跳到主要内容
知仓学习社ZHICANG

dpa-review

Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain la…

不碰外部(只输出文字)无严重或高危命中mohitagw15856/pm-claude-skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

DPA Review

Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread — which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's missing — ranked by how much it can hurt.

> Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement.

What This Skill Produces

  • The plain-English summary — what this DPA actually commits each side to
  • Risk-ranked findings — 🔴 sign-blockers, 🟡 negotiate, 🟢 standard — each with the clause and why it matters
  • The missing-clause checklist — the protections a good DPA has that this one lacks
  • The redline questions — what to send back to the vendor before signing

Required Inputs

Ask for these if not provided:

  • The DPA text — the document, or its key clauses pasted
  • Your role — are you the controller (your data) or the processor (you're the vendor)? The risks flip
  • The data — what personal/sensitive data is involved, and any regime that applies (GDPR, CCPA, HIPAA)
  • Deal context — how critical the vendor is; leverage shapes what's worth fighting

Framework: What a DPA Must Get Right

  1. Scope & roles — controller vs processor, and the processing purpose; a mismatch here voids the rest.
  2. Sub-processors — who else gets the data, notice of new ones, and a right to object.
  3. International transfers — the mechanism (SCCs, adequacy, DPF) for data leaving its region.
  4. Security & breach — the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
  5. Deletion & return — what happens to your data at termination, and by when.
  6. Audit & liability — your right to verify, and whether liability is capped below the data risk.

Output Format

DPA Review — [vendor] · you are the [controller/processor]

Verdict: Safe to sign / Negotiate first / Do not sign — one line why

Risk-ranked findings

| Risk | Clause | What it says | Why it matters |

|---|---|---|---|

| 🔴 | … | … | … |

Missing protections

  • [clause a good DPA has that this lacks]

Send back before signing

  1. [redline question / requested change]

Quality Checks

  • [ ] Controller/processor role identified — findings framed from your side
  • [ ] Sub-processor, transfer, breach-window, and deletion terms each assessed (or flagged absent)
  • [ ] The breach-notification window is stated in hours/days, not left as "reasonable"
  • [ ] Every 🔴 names the exact clause and the concrete exposure
  • [ ] Missing-clause list distinguishes "unusual gap" from "standard omission"
  • [ ] Flagged for counsel review on anything material

Anti-Patterns

  • Summarising without ranking — a wall of clauses helps no one; rank by damage.
  • Ignoring who you are — a processor and a controller face opposite risks in the same document.
  • Treating "reasonable security" as fine — undefined standards are the finding.
  • Inventing a clause number or requirement not in the text — quote what's there.

Example Trigger Phrases

  • "Review this DPA before we sign the vendor contract."
  • "Is this data processing agreement safe to sign?"
  • "What am I agreeing to on data in this DPA?"
  • "Check this DPA — we're the controller, it's a GDPR deal."

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 3 个不同仓库或目录里都有叫 dpa-review 的技能。它们内容并不相同,别混用: