Official agent skill

Dpa Review

by anthropics in anthropics/claude-for-legal

Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook.

OfficialApache-2.0Auto-check passedLegal & Compliance

Install Dpa Review

skills CLI
$ npx skills add anthropics/claude-for-legal --skill dpa-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal dpa-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/privacy-legal/skills/dpa-review .claude/skills/dpa-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dpa-review
GitHub stars
9.6k
Used in
2 other repos
Token cost
~5.2k tokens
SKILL.md length
2,658 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook.

  • Works in 5 steps: Load… → Get the DPA. Determine direction: are we… → Run the workflow below — term-by-term… → …
  • The user says review this DPA
  • SKILL.md covers Matter context, Purpose, First: which direction? and Jurisdiction assumption, plus 11 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dpa Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says "review this DPA", "check this data processing addendum", "customer sent their DPA", "is this DPA okay", or attaches a DPA.

Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • The user says review this DPA
  • Check this data processing addendum
  • Customer sent their DPA
  • Is this DPA okay

Example prompts

  • “review this DPA”
  • “check this data processing addendum”
  • “customer sent their DPA”
  • “/dpa-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DPA playbook. If placeholders, stop and prompt setup.
  2. Get the DPA. Determine direction: are we processor (customer's DPA) or controller (vendor's)? Ask if ambiguous.
  3. Run the workflow below — term-by-term against the appropriate playbook row.
  4. Run privacy policy consistency check.
  5. Output: review memo with redlines. Save per house style.

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dpa Review loads about 5.2k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 2,658 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,658 words, ~5,244 tokens.

Download SKILL.mdSave it as .claude/skills/dpa-review/SKILL.md (or your agent's skills folder).
name
dpa-review
description
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says "review this DPA", "check this data processing addendum", "customer sent their DPA", "is this DPA okay", or attaches a DPA.
argument-hint
[file | Drive link | paste text]

/dpa-review

  1. Load ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DPA playbook. If placeholders, stop and prompt setup.
  2. Get the DPA. Determine direction: are we processor (customer's DPA) or controller (vendor's)? Ask if ambiguous.
  3. Run the workflow below — term-by-term against the appropriate playbook row.
  4. Run privacy policy consistency check.
  5. Output: review memo with redlines. Save per house style.
/privacy-legal:dpa-review customer-dpa.pdf

DPA Review

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /privacy-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Purpose

DPAs come in two flavors and the review is nearly opposite for each. When a customer sends their DPA, we're defending our operational flexibility. When we send one to a vendor, we're protecting our (and our customers') data. Both reviews read from the same ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md playbook but from opposite rows.

First: which direction?

Before anything else, establish:

  • We are the processor → customer is sending us their DPA → read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → "When we are the processor" table
  • We are the controller → we're sending a DPA to a vendor (or reviewing theirs) → read "When we are the controller" table

If unclear, ask. Getting this wrong inverts every recommendation.

Jurisdiction assumption

This review assumes the jurisdictional scope specified in your configuration. Privacy rules, response deadlines, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the controller, processor, or data subjects are in a different jurisdiction than configured, this review may not apply as written.

Load prior context on this counterparty / activity

Before reviewing, check the outputs folder for prior work on this counterparty or processing activity. Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## Outputs for the outputs folder path. Scan for:

  • Prior use-case-triage results for the same counterparty / processing activity — the triage produces a risk rating and conditions that this DPA review should honor or explicitly depart from.
  • Prior pia-generation outputs covering this counterparty / processing activity — the PIA may have flagged risk mitigations the DPA needs to implement.
  • Prior dpa-review outputs for the same counterparty — earlier DPA reviews set expectations about what was acceptable, what was flagged, and what was settled. A fresh review that silently contradicts the earlier one erodes trust in the work product.

If a prior output is found, cite it in the review:

"Prior triage ([date]) rated this [risk level] and conditioned approval on [X]. This DPA review is consistent with that finding." — or — "Prior triage ([date]) rated this [risk level]. This DPA review departs from that finding because [reason — new facts, different scope, contract term that changed the picture]."

Carry severity from the upstream output as a floor per the cross-skill severity floor rule in ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## Shared guardrails. A processing activity the triage rated 🔴 cannot be quietly downgraded to 🟢 in the DPA review; any demotion is stated and explained.

If no prior output is found (new counterparty / new activity), say so explicitly in the review — "No prior triage or PIA on this counterparty in outputs folder" — so the reviewing attorney knows the check ran.

Load the playbook

Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## DPA playbook. Also read ## Privacy policy commitments — the DPA can't contradict what the privacy policy promises.

Federal sectoral overlay (ask first, before the term-by-term walk)

Before walking the term-by-term review, answer: does the data flowing through this DPA include any federally-regulated category? GDPR and state consumer-privacy law supply one floor; federal sectoral law often supplies another that does not appear in the generic DPA playbook. A DPA that is GDPR-complete can still be GLBA-blind, HIPAA-blind, or COPPA-blind, and a fintech / healthtech / edtech / kidtech counterparty will notice.

Activity-based federal overlays — ask first:

Does this processing touch:

  • Financial account data or "nonpublic personal information" about consumers (GLBA / Reg P)? If yes, the DPA needs: (a) an NPI-sharing restriction consistent with 15 U.S.C. § 6802(a)-(c) and Reg P (no sharing for marketing to non-affiliated third parties without opt-out / opt-in), (b) safeguards language aligned with the Safeguards Rule (16 C.F.R. Part 314), (c) incident notification that reaches FTC/OCC timing where applicable, (d) a clean carve-out so a CCPA § 1798.145(e) exemption doesn't accidentally waive GLBA-level obligations.
  • Protected health information held by a covered entity or business associate (HIPAA Privacy / Security Rules)? If yes, the DPA needs: a Business Associate Agreement (BAA) layered with or integrated into the DPA per 45 C.F.R. § 164.504(e), breach notification timing aligned with HITECH (60 days to CE; CE 60 days to HHS; 500+ threshold for media), permitted-uses clause, subcontractor BAA flow-down. A commercial DPA without BAA flow-down for PHI is a defect.
  • Education records held by a school or a service provider acting for a school (FERPA)? If yes, the DPA needs: a "school official" / directory-information framing consistent with 34 C.F.R. § 99.31, parental-consent flow-through, state student-privacy analog handling (NY Ed Law 2-d, CA SOPIPA, IL SOPPA).
  • Data from children under 13 collected by an operator of an online service directed to children or with actual knowledge (COPPA)? If yes, the DPA needs: verifiable-parental-consent flow-through, retention limits, deletion-on-request machinery, prohibition on behavioral advertising absent VPC.
  • Another sectoral federal regime (VPPA for video-viewing records, CPNI for carrier data, DPPA for DMV records, TCPA / Shaken-Stir for call/SMS, GLBA Reg S-P for broker-dealers, §5 FTC Act for unfair/deceptive practices around sensitive data)?

If yes to any: the federal overlay usually supplies the controlling substantive restriction, not just an exemption from a state consumer privacy law. Research the currently-operative provision and cite it. A DPA that is "exempt" from CCPA under § 1798.145(e) because it is GLBA-covered is still subject to the GLBA restrictions — the CCPA exemption moves the governing framework, it doesn't eliminate it. Flag sectoral gaps in the deal-breakers list alongside GDPR / state-privacy gaps.

If no sectoral overlay applies, note that explicitly — "no federally-regulated data categories identified; sectoral overlay n/a" — so the reviewing attorney sees that the check happened, rather than wondering whether it was skipped.

The term-by-term review

Core terms (check every DPA)

Walk every DPA through these terms, clause by clause. The specific numeric and substantive positions (notice periods, breach timelines, acceptable/unacceptable floors) come from ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## DPA playbook. The regulatory floors that any DPA has to clear come from primary law — research the currently operative rule for each applicable regime and cite primary sources before stating a floor.

No silent supplement. If a research query to the configured legal research tool returns few or no results for a regime's breach window, transfer-mechanism requirement, subprocessor-change rule, or any other floor, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [regime / topic]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged [web search — verify] and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.

Source attribution tiering. Tag every citation in the review — regulatory floors, SCC versions, adequacy decisions, regulator guidance, case law — with its source. For model-knowledge citations, use one of three tiers rather than a single blanket "verify" tag:

  • [settled] — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 28, Art. 33 72-hour breach notice, SCC Decision 2021/914 by number). Still verify before filing, but lower priority.
  • [verify] — model-knowledge citations that are real but should be verified: specific implementing regulations, regulator guidance, case holdings, adequacy decisions, SCC modules and versions, UK Addendum / IDTA status, thresholds, effective dates.
  • [verify-pinpoint] — pinpoint citations (specific subsection letters, clause numbers within SCCs, paragraph numbers, volume/page references) carry the highest fabrication risk and should ALWAYS be verified against a primary source.

Tool-retrieved citations keep their source tag ([Westlaw], [Commission / regulator site], or the MCP tool name); web-search citations remain [web search — verify]; user-supplied citations remain [user provided]. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.

TermLooking forPlaybook fieldCommon fights
RolesClear controller/processor designation; matches reality—Counterparty labels the relationship (e.g., "joint controller") in a way that doesn't match reality
Processing scopeLimited to documented instructions; defined purposes—Open-ended scope expanders ("and related purposes")
SubprocessorsCurrent list disclosed, change mechanism definedSubprocessor changesBlanket approval vs. veto vs. notice-only
Security measuresAnnex references specific controls or standardsSecurity standards"appropriate technical and organizational measures" with no annex = empty promise
Breach notificationDefined trigger ("discovery" vs "confirmation"), defined timelineBreach notificationTimeline tightness; clock trigger; "without undue delay" is vague
Audit rightsMethod (report vs. on-site), frequency, notice, cost allocationAudit rightsOn-site audits on tight notice
International transfersTransfer mechanism identified, supplementary measures, transfer impact assessment referenceTransfersOutdated or missing transfer mechanisms
Deletion/returnTimeline post-termination, certification, backup carveoutDeletion on termination"Commercially reasonable" deletion = ???
LiabilityWithin MSA cap or separate; carveoutsLiability for dataUncapped data breach liability = existential
Show full SKILL.md (1,132 more words)Show less
When we're the processor: defensive review

Customer DPAs try to push operational burden onto us. For each clause below, compare the customer's ask to the playbook. Where the customer's ask is outside the playbook, push back to the team's standard position (from the config CLAUDE.md) and be ready to fall back to the acceptable position.

ClauseRiskResearch / playbook lookup
Subprocessor approval right (veto)Can't add infrastructure without customer-by-customer approvalApply playbook position on subprocessor changes
On-site audit on short noticeUnworkable at scaleApply playbook position on audit rights
Aggressive breach notification windowOften demands notice before we know what happenedResearch the regulatory floor for each applicable regime (cite primary sources); compare to playbook position
Hard data residency (single country/DC)May not match architectureApply playbook position on data location; confirm what we can actually commit to
Processor liability uncappedBet-the-companyApply playbook position on liability for data
Customer may issue binding "instructions"Open-ended operational controlDefine instructions as "documented in the Agreement or agreed in writing"
Deletion on very short timelineBackup and log retention makes this impossibleApply playbook position on deletion on termination; document backup rotation carveout
When we're the controller: protective review

Vendor DPAs try to give us nothing. For each clause below, compare to the controller-side playbook.

ClauseGapResearch / playbook lookup
No subprocessor listDon't know who touches our dataRequire published current list + advance notice per playbook
"Industry standard security"Means nothingRequire annex with specific controls, or reference to a named standard (e.g., SOC 2, ISO 27001)
No breach notification timelineThey tell us wheneverResearch applicable regulatory floor; require playbook position
No audit rights at allCan't verify anythingRequire at minimum an independent audit report per playbook
Vendor can use data for "service improvement"Potential training on our dataStrike; processing limited to providing the service to us
No international transfer mechanismNo lawful transfer mechanismResearch the currently operative transfer mechanism for the corridor in question (origin/destination jurisdictions, applicable regime, any adequacy decision, any supplementary measures). Cite primary sources and verify currency.
No deletion commitmentData lives foreverRequire playbook position on deletion + certification on request

Consistency check: privacy policy

The DPA you sign can't promise something the privacy policy doesn't cover, and vice versa.

  • If the DPA commits to processing only for purposes X, Y, Z — does the privacy policy list those purposes?
  • If the privacy policy says "we never sell data" — does any DPA clause look like a sale under CCPA?
  • If the privacy policy names specific subprocessor categories — does the DPA subprocessor list match?

Flag mismatches. They're usually the privacy policy being stale, not the DPA being wrong, but someone needs to fix one of them.

Redline granularity

Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.

Default to the smallest edit that achieves the playbook position:

  • Replace a word before a phrase. ("twelve (12)" → "twenty-four (24)")
  • Replace a phrase before a sentence. ("paid by the Buyer" → "paid and payable by the Buyer")
  • Restructure a subclause before replacing the sentence. (Add "(a)" and "(b)" to split a compound condition.)
  • Replace a sentence before replacing the clause.
  • Only replace a whole clause when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: "We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta."

When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.

Output

Prepend the work-product header from ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md ## Outputs (it differs by user role — see ## Who's using this).

markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs]

# DPA Review: [Counterparty]

**Direction:** [We are processor / We are controller]
**Reviewed:** [date]
**Attached to:** [MSA / standalone]

---

## Bottom line

[Two sentences. Can we sign? What has to change?]

**Issues:** [N]🟢 [N]🟡 [N]🟠 [N]🔴

---

## Term-by-term

[For each core term, use a standard deviation-memo format: what the
counterparty's DPA says, what our playbook says, the gap, the risk, and the
proposed redline language. Keep each term to a short self-contained block so a
reviewer can skim.]

---

## Privacy policy consistency

[🟢 Consistent | 🟡 Flags: list]

---

## Recommended redlines

[Consolidated — ready to send back]

---

## If they won't move

[For each issue: the fallback from the config CLAUDE.md, or escalation routing if no
fallback exists]

International transfers note

If the DPA contemplates cross-border data transfers, research the currently operative transfer mechanism requirements for the applicable corridor(s). For each origin/destination pair, identify: the applicable regime, whether any adequacy decision is in force, which transfer mechanism is required or available (e.g., Standard Contractual Clauses and their applicable version/module, UK Addendum or IDTA, BCRs, derogations), whether a transfer impact assessment or equivalent is required, and what supplementary measures may be needed. Cite primary sources (regulation, Commission decision, regulator guidance, controlling case law) with pinpoint cites and verify currency — adequacy decisions, SCC versions, and required supplementary measures change through new Commission decisions, court rulings, and regulator guidance. Flag uncertainty for attorney verification.

If a transfer mechanism is missing and there is an international transfer, that is a 🔴 — there is no lawful transfer mechanism.

Gate: signing a DPA

Reviewing a DPA is research. Signing it — or instructing someone to countersign on our behalf — is the consequential act.

Before proceeding to sign or countersign a DPA (including returning an executed version, consenting to automatic execution on a counterparty platform, or instructing a signatory to execute): Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md. If the Role is Non-lawyer:

Signing a DPA is a legal act — it binds the company to specific data-protection obligations that flow to regulators and data subjects. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:

[Generate a 1-page summary: counterparty, direction (we are processor / controller), the terms that deviate from the playbook and how they were resolved, any open fallback decisions, and the three things to ask the attorney before executing.]

If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).

Do not proceed past this gate without an explicit yes.

Close with the next-steps decision tree

End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.

What this skill does not do

  • It doesn't draft a DPA from scratch. If the answer is "use our template," pull the template from the seed docs path in the config CLAUDE.md.
  • It doesn't do the Transfer Impact Assessment itself — it flags when one is needed.
  • It doesn't decide whether to accept terms outside the fallbacks. It routes those per the escalation table.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in privacy-legal/skills/dpa-review of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dpa Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dpa Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dpa Review this skillanthropics/claude-for-legal9.6k2 repos~5.2kAutomated safety check: PassApache-2.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone
Employment Contract Templatesynulihao/AgentSkillOS61812 repos~4.1kAutomated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed
  • Commercial Legal Pl

    apiotrowski-afk/commercial-legal-pl

    Skill do analizy i tworzenia umów według polskiego prawa, ze szczególnym uwzględnieniem umów B2B, IP i IT (body leasing, NDA, wdrożenia, SaaS, przeniesienie praw autorskich, ugody).

    176 GitHub starsUsed in 1 repo~4.1k tokens
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about Dpa Review

What does Dpa Review do?

Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Dpa Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook.

When should I use Dpa Review?

Dpa Review fits situations like: the user says review this DPA; check this data processing addendum; customer sent their DPA; is this DPA okay.

How do I install Dpa Review in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill dpa-review -a claude-code`. Or copy the skill folder (privacy-legal/skills/dpa-review in anthropics/claude-for-legal) into .claude/skills/dpa-review in your project. Claude Code loads it when a task matches its description.

How do I install Dpa Review in Codex?

Run `npx skills add anthropics/claude-for-legal --skill dpa-review -a codex`. Or copy the skill folder (privacy-legal/skills/dpa-review in anthropics/claude-for-legal) into .agents/skills/dpa-review in your project. Codex loads it when a task matches its description.

Can I use Dpa Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill dpa-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpa-review, .gemini/skills/dpa-review, .github/skills/dpa-review and .opencode/skills/dpa-review in your project.

What does Dpa Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Dpa Review is instructions for the agent only.

Does Dpa Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dpa Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dpa Review use?

Dpa Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dpa Review use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dpa Review?

Skills that share tags, products or a category with Dpa Review: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Paper To Cn Patent (snipp-zha/Paper-to-patent-Skill, 107 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dpa Review?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.