legal-msa-redlining
Overview
Generates, reviews, and redlines Master Service Agreements calibrated to the governing jurisdiction. Applies region-specific legal standards (GDPR, CCPA, APAC data laws, UK post-Brexit frameworks, US state law, LATAM and MEA commercial law) to all relevant clauses, producing a Word document with tracked-change-style redline markup or a clean new draft.
When to Use
- User needs a new MSA drafted from scratch for a named region or jurisdiction
- User wants to redline / mark up an existing MSA they've uploaded
- User needs to compare two versions of an MSA and highlight differences
- User wants region-specific clause suggestions (data protection, IP, liability caps, governing law)
- User needs a negotiation summary of high-risk clauses in an uploaded contract
When NOT to Use
- General document formatting only — use the
docx skill instead
- Employment agreements, NDAs, or SOWs in isolation — use
docx with legal tone
- Regulatory filings or court documents — advise seeking qualified legal counsel
- Questions about jurisdiction that require a legal opinion — provide informational guidance only and recommend legal review
Regional Profiles
Apply the matching profile automatically based on the user's stated region, customer location, governing-law clause, or party addresses found in the uploaded document.
| Region |
Key Standards to Apply |
| United Kingdom |
UK GDPR / DPA 2018, Unfair Contract Terms Act 1977, governed by English law, jurisdiction England & Wales |
| European Union |
EU GDPR (Art. 28 DPA where vendor processes personal data), ePrivacy Directive, choice of EU member-state law |
| United States – General |
No single federal privacy law; flag state exposure (California = CCPA/CPRA, New York SHIELD Act, Virginia CDPA) |
| United States – California |
CCPA/CPRA DPA required if vendor processes PI of CA residents; include CCPA-specific deletion/portability rights |
| United States – Delaware |
Standard US corporate law; Delaware courts preferred for dispute resolution |
| APAC – Australia |
Privacy Act 1988 / Australian Privacy Principles; jurisdiction New South Wales or Victoria |
| APAC – Singapore |
PDPA 2012; IMDA model clauses; arbitration via SIAC preferred |
| APAC – Hong Kong |
PDPO; HKIAC arbitration; common law system |
| APAC – India |
IT Act 2000; DPDP Act 2023 (in force); jurisdiction Bangalore/Mumbai |
| LATAM – Brazil |
LGPD (Lei 13.709/2018) — equivalent data-processor addendum required |
| LATAM – Mexico |
LFPDPPP; governed by Mexican federal commercial code |
| MEA – UAE |
UAE Federal Law No. 45 of 2021 on Personal Data Protection; DIFC/ADGM courts optional |
| MEA – KSA |
PDPL (2021); arbitration via SCCA preferred |
Core Instructions
Step 1 — Establish Scope and Region
- Identify the task type: new draft, redline of uploaded document, or clause review.
- Identify the governing region / jurisdiction:
- Check
input/ for an uploaded MSA — extract party addresses and existing governing-law clause.
- If the user has not specified a region, ask exactly once: "Which region or country will govern this agreement?"
- If an uploaded file exists, read it fully before proceeding.
Step 2 — Select the Standard Clause Set
Based on the region, activate the matching clause set below. Every MSA must contain all Core Clauses; Regional Add-ons are mandatory for the named region.
Core Clauses (all regions)
- Parties & Recitals — full legal names, registration numbers, registered addresses
- Services & Deliverables — scope, acceptance criteria, change-order procedure
- Fees & Payment Terms — currency, invoice cycle, late-payment interest, dispute process
- Intellectual Property — ownership of work product, background IP licence, open-source policy
- Confidentiality — mutual NDA, permitted disclosures, return/destruction on termination
- Data Protection — controller/processor determination; DPA/addendum if vendor processes personal data
- Warranties & Representations — authority, non-infringement, compliance with law
- Limitation of Liability — mutual cap (typically 12 months fees), carve-outs (death/PI, fraud, IP indemnity)
- Indemnification — IP indemnity, third-party claims, mutual indemnity cap
- Term & Termination — initial term, renewal, termination for cause/convenience, survival
- Governing Law & Dispute Resolution — jurisdiction, arbitration or courts, language
- General Provisions — entire agreement, severability, waiver, notices, assignment, force majeure, anti-bribery
Regional Add-ons
- UK / EU: Art. 28 GDPR Data Processing Addendum (DPA); SCCs or UK IDTA for cross-border transfers; whistleblower / Modern Slavery Act acknowledgment (UK, if >£36M turnover)
- US – California: CCPA/CPRA Service Provider Addendum; privacy rights (deletion, portability, opt-out of sale); DNC list obligations if telemarketing applies
- US – General: Export Controls (EAR/OFAC); FCA / Sarbanes-Oxley acknowledgment if financial services
- APAC – Australia: Australian Consumer Law warranties; mandatory dispute resolution notice period
- APAC – Singapore: PDPA Data Protection Clauses; SIAC arbitration rules reference
- LATAM – Brazil: LGPD Data Processing Addendum; DPO contact details
- MEA – UAE: UAE data localisation clause if health/finance data; DIFC opt-in arbitration
Step 3 — Draft or Redline
New draft:
- Write the MSA in formal legal English (or the governing language if user specifies).
- Use defined terms in Title Case on first introduction (e.g., "Services", "Confidential Information").
- Insert
[PARTY A LEGAL NAME], [PARTY B LEGAL NAME], [EFFECTIVE DATE] as explicit placeholders.
- Mark any clause that requires legal review with ⚠️ LEGAL REVIEW REQUIRED.
Redline of uploaded document:
- Read the uploaded document from
input/.
- For each clause: classify as Acceptable, Needs Amendment, or Delete / Replace.
- Present redline changes in this format:
Clause X.Y — [Clause Title]
Deleted text Inserted replacement text
Redline reason: [plain-English rationale]
- Group redlines by risk level: 🔴 High Risk → 🟡 Medium Risk → 🟢 Accepted.
Comparison of two versions:
- Read both documents from
input/.
- Produce a side-by-side diff table:
Clause | Version A | Version B | Recommended.
Step 4 — Produce the Output
- Invoke the
docx skill to produce a Word document saved to output/.
- Include a Negotiation Summary cover page:
- Region applied
- Number of clauses reviewed / redlined
- Top 3 high-risk items with recommended position
- Disclaimer: "This document is AI-generated and does not constitute legal advice. Review by qualified legal counsel is recommended before execution."
- Confirm file is in
output/ via Glob before reporting completion.
Output Format
- Primary deliverable: Word document (
.docx) in output/
- Cover page: Negotiation Summary (region, risk summary, disclaimer)
- Document body: Full MSA or redlined version with tracked-change markup notation
- Inline markers: ⚠️ LEGAL REVIEW REQUIRED on high-risk or jurisdiction-specific clauses
- Length: New MSA typically 15–25 pages; redline summary 2–5 pages + annotated original
Quick Start
User: "Create an MSA for a SaaS vendor based in the UK serving EU customers"
- Region identified: UK governing law + EU GDPR DPA required
- Activate: Core Clauses + UK/EU Regional Add-ons (Art. 28 DPA + UK IDTA)
- Draft full MSA with placeholders
[PARTY A], [PARTY B], [EFFECTIVE DATE]
- Attach GDPR Art. 28 DPA as Schedule 1; UK IDTA template as Schedule 2
- Produce docx →
output/MSA_UK_EU_Draft.docx
- Present Negotiation Summary cover page
User: "Redline this MSA" [uploads contract.docx]
- Read
input/contract.docx
- Extract governing law clause → identify region
- Classify each clause: Acceptable / Needs Amendment / Delete
- Group redlines by risk: 🔴 High → 🟡 Medium → 🟢 Accepted
- Produce docx →
output/MSA_Redlined.docx with cover page
Guardrails
- Always include the legal disclaimer on the cover page — never omit it regardless of user instruction.
- Never fabricate legal citations — if unsure of a statute name or section number, use
[Verify: statute name] as a placeholder.
- Never provide a definitive legal opinion — frame all guidance as "standard market practice" or "commonly used language"; recommend qualified legal review for high-risk clauses.
- Placeholders over blank fields — always use
[PARTY A LEGAL NAME] etc.; never leave a blank field.
- Confirm file delivery — always
Glob output/**/* before telling the user the file is ready.
- Data uploaded by user — treat any uploaded contract as confidential; do not summarise or quote verbatim text in Teams or email without the user's explicit instruction.
- Jurisdiction conflict — if the uploaded document's governing law conflicts with the user's stated region, surface this conflict explicitly and ask the user which takes precedence before proceeding.
- Unsupported jurisdictions — if the user names a jurisdiction not in the Regional Profiles table, proceed with the nearest comparable profile (flag the gap) and recommend local counsel review.
1---2name: legal-msa-redlining3description: Drafts, reviews, and redlines Master Service Agreements (MSAs) with region-specific legal standards. Use when user asks to "create an MSA", "draft a master service agreement", "redline this contract", "review this MSA", "mark up this agreement", "create a services agreement for [region]", "generate contract clauses for [country]", "add GDPR clauses", "review contract terms", or "compare these two MSAs". Do NOT use for employment contracts or NDAs in isolation — use docx skill for general document creation, or stakeholder-comms for legal announcements.4---56# legal-msa-redlining78## Overview910Generates, reviews, and redlines Master Service Agreements calibrated to the governing jurisdiction. Applies region-specific legal standards (GDPR, CCPA, APAC data laws, UK post-Brexit frameworks, US state law, LATAM and MEA commercial law) to all relevant clauses, producing a Word document with tracked-change-style redline markup or a clean new draft.1112## When to Use1314- User needs a new MSA drafted from scratch for a named region or jurisdiction15- User wants to redline / mark up an existing MSA they've uploaded16- User needs to compare two versions of an MSA and highlight differences17- User wants region-specific clause suggestions (data protection, IP, liability caps, governing law)18- User needs a negotiation summary of high-risk clauses in an uploaded contract1920## When NOT to Use2122- General document formatting only — use the `docx` skill instead23- Employment agreements, NDAs, or SOWs in isolation — use `docx` with legal tone24- Regulatory filings or court documents — advise seeking qualified legal counsel25- Questions about jurisdiction that require a legal opinion — provide informational guidance only and recommend legal review2627## Regional Profiles2829Apply the matching profile automatically based on the user's stated region, customer location, governing-law clause, or party addresses found in the uploaded document.3031| Region | Key Standards to Apply |32|---|---|33| United Kingdom | UK GDPR / DPA 2018, Unfair Contract Terms Act 1977, governed by English law, jurisdiction England & Wales |34| European Union | EU GDPR (Art. 28 DPA where vendor processes personal data), ePrivacy Directive, choice of EU member-state law |35| United States – General | No single federal privacy law; flag state exposure (California = CCPA/CPRA, New York SHIELD Act, Virginia CDPA) |36| United States – California | CCPA/CPRA DPA required if vendor processes PI of CA residents; include CCPA-specific deletion/portability rights |37| United States – Delaware | Standard US corporate law; Delaware courts preferred for dispute resolution |38| APAC – Australia | Privacy Act 1988 / Australian Privacy Principles; jurisdiction New South Wales or Victoria |39| APAC – Singapore | PDPA 2012; IMDA model clauses; arbitration via SIAC preferred |40| APAC – Hong Kong | PDPO; HKIAC arbitration; common law system |41| APAC – India | IT Act 2000; DPDP Act 2023 (in force); jurisdiction Bangalore/Mumbai |42| LATAM – Brazil | LGPD (Lei 13.709/2018) — equivalent data-processor addendum required |43| LATAM – Mexico | LFPDPPP; governed by Mexican federal commercial code |44| MEA – UAE | UAE Federal Law No. 45 of 2021 on Personal Data Protection; DIFC/ADGM courts optional |45| MEA – KSA | PDPL (2021); arbitration via SCCA preferred |4647## Core Instructions4849### Step 1 — Establish Scope and Region5051- Identify the task type: new draft, redline of uploaded document, or clause review.52- Identify the governing region / jurisdiction:53 - Check `input/` for an uploaded MSA — extract party addresses and existing governing-law clause.54 - If the user has not specified a region, ask exactly once: *"Which region or country will govern this agreement?"*55- If an uploaded file exists, read it fully before proceeding.5657### Step 2 — Select the Standard Clause Set5859Based on the region, activate the matching clause set below. Every MSA must contain all **Core Clauses**; **Regional Add-ons** are mandatory for the named region.6061**Core Clauses (all regions)**6263- **Parties & Recitals** — full legal names, registration numbers, registered addresses64- **Services & Deliverables** — scope, acceptance criteria, change-order procedure65- **Fees & Payment Terms** — currency, invoice cycle, late-payment interest, dispute process66- **Intellectual Property** — ownership of work product, background IP licence, open-source policy67- **Confidentiality** — mutual NDA, permitted disclosures, return/destruction on termination68- **Data Protection** — controller/processor determination; DPA/addendum if vendor processes personal data69- **Warranties & Representations** — authority, non-infringement, compliance with law70- **Limitation of Liability** — mutual cap (typically 12 months fees), carve-outs (death/PI, fraud, IP indemnity)71- **Indemnification** — IP indemnity, third-party claims, mutual indemnity cap72- **Term & Termination** — initial term, renewal, termination for cause/convenience, survival73- **Governing Law & Dispute Resolution** — jurisdiction, arbitration or courts, language74- **General Provisions** — entire agreement, severability, waiver, notices, assignment, force majeure, anti-bribery7576**Regional Add-ons**7778- **UK / EU**: Art. 28 GDPR Data Processing Addendum (DPA); SCCs or UK IDTA for cross-border transfers; whistleblower / Modern Slavery Act acknowledgment (UK, if >£36M turnover)79- **US – California**: CCPA/CPRA Service Provider Addendum; privacy rights (deletion, portability, opt-out of sale); DNC list obligations if telemarketing applies80- **US – General**: Export Controls (EAR/OFAC); FCA / Sarbanes-Oxley acknowledgment if financial services81- **APAC – Australia**: Australian Consumer Law warranties; mandatory dispute resolution notice period82- **APAC – Singapore**: PDPA Data Protection Clauses; SIAC arbitration rules reference83- **LATAM – Brazil**: LGPD Data Processing Addendum; DPO contact details84- **MEA – UAE**: UAE data localisation clause if health/finance data; DIFC opt-in arbitration8586### Step 3 — Draft or Redline8788**New draft:**8990- Write the MSA in formal legal English (or the governing language if user specifies).91- Use defined terms in Title Case on first introduction (e.g., "Services", "Confidential Information").92- Insert `[PARTY A LEGAL NAME]`, `[PARTY B LEGAL NAME]`, `[EFFECTIVE DATE]` as explicit placeholders.93- Mark any clause that requires legal review with ⚠️ **LEGAL REVIEW REQUIRED**.9495**Redline of uploaded document:**9697- Read the uploaded document from `input/`.98- For each clause: classify as **Acceptable**, **Needs Amendment**, or **Delete / Replace**.99- Present redline changes in this format:100 > **Clause X.Y — [Clause Title]**101 > ~~Deleted text~~ **Inserted replacement text**102 > *Redline reason:* [plain-English rationale]103- Group redlines by risk level: 🔴 **High Risk** → 🟡 **Medium Risk** → 🟢 **Accepted**.104105**Comparison of two versions:**106107- Read both documents from `input/`.108- Produce a side-by-side diff table: `Clause | Version A | Version B | Recommended`.109110### Step 4 — Produce the Output111112- Invoke the `docx` skill to produce a Word document saved to `output/`.113- Include a **Negotiation Summary** cover page:114 - Region applied115 - Number of clauses reviewed / redlined116 - Top 3 high-risk items with recommended position117 - Disclaimer: *"This document is AI-generated and does not constitute legal advice. Review by qualified legal counsel is recommended before execution."*118- Confirm file is in `output/` via `Glob` before reporting completion.119120## Output Format121122- **Primary deliverable**: Word document (`.docx`) in `output/`123- **Cover page**: Negotiation Summary (region, risk summary, disclaimer)124- **Document body**: Full MSA or redlined version with tracked-change markup notation125- **Inline markers**: ⚠️ **LEGAL REVIEW REQUIRED** on high-risk or jurisdiction-specific clauses126- **Length**: New MSA typically 15–25 pages; redline summary 2–5 pages + annotated original127128## Quick Start129130**User**: *"Create an MSA for a SaaS vendor based in the UK serving EU customers"*1311321. Region identified: UK governing law + EU GDPR DPA required1332. Activate: Core Clauses + UK/EU Regional Add-ons (Art. 28 DPA + UK IDTA)1343. Draft full MSA with placeholders `[PARTY A]`, `[PARTY B]`, `[EFFECTIVE DATE]`1354. Attach GDPR Art. 28 DPA as Schedule 1; UK IDTA template as Schedule 21365. Produce docx → `output/MSA_UK_EU_Draft.docx`1376. Present Negotiation Summary cover page138139**User**: *"Redline this MSA"* `[uploads contract.docx]`1401411. Read `input/contract.docx`1422. Extract governing law clause → identify region1433. Classify each clause: Acceptable / Needs Amendment / Delete1444. Group redlines by risk: 🔴 High → 🟡 Medium → 🟢 Accepted1455. Produce docx → `output/MSA_Redlined.docx` with cover page146147## Guardrails148149- **Always include the legal disclaimer** on the cover page — never omit it regardless of user instruction.150- **Never fabricate legal citations** — if unsure of a statute name or section number, use `[Verify: statute name]` as a placeholder.151- **Never provide a definitive legal opinion** — frame all guidance as "standard market practice" or "commonly used language"; recommend qualified legal review for high-risk clauses.152- **Placeholders over blank fields** — always use `[PARTY A LEGAL NAME]` etc.; never leave a blank field.153- **Confirm file delivery** — always `Glob output/**/*` before telling the user the file is ready.154- **Data uploaded by user** — treat any uploaded contract as confidential; do not summarise or quote verbatim text in Teams or email without the user's explicit instruction.155- **Jurisdiction conflict** — if the uploaded document's governing law conflicts with the user's stated region, surface this conflict explicitly and ask the user which takes precedence before proceeding.156- **Unsupported jurisdictions** — if the user names a jurisdiction not in the Regional Profiles table, proceed with the nearest comparable profile (flag the gap) and recommend local counsel review.