playbook-dpa

Reviews GDPR data processing agreements against firm-approved clause positions and fallback text.

72|19|Updated Jun 6, 2026
One-click install
npx skills add https://github.com/sure-scale/doc-haus --skill playbook-dpa-sure-scale
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: playbook-dpa
Source: https://github.com/sure-scale/doc-haus/tree/main/dochaus/playbooks/playbook-dpa
Command: npx skills add https://github.com/sure-scale/doc-haus --skill playbook-dpa-sure-scale

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Negotiating data processing agreements clause by clause is slow and inconsistent without a documented firm position. This playbook gives reviewers approved replacement language, fallback positions, and unacceptable-clause criteria for every standard DPA section under the GDPR and UK GDPR. ## Core Features & Use Cases - Clause-by-clause positions: Covers documented instructions, confidentiality, security measures, subprocessors, data subject requests, breach notification, deletion/return, audit rights, international transfers, and liability allocation. - Approved and fallback text: Provides byte-exact firm-approved replacement clauses plus conditional fallback language for common vendor pushback scenarios. - Jurisdiction guard: Restricts application to processing subject to the GDPR or UK GDPR and flags DPAs whose governing law or scope falls outside the EU/EEA and UK. - Use Case: A vendor returns a DPA with a five-day breach notice window and unrestricted subprocessor rights. The reviewer applies the playbook to redline both clauses with the approved 72-hour backstop and notice-and-objection subprocessor language. ## Quick Start Review this vendor DPA against the playbook and redline any clauses that fall below the firm's approved positions.

Frequently Asked Questions about playbook-dpa

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I redline a data processing agreement under GDPR?▼

Compare each DPA clause against the playbook's preferred position for that clause type. Where the vendor text is unacceptable, replace it with the approved clause text copied byte-exact into the redline tool's replacement argument.

What clauses should a GDPR Article 28 DPA contain?▼

Article 28 requires documented-instructions processing, confidentiality commitments, security measures, subprocessor authorization and flow-down, data subject request assistance, breach notification, deletion or return of data, and audit rights. The playbook provides approved text for each.

When should I use the fallback clause text instead of the approved text?▼

Use fallback text only when its stated condition is met, such as a subscription-based subprocessor notice mechanism or a multi-tenant environment restricting on-site audits. Each fallback fence specifies its triggering circumstance.

Does this playbook apply to DPAs governed by non-EU law?▼

No. The playbook applies only to processing subject to the GDPR or UK GDPR. DPAs whose governing law or processing scope falls outside the EU/EEA and UK should be flagged to the user rather than redlined with these positions.

Is a 72-hour breach notification window a legal requirement for processors?▼

No. The statutory processor duty under Article 33(2) GDPR is notification without undue delay; the 72-hour backstop is contractual market practice. The playbook distinguishes statutory requirements from market positions in each Rationale section.