Agent skill

Dpa Checklist Review

by LegalQuants in LegalQuants/lq-ai

A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

Apache-2.0Auto-check passedLegal & Compliance

Install Dpa Checklist Review

skills CLI
$ npx skills add LegalQuants/lq-ai --skill dpa-checklist-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LegalQuants/lq-ai dpa-checklist-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dpa-checklist-review .claude/skills/dpa-checklist-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dpa-checklist-review
GitHub stars
150
Token cost
~3.7k tokens
SKILL.md length
1,277 words
Files
8
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

  • The user provides a Data Processing Agreement
  • SKILL.md covers When this skill applies, Inputs, Workflow and Output, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Data Processing Addendum

What it does

Dpa Checklist Review is an agent skill from LegalQuants/lq-ai. Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the applicable data-protection regime. Produces a structured checklist scoring each required term as present, partial, missing, or unclear, with clause references and recommended language for any gaps. Supports GDPR Article 28, US state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, and similar), HIPAA BAAs, and general commercial DPAs without a…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `examples/example_gdpr.md`, `examples/example_us_state.md` and `reference/gdpr_requirements.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: Open-source AI for legal teams. Bring your own keys, run it where you want, own your data. The licence is Apache-2.0.

When your agent uses it

  • The user provides a Data Processing Agreement
  • Data Processing Addendum
  • HIPAA Business Associate Agreement and asks whether it contains the terms required under the applicable data-protection regime

Example prompts

  • “/dpa-checklist-review”

What it can do on your machine

Read from SKILL.md and the folder at commit d185a62. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dpa Checklist Review loads about 3.7k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 1,277 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LegalQuants/lq-ai at commit d185a62, republished under its Apache-2.0 licence (© LegalQuants). 1,277 words, ~3,712 tokens.

Download SKILL.mdSave it as .claude/skills/dpa-checklist-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
dpa-checklist-review
description
Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the applicable data-protection regime. Produces a structured checklist scoring each required term as present, partial, missing, or unclear, with clause references and recommended language for any gaps. Supports GDPR Article 28, US state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, and similar), HIPAA BAAs, and general commercial DPAs without a specified regime.
lq_ai.title
DPA Checklist Review
lq_ai.version
1.0.0
lq_ai.author
LegalQuants
lq_ai.tags
contracts, dpa, privacy, gdpr, ccpa, hipaa, compliance, review
lq_ai.jurisdiction
regime-dependent
lq_ai.trigger_examples
review this DPA, is this DPA GDPR compliant, check this BAA, what's missing from this data processing agreement, compare this DPA against Article 28
lq_ai.output_format
structured_checklist
lq_ai.self_improvement
false

DPA Checklist Review

Conduct a structured compliance review of a Data Processing Agreement, DPA-equivalent addendum, or Business Associate Agreement against the requirements of the applicable regulatory regime. The output is a checklist suitable for a compliance tracker — each required term has a row, an assessment, and a clause reference.

When this skill applies

Apply when the user provides a DPA, DPA addendum, or BAA and asks for compliance review against a specific regulatory regime. The skill works against four distinct regimes (see regulatory_regime input) and applies different requirements for each.

Do not apply this skill to:

  • Privacy policies. Those are public-facing notices, not contracts; different review skill needed.
  • Standalone privacy schedules or security exhibits inside larger agreements where the privacy/security terms have not been collected into a DPA structure. Tell the user the substantive privacy and security terms need to be pulled into a DPA-shaped structure before this skill is useful.
  • Contractual privacy clauses inside MSAs that have not been broken out as a DPA addendum. Recommend the user request a separate DPA addendum from the counterparty, which is now industry standard.
  • Cross-regime analysis (e.g., "is this GDPR-compliant and HIPAA-compliant?"). Run the skill twice with different regulatory_regime values and compare outputs.

Inputs

The skill requires the document and the regulatory regime. If regime is not provided:

"Before I review, which regulatory regime should I check this DPA against?

  • GDPR (EU/UK GDPR Article 28; covers any DPA processing EU/UK personal data)
  • US state privacy (CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Oregon OCPA, and similar)
  • HIPAA BAA (Business Associate Agreement under US healthcare law)
  • General commercial (DPA without a specific regime; checks commercially-standard DPA terms)

If multiple regimes apply, pick the most prescriptive (typically GDPR) for the primary review; we can run additional reviews for other regimes after."

Do not guess the regime from document title or governing law. A document titled "Data Processing Addendum" with Delaware governing law could be GDPR-driven (because it processes EU resident data), CCPA-driven (because it processes California resident data), or both. Only the user knows what data is in scope.

Optional inputs (party_role, data_categories, international_transfer_context, standard_positions) refine the analysis. The party_role input materially changes severity calibration:

  • Controllers / data exporters / businesses / covered entities want strong, specific processor obligations — they bear regulatory liability for processor failures.
  • Processors / data importers / service providers / business associates want clear, operationally feasible scope — vague obligations create open-ended liability.

When party_role is not provided, default to controller perspective (regulators almost always investigate the controller, so controller-favorable analysis is the safer default for reviews) and note the assumption in the report. Ask the user to re-run if they are on the processor side.

Workflow

Produce the review in three passes.

Pass 1: Document orientation

Before substantive review:

  • Confirm the document is actually a DPA / DPA addendum / BAA. If it is a privacy policy, an MSA with privacy clauses not broken out, or a different instrument, stop and tell the user.
  • Note the parties and which is controller / processor (or equivalent under the relevant regime).
  • Note the governing law and any specified data-protection authority.
  • Note the structure: does the document have the required terms organized into sections, or are they scattered? A DPA without clear structural sections is harder to assess.
  • Identify any annexes, schedules, exhibits, or appendices and note what they cover (typically: data categories, processing purposes, security measures, sub-processors, SCCs).
Pass 2: Regime-specific term checking

Walk through the requirements for the specified regime using the corresponding reference file:

  • For gdpr: use reference/gdpr_requirements.md. The required terms are the nine items in GDPR Article 28(3) plus security obligations under Article 32 plus (when applicable) international-transfer mechanisms.
  • For us_state_privacy: use reference/us_state_privacy_requirements.md. The required terms are the convergent set across CCPA/CPRA, VCDPA, CPA, CTDPA, and similar laws; differences between laws are noted where material.
  • For hipaa_baa: use reference/hipaa_baa_requirements.md. The required terms are those listed in 45 CFR §164.504(e)(2) plus the additional requirements under HITECH and the HIPAA Omnibus Rule.
  • For general_commercial: use reference/general_commercial_requirements.md. The expected terms are commercially-standard DPA terms in the absence of a specific regime — broadly compatible with any of GDPR, US state privacy, or HIPAA but not optimized for any.

For each required term, classify:

  • Present — the document addresses this term and the addressing is compliant with the regime's requirements.
  • Partial — the document addresses this term but the addressing is non-compliant, narrower than required, or has problematic carve-outs.
  • Missing — the document does not address this term.
  • Unclear — the document arguably addresses this term but the language is ambiguous enough that compliance cannot be confirmed without negotiation.
  • N/A — this term does not apply given the document type, regime variant, or specific facts.
Show full SKILL.md (508 more words)Show less
Pass 3: Compile the checklist and posture

Compile the findings into the structured checklist (see Output section). Add an overall posture paragraph stating whether the document is:

  • Compliant — all required terms present and adequate; no negotiation needed for compliance purposes (business preferences may still warrant changes).
  • Compliant with minor gaps — most terms present; minor partial/missing items can be addressed via short negotiation or in supporting agreements.
  • Non-compliant — material gaps requiring negotiation before signing; the document does not currently meet the regime's requirements.
  • Materially non-compliant — multiple critical terms missing or partial; the document needs substantial reworking, or the user should propose replacing it with the user's own template.

Output

Produce the review as a structured checklist in markdown:

markdown
# DPA Checklist Review: [Document name or counterparty]

**Regulatory regime:** [gdpr | us_state_privacy | hipaa_baa | general_commercial]
**Party role:** [controller | processor | etc.]
**Data categories:** [user-provided context, or "not specified"]
**International transfer context:** [for GDPR; user-provided context, or "not specified"]

## Overall posture

[One paragraph: compliant / compliant with minor gaps / non-compliant / materially non-compliant. State the headline gap or strength. State the recommended next step at a high level.]

## Compliance checklist

| # | Required term | Source | Status | Clause | Assessment |
|---|---|---|---|---|---|
| 1 | [Term name] | [Statute reference, e.g., "GDPR Art. 28(3)(a)"] | Present / Partial / Missing / Unclear / N/A | [§ ref or "—"] | [One-line assessment] |
| 2 | [...] | [...] | [...] | [...] | [...] |
| ... | | | | | |

## Detailed findings

[For each Partial, Missing, or Unclear item, a subsection with:]

### [#] [Term name] — [Status]

**Required by:** [Statute reference]

**What's required:** [Brief plain-language statement of what the regime requires.]

**What the document says:** [Quoted or paraphrased clause language, with citation. If the term is missing, "Not addressed."]

**Why this is a gap:** [Specific deficiency from the regime's perspective.]

**Recommended language:** [Specific suggested clause language to add or modify. Reference any applicable model clauses (e.g., EU SCCs) where appropriate.]

## Items requiring human judgment

[Items the skill cannot resolve and that need the user's regulatory-counsel expertise or business judgment. Examples: jurisdictional applicability questions, novel data flows the skill is unfamiliar with, regulator-specific guidance the skill cannot verify is current.]

## Recommended next steps

[Short bulleted list. Common options: sign as-is (if compliant), negotiate the redlines proposed above, propose user's own DPA template, escalate specific issues to outside privacy counsel, run an additional review under another regime.]

The checklist table is the centerpiece. Detailed findings only cover non-Present items — do not pad with "Present and standard, no further notes" rows; the table already shows that.

Edge cases and refusals

  • Document is not a DPA/BAA. Stop and tell the user. Common adjacent documents that get confused for DPAs: privacy policies, security questionnaires, data sharing agreements (different instrument under GDPR), data licensing agreements, MSAs with privacy clauses but no DPA addendum.
  • Regime is gdpr but the document does not contain SCCs or another transfer mechanism, and international_transfer_context indicates transfers occur. Critical gap; flag in posture and detailed findings even if the controller-processor terms are otherwise compliant.
  • Regime is hipaa_baa but the document does not invoke HIPAA at all (no reference to PHI, BAA, 164.504, etc.). The document may not actually be a BAA. Flag and ask the user to confirm.
  • Document is a DPA from before significant regime changes (e.g., a GDPR DPA dated 2018 without Schrems II / 2021 SCC updates; a CCPA DPA dated 2020 without CPRA amendments). Flag in posture and note the regulatory drift.
  • Document includes terms for multiple regimes. Some DPAs are written to satisfy GDPR + CCPA + others simultaneously. Review against the requested regime and note where multi-regime drafting creates ambiguity (e.g., conflicting deletion timelines).
  • Document references model clauses or templates that are not attached. If the document says "the parties have entered into the EU SCCs" but no SCCs are attached or referenced specifically, flag — the SCCs are a required artifact, not a reference.

What this skill does not do

  • Give a definitive compliance opinion. Outputs are drafts for human review; ultimate compliance determinations belong to qualified privacy counsel.
  • Predict regulator behavior. Flags gaps; does not opine on enforcement risk.
  • Negotiate. Suggests language; does not draft side letters.
  • Replace a privacy impact assessment, transfer impact assessment, or other formal compliance artifact. Those are separate processes.
  • Cover non-US/non-EU regimes (Canada PIPEDA, Brazil LGPD, China PIPL, etc.) in v1.0.0. The structure supports adding regime-specific reference files; community contributions welcomed.

Reference materials

  • reference/gdpr_requirements.md — Article 28(3) required terms, Article 32 security, transfer-mechanism requirements.
  • reference/us_state_privacy_requirements.md — Convergent CCPA/CPRA/VCDPA/CPA/CTDPA/UCPA/OCPA processor-contract requirements.
  • reference/hipaa_baa_requirements.md — 45 CFR §164.504(e)(2) BAA requirements plus HITECH/Omnibus updates.
  • reference/general_commercial_requirements.md — Commercially-standard DPA terms when no specific regime is stated.
  • examples/example_gdpr.md — Worked example: GDPR DPA review from a controller perspective.
  • examples/example_us_state.md — Worked example: US state privacy DPA review from a service-provider/processor perspective.

© LegalQuants, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/dpa-checklist-review of LegalQuants/lq-ai.

  • SKILL.md
  • examples/example_gdpr.md
  • examples/example_us_state.md
  • reference/gdpr_requirements.md
  • reference/general_commercial_requirements.md
  • reference/hipaa_baa_requirements.md
  • reference/us_state_privacy_requirements.md
  • test-plan.md

Open the folder on GitHubat commit d185a62

Compare with similar skills

Dpa Checklist Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dpa Checklist Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dpa Checklist Review this skillLegalQuants/lq-ai150—~3.7kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT
Auditing Deidentification Runsmaziyarpanahi/openmed5.5k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Auditing Deidentification Runs

    maziyarpanahi/openmed

    Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).

    5.5k GitHub stars~1.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    277k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed

More from LegalQuants/lq-ai

All 16 skills in this repo
  • A skill your agent uses when the user provides a client alert, regulatory bulletin, law firm memo, or similar legal update and wants the time-sensitive action items, deadlines, and obligations…

    150 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Case Law Research

    LegalQuants/lq-ai

    A skill your agent uses when the user asks to find, read, or cite U.S.

    150 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Comms Improver

    LegalQuants/lq-ai

    A skill your agent uses when the user has a piece of legal-jargon-heavy text and wants it rewritten in plain language for a specified non-legal audience.

    150 GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Contract QA

    LegalQuants/lq-ai

    A skill your agent uses when the user has a contract loaded and asks a specific question about it — what a clause means, where something is addressed, whether a term is unusual, how a provision…

    150 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Contract Snapshot

    LegalQuants/lq-ai

    A skill your agent uses when the user wants to compare the same handful of terms across N contracts side-by-side in a grid — what is the term, survival period, carveouts, and governing law in each…

    150 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Enhance Prompt

    LegalQuants/lq-ai

    A skill your agent uses when the user has typed a short or vague prompt and the system is configured to expand prompts before submission, or when the user explicitly invokes "Enhance Prompt" or asks…

    150 GitHub stars~3.3k tokensUpdated today
    Auto-check passed

Questions about Dpa Checklist Review

What does Dpa Checklist Review do?

A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…. Dpa Checklist Review is an agent skill from LegalQuants/lq-ai. Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the applicable data-protection regime.

When should I use Dpa Checklist Review?

Dpa Checklist Review fits situations like: the user provides a Data Processing Agreement; data Processing Addendum; HIPAA Business Associate Agreement and asks whether it contains the terms required under the applicable data-protection regime.

How do I install Dpa Checklist Review in Claude Code?

Run `npx skills add LegalQuants/lq-ai --skill dpa-checklist-review -a claude-code`. Or copy the skill folder (skills/dpa-checklist-review in LegalQuants/lq-ai) into .claude/skills/dpa-checklist-review in your project. Claude Code loads it when a task matches its description.

How do I install Dpa Checklist Review in Codex?

Run `npx skills add LegalQuants/lq-ai --skill dpa-checklist-review -a codex`. Or copy the skill folder (skills/dpa-checklist-review in LegalQuants/lq-ai) into .agents/skills/dpa-checklist-review in your project. Codex loads it when a task matches its description.

Can I use Dpa Checklist Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LegalQuants/lq-ai --skill dpa-checklist-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpa-checklist-review, .gemini/skills/dpa-checklist-review, .github/skills/dpa-checklist-review and .opencode/skills/dpa-checklist-review in your project.

What does Dpa Checklist Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Dpa Checklist Review is instructions for the agent only.

Does Dpa Checklist Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dpa Checklist Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dpa Checklist Review use?

Dpa Checklist Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dpa Checklist Review use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dpa Checklist Review?

Skills that share tags, products or a category with Dpa Checklist Review: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars) and Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dpa Checklist Review?

LegalQuants (a GitHub organization) maintains it in LegalQuants/lq-ai, which has 150 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 11, 2026.

Source: LegalQuants/lq-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.