All prompts

Analyze/Featured

Audit a Data Processing Addendum for gaps

Runs a vendor DPA against Article 28, the CCPA service-provider terms, sub-processor control, breach timing, and transfer mechanics, then tells you which annex is empty and gives you redlines for each gap.

About 18 minintermediateIn-house, Privacy, Transactional

Your prompt5,383 characters

Still to fill in: DPA text, Data in scope, Regimes and forum

RoleYou are a privacy counsel who has read hundreds of DPAs and knows the failures are almost never in the recitals. You go to the annexes first, because that is where a beautifully drafted DPA turns out to describe no processing, no security measures, and no sub-processors. You do not accept "industry standard" as a technical measure, and you never call a document compliant when you mean well organized.What I needAudit the DPA below as Controller: we are the customer sending data, for the data described in Data in scope, under Regimes and forum. The vendor: Vendor and its footprint. Score it, show me the gaps in a table, and give me redlines I can send.InputsDPA: DPA text Data in scope: Data in scope Which side we are on: Controller: we are the customer sending data Regimes and forum: Regimes and forum Vendor and footprint: Vendor and its footprintHow to work this1. State the roles the DPA assigns and test them against what Data in scope says the vendor actually does. If the document says processor and the facts say otherwise, that is finding one. 2. Walk Article 28(3)(a) through (h) one at a time. For each, give the DPA section covering it or mark it missing. Do not summarize the group. 3. Check for the CCPA service-provider restrictions as express contractual language, not a general reference to the statute. 4. Assess sub-processor control: is it prior consent or general authorization, is there a notice period, an objection right, and an exit if the objection stands? 5. Extract the breach terms verbatim. Give the clock in hours from what trigger, and what the notice must contain. Flag any "promptly" or "without undue delay" standing alone. 6. Handle transfers by access path, not storage location. Name the mechanism the DPA relies on, whether the right module or annex is selected, and whether an assessment is attached. If unsure which instrument is current, mark it [UNVERIFIED - confirm the current form]. 7. Open each annex and say what is actually in it. An empty Annex I, a one-line Annex II, or a sub-processor list without countries is a blocking finding. 8. Close with no more than five redlines that must land before signature, ordered by what a regulator asks about first.Ask me firstBefore you produce anything, ask me these questions, then stop and wait: 1. Where will the data physically sit, and who can reach it from where, including support and engineering staff in other countries? Remote access is a transfer even when storage never moves. 2. Is this vendor a processor for everything it does, or is it acting as a controller for some slice: analytics, benchmarking, fraud scoring, model training? A DPA cannot fix a mislabeled role. 3. What have we promised our own customers in their DPAs: audit rights, sub-processor notice, breach timing? A vendor DPA that gives us less than we owe downstream is the real exposure. 4. Do I have the vendor's sub-processor list, technical measures, and latest audit report, or am I reviewing the annexes blind? Do not begin the audit until I answer. If I tell you to proceed anyway, state each assumption at the top of your output and mark it [ASSUMPTION - verify].Output formatScore: green / yellow / red, one-sentence rationale. Roles: what the DPA says, what the facts say. Gap table: Requirement | Present, weak, missing | DPA § | The gap | Paste-ready redline, covering Article 28 elements, CCPA restrictions, sub-processors, breach, transfers, audit, deletion. Transfer check: mechanism, module selection, assessment status. Annex verdict: I, II, III judged on what is actually written. Top five redlines before signature. End with one line naming the two of my answers that most changed the score and the top-five list, and what you would have graded this DPA without them. If an answer changed nothing, say so. It means I should not have been asked.Never do this- If this audit would read the same for any vendor processing any data, it is too generic. Tie every gap to the data and access paths I described. - No hedging filler. Cut "arguably," "it should be noted," and "organizations should consider." Do not tell me to consult an attorney. I am the privacy counsel. - Every article, section, or standard-clause reference must come from my inputs or carry [UNVERIFIED - confirm the current instrument]. Never invent a recital number, a decision citation, or a certification standard. - Where you do not know whether a transfer instrument is current, whether Regimes and forum has adopted a rule, or how a supervisory authority reads a clause, say you do not know. Do not smooth over the gap. This is the document a regulator reads line by line. - Do not pad. A DPA with three gaps gets three rows. Length is not value.Before you answer- Did I go to the annexes, or did I audit the body and assume the schedules were filled in? - Does every gap row cite an actual DPA section number, and is every missing item marked missing rather than glossed? - Did I give the breach clock in hours from a named trigger, with required content? - Is every legal instrument I named either from my inputs or marked unverified? - Would this audit be useless against another vendor's DPA? It should be.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

Which of my redlines misread the law rather than the contract? Answer as the vendor's privacy counsel, who has answered these objections in forty enterprise deals and knows their product architecture cannot deliver two of my asks. Which three are opening positions you concede in round one to protect the one that actually threatens the architecture, and which one is that? Rewrite the misread items correctly and tell me what I should trade to get the one that matters.
3

Go deeper

Pushes the work further once the basics are right.

Who can reach this data, and from where? That has to be answered on paper. Draft the transfer impact assessment for this data flow: the specific access paths and who holds the keys, the legal environment questions that matter for the destination countries, the supplementary technical and contractual measures worth requiring, and the conclusion template with the evidence you would need to sign it. Keep it to one page a regulator could read.

Before you run it

What to gather first

  • Where the data subjects live and where the data is stored and accessed from
  • Categories, volume, and sensitivity of the personal data in scope
  • Whether the vendor is a pure processor or a controller for any part of the processing
  • What you have already promised your own customers in their DPAs
  • The vendor's sub-processor list, technical measures, and most recent audit report

Watch for

  • Standard contractual clauses, UK transfer instruments, and adequacy decisions change. Confirm which version and which module the DPA actually incorporates against the current official text before you rely on any conclusion here.
  • Remote access from a third country is a transfer even when the data never leaves the region. Support and engineering rotas are where this is missed.
  • Sub-processor lists go stale within a quarter. Require notice of changes and a right to object, not a static annex.
  • Technical measures described as "industry standard" or "commercially reasonable" commit the vendor to nothing. Insist on named controls: encryption standard, key management, MFA, retention, logging.
  • A DPA that gives you less than you have promised your own customers creates a gap you cannot close later. Compare the two before signature, not at renewal.

What comes back

A green/yellow/red score with rationale, a roles finding comparing the document to the facts, a gap table covering Article 28 elements, CCPA restrictions, sub-processors, breach notification, transfers, audit rights and deletion, each marked present, weak, or missing with a section cite and paste-ready redline; a transfer check naming the mechanism and assessment status, an annex-by-annex verdict, and the five redlines that must land before signature.

See an example of what you’ll get
*(After you answer the four questions: data in AWS eu-west-1 with support access from Manila, vendor is a pure processor, our customer DPAs promise 30-day sub-processor notice and 48-hour breach notice, and we do not have their current sub-processor list.)* Score: RED. The annexes are empty, the breach clock is missing, and Manila support access is not covered by any transfer mechanism in the document. Not signable in this form. Roles. The DPA designates the vendor as processor throughout (§ 2.1), and the scope you described is warehousing and aggregation on the controller's instructions only. The designation holds. But § 4.3 permits the vendor to use "aggregated and de-identified data to improve its services" without defining de-identification. That is a controller activity wearing a processor label. Flag and constrain. Gap table | Requirement | Status | DPA § | Gap | Redline | |---|---|---|---|---| | Art. 28(3)(a) documented instructions | Present | § 3.1 | none | none | | Art. 28(3)(b) confidentiality of personnel | Missing | none | No personnel confidentiality undertaking | "Processor shall ensure that persons authorised to process the Personal Data are subject to an appropriate statutory or contractual obligation of confidentiality." | | Art. 28(3)(c) security measures | Weak | § 6, Annex II | Annex II reads "industry-standard safeguards" | Replace Annex II with named controls: AES-256 at rest, TLS 1.2+ in transit, customer-managed keys, MFA for all administrative access, 90-day log retention, annual penetration test | | Art. 28(3)(d) sub-processors | Weak | § 5 | General authorisation with no notice period and no objection right | "Processor shall give Controller at least thirty (30) days' written notice before appointing any new Sub-processor. Controller may object on reasonable data protection grounds, and if the objection is not resolved within thirty (30) days may terminate the affected Services without penalty or early termination charge." | | Art. 28(3)(e) assistance with data subject rights | Present | § 7 | none | none | | Art. 28(3)(f) breach assistance | Weak | § 8 | See breach row | none | | Art. 28(3)(g) deletion or return | Weak | § 12 | "Upon termination" with no deadline, no format, no certification | "Within thirty (30) days of termination Processor shall, at Controller's election, return the Personal Data in a documented machine-readable format or securely delete it, and shall certify completion in writing within sixty (60) days." | | Art. 28(3)(h) audits and information | Weak | § 10 | Annual certification report only, described as satisfying audit rights | "Once per twelve months on thirty days' notice, and additionally following any confirmed Personal Data Breach, Controller or a mutually approved auditor may audit Processor's compliance. Processor shall make available all information necessary to demonstrate compliance with this DPA." | | CCPA service-provider restrictions | Missing | none | No contractual restriction on selling, sharing, retaining, or combining | Add the four restrictions as express covenants, plus the vendor's obligation to notify if it can no longer meet them | | Breach notification | Missing | § 8 | "Processor shall notify Controller promptly": no clock, no content | "Processor shall notify Controller without undue delay and in any event within twenty-four (24) hours of becoming aware of a Personal Data Breach, including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed." 24 hours, not 72; we owe our own customers notice within 48. | | Transfers | Missing | none | No transfer mechanism for Manila support access | See transfer check | Transfer check. Storage in eu-west-1 does not resolve anything: administrative access from Manila and Bangalore is an onward transfer, and the DPA is silent. Requires an appropriate transfer instrument with the controller-to-processor module selected, plus the UK mechanism because UK data subjects are in scope, plus a transfer impact assessment covering both access countries. [UNVERIFIED - confirm the current official form and module numbering before attaching; do not rely on my recollection of the version.] Annex verdict. Annex I: blank except the party names. It must describe subject matter, duration, nature and purpose, data types, and data subject categories. Right now the DPA governs nothing identifiable. Annex II: one sentence, unenforceable. Annex III: lists three sub-processors with no countries and no processing description; we also know from the vendor's own footprint that this list is incomplete. Top five redlines before signature. 1. Complete Annex I, rewrite Annex II with named controls, and republish Annex III with countries and roles. 2. Add the transfer instrument covering Manila and Bangalore access, with the UK addition, and supply the transfer assessment. 3. Breach notice at 24 hours from awareness with the specified content. 4. Sub-processor notice at 30 days with an objection right and a penalty-free exit. 5. Add the CCPA service-provider restrictions and delete or tightly define the § 4.3 "aggregated and de-identified" carve-out. What your answers changed. Support access from Manila and Bangalore is what makes this RED rather than YELLOW and what put redline 2 on the list at all. If the data were reachable only from inside eu-west-1, the transfer row falls away and this grades YELLOW on the empty annexes alone. What you owe your own customers is why the breach redline reads 24 hours and not 72: against a 48-hour downstream commitment, a 72-hour vendor clock means you are late before you know you have a breach, and it is why the sub-processor redline is a fixed 30 days rather than "reasonable notice." Your answer that the vendor is a pure processor changed nothing; § 2.1 already designates them processor and the warehousing-and-aggregation scope you described matches it. Had you told me they benchmark or train on this data, the roles paragraph would have been the blocking finding instead of a flag on § 4.3.
Why this prompt is built the way it is
## Framework 1. **Roles before clauses.** Controller, processor, joint controller, or independent controller for part of the processing. A DPA that mislabels the relationship cannot be fixed by better drafting. 2. **Article 28 is a checklist, not a vibe.** Subject matter, duration, nature and purpose, types of personal data, categories of data subjects, plus the processor obligations in 28(3)(a) through (h). Walk them one at a time. 3. **CCPA needs its own words.** Service-provider or contractor status depends on specific contractual restrictions: no selling or sharing, no retaining or using outside the business purpose, no combining with other sources, and notice if the processor can no longer comply. 4. **Sub-processors: consent or notice plus objection.** A silent right to appoint sub-processors is a gap. So is a notice mechanism with no right to object and no exit. 5. **Breach terms need a clock and a payload.** "Promptly" is not a term. Specify hours from becoming aware, and what the notice must contain. 6. **Transfers turn on access, not storage.** If support staff outside the region can reach the data, that is a transfer. Check the mechanism, the module selection, and whether an assessment is required and supplied. 7. **Audit rights and deletion are the two most commonly hollowed out.** A certification report is not an audit right; "upon termination" is not a deletion deadline. 8. **The annexes are the document.** An empty Annex I or a generic Annex II means the DPA promises nothing specific.