Vendor Data Processing Agreement (DPA) Review
When procurement or a business team sends a vendor's paper DPA and you need a clause-by-clause compliance and negotiation view before signing.
Almost every vendor that touches personal data comes with a data processing agreement, and most of them are written by the vendor. The terms that matter most to the customer, such as how quickly the vendor must report a breach, whether you can object to a new subprocessor, what happens to the data at the end, and which transfer mechanism applies, are often vague or missing. Reviewing them one by one against GDPR Article 28 and the applicable state privacy laws is careful, repetitive work.
This prompt tells Claude which side you are on, what data is involved, which laws apply and what your internal positions are, then asks for a topic-by-topic table. Each row quotes the DPA language (or records that the topic is not addressed), assigns a compliant, gap or negotiate rating, and proposes replacement language. The result reads like a reviewer's markup and leads straight into negotiation.
Statutory requirements change, and state privacy laws differ in their contract terms. Claude may not reflect the latest amendments or regulations, so the prompt marks uncertain requirements for verification. The reviewing attorney remains responsible for confirming each legal requirement, judging commercial risk, and approving the final agreement.
The Prompt
I represent [COMPANY] as the [CONTROLLER / BUSINESS] reviewing a vendor's data processing agreement. Vendor service: [DESCRIBE SERVICE]. Personal data involved: [CATEGORIES, e.g., customer contact data, employee HR data, any sensitive data]. Data subjects located in: [REGIONS]. Laws we need the DPA to address: GDPR Article 28 (if EU/UK data is processed) and [US STATE PRIVACY LAW(S)] service-provider or processor contract requirements. Our internal positions, if any: [PASTE PLAYBOOK POSITIONS OR "NONE"]. <document> [PASTE THE DPA, INCLUDING ANNEXES, SECURITY SCHEDULE AND SUBPROCESSOR LIST] </document> <document> [OPTIONAL: PASTE THE MAIN SERVICES AGREEMENT SECTIONS ON LIABILITY, CONFIDENTIALITY AND ORDER OF PRECEDENCE] </document> Review the DPA against these topics: processing only on documented instructions; subject matter, duration, nature, purpose, data types and data subject categories; confidentiality of personnel; security measures; subprocessor authorization, notice and objection rights; assistance with data subject requests, security, breach notification and impact assessments; breach notice timing and content; deletion or return at the end of services; audit and information rights; cross-border transfer mechanism; restrictions on selling, sharing or combining data and any certification language required by [US STATE PRIVACY LAW(S)]; liability and order of precedence. Output a table: Topic | Quoted DPA text (or "Not addressed") | Rating (Compliant / Gap / Negotiate) | Why | Proposed language. Then list the top five negotiation asks and any questions for the vendor. Quote the DPA for every rating. Where a state-law requirement is uncertain, mark it [VERIFY UNDER STATUTE] rather than stating it. This is a draft for attorney review.
Example Output
A topic-by-topic table with quoted DPA language, a compliant, gap or negotiate rating, proposed fixes, and a short list of priority asks and vendor questions.
Illustrative example — names, figures, and facts are fictional.
VENDOR DPA REVIEW (DRAFT FOR ATTORNEY REVIEW) Vendor: Corvane Ticketing Cloud (fictional) | Our role: Controller / Business Data: customer names, emails, purchase history | Regions: EU, [US STATES] Topic | Quoted DPA text | Rating | Why | Proposed language 1. Documented instructions | "Processor shall process Customer Data as necessary to provide the Services and improve its products." | Negotiate | "Improve its products" goes beyond customer instructions. | Delete "and improve its products" or limit to aggregated, de-identified data [VERIFY UNDER STATUTE]. 2. Subprocessors | "Processor may engage subprocessors listed at its website." | Gap | No notice of changes, no objection right. | Add 30 days' notice and a right to object and terminate. 3. Breach notice | "Processor will notify Customer of a Security Incident within a commercially reasonable time." | Negotiate | Too open-ended for the controller to meet its own notice duties. | Notify "without undue delay and in any event within [X] hours," with specified content. 4. Deletion or return | Not addressed | Gap | Required topic. | Add deletion or return at Customer's choice on termination, with certification. 5. Audit | "Customer may review Processor's SOC 2 report annually." | Negotiate | Report only; no on-site or regulator audit. | Add audit right on reasonable notice after an incident or regulator request. 6. Transfers | "Data may be processed in any country where Processor operates." | Gap | No transfer mechanism identified. | Incorporate the applicable standard contractual clauses and list processing locations. TOP FIVE ASKS: 1, 3, 4, 6, 2. VENDOR QUESTIONS: Which subprocessors handle EU data? Where are backups stored? Gaps in what was provided: security annex referenced but not pasted.
Tips
- •Paste the annexes and the subprocessor list. Most gaps hide in the security schedule and in how subprocessor changes are notified.
- •Name the specific state laws that apply to the data. A generic "US privacy law" instruction produces generic results.
- •Include the main agreement's order-of-precedence and liability sections; a strong DPA can be undercut by a cap in the master agreement.
- •Add your own playbook positions, such as a maximum breach notice window, so the ratings reflect your standards rather than defaults.
- •Verify each statutory requirement against the current text and regulations. The table is a draft for attorney review, not a compliance certification.
Frequently Asked Questions
Does the prompt cover both GDPR and US state privacy laws?
It is built for both, but you have to name the state laws that apply. GDPR Article 28 sets out a well-known list of processor terms, while state laws impose their own service-provider or processor contract requirements that vary by state and change over time. Claude marks uncertain state requirements for verification rather than stating them as settled.
Can I use my own DPA playbook with this prompt?
Yes, and you should. Paste your preferred and fallback positions into the playbook placeholder, such as maximum breach notice windows or subprocessor objection rights. Claude then rates each clause against your standards instead of a generic baseline, which makes the negotiate ratings far more useful to your team.
What if the vendor's DPA incorporates standard contractual clauses by reference?
Paste whatever annexes and module selections you have. Claude will check whether the DPA identifies the mechanism and fills in the required details, and it will flag anything referenced but not provided. Confirm which clauses and modules apply to your data flows yourself.
Related Prompts
Get New Prompts Like This Every Week
Join the free Claude for Lawyers newsletter — weekly prompts, tutorials, and practice-specific guides.