Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk.

MITAuto-check passedWriting & Content

Install Dpa Review

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills dpa-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dpa-review .claude/skills/dpa-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dpa-review
GitHub stars
1.4k
Token cost
~989 tokens
SKILL.md length
502 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk.

  • Works in 6 steps: Scope & roles — controller vs processor,… → Sub-processors — who else gets the data,… → International transfers — the mechanism… → …
  • Asked to review a DPA
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: What a DPA Must Get… and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dpa Review is an agent skill from mohitagw15856/pm-claude-skills. Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Writing & Content, covering Plain language and style rules. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to review a DPA
  • Check a data processing agreement
  • Is this DPA safe to sign
  • What am I agreeing to on data

Example prompts

  • “/dpa-review”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Scope & roles — controller vs processor, and the processing purpose; a mismatch here voids the rest.
  2. Sub-processors — who else gets the data, notice of new ones, and a right to object.
  3. International transfers — the mechanism (SCCs, adequacy, DPF) for data leaving its region.
  4. Security & breach — the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
  5. Deletion & return — what happens to your data at termination, and by when.
  6. Audit & liability — your right to verify, and whether liability is capped below the data risk.

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dpa Review loads about 989 tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 502 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~989

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 502 words, ~989 tokens.

Download SKILL.mdSave it as .claude/skills/dpa-review/SKILL.md (or your agent's skills folder).
name
dpa-review
description
Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.

DPA Review

Every SaaS contract now drags a Data Processing Agreement behind it, and most get signed unread — which is how you inherit a vendor's sub-processors, a 30-day breach-notice window, and no deletion guarantee. This reads the DPA the way a privacy counsel skims it: what data is processed, who else touches it, where it goes, what happens on a breach, and what's missing — ranked by how much it can hurt.

Not legal advice. Flags issues for review; have privacy counsel sign off on a material agreement.

What This Skill Produces

  • The plain-English summary — what this DPA actually commits each side to
  • Risk-ranked findings — 🔴 sign-blockers, 🟡 negotiate, 🟢 standard — each with the clause and why it matters
  • The missing-clause checklist — the protections a good DPA has that this one lacks
  • The redline questions — what to send back to the vendor before signing

Required Inputs

Ask for these if not provided:

  • The DPA text — the document, or its key clauses pasted
  • Your role — are you the controller (your data) or the processor (you're the vendor)? The risks flip
  • The data — what personal/sensitive data is involved, and any regime that applies (GDPR, CCPA, HIPAA)
  • Deal context — how critical the vendor is; leverage shapes what's worth fighting

Framework: What a DPA Must Get Right

  1. Scope & roles — controller vs processor, and the processing purpose; a mismatch here voids the rest.
  2. Sub-processors — who else gets the data, notice of new ones, and a right to object.
  3. International transfers — the mechanism (SCCs, adequacy, DPF) for data leaving its region.
  4. Security & breach — the standard, and the breach-notification window (72 hours is the GDPR bar; "reasonable" is a red flag).
  5. Deletion & return — what happens to your data at termination, and by when.
  6. Audit & liability — your right to verify, and whether liability is capped below the data risk.
Show full SKILL.md (199 more words)Show less

Output Format

DPA Review — [vendor] · you are the [controller/processor]

Verdict: Safe to sign / Negotiate first / Do not sign — one line why

Risk-ranked findings
RiskClauseWhat it saysWhy it matters
🔴………
Missing protections
  • [clause a good DPA has that this lacks]
Send back before signing
  1. [redline question / requested change]

Quality Checks

  • Controller/processor role identified — findings framed from your side
  • Sub-processor, transfer, breach-window, and deletion terms each assessed (or flagged absent)
  • The breach-notification window is stated in hours/days, not left as "reasonable"
  • Every 🔴 names the exact clause and the concrete exposure
  • Missing-clause list distinguishes "unusual gap" from "standard omission"
  • Flagged for counsel review on anything material

Anti-Patterns

  • Summarising without ranking — a wall of clauses helps no one; rank by damage.
  • Ignoring who you are — a processor and a controller face opposite risks in the same document.
  • Treating "reasonable security" as fine — undefined standards are the finding.
  • Inventing a clause number or requirement not in the text — quote what's there.

Example Trigger Phrases

  • "Review this DPA before we sign the vendor contract."
  • "Is this data processing agreement safe to sign?"
  • "What am I agreeing to on data in this DPA?"
  • "Check this DPA — we're the controller, it's a GDPR deal."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dpa-review of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Dpa Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dpa Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dpa Review this skillmohitagw15856/pm-claude-skills1.4k—~989Automated safety check: PassMIT
Plain Language for Legal TextGaZmagik/iso-24495190—~2.4kAutomated safety check: PassMIT
Shopify Admin Agentic Policy Readability40RTY-ai/shopify-admin-skills194—~1.6kAutomated safety check: PassMIT
Agreement Generatorjeremylongshore/tons-of-skills-marketplace2.8k—~2.5kAutomated safety check: PassMIT
Jev Question Translatorlawve-ai/awesome-legal-skills847—~6.9kAutomated safety check: PassApache-2.0
Client Explanation Translator Larissa Meredith Flisterlawve-ai/awesome-legal-skills847—~1.6kAutomated safety check: PassCustom licence

Similar skills

  • Applies ISO 24495-2 style plain-language rules to contracts and legal writing, standardizing modal verbs without weakening enforceability.

    190 GitHub stars~2.4k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Shopify Admin Agentic Policy Readability

    40RTY-ai/shopify-admin-skills

    Ensure shipping, returns, refund, privacy, and terms policies exist as clean machine-readable text so AI agents can answer shopper questions and close the sale without escalating.

    194 GitHub stars~1.6k tokensUpdated 1 mo ago
    Writing & ContentAuto-check passed
  • Agreement Generator

    jeremylongshore/tons-of-skills-marketplace

    Generates customized business agreements for 10 common relationship types with plain English annotations.

    2.8k GitHub stars~2.5k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Jev Question Translator

    lawve-ai/awesome-legal-skills

    Turns a legal question, a set of draft questions, or source material such as a statute, jury instruction, rubric, contract checklist, or coding manual into a battery of narrow questions that…

    847 GitHub stars~6.9k tokensUpdated 8 days ago
    Writing & ContentAuto-check passed
  • Asd Ste100

    danyuchn/asd-ste100-skill

    A skill your agent uses when English text must be parsed without a human to resolve ambiguity — tool descriptions, error messages, inter-agent instructions, system prompts, status reports — and…

    4.3k GitHub stars~4.1k tokensUpdated 7 days ago
    Writing & ContentAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Dpa Review

What does Dpa Review do?

Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Dpa Review is an agent skill from mohitagw15856/pm-claude-skills. Read a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk.

When should I use Dpa Review?

Dpa Review fits situations like: asked to review a DPA; check a data processing agreement; is this DPA safe to sign; what am I agreeing to on data.

How do I install Dpa Review in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -a claude-code`. Or copy the skill folder (skills/dpa-review in mohitagw15856/pm-claude-skills) into .claude/skills/dpa-review in your project. Claude Code loads it when a task matches its description.

How do I install Dpa Review in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -a codex`. Or copy the skill folder (skills/dpa-review in mohitagw15856/pm-claude-skills) into .agents/skills/dpa-review in your project. Codex loads it when a task matches its description.

Can I use Dpa Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill dpa-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpa-review, .gemini/skills/dpa-review, .github/skills/dpa-review and .opencode/skills/dpa-review in your project.

What does Dpa Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Dpa Review is instructions for the agent only.

Does Dpa Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dpa Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dpa Review use?

Dpa Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dpa Review use?

About 989 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dpa Review?

Skills that share tags, products or a category with Dpa Review: Plain Language for Legal Text (GaZmagik/iso-24495, 190 stars), Shopify Admin Agentic Policy Readability (40RTY-ai/shopify-admin-skills, 194 stars), Agreement Generator (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Jev Question Translator (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dpa Review?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.