▸case-01 We are preparing to contract with CloudMetrics for our customer database, acting as the data controller handling EU customer PII under GDPR. Below is their proposed DPA text. Please review it and provide: 1) A clear overall verdict on signing safety, 2) A list of findings ranked by risk severity detailing the relevant clause and why it matters to us, 3) An outline of important protective clauses missing from this text, and 4) Concrete redlines or questions to send back to their team before we sign. | fail→fail | 13,716 | 10,868 | -21% | 1 | 1 | 0% | 1,316 | 1,906 | +45% | 0 | 0 | — |
▸case-02 Our company is acting as the data processor for an enterprise client using our analytics platform, processing US employee telemetry data. They sent us their standard DPA to sign (text below). Please evaluate it from a processor's perspective: give us a bottom-line verdict line, a risk-categorized breakdown of clauses and why they create exposure for us, a checklist of standard processor safeguards that are omitted, and a numbered list of redline changes to send back to the buyer. | fail→fail | 33,854 | 29,539 | -13% | 1 | 1 | 0% | 4,079 | 2,506 | -39% | 0 | 0 | — |
▸case-03 We are evaluating a vendor's DPA where we act as the controller uploading healthcare user data subject to HIPAA and GDPR. This vendor is critical to our stack. Can you analyze the attached text and output a final sign/negotiate verdict, a structured table of findings ordered by risk level detailing what the clause states and its business impact, a list of missing standard protections, and a set of redline questions to submit to the vendor? | fail→fail | 27,825 | 13,966 | -50% | 1 | 1 | 0% | 4,203 | 2,296 | -45% | 0 | 0 | — |
▸case-04 We are a data controller reviewing Section 5 of an enterprise vendor's DPA: 'In the event of a confirmed Personal Data Breach, Processor shall notify Controller without undue delay and no later than 48 hours after becoming aware of the breach. Processor shall provide reasonable details regarding the nature of the breach, affected data categories, and mitigation measures taken.' Please evaluate this breach notification clause under GDPR. | fail→pass | 23,947 | 16,756 | -30% | 1 | 1 | 0% | 2,732 | 2,910 | +7% | 0 | 0 | — |
▸case-05 We are an EU-based data controller transferring EU customer personal data to a US data processor. Section 12 of their DPA states: 'Cross-Border Data Transfers: To the extent processing involves transfers of Personal Data subject to EU GDPR from the EEA to the United States, the parties hereby incorporate and execute the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) Module 2 (Controller-to-Processor).' Evaluate this transfer mechanism for GDPR Chapter V compliance. | fail→fail | 18,172 | 19,986 | +10% | 1 | 1 | 0% | 3,153 | 3,484 | +10% | 0 | 0 | — |
▸case-06 We are a data controller evaluating Section 4 of a SaaS provider's DPA: 'Vendor maintains an up-to-date list of sub-processors on its public website. Vendor shall provide Customer with written notice at least 30 days prior to authorizing any new sub-processor. Customer may object to such change in writing within 14 days on reasonable data protection grounds.' Evaluate this sub-processor authorization clause under GDPR Article 28. | fail→fail | 24,040 | 17,507 | -27% | 1 | 1 | 0% | 2,999 | 3,060 | +2% | 0 | 0 | — |
▸case-07 We are the data controller entering into a contract with CloudStore (processor) handling customer PII subject to GDPR. Below is Clause 8 from their DPA: 'Section 8: Security Incidents. Vendor will use commercially reasonable efforts to inform Customer of any confirmed Security Breach affecting Customer Data within a reasonable timeframe after completion of internal investigation.' Evaluate this clause, state whether it meets statutory requirements, and provide redline guidance. | pass→pass | 19,352 | 16,310 | -16% | 1 | 1 | 0% | 2,451 | 2,870 | +17% | 0 | 0 | — |
▸case-08 We are the controller engaging AnalyticsCo as processor for EU user tracking data under GDPR. Clause 4 states: 'Vendor may engage new sub-processors at any time without prior notice to Customer. Customer's continued use of the service constitutes acceptance of all sub-processors.' Evaluate this sub-processor provision and provide requested redline modifications. | pass→pass | 21,287 | 11,036 | -48% | 1 | 1 | 0% | 3,002 | 2,829 | -6% | 0 | 0 | — |
▸case-09 We are an EU-based controller transferring EU resident personal data to a US-based cloud hosting vendor. Section 11 of their DPA states: 'Data Processing Location. Vendor may store and process Customer Personal Data in data centers located in the United States or any other country where Vendor maintains facilities.' No transfer mechanisms such as Standard Contractual Clauses (SCCs) or Data Privacy Framework (DPF) certifications are mentioned. Assess this transfer clause for GDPR compliance and state necessary changes. | pass→pass | 19,337 | 17,190 | -11% | 1 | 1 | 0% | 2,595 | 2,970 | +14% | 0 | 0 | — |
▸case-10 We are a controller subscribing to HRCloud's SaaS platform containing employee records. Clause 14 reads: 'Upon termination, Vendor shall retain Customer Data in backup systems for up to 3 years and may charge Customer standard storage fees for such retention.' Evaluate this termination data deletion clause and state redline requirements. | pass→pass | 20,259 | 17,699 | -13% | 1 | 1 | 0% | 2,663 | 2,866 | +8% | 0 | 0 | — |
▸case-11 We are a data controller transferring sensitive medical data to MedTech SaaS. Clause 9 states: 'Vendor's aggregate liability under this DPA for any data breach or security incident shall not exceed $500 total.' Evaluate this liability limitation in light of potential regulatory exposure under GDPR. | pass→pass | 39,564 | 20,271 | -49% | 1 | 1 | 0% | 2,975 | 3,009 | +1% | 0 | 0 | — |
▸case-12 We are a controller evaluating SecurityVault's DPA. Section 6 states: 'Customer shall have no right to audit Vendor facilities or inspect Vendor systems. Vendor's internal SOC 2 summary report provided annually shall constitute sole proof of compliance.' Evaluate whether this meets controller audit requirements under GDPR Article 28. | pass→pass | 20,261 | 18,838 | -7% | 1 | 1 | 0% | 2,379 | 3,247 | +36% | 0 | 0 | — |
▸case-13 Our company is acting as the data processor providing CRM infrastructure to an enterprise client (controller). The client sent us a DPA containing Clause 3: 'Processor shall independently determine whether Processing of Personal Data complies with applicable privacy laws and shall bear sole financial liability for any regulatory fines assessed against Controller.' Evaluate this clause from our perspective as the processor. | pass→pass | 14,577 | 20,073 | +38% | 1 | 1 | 0% | 2,439 | 3,282 | +35% | 0 | 0 | — |
▸case-14 We are a business subject to CCPA engaging a vendor to handle US customer analytics. Section 2 of their DPA states: 'Vendor acts as Service Provider and agrees not to sell personal information.' No other restrictions are stated. Assess whether this clause satisfies CCPA/CPRA Service Provider contract requirements. | pass→pass | 19,315 | 17,660 | -9% | 1 | 1 | 0% | 2,411 | 3,210 | +33% | 0 | 0 | — |
▸case-15 We are a controller storing payment records with PayFlow. Clause 5 states: 'Vendor will maintain reasonable physical and technical security controls to protect data against unauthorized access.' The agreement includes no schedule of Technical and Organizational Measures (TOMs) or security standards. Evaluate this security commitment. | pass→pass | 19,715 | 15,361 | -22% | 1 | 1 | 0% | 2,357 | 2,605 | +11% | 0 | 0 | — |
▸case-16 We are a data controller evaluating a SaaS vendor's DPA. Section 12 states: 'Customer shall indemnify and defend Vendor against any third-party claims, fines, or regulatory actions arising out of Vendor's security breaches or unauthorized disclosures of Customer Data.' Evaluate this indemnity provision and state redlines. | pass→pass | 20,249 | 15,671 | -23% | 1 | 1 | 0% | 2,480 | 2,558 | +3% | 0 | 0 | — |
▸case-17 We are an EU controller engaging a cloud storage vendor. Clause 1 of their DPA states: 'Vendor will process customer data as necessary to perform the main agreement.' It does not state that the processor shall act only on documented instructions from the controller. Evaluate this clause under GDPR Article 28. | pass→pass | 18,535 | 15,504 | -16% | 1 | 1 | 0% | 2,218 | 2,488 | +12% | 0 | 0 | — |
▸case-18 We are a controller using an AI vendor. Section 7 of their DPA states: 'Vendor shall own all de-identified, aggregated, or derivative data generated from Customer Data and may use it for any commercial purpose, including training proprietary Machine Learning models.' Evaluate this provision. | pass→pass | 22,035 | 28,473 | +29% | 1 | 1 | 0% | 2,620 | 3,273 | +25% | 0 | 0 | — |
▸case-19 We are a controller subject to GDPR evaluating a vendor DPA. Clause 10 states: 'In the event of a security breach affecting Customer Personal Data, Vendor shall notify Customer within 30 calendar days of discovering the incident.' Evaluate this notification timeframe. | pass→pass | 21,814 | 15,777 | -28% | 1 | 1 | 0% | 2,105 | 2,735 | +30% | 0 | 0 | — |
▸case-20 We are a data controller entering an agreement with CloudHost. Clause 4.2 states: 'Vendor may contract with sub-processors to fulfill service obligations.' It contains no requirement that sub-processors enter into written agreements imposing equivalent data protection obligations. Evaluate this sub-processor flow-down clause. | pass→pass | 18,706 | 12,540 | -33% | 1 | 1 | 0% | 2,298 | 2,709 | +18% | 0 | 0 | — |
▸case-21 We are an EU controller evaluating a vendor DPA. Clause 8 states: 'Vendor shall assist Controller with Data Subject Requests (DSRs) under GDPR, provided Controller reimburses Vendor at Vendor's standard hourly rate of $350/hour plus a $1,000 administrative fee per request.' Assess this fee structure for DSR assistance. | pass→pass | 20,932 | 18,463 | -12% | 1 | 1 | 0% | 2,387 | 2,864 | +20% | 0 | 0 | — |
▸case-22 We are a controller evaluating a CRM vendor's DPA. Section 15 states: 'Upon written request following contract termination, Vendor will attempt to delete Customer Data within a commercially reasonable period.' Evaluate this post-termination clause. | pass→pass | 14,081 | 18,070 | +28% | 1 | 1 | 0% | 2,131 | 2,623 | +23% | 0 | 0 | — |