> ## Documentation Index
> Fetch the complete documentation index at: https://vaquill.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# DPA Review & Vendor Inventory

> Review Data Processing Addenda against an in-house checklist, track sub-processors, and validate Standard Contractual Clauses

DPA Review helps in-house privacy and vendor counsel get through Data Processing Addenda quickly and consistently. Upload a vendor's DPA and Vaquill reviews it clause by clause against a 15-point in-house checklist, surfaces the sub-processors it names, validates the Standard Contractual Clauses, and tracks renewal and audit dates across your vendor portfolio.

<Frame caption="A DPA reviewed against an in-house checklist, with sub-processors and SCC status surfaced">
  <img src="https://mintcdn.com/vaquill/3D9oAmhF2gXcIwdJ/images/dpa-review.webp?fit=max&auto=format&n=3D9oAmhF2gXcIwdJ&q=85&s=75e59d464efa34b055c3e7adb3b5e712" alt="DPA Review showing a Data Processing Addendum analyzed against an in-house checklist with sub-processor inventory and Standard Contractual Clause validation" style={{ borderRadius: '0.5rem' }} width="2992" height="1610" data-path="images/dpa-review.webp" />
</Frame>

## When To Use It

* Reviewing a vendor's DPA before signing an MSA or order form
* Building and maintaining a sub-processor inventory across all vendors
* Validating that Standard Contractual Clauses are the current version and correctly completed
* Tracking DPA renewal dates, audit windows, and breach-notification timelines
* Responding to a customer DPA request with your own processing terms

## What It Checks

Vaquill reviews each DPA against the points in-house teams actually care about:

| Area                     | What it surfaces                                                          |
| ------------------------ | ------------------------------------------------------------------------- |
| **Roles**                | Controller vs processor characterization, and whether it matches reality  |
| **Sub-processors**       | The named sub-processors, change-notice rights, and objection windows     |
| **SCCs**                 | Whether Standard Contractual Clauses are attached, current, and completed |
| **Security**             | Technical and organizational measures, encryption, and access controls    |
| **Breach notice**        | Notification timelines and what the vendor commits to provide             |
| **Audit rights**         | Audit scope, frequency, and cost allocation                               |
| **Data transfers**       | Transfer mechanisms and onward-transfer restrictions                      |
| **Retention & deletion** | Return-or-delete obligations on termination                               |
| **Liability**            | Carve-outs, caps, and indemnities that actually move                      |

## Sub-Processor Inventory

Every DPA you review feeds a running inventory of the sub-processors your vendors rely on, so you can answer "which of our vendors send data to which downstream providers" without re-reading each contract. Track change notices and objection deadlines in one place.

## How To Use It

<Steps>
  <Step title="Upload the DPA">
    Add the vendor's Data Processing Addendum to the matter, or paste the text.
  </Step>

  <Step title="Run the review">
    Vaquill analyzes the document against the in-house checklist and returns a per-point status with citations to the exact clauses.
  </Step>

  <Step title="Review sub-processors and SCCs">
    Check the surfaced sub-processor list and the SCC validation, and add anything missing to your inventory.
  </Step>

  <Step title="Track renewals">
    Capture renewal, audit, and notice dates so you are not caught off guard at renewal.
  </Step>
</Steps>

<Warning>
  DPA Review flags gaps and inconsistencies; it does not replace privacy-counsel judgment. Confirm the SCC version and transfer mechanism against current guidance before you rely on the result.
</Warning>

## Related

<CardGroup cols={2}>
  <Card title="Compliance Check" icon="clipboard-check" href="/docs/guides/compliance-check">
    Check contracts and policies against CCPA, GDPR, HIPAA, SOX, and more.
  </Card>

  <Card title="Contract Review" icon="file-contract" href="/docs/guides/contract-review">
    Clause-by-clause review with severity flags and redlines.
  </Card>
</CardGroup>
