| name | review-a-data-processing-agreement |
| category | write |
| description | Map a proposed data processing agreement to operational capabilities and unresolved decisions. Use when privacy, security, procurement, legal, and service owners need a structured review before signing or renewal. |
review-a-data-processing-agreement
Translate contractual language into systems, controls, owners, and questions. This operational review supports, but does not replace, advice or approval from authorized legal and privacy professionals.
Inputs
- Current agreement, schedules, amendments, order form, service description, and negotiation version
- Data inventory, flows, subprocessors, locations, security controls, retention, and deletion behavior
- Incident, rights-request, audit, transfer, and termination procedures
- Authorized legal and privacy interpretations
Procedure
- Confirm parties, roles, covered service, document precedence, term, and exact version.
- Extract defined terms and obligations without paraphrasing away qualifiers or exceptions.
- Map purposes, data categories, people, locations, subprocessors, transfers, and instructions to the real design.
- Build an obligation matrix for security, confidentiality, incidents, assistance, rights, records, audits, deletion, return, and termination.
- For each obligation, identify owner, control, evidence, timing, dependency, and operational gap.
- Separate accepted fact, contractual interpretation, proposed negotiation position, and unresolved question.
- Test notification, export, deletion, subprocessor change, audit, and termination scenarios against actual lead times.
- Route legal meaning, enforceability, transfer basis, and liability decisions to authorized counsel.
- Track redlines and ensure operational owners approve commitments they must deliver.
- Reconcile the signed version to the control plan and schedule required changes.
Guardrails
- Do not provide a legal conclusion outside authorized review.
- Never assume a security exhibit proves the product or environment is in scope.
- Avoid inserting personal data or credentials into the review record.
- Stop signature when a material promise lacks an owner or credible capability unless accountable authority accepts it.
Done
- Agreement language is traceable to operational owners and evidence
- Gaps, redlines, and legal questions remain distinct
- Material scenarios have been checked against real capability
- Signed obligations feed implementation and review tracking