---
name: dpa-article28-review
source: https://app.decimal.ai/s/dpa-article28-review@1/SKILL.md
source_sha256: bfa22be5e8b8
---

# DPA Article 28(3) Review

Review a Data Processing Agreement for **completeness against the GDPR Article 28(3) mandatory-term list**, not for readability. A capable model can read a DPA and summarize it, but by default it describes what is *present* and stays quiet about what is *absent* — so a DPA that never obliges the processor to assist with data-subject requests, or that lets it delete data with no return option, reads as fine. This skill makes the review systematic: walk every mandatory term, mark each present / weak / missing, and flag the gaps explicitly.

Article 28(3) says the processing must be governed by a contract that binds the processor to the controller and sets out the processing scope **and** stipulates the eight obligations below. A DPA that omits or waters down any of them is non-conforming — that is the thing to catch.

## When to activate

Activate when the request supplies a **DPA, data processing addendum, or the processor-obligations section of a contract** and asks you to review, redline, or check it for GDPR completeness — "review this DPA before we sign", "what's missing from this data processing addendum", "does this cover the Article 28 processor obligations".

Do **not** activate to draft a fresh DPA or clause from nothing, to extract DPA fields into a schema (that is a data-extraction task), or to review a different clause type (indemnification, limitation of liability, pricing, general termination).

## The scope terms (chapeau)

Before the eight obligations, Article 28(3) requires the contract to set out the **subject-matter and duration** of the processing, its **nature and purpose**, the **type of personal data**, the **categories of data subjects**, and the controller's rights. Flag a DPA that leaves these open — no stated duration, no description of what data or whose data is processed — as an incomplete scope, often pushed to an annex that is blank or absent.

## The eight mandatory obligations

Check the DPA against all eight. For each, state **present** (with the specific terms), **weak** (addressed but deficient), or **missing / not addressed**, then collect the gaps. Silence is not coverage — a term the DPA never governs is missing even though nothing in the DPA is wrong.

- **(a) Documented instructions.** The processor processes personal data only on the controller's documented instructions, including for transfers to a third country, unless required by law — in which case it notifies the controller first (absent a legal prohibition). Flag a DPA with no instructions-limitation, or one that lets the processor process for its own purposes.

- **(b) Confidentiality.** Persons authorized to process the data are bound to confidentiality (by contract or statutory duty). Flag the absence of any confidentiality commitment covering the processor's personnel.

- **(c) Security (Article 32).** The processor takes all measures required under Article 32 — appropriate technical and organisational measures given the risk. Flag a DPA that states no security obligation, or one that gestures at "reasonable security" with no reference to Article 32 or to a measures schedule.

- **(d) Sub-processor authorization.** The processor engages another processor only with the controller's prior specific or general written authorization; on general authorization it informs the controller of intended changes and gives a chance to object; and it flows the same data-protection obligations down to the sub-processor. Flag a DPA that permits sub-processors with no authorization mechanism, no notice/objection right, or no flow-down.

- **(e) Data-subject-rights assistance.** The processor assists the controller, by appropriate technical and organisational measures, to respond to data-subject requests (access, erasure, portability, objection). Flag the absence of any obligation to help the controller answer data-subject requests.

- **(f) Article 32-36 assistance.** The processor assists the controller in meeting its obligations under Articles 32-36 — security, **personal-data-breach notification** to the authority and to data subjects, data protection impact assessments, and prior consultation. Flag a DPA with no breach-notification duty on the processor, or no DPIA assistance.

- **(g) Deletion or return.** At the controller's choice, the processor deletes or returns all personal data at the end of the services and deletes existing copies, unless law requires retention. Flag a DPA that only deletes (with no return option), only returns, or is silent on end-of-term handling.

- **(h) Audit and information rights.** The processor makes available all information needed to demonstrate compliance with Article 28, and allows for and contributes to audits and inspections by the controller or a mandated auditor. Flag a DPA that gives the controller no audit right, or substitutes a third-party certification with no inspection option.

## How to report

Do not narrate the DPA. Produce a term-by-term checklist: the scope terms and each of the eight obligations marked **present** (with the terms found), **weak** (what is deficient), or **missing**, followed by a short, prioritized list of the gaps to flag. If every mandatory term is addressed, say so plainly — "no missing Article 28(3) terms" — rather than padding.

Distinguish **weak** from **missing**: a sub-processor clause that names no notice or objection right is present-but-weak, not absent; a deletion clause that omits the return option is weak. Weak terms are the ones a reviewer most often misses, because the topic appears covered.

For the full per-obligation sub-checklist — every item a reviewer drills into within each Article 28(3) letter, and the common weak-term tells — see `references/article28-checklist.md`.
