Skip to main content
DPA Review is the interactive, one document at a time pass over a Data Processing Addendum. You attach the vendor’s DPA to their record, run the analysis, and Vaquill AI reads the agreement and fills in the things you would otherwise be highlighting by hand: who is the controller and who is the processor, what transfer mechanism the agreement relies on, every sub-processor it names, the breach notice window, the audit terms, the deletion period, and an assessed risk tier with a one line reason. The result lands on the vendor record itself, not in a separate report you have to remember to open. Six months later, when a customer asks which of your vendors touch health data under a US transfer, the answer is already sitting in the registry.
A vendor record showing the DPA review panel with transfer risk flags, assessed risk tier, controller and processor roles, and a list of named sub-processors

The DPA review panel on a vendor record: risk flags first, then roles, transfer mechanism, breach and deletion and audit terms, and the named sub-processors

When to use it

  • A vendor sent their standard DPA and you need the shape of it in two minutes, not twenty
  • You are onboarding a vendor and want the registry entry built from the agreement rather than typed from scratch
  • Someone asks which downstream sub-processors a vendor discloses, and you do not want to reopen the PDF
  • You need to know whether the agreement addresses cross-border transfers at all, and on what basis
  • A DPA was renegotiated and you want the record refreshed against the new version
For a standardized scored review across many DPAs at once, with GDPR Article 28(3) coverage tables, SCC module fit, a Schrems II transfer impact assessment, and HIPAA BAA scoring, use the DPA Reviewer workflow instead. This guide covers the fast interactive path.

How to run it

There are two entry points, depending on whether the vendor already exists.
1

Start from the DPA, if the vendor is new

On the Vendors and Sub-processors page, open Import and choose From a DPA (AI). Pick the file, and Vaquill AI uploads it, reads it, and proposes a vendor entry.The proposal opens in the normal vendor form so you can correct anything before saving. Nothing is written to the registry until you confirm it, by design: a wrong compliance registry is worse than an empty one.
2

Or attach the DPA to an existing vendor

Open the vendor record and use Upload DPA in the Documents section. The file is attached to the vendor and the analysis runs automatically as soon as the upload lands.If the upload succeeds but the analysis does not, the document stays attached. Run it again from the panel.
3

Read the DPA review panel

The panel sits between the vendor overview and the document list. Risk flags render at the top, then the extracted terms, then the sub-processor list, then a timestamp of when the analysis last ran.
4

Re-run after a renegotiation

Upload the new version and press Re-analyze DPA. The panel is rewritten from the latest analysis, and the registry fields you filled in by hand are left alone.
Pressing Analyze DPA from the panel reads the most recently updated document attached to that vendor. If a vendor has several attached files, upload or update the one you want first so the right document is the newest.

What the review surfaces

Any field the agreement does not address is left out of the panel rather than filled with a guess. An empty transfer mechanism is itself a finding.

Risk flags

Two things are pulled above the extracted terms, because they are the reason you opened the record:
  • Transfer gaps appear as amber banners. The most common is an agreement that references EU Standard Contractual Clauses but has no UK IDTA or UK Addendum when UK data subjects may be in scope. Only gaps the text actually supports are flagged.
  • Special-category data appears as a red banner, with the categories listed: health, biometric, genetic, racial, political, religious, sexual, or criminal data.
A non-adequate transfer combined with special-category data is treated as High risk by default. That assessment is a starting point for your own risk framework, not a substitute for it.

What it writes back to the vendor record

The analysis fills empty registry fields and never overwrites one you set yourself. Your corrections survive every re-run. The review layer itself, meaning the roles, transfer terms, flags, and the sub-processor list, is rewritten on every run so the panel always reflects the most recent analysis.
Set the vendor’s risk tier by hand if you disagree with the assessment. Once you set it, later runs leave it alone, and the model’s own view stays visible in the panel as the assessed risk.

Reading the agreement alongside the review

Click any attached document to open the preview. The document text sits on the left, and on the right there are two tabs:
  • Summary, a short plain-English summary plus three to seven key points covering parties, data, transfers, sub-processors, and the breach, audit, and deletion terms.
  • Chat, a question box scoped to that one document. Ask “what is the breach-notice window?” or “does this allow onward transfers?” and the answer is grounded strictly in the text of that document. If the answer is not in the document, it says so rather than guessing.
Open in editor takes the document into the drafting editor if you want to redline it. Draft DPA on the vendor record starts a new Data Processing Agreement instead of reviewing an incoming one.

From one review to the portfolio view

A single review is most useful when it rolls up. Because results land on vendor records, the registry answers portfolio questions directly:
  • Filter the vendor list by DPA: missing, DPA: requested, DPA: signed, or DPA: expired, or narrow to sub-processors only.
  • Export Audit CSV (all vendors) for the internal audit list, or Sub-processor list CSV for the sub-processor disclosure you publish or hand to a customer’s security review. The sub-processor export carries the downstream sub-processors these reviews extracted.
  • Renewal dates drive the “renews in N days” and overdue labels on the list, escalating as the date approaches within the lead time you set per vendor.
See the Vendor and Sub-processor Registry guide for the registry itself.

Going deeper on one agreement

Contract Review with a playbook gives you positions, fallbacks, and redlines instead of extracted facts. Vaquill AI ships controller-side and processor-side DPA playbooks with standard positions on breach windows, sub-processor approval and objection rights, audit, deletion, and transfer mechanisms, plus escalation triggers for the terms that should not pass quietly.
Compliance Check scores a document against a named regulation with per-requirement status and article-level references. Use it when the question is “does this satisfy Article 28” rather than “what does this say”.
The DPA Reviewer workflow scores up to 500 agreements against Article 28(3), the 2021 SCCs, a Schrems II transfer impact assessment, and the HIPAA BAA elements, and returns an executive memo plus per-DPA detail with proposed redlines.

Limitations

  • This is extraction, not adjudication. The interactive review reports what the agreement says. It does not score the DPA against Article 28(3), validate which SCC module was used, or check that the SCC version is current. The workflow does those.
  • No clause citations in the panel. Findings are not linked back to the exact clause they came from. Open the preview and use document chat when you need the wording.
  • One document per run. The analysis reads a single attached document, the most recently updated one unless you upload a new file. It does not merge a DPA with a separately attached SCC annex or BAA.
  • Long documents are truncated. Roughly the first 24,000 characters are analyzed, which covers most DPAs including the annex, but a sub-processor list buried deep inside an unusually long master agreement can fall outside that window.
  • Renewal reminders are in-app. The registry shows escalating “renews in N days” and overdue labels and records the alert server side. It does not email you.
  • Dates it never saw cannot warn you. If the agreement states no signed or renewal date, nothing is filled in, and the reminder has nothing to fire against.
  • It does not verify practice. The review reads the paper. It says nothing about whether the vendor’s real sub-processor chain, security posture, encryption key custody, or incident history matches what the DPA promises.
  • Text-based documents only. Attach text-searchable PDF, DOCX, DOC, TXT, RTF, or Markdown. A scanned image with no extractable text gives the analysis nothing to read.
  • Privacy counsel still signs off. Confirm the transfer mechanism, the special-category assessment, and the risk tier against current guidance before you rely on any of it.

Vendor and Sub-processor Registry

The record these reviews write to, plus filters, exports, and renewal tracking.

DPA Reviewer workflow

Batch scoring against Article 28(3), the SCCs, a Schrems II TIA, and BAA elements.

Compliance Check

Per-requirement scoring against GDPR, CCPA, HIPAA, and more.

Contract Review

Clause-by-clause review with playbook positions, severity flags, and redlines.

Playbooks

The controller-side and processor-side DPA negotiation positions.

Privacy and Data Protection Audit

Privacy posture across policies and agreements together.
Last modified on August 6, 2026