Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    GDPR Contract Review Triage Agent

    2

    Reviews contracts and DPAs for GDPR-related triage issues, extracts obligations, flags missing clauses, creates risk tables, and generates legal-review checklists.

    $50

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    GDPR Contract Review Triage Agent

    GDPR Contract Review Triage Agent

    Example session with this skill installed

    Review this SaaS vendor DPA for GDPR risk areas. Create a triage report with role classification, clause presence matrix, risk table, missing clauses, subprocessor review, international transfer review, retention/deletion review, security review, breach notification review, vendor questions, redline comment suggestions, and legal-review checklist. Treat this as legal triage, not legal advice.

    • Read your context and instructions
    • Compiled the gdpr contract review
    • Generated the document

    === GDPR CONTRACT REVIEW TRIAGE REPORT ===

    Legal positioning
    This is legal triage and issue spotting, not legal advice. Final contract approval requires qualified legal/privacy review.

    Contract
    SaaS Vendor Data Processing Agreement

    Documents reviewed

    • DPA text provided by user
    • No main agreement provided
    • No security schedule provided
    • No subprocessor list provided

    Parties
    Customer and SaaS vendor

    Likely role structure
    Controller-to-processor, based on the vendor processing customer personal data to provide SaaS services.

    Processing summary
    The vendor appears to process customer-provided personal data for service delivery, support, hosting, and related operational purposes.

    Personal data categories
    Not clearly listed.

    Data subject categories
    Not clearly listed.

    Processing purposes
    Service provision is mentioned, but the purposes are broad and should be clarified.

    Processing duration
    Not clearly defined beyond the term of the services.

    Overall risk rating
    High

    Executive summary
    The DPA contains basic processor language but has several gaps requiring privacy/legal review. The most important issues are missing data categories, unclear data subject categories, unclear deletion timeline, missing security schedule, no subprocessor list, and unclear international transfer mechanism.

    Clause presence matrix

    Party roles
    Found, but should be confirmed.

    Subject matter
    Ambiguous.

    Duration
    Ambiguous.

    Nature and purpose
    Ambiguous.

    Types of personal data
    Missing.

    Categories of data subjects
    Missing.

    Documented instructions
    Found.

    Confidentiality
    Found.

    Security measures
    Ambiguous. No detailed TOMs attached.

    Subprocessors
    Ambiguous. Subprocessors appear allowed, but list and objection process are not provided.

    Breach notification
    Found, but timeline should be reviewed.

    Return/deletion
    Ambiguous. Deletion timing and backup handling unclear.

    Audit and information rights
    Ambiguous. Audit rights appear limited.

    International transfers
    Ambiguous. Transfer mechanism not clear from provided text.

    GDPR contract risk table

    AreaStatusRisk levelIssueEvidenceWhy it mattersRecommended human review
    Data categoriesMissingHighDPA does not clearly list types of personal dataNo schedule providedProcessing scope is incompletePrivacy/legal
    Data subjectsMissingHighData subject categories not listedNo schedule providedRequired for understanding scopePrivacy/legal
    Security measuresAmbiguousHighTOMs are vague or missingNo security scheduleSecurity obligations may be insufficientSecurity/privacy
    SubprocessorsAmbiguousHighNo subprocessor list or objection process providedDPA references subprocessorsOnward processing riskPrivacy/procurement
    TransfersAmbiguousHighTransfer locations/mechanism unclearNo transfer schedule/SCCs providedCross-border transfer review neededPrivacy/legal
    DeletionAmbiguousMediumDeletion timeline and backups unclearEnd-of-services language vagueRetention riskLegal/privacy

    Questions for vendor

    1. Please provide the current subprocessor list, including processing locations and services performed.
    2. Please identify all personal data categories and data subject categories processed under the services.
    3. Please provide the technical and organizational measures/security schedule.
    4. Please confirm whether personal data is transferred outside the EEA/UK and identify the applicable transfer mechanism.
    5. Please clarify deletion timing, backup deletion, and whether deletion confirmation is available.
    6. Please clarify breach notification timing and information included in notices.

    Questions for internal legal/privacy team

    1. Is this relationship correctly classified as controller-to-processor?
    2. Are the vendor’s security measures sufficient for the data involved?
    3. Is the liability cap acceptable for the processing risk?
    4. Are the transfer terms acceptable after vendor clarification?

    Suggested redline comments

    Comment
    Please add a schedule listing the categories of personal data, categories of data subjects, processing purposes, processing duration, and processing locations.

    Comment
    Please provide a current subprocessor list and clarify notice and objection rights for new subprocessors.

    Legal-review checklist

    • confirm role classification
    • confirm processing scope
    • confirm subprocessor controls
    • confirm transfer mechanism
    • confirm TOMs
    • confirm breach timeline
    • confirm deletion/return process
    • confirm audit rights
    • confirm liability alignment
    • confirm order of precedence with main agreement

    Audit-ready review record

    Reviewer
    [Name]

    Date
    [Date]

    Documents reviewed
    DPA only

    Review scope
    GDPR contract triage

    Final status
    Not ready for approval. Vendor clarification and legal/privacy review required.

    Final triage recommendation
    Do not treat this DPA as ready for signature until the missing schedules, subprocessor information, security measures, transfer mechanism, and deletion terms are clarified and reviewed by legal/privacy counsel.

    gdpr-contract-review-triage-agent.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Review vendor DPAs for missing GDPR-required clauses before signature.Generate lists of privacy questions for procurement to send to new vendors.Extract and summarize data processing obligations from master service agreements.Automate legal-review checklists for internal privacy teams.Flag risky liability caps or breach notification timelines in vendor docs.

    About this skill

    GDPR Contract Review Triage Agent helps EU companies, SaaS businesses, legal teams, privacy teams, compliance consultants, procurement teams, and DPO offices perform structured first-pass GDPR contract review. It analyzes contracts, DPAs, privacy addenda, vendor agreements, security schedules, subprocessor terms, SCC references, retention clauses, breach notification terms, audit rights, assistance obligations, data transfer language, and liability provisions. The skill extracts obligations, identifies missing or ambiguous clauses, creates clause presence matrices, risk tables, vendor questions, redline comment suggestions, legal-review checklists, obligation inventories, and audit-ready review records. It is framed as legal triage and issue spotting, not legal advice or final contract approval.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Passed all security checks, Safe to install

    Listed4 months ago

    What's inside

    Frequently Asked Questions