← Files Rohas Legal AI: PrivacyARCHIVED FILE

skills/data-processing-agreement-reviewer/SKILL.md

3.1 KB · Oct 4, 2026 · 12:29 UTC

↓ Download file

---
name: data-processing-agreement-reviewer
description: >-
  Review and draft data-processing agreements and privacy schedules for
  controller-processor, fiduciary-processor, joint-controller, service-provider,
  or independent-controller relationships. Use for instructions, security,
  breaches, subprocessors, assistance, transfers, audits, deletion, and liability.
---

# Data Processing Agreement Reviewer

Test the agreement against the actual service and data flow. Contract labels do
not determine legal roles when operational facts show otherwise.

## Intake

Obtain the main agreement, proposed DPA, parties and affiliates, service
description, data-flow and system diagrams, data and subject categories, purposes,
instructions, jurisdictions, hosting and access locations, subprocessors,
security materials, retention, incident process, audits, transfer mechanisms,
sector rules, insurance, and liability terms.

## Review method

1. Determine each party's role per processing purpose and identify independent,
   joint, processor, subprocessor, fiduciary, or other regulated activities.
2. Verify the processing schedule: subject, duration, nature, purpose, data,
   people, frequency, locations, retention, and controller instructions.
3. Test limits on use, sale, sharing, combination, profiling, advertising,
   product improvement, AI training, de-identification, re-identification, and
   independent purposes.
4. Review confidentiality, personnel access, training, screening, security
   measures, testing, certifications, evidence, and change controls.
5. Align incident definitions, immediate escalation, investigation cooperation,
   evidence, notice content, notification control, costs, and remediation.
6. Review subprocessor authorisation, current list, change notice, objection,
   equivalent obligations, location, flow-down, and primary responsibility.
7. Require proportionate assistance with rights requests, notices, DPIAs,
   consultations, records, audits, regulators, litigation holds, and complaints.
8. Map international transfers, onward transfers, approved mechanisms, annexes,
   government requests, supplementary safeguards, suspension, and updates.
9. Review retention, return, deletion, backups, legal holds, certification,
   transition, portability, and post-termination access.
10. Make audit and assurance rights operational, risk-based, non-duplicative,
    confidentiality-protected, and capable of escalating material gaps.
11. Reconcile privacy indemnities, liability caps, exclusions, insurance,
    precedence, termination, change control, and survival with the main agreement.

## Output

Provide a role and data-flow matrix, clause-by-clause issue list, operational-gap
schedule, proposed language, processing annex, security and subprocessor checklist,
transfer map, and negotiation priorities.

## Guardrails

Do not accept inaccurate roles, empty processing schedules, security promises
unsupported by evidence, blanket secondary use, or unworkable audit language.
Do not assume a DPA supplies lawful basis, notice, consent, or transfer compliance.
Verify current mandatory terms in every relevant jurisdiction.

SHA-256: ed11877f08812bd7351ed2ac369bae29bafa8edfdeaed5b7e34e53d264f71b2f