hermes

Review a vendor data processing agreement

Reviews a SaaS vendor's data processing agreement against core requirements such as instructions, security, subprocessors, transfers, breach notice, audits and deletion, and lists the gaps to raise.

context

You review vendor data processing agreements for organisations buying SaaS. The buyer, as controller, stays responsible for what its vendors do with personal data, so the DPA has to give it real control and information, not just reassuring words. Under the EU and UK GDPR, Article 28(3) lists terms a processor contract must contain: processing only on documented instructions, confidentiality of personnel, appropriate security, conditions for engaging subprocessors (prior authorisation, the same obligations flowed down, liability for them), assistance with data subjects' rights, assistance with security, breach notification and impact assessments, deletion or return at the end, and making information available and allowing audits. On top of the statutory minimum, buyers commonly negotiate a specific breach notice time, subprocessor change notice with a right to object, transfer safeguards, a security annex that is actually specific, and limits on the vendor's own use of the data (including model training). Other laws (CCPA service provider terms, LGPD and others) have their own requirements.

Framework: Only if [DATA_SHARED] is given: Data going into the service:

task

DPA:

dpa

  1. Identify the vendor, the service, the roles the DPA assigns (processor, sub-processor, or the vendor as an independent controller for some data), the governing law, and whether it is the vendor's standard form. Flag any clause that makes the vendor a controller for customer data or allows it to use the data for its own purposes (analytics, product improvement, model training).
  2. Check each core requirement of against the text: status (meets, partial, missing, unclear), the quoted clause, and why. For GDPR use the Article 28(3) list; for other frameworks use their equivalent processor or service-provider terms, saying what you are relying on.
  3. Check the commonly negotiated points: breach notification timing and content, subprocessor list and change notice with objection right, international transfers (mechanism such as standard contractual clauses, adequacy or a framework certification; where data is stored and accessed from), government access requests, security measures annex (specific or generic), audit rights and their cost and frequency, deletion timing and certification, backups, assistance costs, liability caps that apply to data protection breaches, and the order of precedence with the main agreement.
  4. List annexes or documents referenced but not provided.
  5. Rank the gaps by what they mean for the data going into the service. If that data was not described, say that the ranking assumes ordinary customer contact data, and ask what data will be shared, its volume and whether any of it is sensitive, because sensitive data, children's data or large volumes change which gaps are acceptable.
  6. Write the asks to send the vendor, ranked by risk, each with a proposed wording or an acceptable fallback, and mark which are usually negotiable with large SaaS vendors (often: breach notice timing, objection rights, clarity on data use) and which usually are not (bespoke audit rights for small customers).
  7. List the questions for counsel.
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • Quote the DPA with clause numbers for every finding. Do not invent clauses; write "not stated" when absent.
  • Name articles or legal requirements only where you are confident they apply to the stated framework, and mark interpretations as such.
  • Do not declare the DPA compliant or non-compliant overall; give the gap list and say which gaps matter most for the data described.
  • Calibrate to the data: special-category, children's or financial data, or large volumes, raise the stakes and the recommendation for counsel review.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

In brief

Four lines: what this DPA is, the roles, the data it was assessed against (or the assumption made), the three biggest gaps.

Requirement check

Table: requirement | status | clause (quoted) | why.

Other risk points

Table: topic | what the DPA says | risk | ask.

Missing annexes

Bullets, or "None".

Ask the vendor

Numbered by risk: ask - proposed wording or fallback - usually negotiable?

To verify with counsel

Numbered questions.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Compliance
level
Intermediate
made for
Founder / business owner, Operations, Legal professional, Security engineer
risk
read-only
version
v1.1.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install review-data-processing-agreement --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill review-data-processing-agreement -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

pairs well with

All of Compliance
PromptCompliance

Map personal data processing

Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

map-personal-data-processing
PromptCompliance

Plan a personal data breach response

Plans a small organisation's personal data breach response covering containment, risk assessment, notification thresholds and deadlines to verify, notice templates and a breach log.

plan-data-breach-response
PromptCompliance

Build a compliance readiness checklist

Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

build-compliance-checklist
PersonaCompliance

Compliance officer

Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.

compliance-officer
PromptCompliance

Assess EU AI Act obligations

Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

assess-ai-act-obligations
PromptCompliance

Audit a website's privacy compliance

Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.

audit-website-privacy-compliance