skills/legal/data-processing-addendum/SKILL.md
Drafts a GDPR Article 28-compliant Data Processing Addendum (DPA) between data controllers and processors. Extracts party details, processing scope, and service terms from uploaded documents. Produces an execution-ready DPA with all mandatory Art. 28(3) elements and four schedules. Use when supplementing a service agreement with data protection terms, negotiating processor contracts, or establishing GDPR-compliant EU data processing relationships.
npx skillsauth add casemark/skills data-processing-addendumInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts an Art. 28-compliant DPA as a standalone addendum to an underlying service agreement, covering all mandatory processor obligations and four execution-ready schedules.
Extract from uploaded documents before drafting:
Produce a numbered, cross-referenced document: recitals, operative provisions (Sections 1–11), signature block, and four schedules (A–D). Draft schedules in parallel with their corresponding sections.
| Element | Requirement | |---|---| | Party identification | Full legal name, address, registration number, DPO details | | Hierarchy | DPA prevails over main agreement on data protection matters | | Effective date | Specify; note retroactive application if processing already underway | | Integration | DPA forms integral part of main agreement |
Schedule C minimum domains:
| Domain | Scope | |---|---| | Pseudonymization & encryption | At-rest, in-transit, key management | | Confidentiality & integrity | Access controls, least-privilege, logging | | Availability & resilience | Redundancy, DR, RTO/RPO | | Testing & evaluation | Pen-test cadence, vulnerability management | | Personnel | Confidentiality obligations for all authorized personnel |
Reference existing certifications (ISO 27001, SOC 2 Type II, TISAX) as baseline evidence.
| Parameter | Position | |---|---| | Notice | 30 days (routine); shorter for cause | | Frequency | Annual unless cause exists | | Auditor | Controller team or independent third party (under NDA) | | Remote audits | Permitted | | Alternative evidence | Art. 42/40 certification, SOC 2 Type II, ISO 27001 (current and comprehensive) | | Costs | Controller bears routine; processor bears remediation costs for non-compliance | | Remediation | Specified timeline; escalation; controller may suspend or terminate for material breach |
| Schedule | Contents | |---|---| | A | Approved sub-processors: name, address, processing location, activity | | B | Processing description: subject matter, duration, nature/purpose, data types, data subject categories | | C | Technical and organizational security measures (by domain per Section 4) | | D | Certifications, audit reports, compliance documentation |
Flag any schedule where source documents lack sufficient detail; note required information for completion.
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.