
The DPA review panel on a vendor record: risk flags first, then roles, transfer mechanism, breach and deletion and audit terms, and the named sub-processors
When to use it
- A vendor sent their standard DPA and you need the shape of it in two minutes, not twenty
- You are onboarding a vendor and want the registry entry built from the agreement rather than typed from scratch
- Someone asks which downstream sub-processors a vendor discloses, and you do not want to reopen the PDF
- You need to know whether the agreement addresses cross-border transfers at all, and on what basis
- A DPA was renegotiated and you want the record refreshed against the new version
How to run it
There are two entry points, depending on whether the vendor already exists.Start from the DPA, if the vendor is new
Or attach the DPA to an existing vendor
Read the DPA review panel
Re-run after a renegotiation
What the review surfaces
Risk flags
Two things are pulled above the extracted terms, because they are the reason you opened the record:- Transfer gaps appear as amber banners. The most common is an agreement that references EU Standard Contractual Clauses but has no UK IDTA or UK Addendum when UK data subjects may be in scope. Only gaps the text actually supports are flagged.
- Special-category data appears as a red banner, with the categories listed: health, biometric, genetic, racial, political, religious, sexual, or criminal data.
What it writes back to the vendor record
The analysis fills empty registry fields and never overwrites one you set yourself. Your corrections survive every re-run.Reading the agreement alongside the review
Click any attached document to open the preview. The document text sits on the left, and on the right there are two tabs:- Summary, a short plain-English summary plus three to seven key points covering parties, data, transfers, sub-processors, and the breach, audit, and deletion terms.
- Chat, a question box scoped to that one document. Ask “what is the breach-notice window?” or “does this allow onward transfers?” and the answer is grounded strictly in the text of that document. If the answer is not in the document, it says so rather than guessing.
From one review to the portfolio view
A single review is most useful when it rolls up. Because results land on vendor records, the registry answers portfolio questions directly:- Filter the vendor list by DPA: missing, DPA: requested, DPA: signed, or DPA: expired, or narrow to sub-processors only.
- Export Audit CSV (all vendors) for the internal audit list, or Sub-processor list CSV for the sub-processor disclosure you publish or hand to a customer’s security review. The sub-processor export carries the downstream sub-processors these reviews extracted.
- Renewal dates drive the “renews in N days” and overdue labels on the list, escalating as the date approaches within the lead time you set per vendor.
Going deeper on one agreement
Negotiate it clause by clause
Negotiate it clause by clause
Check it against a regulation
Check it against a regulation
Review a whole stack of DPAs
Review a whole stack of DPAs
Limitations
- This is extraction, not adjudication. The interactive review reports what the agreement says. It does not score the DPA against Article 28(3), validate which SCC module was used, or check that the SCC version is current. The workflow does those.
- No clause citations in the panel. Findings are not linked back to the exact clause they came from. Open the preview and use document chat when you need the wording.
- One document per run. The analysis reads a single attached document, the most recently updated one unless you upload a new file. It does not merge a DPA with a separately attached SCC annex or BAA.
- Long documents are truncated. Roughly the first 24,000 characters are analyzed, which covers most DPAs including the annex, but a sub-processor list buried deep inside an unusually long master agreement can fall outside that window.
- Renewal reminders are in-app. The registry shows escalating “renews in N days” and overdue labels and records the alert server side. It does not email you.
- Dates it never saw cannot warn you. If the agreement states no signed or renewal date, nothing is filled in, and the reminder has nothing to fire against.
- It does not verify practice. The review reads the paper. It says nothing about whether the vendor’s real sub-processor chain, security posture, encryption key custody, or incident history matches what the DPA promises.
- Text-based documents only. Attach text-searchable PDF, DOCX, DOC, TXT, RTF, or Markdown. A scanned image with no extractable text gives the analysis nothing to read.
- Privacy counsel still signs off. Confirm the transfer mechanism, the special-category assessment, and the risk tier against current guidance before you rely on any of it.

