Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says "review this DPA", "check this data processing addendum", "customer sent their DPA", "is this DPA okay", or attaches a DPA.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "dpa-review" skill from askskill: 1. Download https://raw.githubusercontent.com/anthropics/claude-for-legal/main/privacy-legal/skills/dpa-review/SKILL.md 2. Save it as ~/.claude/skills/dpa-review/SKILL.md 3. Reload skills and tell me it's ready
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → DPA playbook. If placeholders, stop and prompt setup./privacy-legal:dpa-review customer-dpa.pdf
Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /privacy-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.
DPAs come in two flavors and the review is nearly opposite for each. When a customer sends their DPA, we're defending our operational flexibility. When we send one to a vendor, we're protecting our (and our customers') data. Both reviews read from the same ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md playbook but from opposite rows.
Before anything else, establish:
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → "When we are the processor" tableIf unclear, ask. Getting this wrong inverts every recommendation.
This review assumes the jurisdictional scope specified in your configuration. Privacy rules, response deadlines, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the controller, processor, or data subjects are in a different jurisdiction than configured, this review may not apply as written.
Before reviewing, check the outputs folder for prior work on this counterparty or processing activity. Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## Outputs for the outputs folder path. Scan for:
use-case-triage results for the same counterparty / processing activity — the triage produces a risk rating and conditions that this DPA review should honor or explicitly depart from.pia-generation outputs covering this counterparty / processing activity — the PIA may have flagged risk mitigations the DPA needs to implement.dpa-review outputs for the same counterparty — earlier DPA reviews set expectations about what was acceptable, what was flagged, and what was settled. A fresh review that silently contradicts the earlier one erodes trust in the work product.If a prior output is found, cite it in the review:
"Prior triage ([date]) rated this [risk level] and conditioned approval on [X]. This DPA review is consistent with that finding." — or — "Prior triage ([date]) rated this [risk level]. This DPA review departs from that finding because [reason — new facts, different scope, contract term that changed the picture]."
Carry severity from the upstream output as a floor per the cross-skill severity floor rule in ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## Shared guardrails. A processing activity the triage rated 🔴 cannot be quietly downgraded to 🟢 in the DPA review; any demotion is stated and explained.
…
Run structured legal client intake and generate organized case summaries.
Build or extend a course outline scaffold from notes and casebook materials.
Manage matter workspaces to separate, switch, and archive client contexts.
Safely uninstall hub-installed community skills with confirmation and audit logging.
Temporarily disable or re-enable an installed community skill without deleting files.
Draft board or committee minutes from calendar events, agendas, and pre-read materials.