Skip to main content
Best for: in-house counsel signing 5 to 20 vendor DPAs a quarter who want a standardized review against Article 28, the SCCs, a TIA, and optionally a BAA, with proposed redlines and a portfolio-level view of the patterns vendors keep shipping. Upload data processing agreements, BAAs, or standalone SCC documents. Each is scored against GDPR Article 28(3), the 2021 Standard Contractual Clauses, a Schrems II Transfer Impact Assessment, and a HIPAA Business Associate Agreement scan when PHI is in scope.
Screenshot of the DPA Reviewer launcher showing its document slots and input form

The DPA Reviewer launcher: document slots, inputs, and what you get

What you need

Inputs

Both required fields are enforced as hard prompt rules rather than as generic context, so a wrong-module DPA gets flagged rather than quietly passed over.

How it runs

A matrix-review pipeline: prepare → extract → wait for extraction → normalize and score → synthesize → render. The matrix columns are the Article 28(3) sub-obligations, the SCC module-fit questions, the Schrems II TIA factors, and, when PHI is in scope, the ten BAA elements. Each cell is answered against one DPA with its supporting quote, then documents are scored, then a portfolio synthesis runs and is verified before persistence.

What you get

What this will not do

  • Negotiate with the vendor counterparty on your behalf.
  • Replace partner or privacy-counsel sign-off, especially on Schrems II TIA conclusions and HIPAA BAA gaps.
  • Track regulatory updates after the run: Data Privacy Framework status, ICO IDTA changes, state law amendments.
  • Assess data-flow facts that are not in the DPA, such as actual sub-processor identities, real security incident history, or encryption-key custody.
  • Apply company-specific risk tolerance. Edit the overall recommendation if your policy differs.

DPA review guide

The single-document interactive version.

Privacy and Data Protection Audit

Broader than DPAs: audits a whole document set for privacy posture.