or comparable identifier.3233## 4. Analytical scaffolds34- Playbook mapping: identify each DPA topic in the playbook, then align the counterparty language to the required position before editing for style.35- Clause-by-clause markup: for each substantive provision, decide whether to keep, tighten, delete, or replace; then express the change in a plain-text-safe redline convention.36- Sub-processor review: test whether the list is identifiable, current, and consistent with the approval and notice mechanics in the body of the DPA.37- Security review: compare the body of the DPA against the security exhibit and confirm the contract contains enforceable commitments, not only references.38- Transfer review: determine whether any processing, support, hosting, or sub-processing path triggers cross-border language; if yes, add the applicable mechanism rather than generic compliance language.39- Commentary memo: convert each issue into a risk item with a severity label, a short reason, the business consequence, and the recommended negotiation posture.40- Authority support: when the memo states a rule-based conclusion, cite the governing statute, regulation, rule, or recognized authority that supports it.4142## 5. Vertical / structural / temporal relationships43- Read the DPA as a hierarchy: definitions control operative clauses, operative clauses control exhibits, and later or bespoke schedules control only where the document expressly makes them controlling.44- Track vertical consistency between the DPA, sub-processor list, and security materials so that an obligation stated in one place is not silently negated in another.45- Watch temporal mechanics for notice, approval, objection, response, remediation, deletion, retention, and update cycles; the markup should preserve workable timelines rather than abstract commitments.46- If multiple jurisdictions, data categories, or processing roles appear in the source set, assess each one separately before consolidating the final position.47- Where a provision depends on a future event, make the trigger and consequence explicit so the clause remains administrable after signing.4849## 6. Output structure conventions50- Redlined DPA: use a plain-text-safe markup convention for every substantive change, such as [DELETED: …], [INSERTED: …], or [REPLACED: old → new], and attach a short [Rationale: …] note to each change.51- Commentary memo: define a simple ordinal severity scale once at the top, then give each issue a severity label, concise rationale, business impact, and negotiation stance.52- Commentary entries should be issue-based, not clause-reprint summaries; focus on what changed, why it matters, and what the team should do next.53- End the memo with a Recommended Actions block that gives an imperative action, the responsible role, and a timing anchor tied to the deal process.54- Preserve the DPA as the primary file and ensure the markup is complete before relying on the memo.55- Confirm the final deliverables are named exactly as requested: `axiom-dpa-v3.1-redline.docx` and `dpa-markup-commentary.docx`.