analyse-dpa-fournisseur-hugo-salard
Analyse systématique d'un Data Processing Agreement (DPA) au regard de l'article 28 RGPD, des lignes directrices EDPB 07/2020 et 02/2024, des CCT 2021 (décision d'exécution 2021/914), des recommandations EDPB 01/2020 (mesures supplémentaires post-Schrems II), et du Règlement (UE) 2024/1689 (Règlement IA). Produit un rapport structuré clause par clause (18 clauses : 13 obligatoires + 5 complémentaires) avec diagnostic 🟢/🟡/🔴, remédiations prêtes à insérer, analyse détaillée des transferts internationaux, vérification Règlement IA, et questions à poser au fournisseur. "data processing agreemen
npx skills add lawve-ai/awesome-legal-skills --skill analyse-rgpd-de-dpa-fournisseur-hugo-salard --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
Analyses systematically a Data Processing Agreement (DPA) for compliance with article 28 RGPD, EDPB guidelines 07/2020 and 02/2024, CCT 2021 (Implementing Decision 2021/914), EDPB 01/2020 recommendations, and Regulation (EU) 2024/1689 (AI Act). Produces a clause-by-clause report (18 clauses: 13 mandatory + 5 supplementary) with a diagnostic using symbols 🟢/🟡/🔴, actionable remediations, detailed analysis of international transfers, IA Regulation verification, and questions to ask the supplier.
How it works
- It refers to: loading reference resources for clause-by-clause comparison, remediation dictionary, and a final report template.
- It profiles the practitioner role as a DPA expert and instructs to assess the 18 clauses against a predefined grid, capturing presence, exact text, conformity, and a status per clause. It requires consistency checks between status and remediations, and between referenced annexes and their presence.
- For transfers, it creates a dedicated three-subsection section (Table, analysis prose, and government-access focus) if transfers are identified; otherwise, it states no transfers.
- If IA is identified or suspected, it adds a dedicated IA regulation section detailing systems identified, applicable obligations, and rights interactions.
- It follows a seven-step workflow: identify practitioner name, receive the DPA, read and map the DPA, clause-by-clause analysis, remediations, transfers section, IA section, then synthesize the final report following the exact model structure.
When to use it
- Triggers include: "analyse de DPA", "audit DPA", "vérifier un DPA", "DPA fournisseur", "data processing agreement", "art. 28 RGPD", "sous-traitant RGPD", "négociation DPA", "review DPA", "conformité contrat sous-traitance".
- Use when the need is a rapid, structured, clause-by-clause review of a supplier DPA, with concrete remediations and questions for the supplier.
What it can touch
- References and loads:
resources/grille-analyse-dpa-art28.md,resources/clauses-remediation-types.md, andtemplates/modele-rapport-sortie.mdfor the required structure. - Outputs: a final report following
templates/modele-rapport-sortie.mdstructure, including a clause-by-clause table and dedicated sections for transfers and IA if applicable.
Caveats
- This is a technical compliance analysis, not legal advice.
- The practitioner validates all statuses and remediations before use; the final decision rests with the practitioner and client.
- The tool cites and uses external reference materials but does not replace them; ensure you supply all referenced annexes and attachables when evaluating the DPA.
# Analyse DPA fournisseur Skill d'analyse systématique d'un Data Processing Agreement (DPA) pour un praticien RGPD/DPO. Produit un rapport structuré clause par clause, avec remédiations actionnables et questions à poser au fournisseur. ## Disclaimer (à afficher en début de session) > **Important** : ce skill produit une analyse technique de conformité, pas un conseil juridique. L'auteur n'est pas avocat. Le praticien valide tous les statuts attribués (🟢/🟡/🔴) et les remédiations proposées avant toute utilisation. La décision finale (acceptable / à modifier / à rejeter) appartient toujours au praticien et à son client responsable du traitement. ## Routing Avant la première utilisation, ouvre les fichiers de référence selon le besoin : | Phase | Charger | Action | |-------|---------|--------| | Analyse clause par clause | `resources/grille-analyse-dpa-art28.md` | Comparer chaque clause du DPA aux 18 critères de la grille | | Rédaction des remédiations | `resources/clauses-remediation-types.md` | Puiser dans le dictionnaire de 13 clauses correctives prêtes à insérer | | Production du rapport final | `templates/modele-rapport-sortie.md` | Respecter exactement la structure du modèle |
- Disclaimer (à afficher en début de session)
- Routing
- Rôle
- Contexte d'usage
- Workflow — séquence d'analyse en 7 étapes
- Étape 0 — Identification du praticien
- Étape 1 — Réception et identification du DPA
- Étape 2 — Lecture intégrale et cartographie
- Étape 3 — Analyse clause par clause
- Étape 4 — Remédiations
- Étape 5 — Transferts internationaux (section dédiée)
- Étape 6 — Vérification Règlement IA (section dédiée si applicable)
- Étape 7 — Synthèse et rapport
- Decision trees — cas limites
What does the analyse-dpa-fournisseur-hugo-salard skill do?
Analyse systématique d'un Data Processing Agreement (DPA) au regard de l'article 28 RGPD, des lignes directrices EDPB 07/2020 et 02/2024, des CCT 2021 (décision d'exécution 2021/914), des recommandations EDPB 01/2020 (mesures supplémentaires post-Schrems II), et du Règlement (UE) 2024/1689 (Règlement IA). Produit un rapport structuré clause par clause (18 clauses : 13 obligatoires + 5 complémentaires) avec diagnostic 🟢/🟡/🔴, remédiations prêtes à insérer, analyse détaillée des transferts internationaux, vérification Règlement IA, et questions à poser au fournisseur. "data processing agreemen
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill analyse-rgpd-de-dpa-fournisseur-hugo-salard --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
