Claude, Dpa Review. — The DPA-Review Skill

A skill called dpa-review has Claude check a vendor's Data Processing Agreement against a fixed list of required clauses, including sub-processor naming and end-of-contract data handling, without judging whether the terms are actually adequate.

1:23 video3 min readWatch on YouTube

When Claude reviews a vendor's Data Processing Agreement, it is not approving the agreement. It is reading a Skill, a folder with one instruction file, and executing a fixed checklist against the document. Understanding that distinction changes what you should and should not expect from the output.

What a Skill is, mechanically

A Skill is a folder Claude reads before it acts. The dpa-review skill is a single file, SKILL.md, written in plain language with no hidden logic and no freeform judgment built in. Claude reads the file, then executes each step in order. The instructions live in a step section, and the process is linear: read the file, execute each step, return the result. There is no branching unless a specific step calls for it. The file is the program; Claude is running it, not improvising around it.

The two clauses that go missing most often

One rule inside this particular skill is specific and worth naming directly. Claude checks whether the agreement names every sub-processor involved in handling the data, and whether it states what happens to the data when the contract ends, whether it gets deleted or returned. According to the skill, these two clauses are the ones vendors leave out most often. Flagging their absence is a mechanical check: is the clause present in the text or not.

What the checklist cannot do

The skill cannot judge whether the security measures described in the agreement are actually strong enough for the data involved. That is a substantive judgment call that requires someone who understands the systems, the data sensitivity, and the vendor's actual practices, not just the words on the page. Claude is not evaluating whether the agreement is good enough. It is checking the SKILL.md's list of required clauses, one step at a time, and only doing what that file instructs.

Running it on your own agreement

The practical exercise is straightforward: before signing a vendor's data processing agreement, ask Claude to read the dpa-review skill and, before checking anything, explain exactly what it will do. Which clauses will it check for, what counts as missing, and what will it not be able to tell you. Running that walkthrough first makes the limits of the review visible before you rely on the output, and it should be run on your own actual agreement rather than a hypothetical.

Why the distinction matters

Treating a Skill's output as a mechanical clause check, rather than a legal opinion, keeps expectations calibrated. The skill is useful precisely because it applies the same fixed list every time, catching the two most commonly missing clauses without variation. But nothing about that mechanism substitutes for a privacy lawyer's judgment on whether the substance of an agreement is adequate. The checklist is the limit of what this step does.

Key takeaways

  • Claude's dpa-review skill checks a Data Processing Agreement against a fixed, written list of required clauses; it does not approve or evaluate the agreement.
  • The skill runs as a linear pipeline: read the file, execute each step, return the result.
  • Two clauses are flagged specifically because they go missing most often: naming every sub-processor, and stating what happens to data at contract end.
  • The skill cannot judge whether described security measures are actually adequate for the data involved; that requires a person who knows the systems.
  • Before relying on the review, ask Claude to walk through what it will check, what counts as missing, and what it cannot tell you.

Who this is for

Anyone responsible for reviewing vendor data processing agreements who wants a fast, repeatable first pass on clause completeness, with a clear understanding that it is not a substitute for legal judgment on substance.

Chapters

  1. 0:00The naive framing: "does Claude approve it, or check clauses?"
  2. 0:10A Skill is a folder
  3. 0:24Read, execute, return
  4. 0:35What the checklist covers
  5. 0:55Carry-out
  6. 1:05Your turn
  7. 1:19Outro
Full transcript(auto-generated, with timestamps)

The naive framing: "does Claude approve it, or check clauses?"

[0:00]Someone asked whether Claude approves of vendor's DPA when it reviews one. It doesn't approve, it checks clauses against a fixed list. So, when Claude reviews a DPA, is it checking a list? A

A Skill is a folder

[0:10]Skill is a folder Claude reads before it acts. This one is called DPA review. It's one file skill. MD holds the whole instruction set written in plain language, no hidden logic. Claude reads it, then acts. The file is the program.

Read, execute, return

[0:24]The instructions live in a step section. Claude reads each step in order and executes it. Read the file, execute each step, return the result. Linear, no branching unless a step says otherwise.

What the checklist covers

[0:35]One instruction inside it is specific. Check whether the agreement names every sub-processor and states what happens to the data when the contract ends, deleted or returned. Those two clauses go missing most often. What the skill doesn't do is judge whether the described security measures are actually strong enough for the data involved. That call needs a person who knows the systems. Claude isn't judging whether

Carry-out

[0:56]The agreement is good enough, it's checking the skill. MD's list of required clauses, one step at a time, and only doing what that file says. Your turn. Paste this into Claude. I'm

Your turn

[1:06]About to sign a vendor's data processing agreement. Read the DPA review skill, and before you check anything, walk me through exactly what you'll do, which clauses you'll check for, what counts as missing, and what you won't be able to tell me. Claude DPA review, Liam in for Bear.

More from Claude for Education

Humanitarians AI Lyrical Literacy Project