Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+17 more

    GDPR Contract Review Triage Agent

    2

    Reviews contracts and DPAs for GDPR-related triage issues, extracts obligations, flags missing clauses, creates risk tables, and generates legal-review checklists.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    Review this SaaS vendor DPA for GDPR risk areas. Create a triage report with role classification, clause presence matrix, risk table, missing clauses, subprocessor review, international transfer review, retention/deletion review, security review, breach notification review, vendor questions, redline comment suggestions, and legal-review checklist. Treat this as legal triage, not legal advice.

    Your agent does

    === GDPR CONTRACT REVIEW TRIAGE REPORT ===

    Legal positioning: This is legal triage and issue spotting, not legal advice. Final contract approval requires qualified legal/privacy review.

    Contract: SaaS Vendor Data Processing Agreement

    Documents reviewed:

    • DPA text provided by user
    • No main agreement provided
    • No security schedule provided
    • No subprocessor list provided

    Parties: Customer and SaaS vendor

    Likely role structure: Controller-to-processor, based on the vendor processing customer personal data to provide SaaS services.

    Processing summary: The vendor appears to process customer-provided personal data for service delivery, support, hosting, and related operational purposes.

    Personal data categories: Not clearly listed.

    Data subject categories: Not clearly listed.

    Processing purposes: Service provision is mentioned, but the purposes are broad and should be clarified.

    Processing duration: Not clearly defined beyond the term of the services.

    Overall risk rating: High

    Executive summary: The DPA contains basic processor language but has several gaps requiring privacy/legal review. The most important issues are missing data categories, unclear data subject categories, unclear deletion timeline, missing security schedule, no subprocessor list, and unclear international transfer mechanism.

    Clause presence matrix: Party roles: Found, but should be confirmed.

    Subject matter: Ambiguous.

    Duration: Ambiguous.

    Nature and purpose: Ambiguous.

    Types of personal data: Missing.

    Categories of data subjects: Missing.

    Documented instructions: Found.

    Confidentiality: Found.

    Security measures: Ambiguous. No detailed TOMs attached.

    Subprocessors: Ambiguous. Subprocessors appear allowed, but list and objection process are not provided.

    Breach notification: Found, but timeline should be reviewed.

    Return/deletion: Ambiguous. Deletion timing and backup handling unclear.

    Audit and information rights: Ambiguous. Audit rights appear limited.

    International transfers: Ambiguous. Transfer mechanism not clear from provided text.

    GDPR contract risk table: | Area | Status | Risk level | Issue | Evidence | Why it matters | Recommended human review | |---|---|---|---|---|---|---| | Data categories | Missing | High | DPA does not clearly list types of personal data | No schedule provided | Processing scope is incomplete | Privacy/legal | | Data subjects | Missing | High | Data subject categories not listed | No schedule provided | Required for understanding scope | Privacy/legal | | Security measures | Ambiguous | High | TOMs are vague or missing | No security schedule | Security obligations may be insufficient | Security/privacy | | Subprocessors | Ambiguous | High | No subprocessor list or objection process provided | DPA references subprocessors | Onward processing risk | Privacy/procurement | | Transfers | Ambiguous | High | Transfer locations/mechanism unclear | No transfer schedule/SCCs provided | Cross-border transfer review needed | Privacy/legal | | Deletion | Ambiguous | Medium | Deletion timeline and backups unclear | End-of-services language vague | Retention risk | Legal/privacy |

    Questions for vendor:

    1. Please provide the current subprocessor list, including processing locations and services performed.
    2. Please identify all personal data categories and data subject categories processed under the services.
    3. Please provide the technical and organizational measures/security schedule.
    4. Please confirm whether personal data is transferred outside the EEA/UK and identify the applicable transfer mechanism.
    5. Please clarify deletion timing, backup deletion, and whether deletion confirmation is available.
    6. Please clarify breach notification timing and information included in notices.

    Questions for internal legal/privacy team:

    1. Is this relationship correctly classified as controller-to-processor?
    2. Are the vendor’s security measures sufficient for the data involved?
    3. Is the liability cap acceptable for the processing risk?
    4. Are the transfer terms acceptable after vendor clarification?

    Suggested redline comments: Comment: Please add a schedule listing the categories of personal data, categories of data subjects, processing purposes, processing duration, and processing locations.

    Comment: Please provide a current subprocessor list and clarify notice and objection rights for new subprocessors.

    Legal-review checklist:

    • confirm role classification
    • confirm processing scope
    • confirm subprocessor controls
    • confirm transfer mechanism
    • confirm TOMs
    • confirm breach timeline
    • confirm deletion/return process
    • confirm audit rights
    • confirm liability alignment
    • confirm order of precedence with main agreement

    Audit-ready review record: Reviewer: [Name]

    Date: [Date]

    Documents reviewed: DPA only

    Review scope: GDPR contract triage

    Final status: Not ready for approval. Vendor clarification and legal/privacy review required.

    Final triage recommendation: Do not treat this DPA as ready for signature until the missing schedules, subprocessor information, security measures, transfer mechanism, and deletion terms are clarified and reviewed by legal/privacy counsel.

    What you get

    Review vendor DPAs for missing GDPR-required clauses before signature.Generate lists of privacy questions for procurement to send to new vendors.Extract and summarize data processing obligations from master service agreements.Automate legal-review checklists for internal privacy teams.Flag risky liability caps or breach notification timelines in vendor docs.

    About this skill

    GDPR Contract Review Triage Agent helps EU companies, SaaS businesses, legal teams, privacy teams, compliance consultants, procurement teams, and DPO offices perform structured first-pass GDPR contract review. It analyzes contracts, DPAs, privacy addenda, vendor agreements, security schedules, subprocessor terms, SCC references, retention clauses, breach notification terms, audit rights, assistance obligations, data transfer language, and liability provisions. The skill extracts obligations, identifies missing or ambiguous clauses, creates clause presence matrices, risk tables, vendor questions, redline comment suggestions, legal-review checklists, obligation inventories, and audit-ready review records. It is framed as legal triage and issue spotting, not legal advice or final contract approval.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • One-time purchase, yours forever

    Listed3 months ago

    Frequently Asked Questions