--- name: review-a-data-processing-agreement category: write description: Map a proposed data processing agreement to operational capabilities and unresolved decisions. Use when privacy, security, procurement, legal, and service owners need a structured review before signing or renewal. --- # review-a-data-processing-agreement Translate contractual language into systems, controls, owners, and questions. This operational review supports, but does not replace, advice or approval from authorized legal and privacy professionals. ## Inputs - Current agreement, schedules, amendments, order form, service description, and negotiation version - Data inventory, flows, subprocessors, locations, security controls, retention, and deletion behavior - Incident, rights-request, audit, transfer, and termination procedures - Authorized legal and privacy interpretations ## Procedure 1. Confirm parties, roles, covered service, document precedence, term, and exact version. 2. Extract defined terms and obligations without paraphrasing away qualifiers or exceptions. 3. Map purposes, data categories, people, locations, subprocessors, transfers, and instructions to the real design. 4. Build an obligation matrix for security, confidentiality, incidents, assistance, rights, records, audits, deletion, return, and termination. 5. For each obligation, identify owner, control, evidence, timing, dependency, and operational gap. 6. Separate accepted fact, contractual interpretation, proposed negotiation position, and unresolved question. 7. Test notification, export, deletion, subprocessor change, audit, and termination scenarios against actual lead times. 8. Route legal meaning, enforceability, transfer basis, and liability decisions to authorized counsel. 9. Track redlines and ensure operational owners approve commitments they must deliver. 10. Reconcile the signed version to the control plan and schedule required changes. ## Guardrails - Do not provide a legal conclusion outside authorized review. - Never assume a security exhibit proves the product or environment is in scope. - Avoid inserting personal data or credentials into the review record. - Stop signature when a material promise lacks an owner or credible capability unless accountable authority accepts it. ## Done - Agreement language is traceable to operational owners and evidence - Gaps, redlines, and legal questions remain distinct - Material scenarios have been checked against real capability - Signed obligations feed implementation and review tracking