← Rohas Legal AI: PrivacyCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Rohas Legal AI: Privacy
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.2.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Review and draft data-processing agreements and privacy schedules for controller-processor, fiduciary-processor, joint-controller, service-provider, or independent-controller relationships. Use for instructions, security, breaches, subprocessors, assistance, transfers, audits, deletion, and liability.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 346
}
],
"name": "data-processing-agreement-reviewer",
"skill_md_contents": "---\nname: data-processing-agreement-reviewer\ndescription: >-\n Review and draft data-processing agreements and privacy schedules for\n controller-processor, fiduciary-processor, joint-controller, service-provider,\n or independent-controller relationships. Use for instructions, security,\n breaches, subprocessors, assistance, transfers, audits, deletion, and liability.\n---\n\n# Data Processing Agreement Reviewer\n\nTest the agreement against the actual service and data flow. Contract labels do\nnot determine legal roles when operational facts show otherwise.\n\n## Intake\n\nObtain the main agreement, proposed DPA, parties and affiliates, service\ndescription, data-flow and system diagrams, data and subject categories, purposes,\ninstructions, jurisdictions, hosting and access locations, subprocessors,\nsecurity materials, retention, incident process, audits, transfer mechanisms,\nsector rules, insurance, and liability terms.\n\n## Review method\n\n1. Determine each party's role per processing purpose and identify independent,\n joint, processor, subprocessor, fiduciary, or other regulated activities.\n2. Verify the processing schedule: subject, duration, nature, purpose, data,\n people, frequency, locations, retention, and controller instructions.\n3. Test limits on use, sale, sharing, combination, profiling, advertising,\n product improvement, AI training, de-identification, re-identification, and\n independent purposes.\n4. Review confidentiality, personnel access, training, screening, security\n measures, testing, certifications, evidence, and change controls.\n5. Align incident definitions, immediate escalation, investigation cooperation,\n evidence, notice content, notification control, costs, and remediation.\n6. Review subprocessor authorisation, current list, change notice, objection,\n equivalent obligations, location, flow-down, and primary responsibility.\n7. Require proportionate assistance with rights requests, notices, DPIAs,\n consultations, records, audits, regulators, litigation holds, and complaints.\n8. Map international transfers, onward transfers, approved mechanisms, annexes,\n government requests, supplementary safeguards, suspension, and updates.\n9. Review retention, return, deletion, backups, legal holds, certification,\n transition, portability, and post-termination access.\n10. Make audit and assurance rights operational, risk-based, non-duplicative,\n confidentiality-protected, and capable of escalating material gaps.\n11. Reconcile privacy indemnities, liability caps, exclusions, insurance,\n precedence, termination, change control, and survival with the main agreement.\n\n## Output\n\nProvide a role and data-flow matrix, clause-by-clause issue list, operational-gap\nschedule, proposed language, processing annex, security and subprocessor checklist,\ntransfer map, and negotiation priorities.\n\n## Guardrails\n\nDo not accept inaccurate roles, empty processing schedules, security promises\nunsupported by evidence, blanket secondary use, or unworkable audit language.\nDo not assume a DPA supplies lawful basis, notice, consent, or transfer compliance.\nVerify current mandatory terms in every relevant jurisdiction.\n"
}SHA-256 of public snapshot: 90f473c75a67bbc522bfb8699d0cb90a717ec657ea0f4143155d8f894dea3ea7