Nothing here is legal advice. A draft is a starting point for a qualified person, not a substitute for one.
Use this pack to review a routine supplier DPA against your organisation's approved positions, then produce an assignable list of gaps, departures and decisions. It is for commercial lawyers and privacy counsel who need a review record that a deal team can follow.
Nothing here is legal advice. Each output is a draft work product for a qualified person to check, complete and decide on.
Run the review in order
Start with Source and scope check. Paste the executed or proposed DPA, every annex, and the relevant playbook extracts. Add the supplier agreement where a liability clause, hierarchy clause or service description sits outside the DPA. This prevents the common error of comparing only the main body while the processing schedule or transfer wording changes the result.
Run Clause-by-clause position matrix. Treat this as your evidence record. Keep the DPA clause number in every row. The output should distinguish a true departure from wording that is merely different but permitted as a fallback.
Use Departures and missing terms checklist to create the file's action list. This is the document you can allocate to privacy, security, procurement or the business owner. It should not repeat the matrix in prose.
Run Approval question register only after you know which points cannot be resolved under the playbook. A useful approval question names the supplier position, the internal baseline, the actual choice required and the person who can make it.
Use Client review update when the evidence and decisions are stable. Send it to the internal deal team or use it as the basis for a client message. Keep negotiations, approvals and unresolved facts separate.
Key point
Keep the matrix and checklist separate
The matrix proves what the document says. The checklist says what somebody must do next.
Prepare the material before pasting it
Use the current approved positions, not a remembered version or a prior deal's summary. Include clause-library wording where the organisation has it, but also include permitted fallbacks and the approval route for each exception. A statement such as audit rights required is not enough if security can approve a remote audit alternative.
Label each input clearly. For example, write DPA dated [date], Security schedule version [identifier] and Privacy playbook approved [date]. If you paste several documents, say which prevails if they conflict. If that is unknown, leave it unknown. The prompts are designed to surface it.
Watch out
Do not paste a redline without the base position
A redline shows movement, not the operative clause. Provide the current full text or identify the agreed wording explicitly.
When using document upload or a feature that handles long materials, availability and behaviour can be version-dependent. Check the relevant current information in the xAI documentation overview before relying on a particular workflow for a sensitive matter.
Check the outputs against the documents
Read the matrix beside the DPA. Sample every row marked Aligned, Acceptable fallback or Not applicable, as these are easy to accept without checking. Confirm that the cited clause exists and that the short summary does not omit a qualifier such as where feasible, at supplier's discretion, a notice period or a cost condition.
Then test the checklist:
- Every Departure or Missing item in the matrix should appear once in the checklist.
- Every checklist item should state the DPA reference, approved position and next step.
- An approval question should be a decision, not a request to review the whole clause.
- A missing fact should be labelled as missing, not silently treated as an assumption.
- A client update should match the checklist and should not introduce new conclusions.
Check
A reliable review is traceable
You should be able to move from any client-facing statement to a checklist item, then to a matrix row and the source clause.
Know the warning signs
The output is wrong or incomplete if it cites clauses that are not in the DPA, treats a schedule as incorporated when the text does not do so, or fills a playbook gap with a supposed market position. It is also unreliable if it states that a transfer mechanism applies without identifying the actual annex, countries and transfer roles supplied in the documents.
Be especially cautious where the DPA uses defined terms from the main agreement. Ask whether a definition of Confidential Information, Security Measures, Affiliate, Subprocessor or Applicable Law changes the DPA clause. Add the main agreement text to the source check if it does.
Stop
Do not treat a clean-looking checklist as approval
The checklist records the review. The person with the required authority must still decide departures and exceptions.
When the pack does not work
If the first output is broad or vague, do not ask for a better summary. Paste the omitted schedule, the exact playbook section or the definition it lacked, then rerun the relevant prompt. If clause numbering is unreliable after extraction, use page references and short quotations until you can verify the source. If the playbook has no position on a material issue, record No approved position supplied, create an approval or policy question, and avoid presenting an assumed answer as an agreed internal position.