Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Reviews a Data Processing Agreement (DPA) against the GDPR Article 28(3) mandatory-term checklist — the scope terms (subject-matter, duration, nature and purpose, type of data, categories of data subjects) plus the eight lettered processor obligations (a) documented-instructions, (b) confidentiality, (c) Article 32 security, (d) sub-processor authorization, (e) data-subject-rights assistance, (f) Article 32-36 / breach assistance, (g) deletion or return of data, (h) audit and information rights — marking each present, weak, or missing and flagging the gaps, rather than summarizing what the DPA says. Use when reviewing or redlining a data processing agreement or addendum for GDPR completeness. Do NOT use for drafting a fresh DPA clause, extracting DPA fields into a schema, or reviewing an unrelated contract clause (indemnity, pricing, termination).
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 414% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 386% | 0% |
| case-01 | ✗→✗ | = Same ✗ | 385% | 0% |
| case-02 | ✗→✗ | = Same ✗ | 425% | 0% |
| case-03 | ✗→✗ | = Same ✗ | 403% | 0% |
Review a Data Processing Agreement for completeness against the GDPR Article 28(3) mandatory-term list, not for readability. A capable model can read a DPA and summarize it, but by default it describes what is present and stays quiet about what is absent — so a DPA that never obliges the processor to assist with data-subject requests, or that lets it delete data with no return option, reads as fine. This skill makes the review systematic: walk every mandatory term, mark each present / weak / missing, and flag the gaps explicitly.
Article 28(3) says the processing must be governed by a contract that binds the processor to the controller and sets out the processing scope and stipulates the eight obligations below. A DPA that omits or waters down any of them is non-conforming — that is the thing to catch.
Activate when the request supplies a DPA, data processing addendum, or the processor-obligations section of a contract and asks you to review, redline, or check it for GDPR completeness — "review this DPA before we sign", "what's missing from this data processing addendum", "does this cover the Article 28 processor obligations".
Do not activate to draft a fresh DPA or clause from nothing, to extract DPA fields into a schema (that is a data-extraction task), or to review a different clause type (indemnification, limitation of liability, pricing, general termination).
Before the eight obligations, Article 28(3) requires the contract to set out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the controller's rights. Flag a DPA that leaves these open — no stated duration, no description of what data or whose data is processed — as an incomplete scope, often pushed to an annex that is blank or absent.
Check the DPA against all eight. For each, state present (with the specific terms), weak (addressed but deficient), or missing / not addressed, then collect the gaps. Silence is not coverage — a term the DPA never governs is missing even though nothing in the DPA is wrong.
Do not narrate the DPA. Produce a term-by-term checklist: the scope terms and each of the eight obligations marked present (with the terms found), weak (what is deficient), or missing, followed by a short, prioritized list of the gaps to flag. If every mandatory term is addressed, say so plainly — "no missing Article 28(3) terms" — rather than padding.
Distinguish weak from missing: a sub-processor clause that names no notice or objection right is present-but-weak, not absent; a deletion clause that omits the return option is weak. Weak terms are the ones a reviewer most often misses, because the topic appears covered.
For the full per-obligation sub-checklist — every item a reviewer drills into within each Article 28(3) letter, and the common weak-term tells — see references/article28-checklist.md.
Other measured skills in the registry, with their headline benchmark lift.