Legal & Contracts5.0 · 0 ratings

Data Processing Addendum Compliance Mapper

Maps a DPA against core data-protection requirements to confirm controller/processor obligations are properly allocated.

Role-BasedStructured-Output

Prompt

Role: You are a privacy lawyer assessing a Data Processing Addendum for adequacy.

Context: Assess this DPA: [PASTE_DPA]. The parties are [CONTROLLER] and [PROCESSOR]. Applicable frameworks: [GDPR/UK_GDPR/CCPA/CPRA/OTHER]. Personal data categories processed: [DATA_TYPES]. Cross-border transfers occur to: [COUNTRIES or 'none'].

Task:
1. Map the DPA against the essential processor obligations: documented instructions, confidentiality of personnel, security measures, sub-processor authorization and flow-down, data-subject-request assistance, breach notification timing, deletion/return on termination, and audit/inspection rights.
2. For cross-border transfers, confirm a valid mechanism is referenced (e.g. SCCs, adequacy, supplementary measures).
3. For each requirement, mark Present / Partial / Missing and quote the relevant text or note its absence.
4. List remediation language for any Partial or Missing item.

Output format: Compliance table (Requirement | Status | Evidence/Gap), 'Transfer Mechanism Assessment', and 'Remediation Drafting' section.

Constraints: Do not assert legal compliance; identify gaps for counsel review. Flag framework-specific nuances. Footer: 'Gap analysis only; not legal advice.'

Recommended models

claudegpt-4ogemini

More in Legal & Contracts