Skip to main content
DPA Review helps in-house privacy and vendor counsel get through Data Processing Addenda quickly and consistently. Upload a vendor’s DPA and Vaquill reviews it clause by clause against a 15-point in-house checklist, surfaces the sub-processors it names, validates the Standard Contractual Clauses, and tracks renewal and audit dates across your vendor portfolio.
DPA Review showing a Data Processing Addendum analyzed against an in-house checklist with sub-processor inventory and Standard Contractual Clause validation

A DPA reviewed against an in-house checklist, with sub-processors and SCC status surfaced

When To Use It

  • Reviewing a vendor’s DPA before signing an MSA or order form
  • Building and maintaining a sub-processor inventory across all vendors
  • Validating that Standard Contractual Clauses are the current version and correctly completed
  • Tracking DPA renewal dates, audit windows, and breach-notification timelines
  • Responding to a customer DPA request with your own processing terms

What It Checks

Vaquill reviews each DPA against the points in-house teams actually care about:

Sub-Processor Inventory

Every DPA you review feeds a running inventory of the sub-processors your vendors rely on, so you can answer “which of our vendors send data to which downstream providers” without re-reading each contract. Track change notices and objection deadlines in one place.

How To Use It

1

Upload the DPA

Add the vendor’s Data Processing Addendum to the matter, or paste the text.
2

Run the review

Vaquill analyzes the document against the in-house checklist and returns a per-point status with citations to the exact clauses.
3

Review sub-processors and SCCs

Check the surfaced sub-processor list and the SCC validation, and add anything missing to your inventory.
4

Track renewals

Capture renewal, audit, and notice dates so you are not caught off guard at renewal.
DPA Review flags gaps and inconsistencies; it does not replace privacy-counsel judgment. Confirm the SCC version and transfer mechanism against current guidance before you rely on the result.

Compliance Check

Check contracts and policies against CCPA, GDPR, HIPAA, SOX, and more.

Contract Review

Clause-by-clause review with severity flags and redlines.