All prompts
Analyze/Featured
Audit a Data Processing Addendum for gaps
Runs a vendor DPA against Article 28, the CCPA service-provider terms, sub-processor control, breach timing, and transfer mechanics, then tells you which annex is empty and gives you redlines for each gap.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
*(After you answer the four questions: data in AWS eu-west-1 with support access from Manila, vendor is a pure processor, our customer DPAs promise 30-day sub-processor notice and 48-hour breach notice, and we do not have their current sub-processor list.)*
Score: RED. The annexes are empty, the breach clock is missing, and Manila support access is not covered by any transfer mechanism in the document. Not signable in this form.
Roles. The DPA designates the vendor as processor throughout (§ 2.1), and the scope you described is warehousing and aggregation on the controller's instructions only. The designation holds. But § 4.3 permits the vendor to use "aggregated and de-identified data to improve its services" without defining de-identification. That is a controller activity wearing a processor label. Flag and constrain.
Gap table
| Requirement | Status | DPA § | Gap | Redline |
|---|---|---|---|---|
| Art. 28(3)(a) documented instructions | Present | § 3.1 | none | none |
| Art. 28(3)(b) confidentiality of personnel | Missing | none | No personnel confidentiality undertaking | "Processor shall ensure that persons authorised to process the Personal Data are subject to an appropriate statutory or contractual obligation of confidentiality." |
| Art. 28(3)(c) security measures | Weak | § 6, Annex II | Annex II reads "industry-standard safeguards" | Replace Annex II with named controls: AES-256 at rest, TLS 1.2+ in transit, customer-managed keys, MFA for all administrative access, 90-day log retention, annual penetration test |
| Art. 28(3)(d) sub-processors | Weak | § 5 | General authorisation with no notice period and no objection right | "Processor shall give Controller at least thirty (30) days' written notice before appointing any new Sub-processor. Controller may object on reasonable data protection grounds, and if the objection is not resolved within thirty (30) days may terminate the affected Services without penalty or early termination charge." |
| Art. 28(3)(e) assistance with data subject rights | Present | § 7 | none | none |
| Art. 28(3)(f) breach assistance | Weak | § 8 | See breach row | none |
| Art. 28(3)(g) deletion or return | Weak | § 12 | "Upon termination" with no deadline, no format, no certification | "Within thirty (30) days of termination Processor shall, at Controller's election, return the Personal Data in a documented machine-readable format or securely delete it, and shall certify completion in writing within sixty (60) days." |
| Art. 28(3)(h) audits and information | Weak | § 10 | Annual certification report only, described as satisfying audit rights | "Once per twelve months on thirty days' notice, and additionally following any confirmed Personal Data Breach, Controller or a mutually approved auditor may audit Processor's compliance. Processor shall make available all information necessary to demonstrate compliance with this DPA." |
| CCPA service-provider restrictions | Missing | none | No contractual restriction on selling, sharing, retaining, or combining | Add the four restrictions as express covenants, plus the vendor's obligation to notify if it can no longer meet them |
| Breach notification | Missing | § 8 | "Processor shall notify Controller promptly": no clock, no content | "Processor shall notify Controller without undue delay and in any event within twenty-four (24) hours of becoming aware of a Personal Data Breach, including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed." 24 hours, not 72; we owe our own customers notice within 48. |
| Transfers | Missing | none | No transfer mechanism for Manila support access | See transfer check |
Transfer check. Storage in eu-west-1 does not resolve anything: administrative access from Manila and Bangalore is an onward transfer, and the DPA is silent. Requires an appropriate transfer instrument with the controller-to-processor module selected, plus the UK mechanism because UK data subjects are in scope, plus a transfer impact assessment covering both access countries. [UNVERIFIED - confirm the current official form and module numbering before attaching; do not rely on my recollection of the version.]
Annex verdict. Annex I: blank except the party names. It must describe subject matter, duration, nature and purpose, data types, and data subject categories. Right now the DPA governs nothing identifiable. Annex II: one sentence, unenforceable. Annex III: lists three sub-processors with no countries and no processing description; we also know from the vendor's own footprint that this list is incomplete.
Top five redlines before signature.
1. Complete Annex I, rewrite Annex II with named controls, and republish Annex III with countries and roles.
2. Add the transfer instrument covering Manila and Bangalore access, with the UK addition, and supply the transfer assessment.
3. Breach notice at 24 hours from awareness with the specified content.
4. Sub-processor notice at 30 days with an objection right and a penalty-free exit.
5. Add the CCPA service-provider restrictions and delete or tightly define the § 4.3 "aggregated and de-identified" carve-out.
What your answers changed. Support access from Manila and Bangalore is what makes this RED rather than YELLOW and what put redline 2 on the list at all. If the data were reachable only from inside eu-west-1, the transfer row falls away and this grades YELLOW on the empty annexes alone. What you owe your own customers is why the breach redline reads 24 hours and not 72: against a 48-hour downstream commitment, a 72-hour vendor clock means you are late before you know you have a breach, and it is why the sub-processor redline is a fixed 30 days rather than "reasonable notice." Your answer that the vendor is a pure processor changed nothing; § 2.1 already designates them processor and the warehousing-and-aggregation scope you described matches it. Had you told me they benchmark or train on this data, the roles paragraph would have been the blocking finding instead of a flag on § 4.3.
Why this prompt is built the way it is
## Framework
1. **Roles before clauses.** Controller, processor, joint controller, or independent controller for part of the processing. A DPA that mislabels the relationship cannot be fixed by better drafting.
2. **Article 28 is a checklist, not a vibe.** Subject matter, duration, nature and purpose, types of personal data, categories of data subjects, plus the processor obligations in 28(3)(a) through (h). Walk them one at a time.
3. **CCPA needs its own words.** Service-provider or contractor status depends on specific contractual restrictions: no selling or sharing, no retaining or using outside the business purpose, no combining with other sources, and notice if the processor can no longer comply.
4. **Sub-processors: consent or notice plus objection.** A silent right to appoint sub-processors is a gap. So is a notice mechanism with no right to object and no exit.
5. **Breach terms need a clock and a payload.** "Promptly" is not a term. Specify hours from becoming aware, and what the notice must contain.
6. **Transfers turn on access, not storage.** If support staff outside the region can reach the data, that is a transfer. Check the mechanism, the module selection, and whether an assessment is required and supplied.
7. **Audit rights and deletion are the two most commonly hollowed out.** A certification report is not an audit right; "upon termination" is not a deletion deadline.
8. **The annexes are the document.** An empty Annex I or a generic Annex II means the DPA promises nothing specific.