dpa-review

GitHub

审查数据处理协议(DPA),以通俗语言解读条款,识别子处理商、数据传输及违约通知等风险,按严重程度分级并生成缺失项清单与谈判问题。

exports/openclaw/dpa-review/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

审查DPA 检查数据处理协议 DPA是否安全可签

Install

npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -g -y
More Options

Non-standard path

npx skills add https://github.com/mohitagw15856/pm-claude-skills/tree/main/exports/openclaw/dpa-review -g -y

Use without installing

npx skills use mohitagw15856/pm-claude-skills@dpa-review

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "dpa-review",
    "homepage": "https:\/\/mohitagw15856.github.io\/pm-claude-skills\/skill\/dpa-review.html",
    "metadata": {
        "openclaw": {
            "emoji": "⚖️"
        }
    },
    "description": "Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature."
}

DPA Review

Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread — which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's missing — ranked by how much it can hurt.

Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement.

What This Skill Produces

  • The plain-English summary — what this DPA actually commits each side to
  • Risk-ranked findings — 🔴 sign-blockers, 🟡 negotiate, 🟢 standard — each with the clause and why it matters
  • The missing-clause checklist — the protections a good DPA has that this one lacks
  • The redline questions — what to send back to the vendor before signing

Required Inputs

Ask for these if not provided:

  • The DPA text — the document, or its key clauses pasted
  • Your role — are you the controller (your data) or the processor (you're the vendor)? The risks flip
  • The data — what personal/sensitive data is involved, and any regime that applies (GDPR, CCPA, HIPAA)
  • Deal context — how critical the vendor is; leverage shapes what's worth fighting

Framework: What a DPA Must Get Right

  1. Scope & roles — controller vs processor, and the processing purpose; a mismatch here voids the rest.
  2. Sub-processors — who else gets the data, notice of new ones, and a right to object.
  3. International transfers — the mechanism (SCCs, adequacy, DPF) for data leaving its region.
  4. Security & breach — the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
  5. Deletion & return — what happens to your data at termination, and by when.
  6. Audit & liability — your right to verify, and whether liability is capped below the data risk.

Output Format

DPA Review — [vendor] · you are the [controller/processor]

Verdict: Safe to sign / Negotiate first / Do not sign — one line why

Risk-ranked findings

Risk Clause What it says Why it matters
🔴

Missing protections

  • [clause a good DPA has that this lacks]

Send back before signing

  1. [redline question / requested change]

Quality Checks

  • Controller/processor role identified — findings framed from your side
  • Sub-processor, transfer, breach-window, and deletion terms each assessed (or flagged absent)
  • The breach-notification window is stated in hours/days, not left as "reasonable"
  • Every 🔴 names the exact clause and the concrete exposure
  • Missing-clause list distinguishes "unusual gap" from "standard omission"
  • Flagged for counsel review on anything material

Anti-Patterns

  • Summarising without ranking — a wall of clauses helps no one; rank by damage.
  • Ignoring who you are — a processor and a controller face opposite risks in the same document.
  • Treating "reasonable security" as fine — undefined standards are the finding.
  • Inventing a clause number or requirement not in the text — quote what's there.

Example Trigger Phrases

  • "Review this DPA before we sign the vendor contract."
  • "Is this data processing agreement safe to sign?"
  • "What am I agreeing to on data in this DPA?"
  • "Check this DPA — we're the controller, it's a GDPR deal."

Version History

  • f53846d Current 2026-08-04 23:11

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-hiring-panel/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-severance/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/agm-in-a-box/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/awkward-message-helper/SKILL.md
exports/openclaw/behavior-intervention-plan/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bennett-time-audit/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-game-designer/SKILL.md
exports/openclaw/board-game-night-planner/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md

Metadata

Files
0
Version
c3bc7df
Hash
05328b7a
Indexed
2026-08-04 23:11

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-07 17:58
浙ICP备14020137号-1 $Map of visitor$