LearnGrok
Prompts
PromptIntermediateEveryday workflows

Data processing agreement review checklist

Review supplier DPAs against approved positions and produce a clear departures, gaps and approval checklist for commercial and privacy counsel.

4 min read

Nothing here is legal advice. A draft is a starting point for a qualified person, not a substitute for one.

Use this pack to review a routine supplier DPA against your organisation's approved positions, then produce an assignable list of gaps, departures and decisions. It is for commercial lawyers and privacy counsel who need a review record that a deal team can follow.

Nothing here is legal advice. Each output is a draft work product for a qualified person to check, complete and decide on.

Run the review in order

  1. Start with Source and scope check. Paste the executed or proposed DPA, every annex, and the relevant playbook extracts. Add the supplier agreement where a liability clause, hierarchy clause or service description sits outside the DPA. This prevents the common error of comparing only the main body while the processing schedule or transfer wording changes the result.

  2. Run Clause-by-clause position matrix. Treat this as your evidence record. Keep the DPA clause number in every row. The output should distinguish a true departure from wording that is merely different but permitted as a fallback.

  3. Use Departures and missing terms checklist to create the file's action list. This is the document you can allocate to privacy, security, procurement or the business owner. It should not repeat the matrix in prose.

  4. Run Approval question register only after you know which points cannot be resolved under the playbook. A useful approval question names the supplier position, the internal baseline, the actual choice required and the person who can make it.

  5. Use Client review update when the evidence and decisions are stable. Send it to the internal deal team or use it as the basis for a client message. Keep negotiations, approvals and unresolved facts separate.

Key point

Keep the matrix and checklist separate

The matrix proves what the document says. The checklist says what somebody must do next.

Prepare the material before pasting it

Use the current approved positions, not a remembered version or a prior deal's summary. Include clause-library wording where the organisation has it, but also include permitted fallbacks and the approval route for each exception. A statement such as audit rights required is not enough if security can approve a remote audit alternative.

Label each input clearly. For example, write DPA dated [date], Security schedule version [identifier] and Privacy playbook approved [date]. If you paste several documents, say which prevails if they conflict. If that is unknown, leave it unknown. The prompts are designed to surface it.

Watch out

Do not paste a redline without the base position

A redline shows movement, not the operative clause. Provide the current full text or identify the agreed wording explicitly.

When using document upload or a feature that handles long materials, availability and behaviour can be version-dependent. Check the relevant current information in the xAI documentation overview before relying on a particular workflow for a sensitive matter.

Check the outputs against the documents

Read the matrix beside the DPA. Sample every row marked Aligned, Acceptable fallback or Not applicable, as these are easy to accept without checking. Confirm that the cited clause exists and that the short summary does not omit a qualifier such as where feasible, at supplier's discretion, a notice period or a cost condition.

Then test the checklist:

  • Every Departure or Missing item in the matrix should appear once in the checklist.
  • Every checklist item should state the DPA reference, approved position and next step.
  • An approval question should be a decision, not a request to review the whole clause.
  • A missing fact should be labelled as missing, not silently treated as an assumption.
  • A client update should match the checklist and should not introduce new conclusions.

Check

A reliable review is traceable

You should be able to move from any client-facing statement to a checklist item, then to a matrix row and the source clause.

Know the warning signs

The output is wrong or incomplete if it cites clauses that are not in the DPA, treats a schedule as incorporated when the text does not do so, or fills a playbook gap with a supposed market position. It is also unreliable if it states that a transfer mechanism applies without identifying the actual annex, countries and transfer roles supplied in the documents.

Be especially cautious where the DPA uses defined terms from the main agreement. Ask whether a definition of Confidential Information, Security Measures, Affiliate, Subprocessor or Applicable Law changes the DPA clause. Add the main agreement text to the source check if it does.

Stop

Do not treat a clean-looking checklist as approval

The checklist records the review. The person with the required authority must still decide departures and exceptions.

When the pack does not work

If the first output is broad or vague, do not ask for a better summary. Paste the omitted schedule, the exact playbook section or the definition it lacked, then rerun the relevant prompt. If clause numbering is unreliable after extraction, use page references and short quotations until you can verify the source. If the playbook has no position on a material issue, record No approved position supplied, create an approval or policy question, and avoid presenting an assumed answer as an agreed internal position.

Copy-ready prompts

5 prompts. Open one to read it, or take the whole pack.

1Source and scope checkUse first, when the DPA or approved positions may be incomplete, inconsistent or spread across several documents.
You are assisting commercial and privacy counsel with a routine supplier data processing agreement review. This is not legal advice. Do not make legal conclusions or recommend a negotiating position.

Review the materials below and create a source and scope check.

DPA:
[paste the full DPA, including schedules and annexes]

Approved positions:
[paste the organisation's approved DPA playbook, clause library, fallback positions and approval thresholds]

Related documents, if available:
[paste the supplier agreement, statement of work, security schedule, transfer addendum or other relevant documents]

Return a Markdown table with these columns: Item checked | Source and clause or page reference | Present or missing | Review impact | Question for reviewer.

Check specifically for: parties and roles, processing details, categories of data subjects, personal data categories, documented instructions, confidentiality, security measures, subprocessors, assistance with data subject rights, incident support, audits, deletion or return, international transfers, liability links, term and termination, governing law, order of precedence, signatures and schedules.

Quote short source text only where needed to identify the issue. Do not infer a missing schedule or term from usual market practice. If wording is unclear, conflicting or absent, mark it as Ambiguous or Missing and state exactly what document or fact would resolve it. Finish with: Materials needed before substantive review.
2Clause-by-clause position matrixUse after confirming the materials. It gives you a traceable comparison between the supplier wording and the approved position.
You are comparing a supplier data processing agreement with the organisation's approved positions. This is a drafting and review aid for qualified counsel, not legal advice.

DPA:
[paste the full DPA]

Approved positions:
[paste the approved positions, including acceptable fallback wording and escalation rules]

Create a Markdown clause comparison matrix. Use one row per material topic, even if the DPA has no matching clause.

Use these columns exactly: Topic | DPA clause reference | Supplier position, concise summary | Approved position | Status | Departure or gap | Evidence | Required action.

Use only these Status values: Aligned, Acceptable fallback, Departure, Missing, Ambiguous, Not applicable.

Cover at least: controller and processor roles; processing instructions; processing details; confidentiality; technical and organisational measures; special category or sensitive data; subprocessors; data subject request support; security incident notification and cooperation; DPIAs and regulator support; audit rights; deletion and return; international transfers; retention; liability and indemnities where incorporated; term; precedence; governing law; and amendments.

For Evidence, provide the clause number and a short quotation or precise paraphrase. Do not create clause references. If the approved positions do not address a topic, write No approved position supplied. If a clause could support more than one reading, mark Ambiguous, present both plausible readings briefly, and list the wording or fact that needs confirmation. Do not decide whether the agreement should be signed.
3Departures and missing terms checklistUse this to turn the comparison matrix into the working checklist for the file and the negotiation.
Prepare a supplier DPA review checklist from the materials below. This is not legal advice and must be reviewed by qualified counsel.

Clause comparison matrix:
[paste the completed matrix]

Supplier DPA, if needed for context:
[paste the relevant DPA text]

Approved positions and approval thresholds:
[paste the relevant playbook sections]

Return a Markdown checklist grouped under these headings exactly: Missing terms; Departures from approved positions; Ambiguous wording; Approval questions; Evidence to obtain.

For every checklist item, use this format:
- [ ] Topic: [short issue]. DPA reference: [clause/page or Not present]. Approved position: [short position or No approved position supplied]. Why it matters: [practical contract-review impact]. Proposed next step: [ask, amend, accept under approval, or confirm]. Owner: [Privacy, Commercial legal, Security, Procurement, Business owner, or Other].

List only material, supported issues. Keep each item self-contained so it can be assigned without reopening the matrix. Separate a missing term from a departure in wording. Do not label an item low, medium or high risk unless the supplied approval rules define those labels. Where there is no approval rule, write Approval route not supplied. If source text is incomplete or inconsistent, include an Evidence to obtain item rather than guessing.
4Approval question registerUse where the supplier proposes a fallback, the playbook requires escalation, or the business needs a clear decision from a named owner.
Create an approval question register for a supplier data processing agreement. The purpose is to let the right internal owner make documented decisions. This is not legal advice.

DPA review checklist:
[paste the completed checklist]

Approved positions and approval authority rules:
[paste the relevant approval matrix or playbook]

Business context:
[paste supplier service, data types, countries, planned start date, deal owner and any stated constraints]

Return a Markdown table with these columns exactly: Approval question | Triggering DPA clause | Proposed supplier position | Approved baseline or fallback | Decision needed | Recommended owner | Information needed | Deadline or dependency.

Include only points that need a business, privacy, security, procurement or legal decision. State the decision as a specific choice, not as a general request for review. For example, ask whether a named subprocessor or a stated audit restriction is acceptable under the supplied authority rules.

Do not invent an owner, a deadline, a baseline or a fallback. Use Not supplied where needed. If the question cannot be decided from the materials, identify the missing fact and the person or function most likely to hold it. Finish with a short section titled Decisions not required, listing checklist items that can proceed without escalation.
5Client review updateUse after the checklist and approval register are stable. It produces a short update for the internal deal team or client contact.
Draft a concise internal client update on the review of a supplier data processing agreement. This is a work-product draft for qualified counsel, not legal advice.

Matter details:
[paste client or business unit name, supplier name, service and target signature date if supplied]

Completed checklist:
[paste the departures and missing terms checklist]

Approval question register:
[paste the approval register]

Write in plain British English. Return exactly these sections:
1. Subject line, no more than 12 words.
2. Summary, two sentences stating what has been reviewed and the current position.
3. Supplier changes requested, with up to five bullets. Each must name the topic, the requested change and the relevant clause.
4. Decisions needed from you, with one bullet per approval question. State the decision and the information needed.
5. Next steps, with owner and dependency for each item.

Do not say the DPA is compliant, acceptable, market standard or ready to sign unless that conclusion is expressly supplied in the source material. Do not omit unresolved ambiguity. If no deadline is supplied, do not create one. Where there are no requested changes or no decisions, state None identified from the materials provided.

Last checked against xAI’s own pages on 2026-08-21. Grok changes quickly; anything version-specific should be confirmed upstream before you rely on it.

More in Everyday workflows

Found something out of date?

Grok changes quickly and this page is a snapshot. If something here is wrong, or you know a better resource, send it over.

Suggest a link →

Advertise on LearnGrok

$420.69one-time, for a 30-day run

Square works best. PNG, JPEG or WebP, up to 2 MB.

Stripe on the next step. Live once approved.