Agent skill · Security

dpa-review

Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.

mohitagw15856github.com/mohitagw15856GitHub ↗
claude-codecursorMIT
Install
npx skills add mohitagw15856/pm-claude-skills --skill dpa-review --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 4 KB
Bundled scripts: none
Path: skills/dpa-review/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 1,255
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# DPA Review Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread — which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's *missing* — ranked by how much it can hurt. > Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement. ## What This Skill Produces - **The plain-English summary** — what this DPA actually commits each side to - **Risk-ranked findings** — 🔴 sign-blockers, 🟡 negotiate, 🟢 standard — each with the clause and why it matters - **The missing-clause checklist** — the protections a good DPA has that this one lacks - **The redline questions** — what to send back to the vendor before signing ## Required Inputs Ask for these if not provided: - **The DPA text** — the document, or its key clauses pasted - **Your role** — are you the controller (your data) or the processor (you're the vendor)? The risks flip - **The data** — what personal/sensitive data is involved, and any regime that a

What's inside
Steps it walks through
  1. What This Skill Produces
  2. Required Inputs
  3. Framework: What a DPA Must Get Right
  4. Output Format
  5. DPA Review — [vendor] · you are the [controller/processor]
  6. Risk-ranked findings
  7. Missing protections
  8. Send back before signing
  9. Quality Checks
  10. Anti-Patterns
  11. Example Trigger Phrases
More from pm-claude-skills
All skills →
About this skill
What does the dpa-review skill do?

Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.

How do I install it?

Run `npx skills add mohitagw15856/pm-claude-skills --skill dpa-review --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From mohitagw15856/pm-claude-skills, a repository with 1,255 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going