[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-anthropic-dpa-review":3,"mdc--ubx325-key":37,"related-repo-anthropic-dpa-review":2185,"related-org-anthropic-dpa-review":2283},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":12,"stars":26,"repoUrl":27,"updatedAt":28,"license":29,"forks":30,"topics":31,"repo":32,"sourceUrl":35,"mdContent":36},"dpa-review","review Data Processing Agreements","Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says \"review this DPA\", \"check this data processing addendum\", \"customer sent their DPA\", \"is this DPA okay\", or attaches a DPA.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},"anthropic","Anthropic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Fanthropic.png","anthropics",[13,17,20,23],{"name":14,"slug":15,"type":16},"GDPR","gdpr","tag",{"name":18,"slug":19,"type":16},"Contracts","contracts",{"name":21,"slug":22,"type":16},"Legal","legal",{"name":24,"slug":25,"type":16},"Privacy","privacy",8721,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal","2026-05-14T06:01:10.780083",null,1642,[],{"repoUrl":27,"stars":26,"forks":30,"topics":33,"description":34},[],"A suite of plugins for legal workflows","https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal\u002Ftree\u002FHEAD\u002Fprivacy-legal\u002Fskills\u002Fdpa-review","---\nname: dpa-review\ndescription: >\n  Review a Data Processing Agreement against your DPA playbook — auto-detects\n  whether you're processor or controller and applies the right half of the playbook.\n  Use when the user says \"review this DPA\", \"check this data processing addendum\",\n  \"customer sent their DPA\", \"is this DPA okay\", or attaches a DPA.\nargument-hint: \"[file | Drive link | paste text]\"\n---\n\n# \u002Fdpa-review\n\n1. Load `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → DPA playbook. If placeholders, stop and prompt setup.\n2. Get the DPA. Determine direction: are we processor (customer's DPA) or controller (vendor's)? Ask if ambiguous.\n3. Run the workflow below — term-by-term against the appropriate playbook row.\n4. Run privacy policy consistency check.\n5. Output: review memo with redlines. Save per house style.\n\n```\n\u002Fprivacy-legal:dpa-review customer-dpa.pdf\n```\n\n---\n\n# DPA Review\n\n## Matter context\n\n**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run `\u002Fprivacy-legal:matter-workspace switch \u003Cslug>` or say `practice-level`.\" Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F`. Never read another matter's files unless `Cross-matter context` is `on`.\n\n---\n\n## Purpose\n\nDPAs come in two flavors and the review is nearly opposite for each. When a customer sends their DPA, we're defending our operational flexibility. When we send one to a vendor, we're protecting our (and our customers') data. Both reviews read from the same `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` playbook but from opposite rows.\n\n## First: which direction?\n\nBefore anything else, establish:\n\n- **We are the processor** → customer is sending us their DPA → read `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → \"When we are the processor\" table\n- **We are the controller** → we're sending a DPA to a vendor (or reviewing theirs) → read \"When we are the controller\" table\n\nIf unclear, ask. Getting this wrong inverts every recommendation.\n\n## Jurisdiction assumption\n\nThis review assumes the jurisdictional scope specified in your configuration. Privacy rules, response deadlines, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the controller, processor, or data subjects are in a different jurisdiction than configured, this review may not apply as written.\n\n## Load prior context on this counterparty \u002F activity\n\nBefore reviewing, check the outputs folder for prior work on this counterparty or processing activity. Read `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Outputs` for the outputs folder path. Scan for:\n\n- **Prior `use-case-triage` results** for the same counterparty \u002F processing activity — the triage produces a risk rating and conditions that this DPA review should honor or explicitly depart from.\n- **Prior `pia-generation` outputs** covering this counterparty \u002F processing activity — the PIA may have flagged risk mitigations the DPA needs to implement.\n- **Prior `dpa-review` outputs** for the same counterparty — earlier DPA reviews set expectations about what was acceptable, what was flagged, and what was settled. A fresh review that silently contradicts the earlier one erodes trust in the work product.\n\nIf a prior output is found, cite it in the review:\n\n> \"Prior triage ([date]) rated this [risk level] and conditioned approval on [X]. This DPA review is consistent with that finding.\" — or —\n> \"Prior triage ([date]) rated this [risk level]. This DPA review departs from that finding because [reason — new facts, different scope, contract term that changed the picture].\"\n\n**Carry severity from the upstream output as a floor** per the cross-skill severity floor rule in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Shared guardrails`. A processing activity the triage rated 🔴 cannot be quietly downgraded to 🟢 in the DPA review; any demotion is stated and explained.\n\nIf no prior output is found (new counterparty \u002F new activity), say so explicitly in the review — \"No prior triage or PIA on this counterparty in outputs folder\" — so the reviewing attorney knows the check ran.\n\n## Load the playbook\n\nRead `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## DPA playbook`. Also read `## Privacy policy commitments` — the DPA can't contradict what the privacy policy promises.\n\n## Federal sectoral overlay (ask first, before the term-by-term walk)\n\nBefore walking the term-by-term review, answer: **does the data flowing through this DPA include any federally-regulated category?** GDPR and state consumer-privacy law supply one floor; federal sectoral law often supplies another that does not appear in the generic DPA playbook. A DPA that is GDPR-complete can still be GLBA-blind, HIPAA-blind, or COPPA-blind, and a fintech \u002F healthtech \u002F edtech \u002F kidtech counterparty will notice.\n\n> **Activity-based federal overlays — ask first:**\n>\n> Does this processing touch:\n> - **Financial account data or \"nonpublic personal information\" about consumers** (GLBA \u002F Reg P)? If yes, the DPA needs: (a) an NPI-sharing restriction consistent with 15 U.S.C. § 6802(a)-(c) and Reg P (no sharing for marketing to non-affiliated third parties without opt-out \u002F opt-in), (b) safeguards language aligned with the Safeguards Rule (16 C.F.R. Part 314), (c) incident notification that reaches FTC\u002FOCC timing where applicable, (d) a clean carve-out so a CCPA § 1798.145(e) exemption doesn't accidentally waive GLBA-level obligations.\n> - **Protected health information held by a covered entity or business associate** (HIPAA Privacy \u002F Security Rules)? If yes, the DPA needs: a Business Associate Agreement (BAA) layered with or integrated into the DPA per 45 C.F.R. § 164.504(e), breach notification timing aligned with HITECH (60 days to CE; CE 60 days to HHS; 500+ threshold for media), permitted-uses clause, subcontractor BAA flow-down. A commercial DPA without BAA flow-down for PHI is a defect.\n> - **Education records held by a school or a service provider acting for a school** (FERPA)? If yes, the DPA needs: a \"school official\" \u002F directory-information framing consistent with 34 C.F.R. § 99.31, parental-consent flow-through, state student-privacy analog handling (NY Ed Law 2-d, CA SOPIPA, IL SOPPA).\n> - **Data from children under 13 collected by an operator of an online service directed to children or with actual knowledge** (COPPA)? If yes, the DPA needs: verifiable-parental-consent flow-through, retention limits, deletion-on-request machinery, prohibition on behavioral advertising absent VPC.\n> - **Another sectoral federal regime** (VPPA for video-viewing records, CPNI for carrier data, DPPA for DMV records, TCPA \u002F Shaken-Stir for call\u002FSMS, GLBA Reg S-P for broker-dealers, §5 FTC Act for unfair\u002Fdeceptive practices around sensitive data)?\n>\n> If yes to any: the federal overlay usually supplies the controlling substantive restriction, not just an exemption from a state consumer privacy law. Research the currently-operative provision and cite it. A DPA that is \"exempt\" from CCPA under § 1798.145(e) because it is GLBA-covered is still subject to the GLBA restrictions — the CCPA exemption moves the governing framework, it doesn't eliminate it. Flag sectoral gaps in the deal-breakers list alongside GDPR \u002F state-privacy gaps.\n\nIf no sectoral overlay applies, note that explicitly — \"no federally-regulated data categories identified; sectoral overlay n\u002Fa\" — so the reviewing attorney sees that the check happened, rather than wondering whether it was skipped.\n\n## The term-by-term review\n\n### Core terms (check every DPA)\n\nWalk every DPA through these terms, clause by clause. The *specific* numeric and substantive positions (notice periods, breach timelines, acceptable\u002Funacceptable floors) come from `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## DPA playbook`. The regulatory floors that any DPA has to clear come from primary law — **research the currently operative rule** for each applicable regime and cite primary sources before stating a floor.\n\n> **No silent supplement.** If a research query to the configured legal research tool returns few or no results for a regime's breach window, transfer-mechanism requirement, subprocessor-change rule, or any other floor, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: \"The search returned [N] results from [tool]. Coverage appears thin for [regime \u002F topic]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged `[web search — verify]` and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?\" A lawyer decides whether to accept lower-confidence sources.\n>\n> **Source attribution tiering.** Tag every citation in the review — regulatory floors, SCC versions, adequacy decisions, regulator guidance, case law — with its source. For model-knowledge citations, use one of three tiers rather than a single blanket \"verify\" tag:\n>\n> - `[settled]` — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 28, Art. 33 72-hour breach notice, SCC Decision 2021\u002F914 by number). Still verify before filing, but lower priority.\n> - `[verify]` — model-knowledge citations that are real but should be verified: specific implementing regulations, regulator guidance, case holdings, adequacy decisions, SCC modules and versions, UK Addendum \u002F IDTA status, thresholds, effective dates.\n> - `[verify-pinpoint]` — pinpoint citations (specific subsection letters, clause numbers within SCCs, paragraph numbers, volume\u002Fpage references) carry the highest fabrication risk and should ALWAYS be verified against a primary source.\n>\n> Tool-retrieved citations keep their source tag (`[Westlaw]`, `[Commission \u002F regulator site]`, or the MCP tool name); web-search citations remain `[web search — verify]`; user-supplied citations remain `[user provided]`. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.\n\n| Term | Looking for | Playbook field | Common fights |\n|---|---|---|---|\n| **Roles** | Clear controller\u002Fprocessor designation; matches reality | — | Counterparty labels the relationship (e.g., \"joint controller\") in a way that doesn't match reality |\n| **Processing scope** | Limited to documented instructions; defined purposes | — | Open-ended scope expanders (\"and related purposes\") |\n| **Subprocessors** | Current list disclosed, change mechanism defined | Subprocessor changes | Blanket approval vs. veto vs. notice-only |\n| **Security measures** | Annex references specific controls or standards | Security standards | \"appropriate technical and organizational measures\" with no annex = empty promise |\n| **Breach notification** | Defined trigger (\"discovery\" vs \"confirmation\"), defined timeline | Breach notification | Timeline tightness; clock trigger; \"without undue delay\" is vague |\n| **Audit rights** | Method (report vs. on-site), frequency, notice, cost allocation | Audit rights | On-site audits on tight notice |\n| **International transfers** | Transfer mechanism identified, supplementary measures, transfer impact assessment reference | Transfers | Outdated or missing transfer mechanisms |\n| **Deletion\u002Freturn** | Timeline post-termination, certification, backup carveout | Deletion on termination | \"Commercially reasonable\" deletion = ??? |\n| **Liability** | Within MSA cap or separate; carveouts | Liability for data | Uncapped data breach liability = existential |\n\n### When we're the processor: defensive review\n\nCustomer DPAs try to push operational burden onto us. For each clause below, compare the customer's ask to the playbook. Where the customer's ask is outside the playbook, push back to the team's standard position (from the config CLAUDE.md) and be ready to fall back to the acceptable position.\n\n| Clause | Risk | Research \u002F playbook lookup |\n|---|---|---|\n| Subprocessor approval right (veto) | Can't add infrastructure without customer-by-customer approval | Apply playbook position on subprocessor changes |\n| On-site audit on short notice | Unworkable at scale | Apply playbook position on audit rights |\n| Aggressive breach notification window | Often demands notice before we know what happened | Research the regulatory floor for each applicable regime (cite primary sources); compare to playbook position |\n| Hard data residency (single country\u002FDC) | May not match architecture | Apply playbook position on data location; confirm what we can actually commit to |\n| Processor liability uncapped | Bet-the-company | Apply playbook position on liability for data |\n| Customer may issue binding \"instructions\" | Open-ended operational control | Define instructions as \"documented in the Agreement or agreed in writing\" |\n| Deletion on very short timeline | Backup and log retention makes this impossible | Apply playbook position on deletion on termination; document backup rotation carveout |\n\n### When we're the controller: protective review\n\nVendor DPAs try to give us nothing. For each clause below, compare to the controller-side playbook.\n\n| Clause | Gap | Research \u002F playbook lookup |\n|---|---|---|\n| No subprocessor list | Don't know who touches our data | Require published current list + advance notice per playbook |\n| \"Industry standard security\" | Means nothing | Require annex with specific controls, or reference to a named standard (e.g., SOC 2, ISO 27001) |\n| No breach notification timeline | They tell us whenever | Research applicable regulatory floor; require playbook position |\n| No audit rights at all | Can't verify anything | Require at minimum an independent audit report per playbook |\n| Vendor can use data for \"service improvement\" | Potential training on our data | Strike; processing limited to providing the service to us |\n| No international transfer mechanism | No lawful transfer mechanism | **Research the currently operative transfer mechanism** for the corridor in question (origin\u002Fdestination jurisdictions, applicable regime, any adequacy decision, any supplementary measures). Cite primary sources and verify currency. |\n| No deletion commitment | Data lives forever | Require playbook position on deletion + certification on request |\n\n## Consistency check: privacy policy\n\nThe DPA you sign can't promise something the privacy policy doesn't cover, and vice versa.\n\n- If the DPA commits to processing only for purposes X, Y, Z — does the privacy policy list those purposes?\n- If the privacy policy says \"we never sell data\" — does any DPA clause look like a sale under CCPA?\n- If the privacy policy names specific subprocessor categories — does the DPA subprocessor list match?\n\nFlag mismatches. They're usually the privacy policy being stale, not the DPA being wrong, but someone needs to fix one of them.\n\n## Redline granularity\n\n**Edit at the smallest possible granularity.** A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals \"we threw out your drafting\" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal \"we have specific asks\" and are faster to read, understand, and accept.\n\nDefault to the smallest edit that achieves the playbook position:\n- Replace a **word** before a phrase. (\"twelve (12)\" → \"twenty-four (24)\")\n- Replace a **phrase** before a sentence. (\"paid by the Buyer\" → \"paid and payable by the Buyer\")\n- Restructure a **subclause** before replacing the sentence. (Add \"(a)\" and \"(b)\" to split a compound condition.)\n- Replace a **sentence** before replacing the clause.\n- Only replace a **whole clause** when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: \"We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta.\"\n\nWhen in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.\n\n## Output\n\nPrepend the work-product header from `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` `## Outputs` (it differs by user role — see `## Who's using this`).\n\n```markdown\n[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n\n# DPA Review: [Counterparty]\n\n**Direction:** [We are processor \u002F We are controller]\n**Reviewed:** [date]\n**Attached to:** [MSA \u002F standalone]\n\n---\n\n## Bottom line\n\n[Two sentences. Can we sign? What has to change?]\n\n**Issues:** [N]🟢 [N]🟡 [N]🟠 [N]🔴\n\n---\n\n## Term-by-term\n\n[For each core term, use a standard deviation-memo format: what the\ncounterparty's DPA says, what our playbook says, the gap, the risk, and the\nproposed redline language. Keep each term to a short self-contained block so a\nreviewer can skim.]\n\n---\n\n## Privacy policy consistency\n\n[🟢 Consistent | 🟡 Flags: list]\n\n---\n\n## Recommended redlines\n\n[Consolidated — ready to send back]\n\n---\n\n## If they won't move\n\n[For each issue: the fallback from the config CLAUDE.md, or escalation routing if no\nfallback exists]\n```\n\n## International transfers note\n\nIf the DPA contemplates cross-border data transfers, **research the currently operative transfer mechanism requirements** for the applicable corridor(s). For each origin\u002Fdestination pair, identify: the applicable regime, whether any adequacy decision is in force, which transfer mechanism is required or available (e.g., Standard Contractual Clauses and their applicable version\u002Fmodule, UK Addendum or IDTA, BCRs, derogations), whether a transfer impact assessment or equivalent is required, and what supplementary measures may be needed. Cite primary sources (regulation, Commission decision, regulator guidance, controlling case law) with pinpoint cites and verify currency — adequacy decisions, SCC versions, and required supplementary measures change through new Commission decisions, court rulings, and regulator guidance. Flag uncertainty for attorney verification.\n\nIf a transfer mechanism is missing and there is an international transfer, that is a 🔴 — there is no lawful transfer mechanism.\n\n## Gate: signing a DPA\n\nReviewing a DPA is research. *Signing* it — or instructing someone to countersign on our behalf — is the consequential act.\n\n**Before proceeding to sign or countersign a DPA (including returning an executed version, consenting to automatic execution on a counterparty platform, or instructing a signatory to execute):** Read `## Who's using this` in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. If the Role is Non-lawyer:\n\n> Signing a DPA is a legal act — it binds the company to specific data-protection obligations that flow to regulators and data subjects. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:\n>\n> [Generate a 1-page summary: counterparty, direction (we are processor \u002F controller), the terms that deviate from the playbook and how they were resolved, any open fallback decisions, and the three things to ask the attorney before executing.]\n>\n> If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA\u002FBar Standards Board in England & Wales, Law Society in Scotland\u002FNI\u002FIreland\u002FCanada\u002FAustralia, or your jurisdiction's equivalent).\n\nDo not proceed past this gate without an explicit yes.\n\n## Close with the next-steps decision tree\n\nEnd with the next-steps decision tree per CLAUDE.md `## Outputs`. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.\n\n## What this skill does not do\n\n- It doesn't draft a DPA from scratch. If the answer is \"use our template,\" pull the template from the seed docs path in the config CLAUDE.md.\n- It doesn't do the Transfer Impact Assessment itself — it flags when one is needed.\n- It doesn't decide whether to accept terms outside the fallbacks. It routes those per the escalation table.\n",{"data":38,"body":40},{"name":4,"description":6,"argument-hint":39},"[file | Drive link | paste text]",{"type":41,"children":42},"root",[43,51,90,102,106,112,119,202,205,211,223,229,234,265,270,276,281,287,307,360,365,414,438,443,449,476,482,494,568,573,579,586,619,743,1012,1018,1023,1176,1182,1187,1343,1349,1354,1372,1377,1383,1393,1398,1459,1464,1470,1497,2046,2052,2064,2069,2075,2087,2111,2132,2137,2143,2155,2161,2179],{"type":44,"tag":45,"props":46,"children":47},"element","h1",{"id":4},[48],{"type":49,"value":50},"text","\u002Fdpa-review",{"type":44,"tag":52,"props":53,"children":54},"ol",{},[55,70,75,80,85],{"type":44,"tag":56,"props":57,"children":58},"li",{},[59,61,68],{"type":49,"value":60},"Load ",{"type":44,"tag":62,"props":63,"children":65},"code",{"className":64},[],[66],{"type":49,"value":67},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md",{"type":49,"value":69}," → DPA playbook. If placeholders, stop and prompt setup.",{"type":44,"tag":56,"props":71,"children":72},{},[73],{"type":49,"value":74},"Get the DPA. Determine direction: are we processor (customer's DPA) or controller (vendor's)? Ask if ambiguous.",{"type":44,"tag":56,"props":76,"children":77},{},[78],{"type":49,"value":79},"Run the workflow below — term-by-term against the appropriate playbook row.",{"type":44,"tag":56,"props":81,"children":82},{},[83],{"type":49,"value":84},"Run privacy policy consistency check.",{"type":44,"tag":56,"props":86,"children":87},{},[88],{"type":49,"value":89},"Output: review memo with redlines. Save per house style.",{"type":44,"tag":91,"props":92,"children":96},"pre",{"className":93,"code":95,"language":49},[94],"language-text","\u002Fprivacy-legal:dpa-review customer-dpa.pdf\n",[97],{"type":44,"tag":62,"props":98,"children":100},{"__ignoreMap":99},"",[101],{"type":49,"value":95},{"type":44,"tag":103,"props":104,"children":105},"hr",{},[],{"type":44,"tag":45,"props":107,"children":109},{"id":108},"dpa-review-1",[110],{"type":49,"value":111},"DPA Review",{"type":44,"tag":113,"props":114,"children":116},"h2",{"id":115},"matter-context",[117],{"type":49,"value":118},"Matter context",{"type":44,"tag":120,"props":121,"children":122},"p",{},[123,129,131,137,139,145,147,153,155,161,163,169,171,177,179,185,187,193,194,200],{"type":44,"tag":124,"props":125,"children":126},"strong",{},[127],{"type":49,"value":128},"Matter context.",{"type":49,"value":130}," Check ",{"type":44,"tag":62,"props":132,"children":134},{"className":133},[],[135],{"type":49,"value":136},"## Matter workspaces",{"type":49,"value":138}," in the practice-level CLAUDE.md. If ",{"type":44,"tag":62,"props":140,"children":142},{"className":141},[],[143],{"type":49,"value":144},"Enabled",{"type":49,"value":146}," is ",{"type":44,"tag":62,"props":148,"children":150},{"className":149},[],[151],{"type":49,"value":152},"✗",{"type":49,"value":154}," (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run ",{"type":44,"tag":62,"props":156,"children":158},{"className":157},[],[159],{"type":49,"value":160},"\u002Fprivacy-legal:matter-workspace switch \u003Cslug>",{"type":49,"value":162}," or say ",{"type":44,"tag":62,"props":164,"children":166},{"className":165},[],[167],{"type":49,"value":168},"practice-level",{"type":49,"value":170},".\" Load the active matter's ",{"type":44,"tag":62,"props":172,"children":174},{"className":173},[],[175],{"type":49,"value":176},"matter.md",{"type":49,"value":178}," for matter-specific context and overrides. Write outputs to the matter folder at ",{"type":44,"tag":62,"props":180,"children":182},{"className":181},[],[183],{"type":49,"value":184},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F",{"type":49,"value":186},". Never read another matter's files unless ",{"type":44,"tag":62,"props":188,"children":190},{"className":189},[],[191],{"type":49,"value":192},"Cross-matter context",{"type":49,"value":146},{"type":44,"tag":62,"props":195,"children":197},{"className":196},[],[198],{"type":49,"value":199},"on",{"type":49,"value":201},".",{"type":44,"tag":103,"props":203,"children":204},{},[],{"type":44,"tag":113,"props":206,"children":208},{"id":207},"purpose",[209],{"type":49,"value":210},"Purpose",{"type":44,"tag":120,"props":212,"children":213},{},[214,216,221],{"type":49,"value":215},"DPAs come in two flavors and the review is nearly opposite for each. When a customer sends their DPA, we're defending our operational flexibility. When we send one to a vendor, we're protecting our (and our customers') data. Both reviews read from the same ",{"type":44,"tag":62,"props":217,"children":219},{"className":218},[],[220],{"type":49,"value":67},{"type":49,"value":222}," playbook but from opposite rows.",{"type":44,"tag":113,"props":224,"children":226},{"id":225},"first-which-direction",[227],{"type":49,"value":228},"First: which direction?",{"type":44,"tag":120,"props":230,"children":231},{},[232],{"type":49,"value":233},"Before anything else, establish:",{"type":44,"tag":235,"props":236,"children":237},"ul",{},[238,255],{"type":44,"tag":56,"props":239,"children":240},{},[241,246,248,253],{"type":44,"tag":124,"props":242,"children":243},{},[244],{"type":49,"value":245},"We are the processor",{"type":49,"value":247}," → customer is sending us their DPA → read ",{"type":44,"tag":62,"props":249,"children":251},{"className":250},[],[252],{"type":49,"value":67},{"type":49,"value":254}," → \"When we are the processor\" table",{"type":44,"tag":56,"props":256,"children":257},{},[258,263],{"type":44,"tag":124,"props":259,"children":260},{},[261],{"type":49,"value":262},"We are the controller",{"type":49,"value":264}," → we're sending a DPA to a vendor (or reviewing theirs) → read \"When we are the controller\" table",{"type":44,"tag":120,"props":266,"children":267},{},[268],{"type":49,"value":269},"If unclear, ask. Getting this wrong inverts every recommendation.",{"type":44,"tag":113,"props":271,"children":273},{"id":272},"jurisdiction-assumption",[274],{"type":49,"value":275},"Jurisdiction assumption",{"type":44,"tag":120,"props":277,"children":278},{},[279],{"type":49,"value":280},"This review assumes the jurisdictional scope specified in your configuration. Privacy rules, response deadlines, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the controller, processor, or data subjects are in a different jurisdiction than configured, this review may not apply as written.",{"type":44,"tag":113,"props":282,"children":284},{"id":283},"load-prior-context-on-this-counterparty-activity",[285],{"type":49,"value":286},"Load prior context on this counterparty \u002F activity",{"type":44,"tag":120,"props":288,"children":289},{},[290,292,297,299,305],{"type":49,"value":291},"Before reviewing, check the outputs folder for prior work on this counterparty or processing activity. Read ",{"type":44,"tag":62,"props":293,"children":295},{"className":294},[],[296],{"type":49,"value":67},{"type":49,"value":298}," → ",{"type":44,"tag":62,"props":300,"children":302},{"className":301},[],[303],{"type":49,"value":304},"## Outputs",{"type":49,"value":306}," for the outputs folder path. Scan for:",{"type":44,"tag":235,"props":308,"children":309},{},[310,328,345],{"type":44,"tag":56,"props":311,"children":312},{},[313,326],{"type":44,"tag":124,"props":314,"children":315},{},[316,318,324],{"type":49,"value":317},"Prior ",{"type":44,"tag":62,"props":319,"children":321},{"className":320},[],[322],{"type":49,"value":323},"use-case-triage",{"type":49,"value":325}," results",{"type":49,"value":327}," for the same counterparty \u002F processing activity — the triage produces a risk rating and conditions that this DPA review should honor or explicitly depart from.",{"type":44,"tag":56,"props":329,"children":330},{},[331,343],{"type":44,"tag":124,"props":332,"children":333},{},[334,335,341],{"type":49,"value":317},{"type":44,"tag":62,"props":336,"children":338},{"className":337},[],[339],{"type":49,"value":340},"pia-generation",{"type":49,"value":342}," outputs",{"type":49,"value":344}," covering this counterparty \u002F processing activity — the PIA may have flagged risk mitigations the DPA needs to implement.",{"type":44,"tag":56,"props":346,"children":347},{},[348,358],{"type":44,"tag":124,"props":349,"children":350},{},[351,352,357],{"type":49,"value":317},{"type":44,"tag":62,"props":353,"children":355},{"className":354},[],[356],{"type":49,"value":4},{"type":49,"value":342},{"type":49,"value":359}," for the same counterparty — earlier DPA reviews set expectations about what was acceptable, what was flagged, and what was settled. A fresh review that silently contradicts the earlier one erodes trust in the work product.",{"type":44,"tag":120,"props":361,"children":362},{},[363],{"type":49,"value":364},"If a prior output is found, cite it in the review:",{"type":44,"tag":366,"props":367,"children":368},"blockquote",{},[369],{"type":44,"tag":120,"props":370,"children":371},{},[372,374,380,382,387,389,394,396,400,401,405,407,412],{"type":49,"value":373},"\"Prior triage (",{"type":44,"tag":375,"props":376,"children":377},"span",{},[378],{"type":49,"value":379},"date",{"type":49,"value":381},") rated this ",{"type":44,"tag":375,"props":383,"children":384},{},[385],{"type":49,"value":386},"risk level",{"type":49,"value":388}," and conditioned approval on ",{"type":44,"tag":375,"props":390,"children":391},{},[392],{"type":49,"value":393},"X",{"type":49,"value":395},". This DPA review is consistent with that finding.\" — or —\n\"Prior triage (",{"type":44,"tag":375,"props":397,"children":398},{},[399],{"type":49,"value":379},{"type":49,"value":381},{"type":44,"tag":375,"props":402,"children":403},{},[404],{"type":49,"value":386},{"type":49,"value":406},". This DPA review departs from that finding because ",{"type":44,"tag":375,"props":408,"children":409},{},[410],{"type":49,"value":411},"reason — new facts, different scope, contract term that changed the picture",{"type":49,"value":413},".\"",{"type":44,"tag":120,"props":415,"children":416},{},[417,422,424,429,430,436],{"type":44,"tag":124,"props":418,"children":419},{},[420],{"type":49,"value":421},"Carry severity from the upstream output as a floor",{"type":49,"value":423}," per the cross-skill severity floor rule in ",{"type":44,"tag":62,"props":425,"children":427},{"className":426},[],[428],{"type":49,"value":67},{"type":49,"value":298},{"type":44,"tag":62,"props":431,"children":433},{"className":432},[],[434],{"type":49,"value":435},"## Shared guardrails",{"type":49,"value":437},". A processing activity the triage rated 🔴 cannot be quietly downgraded to 🟢 in the DPA review; any demotion is stated and explained.",{"type":44,"tag":120,"props":439,"children":440},{},[441],{"type":49,"value":442},"If no prior output is found (new counterparty \u002F new activity), say so explicitly in the review — \"No prior triage or PIA on this counterparty in outputs folder\" — so the reviewing attorney knows the check ran.",{"type":44,"tag":113,"props":444,"children":446},{"id":445},"load-the-playbook",[447],{"type":49,"value":448},"Load the playbook",{"type":44,"tag":120,"props":450,"children":451},{},[452,454,459,460,466,468,474],{"type":49,"value":453},"Read ",{"type":44,"tag":62,"props":455,"children":457},{"className":456},[],[458],{"type":49,"value":67},{"type":49,"value":298},{"type":44,"tag":62,"props":461,"children":463},{"className":462},[],[464],{"type":49,"value":465},"## DPA playbook",{"type":49,"value":467},". Also read ",{"type":44,"tag":62,"props":469,"children":471},{"className":470},[],[472],{"type":49,"value":473},"## Privacy policy commitments",{"type":49,"value":475}," — the DPA can't contradict what the privacy policy promises.",{"type":44,"tag":113,"props":477,"children":479},{"id":478},"federal-sectoral-overlay-ask-first-before-the-term-by-term-walk",[480],{"type":49,"value":481},"Federal sectoral overlay (ask first, before the term-by-term walk)",{"type":44,"tag":120,"props":483,"children":484},{},[485,487,492],{"type":49,"value":486},"Before walking the term-by-term review, answer: ",{"type":44,"tag":124,"props":488,"children":489},{},[490],{"type":49,"value":491},"does the data flowing through this DPA include any federally-regulated category?",{"type":49,"value":493}," GDPR and state consumer-privacy law supply one floor; federal sectoral law often supplies another that does not appear in the generic DPA playbook. A DPA that is GDPR-complete can still be GLBA-blind, HIPAA-blind, or COPPA-blind, and a fintech \u002F healthtech \u002F edtech \u002F kidtech counterparty will notice.",{"type":44,"tag":366,"props":495,"children":496},{},[497,505,510,563],{"type":44,"tag":120,"props":498,"children":499},{},[500],{"type":44,"tag":124,"props":501,"children":502},{},[503],{"type":49,"value":504},"Activity-based federal overlays — ask first:",{"type":44,"tag":120,"props":506,"children":507},{},[508],{"type":49,"value":509},"Does this processing touch:",{"type":44,"tag":235,"props":511,"children":512},{},[513,523,533,543,553],{"type":44,"tag":56,"props":514,"children":515},{},[516,521],{"type":44,"tag":124,"props":517,"children":518},{},[519],{"type":49,"value":520},"Financial account data or \"nonpublic personal information\" about consumers",{"type":49,"value":522}," (GLBA \u002F Reg P)? If yes, the DPA needs: (a) an NPI-sharing restriction consistent with 15 U.S.C. § 6802(a)-(c) and Reg P (no sharing for marketing to non-affiliated third parties without opt-out \u002F opt-in), (b) safeguards language aligned with the Safeguards Rule (16 C.F.R. Part 314), (c) incident notification that reaches FTC\u002FOCC timing where applicable, (d) a clean carve-out so a CCPA § 1798.145(e) exemption doesn't accidentally waive GLBA-level obligations.",{"type":44,"tag":56,"props":524,"children":525},{},[526,531],{"type":44,"tag":124,"props":527,"children":528},{},[529],{"type":49,"value":530},"Protected health information held by a covered entity or business associate",{"type":49,"value":532}," (HIPAA Privacy \u002F Security Rules)? If yes, the DPA needs: a Business Associate Agreement (BAA) layered with or integrated into the DPA per 45 C.F.R. § 164.504(e), breach notification timing aligned with HITECH (60 days to CE; CE 60 days to HHS; 500+ threshold for media), permitted-uses clause, subcontractor BAA flow-down. A commercial DPA without BAA flow-down for PHI is a defect.",{"type":44,"tag":56,"props":534,"children":535},{},[536,541],{"type":44,"tag":124,"props":537,"children":538},{},[539],{"type":49,"value":540},"Education records held by a school or a service provider acting for a school",{"type":49,"value":542}," (FERPA)? If yes, the DPA needs: a \"school official\" \u002F directory-information framing consistent with 34 C.F.R. § 99.31, parental-consent flow-through, state student-privacy analog handling (NY Ed Law 2-d, CA SOPIPA, IL SOPPA).",{"type":44,"tag":56,"props":544,"children":545},{},[546,551],{"type":44,"tag":124,"props":547,"children":548},{},[549],{"type":49,"value":550},"Data from children under 13 collected by an operator of an online service directed to children or with actual knowledge",{"type":49,"value":552}," (COPPA)? If yes, the DPA needs: verifiable-parental-consent flow-through, retention limits, deletion-on-request machinery, prohibition on behavioral advertising absent VPC.",{"type":44,"tag":56,"props":554,"children":555},{},[556,561],{"type":44,"tag":124,"props":557,"children":558},{},[559],{"type":49,"value":560},"Another sectoral federal regime",{"type":49,"value":562}," (VPPA for video-viewing records, CPNI for carrier data, DPPA for DMV records, TCPA \u002F Shaken-Stir for call\u002FSMS, GLBA Reg S-P for broker-dealers, §5 FTC Act for unfair\u002Fdeceptive practices around sensitive data)?",{"type":44,"tag":120,"props":564,"children":565},{},[566],{"type":49,"value":567},"If yes to any: the federal overlay usually supplies the controlling substantive restriction, not just an exemption from a state consumer privacy law. Research the currently-operative provision and cite it. A DPA that is \"exempt\" from CCPA under § 1798.145(e) because it is GLBA-covered is still subject to the GLBA restrictions — the CCPA exemption moves the governing framework, it doesn't eliminate it. Flag sectoral gaps in the deal-breakers list alongside GDPR \u002F state-privacy gaps.",{"type":44,"tag":120,"props":569,"children":570},{},[571],{"type":49,"value":572},"If no sectoral overlay applies, note that explicitly — \"no federally-regulated data categories identified; sectoral overlay n\u002Fa\" — so the reviewing attorney sees that the check happened, rather than wondering whether it was skipped.",{"type":44,"tag":113,"props":574,"children":576},{"id":575},"the-term-by-term-review",[577],{"type":49,"value":578},"The term-by-term review",{"type":44,"tag":580,"props":581,"children":583},"h3",{"id":582},"core-terms-check-every-dpa",[584],{"type":49,"value":585},"Core terms (check every DPA)",{"type":44,"tag":120,"props":587,"children":588},{},[589,591,597,599,604,605,610,612,617],{"type":49,"value":590},"Walk every DPA through these terms, clause by clause. The ",{"type":44,"tag":592,"props":593,"children":594},"em",{},[595],{"type":49,"value":596},"specific",{"type":49,"value":598}," numeric and substantive positions (notice periods, breach timelines, acceptable\u002Funacceptable floors) come from ",{"type":44,"tag":62,"props":600,"children":602},{"className":601},[],[603],{"type":49,"value":67},{"type":49,"value":298},{"type":44,"tag":62,"props":606,"children":608},{"className":607},[],[609],{"type":49,"value":465},{"type":49,"value":611},". The regulatory floors that any DPA has to clear come from primary law — ",{"type":44,"tag":124,"props":613,"children":614},{},[615],{"type":49,"value":616},"research the currently operative rule",{"type":49,"value":618}," for each applicable regime and cite primary sources before stating a floor.",{"type":44,"tag":366,"props":620,"children":621},{},[622,661,671,707],{"type":44,"tag":120,"props":623,"children":624},{},[625,630,632,637,639,644,646,651,653,659],{"type":44,"tag":124,"props":626,"children":627},{},[628],{"type":49,"value":629},"No silent supplement.",{"type":49,"value":631}," If a research query to the configured legal research tool returns few or no results for a regime's breach window, transfer-mechanism requirement, subprocessor-change rule, or any other floor, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: \"The search returned ",{"type":44,"tag":375,"props":633,"children":634},{},[635],{"type":49,"value":636},"N",{"type":49,"value":638}," results from ",{"type":44,"tag":375,"props":640,"children":641},{},[642],{"type":49,"value":643},"tool",{"type":49,"value":645},". Coverage appears thin for ",{"type":44,"tag":375,"props":647,"children":648},{},[649],{"type":49,"value":650},"regime \u002F topic",{"type":49,"value":652},". Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged ",{"type":44,"tag":62,"props":654,"children":656},{"className":655},[],[657],{"type":49,"value":658},"[web search — verify]",{"type":49,"value":660}," and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?\" A lawyer decides whether to accept lower-confidence sources.",{"type":44,"tag":120,"props":662,"children":663},{},[664,669],{"type":44,"tag":124,"props":665,"children":666},{},[667],{"type":49,"value":668},"Source attribution tiering.",{"type":49,"value":670}," Tag every citation in the review — regulatory floors, SCC versions, adequacy decisions, regulator guidance, case law — with its source. For model-knowledge citations, use one of three tiers rather than a single blanket \"verify\" tag:",{"type":44,"tag":235,"props":672,"children":673},{},[674,685,696],{"type":44,"tag":56,"props":675,"children":676},{},[677,683],{"type":44,"tag":62,"props":678,"children":680},{"className":679},[],[681],{"type":49,"value":682},"[settled]",{"type":49,"value":684}," — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 28, Art. 33 72-hour breach notice, SCC Decision 2021\u002F914 by number). Still verify before filing, but lower priority.",{"type":44,"tag":56,"props":686,"children":687},{},[688,694],{"type":44,"tag":62,"props":689,"children":691},{"className":690},[],[692],{"type":49,"value":693},"[verify]",{"type":49,"value":695}," — model-knowledge citations that are real but should be verified: specific implementing regulations, regulator guidance, case holdings, adequacy decisions, SCC modules and versions, UK Addendum \u002F IDTA status, thresholds, effective dates.",{"type":44,"tag":56,"props":697,"children":698},{},[699,705],{"type":44,"tag":62,"props":700,"children":702},{"className":701},[],[703],{"type":49,"value":704},"[verify-pinpoint]",{"type":49,"value":706}," — pinpoint citations (specific subsection letters, clause numbers within SCCs, paragraph numbers, volume\u002Fpage references) carry the highest fabrication risk and should ALWAYS be verified against a primary source.",{"type":44,"tag":120,"props":708,"children":709},{},[710,712,718,720,726,728,733,735,741],{"type":49,"value":711},"Tool-retrieved citations keep their source tag (",{"type":44,"tag":62,"props":713,"children":715},{"className":714},[],[716],{"type":49,"value":717},"[Westlaw]",{"type":49,"value":719},", ",{"type":44,"tag":62,"props":721,"children":723},{"className":722},[],[724],{"type":49,"value":725},"[Commission \u002F regulator site]",{"type":49,"value":727},", or the MCP tool name); web-search citations remain ",{"type":44,"tag":62,"props":729,"children":731},{"className":730},[],[732],{"type":49,"value":658},{"type":49,"value":734},"; user-supplied citations remain ",{"type":44,"tag":62,"props":736,"children":738},{"className":737},[],[739],{"type":49,"value":740},"[user provided]",{"type":49,"value":742},". The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.",{"type":44,"tag":744,"props":745,"children":746},"table",{},[747,776],{"type":44,"tag":748,"props":749,"children":750},"thead",{},[751],{"type":44,"tag":752,"props":753,"children":754},"tr",{},[755,761,766,771],{"type":44,"tag":756,"props":757,"children":758},"th",{},[759],{"type":49,"value":760},"Term",{"type":44,"tag":756,"props":762,"children":763},{},[764],{"type":49,"value":765},"Looking for",{"type":44,"tag":756,"props":767,"children":768},{},[769],{"type":49,"value":770},"Playbook field",{"type":44,"tag":756,"props":772,"children":773},{},[774],{"type":49,"value":775},"Common fights",{"type":44,"tag":777,"props":778,"children":779},"tbody",{},[780,807,832,858,884,909,934,960,986],{"type":44,"tag":752,"props":781,"children":782},{},[783,792,797,802],{"type":44,"tag":784,"props":785,"children":786},"td",{},[787],{"type":44,"tag":124,"props":788,"children":789},{},[790],{"type":49,"value":791},"Roles",{"type":44,"tag":784,"props":793,"children":794},{},[795],{"type":49,"value":796},"Clear controller\u002Fprocessor designation; matches reality",{"type":44,"tag":784,"props":798,"children":799},{},[800],{"type":49,"value":801},"—",{"type":44,"tag":784,"props":803,"children":804},{},[805],{"type":49,"value":806},"Counterparty labels the relationship (e.g., \"joint controller\") in a way that doesn't match reality",{"type":44,"tag":752,"props":808,"children":809},{},[810,818,823,827],{"type":44,"tag":784,"props":811,"children":812},{},[813],{"type":44,"tag":124,"props":814,"children":815},{},[816],{"type":49,"value":817},"Processing scope",{"type":44,"tag":784,"props":819,"children":820},{},[821],{"type":49,"value":822},"Limited to documented instructions; defined purposes",{"type":44,"tag":784,"props":824,"children":825},{},[826],{"type":49,"value":801},{"type":44,"tag":784,"props":828,"children":829},{},[830],{"type":49,"value":831},"Open-ended scope expanders (\"and related purposes\")",{"type":44,"tag":752,"props":833,"children":834},{},[835,843,848,853],{"type":44,"tag":784,"props":836,"children":837},{},[838],{"type":44,"tag":124,"props":839,"children":840},{},[841],{"type":49,"value":842},"Subprocessors",{"type":44,"tag":784,"props":844,"children":845},{},[846],{"type":49,"value":847},"Current list disclosed, change mechanism defined",{"type":44,"tag":784,"props":849,"children":850},{},[851],{"type":49,"value":852},"Subprocessor changes",{"type":44,"tag":784,"props":854,"children":855},{},[856],{"type":49,"value":857},"Blanket approval vs. veto vs. notice-only",{"type":44,"tag":752,"props":859,"children":860},{},[861,869,874,879],{"type":44,"tag":784,"props":862,"children":863},{},[864],{"type":44,"tag":124,"props":865,"children":866},{},[867],{"type":49,"value":868},"Security measures",{"type":44,"tag":784,"props":870,"children":871},{},[872],{"type":49,"value":873},"Annex references specific controls or standards",{"type":44,"tag":784,"props":875,"children":876},{},[877],{"type":49,"value":878},"Security standards",{"type":44,"tag":784,"props":880,"children":881},{},[882],{"type":49,"value":883},"\"appropriate technical and organizational measures\" with no annex = empty promise",{"type":44,"tag":752,"props":885,"children":886},{},[887,895,900,904],{"type":44,"tag":784,"props":888,"children":889},{},[890],{"type":44,"tag":124,"props":891,"children":892},{},[893],{"type":49,"value":894},"Breach notification",{"type":44,"tag":784,"props":896,"children":897},{},[898],{"type":49,"value":899},"Defined trigger (\"discovery\" vs \"confirmation\"), defined timeline",{"type":44,"tag":784,"props":901,"children":902},{},[903],{"type":49,"value":894},{"type":44,"tag":784,"props":905,"children":906},{},[907],{"type":49,"value":908},"Timeline tightness; clock trigger; \"without undue delay\" is vague",{"type":44,"tag":752,"props":910,"children":911},{},[912,920,925,929],{"type":44,"tag":784,"props":913,"children":914},{},[915],{"type":44,"tag":124,"props":916,"children":917},{},[918],{"type":49,"value":919},"Audit rights",{"type":44,"tag":784,"props":921,"children":922},{},[923],{"type":49,"value":924},"Method (report vs. on-site), frequency, notice, cost allocation",{"type":44,"tag":784,"props":926,"children":927},{},[928],{"type":49,"value":919},{"type":44,"tag":784,"props":930,"children":931},{},[932],{"type":49,"value":933},"On-site audits on tight notice",{"type":44,"tag":752,"props":935,"children":936},{},[937,945,950,955],{"type":44,"tag":784,"props":938,"children":939},{},[940],{"type":44,"tag":124,"props":941,"children":942},{},[943],{"type":49,"value":944},"International transfers",{"type":44,"tag":784,"props":946,"children":947},{},[948],{"type":49,"value":949},"Transfer mechanism identified, supplementary measures, transfer impact assessment reference",{"type":44,"tag":784,"props":951,"children":952},{},[953],{"type":49,"value":954},"Transfers",{"type":44,"tag":784,"props":956,"children":957},{},[958],{"type":49,"value":959},"Outdated or missing transfer mechanisms",{"type":44,"tag":752,"props":961,"children":962},{},[963,971,976,981],{"type":44,"tag":784,"props":964,"children":965},{},[966],{"type":44,"tag":124,"props":967,"children":968},{},[969],{"type":49,"value":970},"Deletion\u002Freturn",{"type":44,"tag":784,"props":972,"children":973},{},[974],{"type":49,"value":975},"Timeline post-termination, certification, backup carveout",{"type":44,"tag":784,"props":977,"children":978},{},[979],{"type":49,"value":980},"Deletion on termination",{"type":44,"tag":784,"props":982,"children":983},{},[984],{"type":49,"value":985},"\"Commercially reasonable\" deletion = ???",{"type":44,"tag":752,"props":987,"children":988},{},[989,997,1002,1007],{"type":44,"tag":784,"props":990,"children":991},{},[992],{"type":44,"tag":124,"props":993,"children":994},{},[995],{"type":49,"value":996},"Liability",{"type":44,"tag":784,"props":998,"children":999},{},[1000],{"type":49,"value":1001},"Within MSA cap or separate; carveouts",{"type":44,"tag":784,"props":1003,"children":1004},{},[1005],{"type":49,"value":1006},"Liability for data",{"type":44,"tag":784,"props":1008,"children":1009},{},[1010],{"type":49,"value":1011},"Uncapped data breach liability = existential",{"type":44,"tag":580,"props":1013,"children":1015},{"id":1014},"when-were-the-processor-defensive-review",[1016],{"type":49,"value":1017},"When we're the processor: defensive review",{"type":44,"tag":120,"props":1019,"children":1020},{},[1021],{"type":49,"value":1022},"Customer DPAs try to push operational burden onto us. For each clause below, compare the customer's ask to the playbook. Where the customer's ask is outside the playbook, push back to the team's standard position (from the config CLAUDE.md) and be ready to fall back to the acceptable position.",{"type":44,"tag":744,"props":1024,"children":1025},{},[1026,1047],{"type":44,"tag":748,"props":1027,"children":1028},{},[1029],{"type":44,"tag":752,"props":1030,"children":1031},{},[1032,1037,1042],{"type":44,"tag":756,"props":1033,"children":1034},{},[1035],{"type":49,"value":1036},"Clause",{"type":44,"tag":756,"props":1038,"children":1039},{},[1040],{"type":49,"value":1041},"Risk",{"type":44,"tag":756,"props":1043,"children":1044},{},[1045],{"type":49,"value":1046},"Research \u002F playbook lookup",{"type":44,"tag":777,"props":1048,"children":1049},{},[1050,1068,1086,1104,1122,1140,1158],{"type":44,"tag":752,"props":1051,"children":1052},{},[1053,1058,1063],{"type":44,"tag":784,"props":1054,"children":1055},{},[1056],{"type":49,"value":1057},"Subprocessor approval right (veto)",{"type":44,"tag":784,"props":1059,"children":1060},{},[1061],{"type":49,"value":1062},"Can't add infrastructure without customer-by-customer approval",{"type":44,"tag":784,"props":1064,"children":1065},{},[1066],{"type":49,"value":1067},"Apply playbook position on subprocessor changes",{"type":44,"tag":752,"props":1069,"children":1070},{},[1071,1076,1081],{"type":44,"tag":784,"props":1072,"children":1073},{},[1074],{"type":49,"value":1075},"On-site audit on short notice",{"type":44,"tag":784,"props":1077,"children":1078},{},[1079],{"type":49,"value":1080},"Unworkable at scale",{"type":44,"tag":784,"props":1082,"children":1083},{},[1084],{"type":49,"value":1085},"Apply playbook position on audit rights",{"type":44,"tag":752,"props":1087,"children":1088},{},[1089,1094,1099],{"type":44,"tag":784,"props":1090,"children":1091},{},[1092],{"type":49,"value":1093},"Aggressive breach notification window",{"type":44,"tag":784,"props":1095,"children":1096},{},[1097],{"type":49,"value":1098},"Often demands notice before we know what happened",{"type":44,"tag":784,"props":1100,"children":1101},{},[1102],{"type":49,"value":1103},"Research the regulatory floor for each applicable regime (cite primary sources); compare to playbook position",{"type":44,"tag":752,"props":1105,"children":1106},{},[1107,1112,1117],{"type":44,"tag":784,"props":1108,"children":1109},{},[1110],{"type":49,"value":1111},"Hard data residency (single country\u002FDC)",{"type":44,"tag":784,"props":1113,"children":1114},{},[1115],{"type":49,"value":1116},"May not match architecture",{"type":44,"tag":784,"props":1118,"children":1119},{},[1120],{"type":49,"value":1121},"Apply playbook position on data location; confirm what we can actually commit to",{"type":44,"tag":752,"props":1123,"children":1124},{},[1125,1130,1135],{"type":44,"tag":784,"props":1126,"children":1127},{},[1128],{"type":49,"value":1129},"Processor liability uncapped",{"type":44,"tag":784,"props":1131,"children":1132},{},[1133],{"type":49,"value":1134},"Bet-the-company",{"type":44,"tag":784,"props":1136,"children":1137},{},[1138],{"type":49,"value":1139},"Apply playbook position on liability for data",{"type":44,"tag":752,"props":1141,"children":1142},{},[1143,1148,1153],{"type":44,"tag":784,"props":1144,"children":1145},{},[1146],{"type":49,"value":1147},"Customer may issue binding \"instructions\"",{"type":44,"tag":784,"props":1149,"children":1150},{},[1151],{"type":49,"value":1152},"Open-ended operational control",{"type":44,"tag":784,"props":1154,"children":1155},{},[1156],{"type":49,"value":1157},"Define instructions as \"documented in the Agreement or agreed in writing\"",{"type":44,"tag":752,"props":1159,"children":1160},{},[1161,1166,1171],{"type":44,"tag":784,"props":1162,"children":1163},{},[1164],{"type":49,"value":1165},"Deletion on very short timeline",{"type":44,"tag":784,"props":1167,"children":1168},{},[1169],{"type":49,"value":1170},"Backup and log retention makes this impossible",{"type":44,"tag":784,"props":1172,"children":1173},{},[1174],{"type":49,"value":1175},"Apply playbook position on deletion on termination; document backup rotation carveout",{"type":44,"tag":580,"props":1177,"children":1179},{"id":1178},"when-were-the-controller-protective-review",[1180],{"type":49,"value":1181},"When we're the controller: protective review",{"type":44,"tag":120,"props":1183,"children":1184},{},[1185],{"type":49,"value":1186},"Vendor DPAs try to give us nothing. For each clause below, compare to the controller-side playbook.",{"type":44,"tag":744,"props":1188,"children":1189},{},[1190,1209],{"type":44,"tag":748,"props":1191,"children":1192},{},[1193],{"type":44,"tag":752,"props":1194,"children":1195},{},[1196,1200,1205],{"type":44,"tag":756,"props":1197,"children":1198},{},[1199],{"type":49,"value":1036},{"type":44,"tag":756,"props":1201,"children":1202},{},[1203],{"type":49,"value":1204},"Gap",{"type":44,"tag":756,"props":1206,"children":1207},{},[1208],{"type":49,"value":1046},{"type":44,"tag":777,"props":1210,"children":1211},{},[1212,1230,1248,1266,1284,1302,1325],{"type":44,"tag":752,"props":1213,"children":1214},{},[1215,1220,1225],{"type":44,"tag":784,"props":1216,"children":1217},{},[1218],{"type":49,"value":1219},"No subprocessor list",{"type":44,"tag":784,"props":1221,"children":1222},{},[1223],{"type":49,"value":1224},"Don't know who touches our data",{"type":44,"tag":784,"props":1226,"children":1227},{},[1228],{"type":49,"value":1229},"Require published current list + advance notice per playbook",{"type":44,"tag":752,"props":1231,"children":1232},{},[1233,1238,1243],{"type":44,"tag":784,"props":1234,"children":1235},{},[1236],{"type":49,"value":1237},"\"Industry standard security\"",{"type":44,"tag":784,"props":1239,"children":1240},{},[1241],{"type":49,"value":1242},"Means nothing",{"type":44,"tag":784,"props":1244,"children":1245},{},[1246],{"type":49,"value":1247},"Require annex with specific controls, or reference to a named standard (e.g., SOC 2, ISO 27001)",{"type":44,"tag":752,"props":1249,"children":1250},{},[1251,1256,1261],{"type":44,"tag":784,"props":1252,"children":1253},{},[1254],{"type":49,"value":1255},"No breach notification timeline",{"type":44,"tag":784,"props":1257,"children":1258},{},[1259],{"type":49,"value":1260},"They tell us whenever",{"type":44,"tag":784,"props":1262,"children":1263},{},[1264],{"type":49,"value":1265},"Research applicable regulatory floor; require playbook position",{"type":44,"tag":752,"props":1267,"children":1268},{},[1269,1274,1279],{"type":44,"tag":784,"props":1270,"children":1271},{},[1272],{"type":49,"value":1273},"No audit rights at all",{"type":44,"tag":784,"props":1275,"children":1276},{},[1277],{"type":49,"value":1278},"Can't verify anything",{"type":44,"tag":784,"props":1280,"children":1281},{},[1282],{"type":49,"value":1283},"Require at minimum an independent audit report per playbook",{"type":44,"tag":752,"props":1285,"children":1286},{},[1287,1292,1297],{"type":44,"tag":784,"props":1288,"children":1289},{},[1290],{"type":49,"value":1291},"Vendor can use data for \"service improvement\"",{"type":44,"tag":784,"props":1293,"children":1294},{},[1295],{"type":49,"value":1296},"Potential training on our data",{"type":44,"tag":784,"props":1298,"children":1299},{},[1300],{"type":49,"value":1301},"Strike; processing limited to providing the service to us",{"type":44,"tag":752,"props":1303,"children":1304},{},[1305,1310,1315],{"type":44,"tag":784,"props":1306,"children":1307},{},[1308],{"type":49,"value":1309},"No international transfer mechanism",{"type":44,"tag":784,"props":1311,"children":1312},{},[1313],{"type":49,"value":1314},"No lawful transfer mechanism",{"type":44,"tag":784,"props":1316,"children":1317},{},[1318,1323],{"type":44,"tag":124,"props":1319,"children":1320},{},[1321],{"type":49,"value":1322},"Research the currently operative transfer mechanism",{"type":49,"value":1324}," for the corridor in question (origin\u002Fdestination jurisdictions, applicable regime, any adequacy decision, any supplementary measures). Cite primary sources and verify currency.",{"type":44,"tag":752,"props":1326,"children":1327},{},[1328,1333,1338],{"type":44,"tag":784,"props":1329,"children":1330},{},[1331],{"type":49,"value":1332},"No deletion commitment",{"type":44,"tag":784,"props":1334,"children":1335},{},[1336],{"type":49,"value":1337},"Data lives forever",{"type":44,"tag":784,"props":1339,"children":1340},{},[1341],{"type":49,"value":1342},"Require playbook position on deletion + certification on request",{"type":44,"tag":113,"props":1344,"children":1346},{"id":1345},"consistency-check-privacy-policy",[1347],{"type":49,"value":1348},"Consistency check: privacy policy",{"type":44,"tag":120,"props":1350,"children":1351},{},[1352],{"type":49,"value":1353},"The DPA you sign can't promise something the privacy policy doesn't cover, and vice versa.",{"type":44,"tag":235,"props":1355,"children":1356},{},[1357,1362,1367],{"type":44,"tag":56,"props":1358,"children":1359},{},[1360],{"type":49,"value":1361},"If the DPA commits to processing only for purposes X, Y, Z — does the privacy policy list those purposes?",{"type":44,"tag":56,"props":1363,"children":1364},{},[1365],{"type":49,"value":1366},"If the privacy policy says \"we never sell data\" — does any DPA clause look like a sale under CCPA?",{"type":44,"tag":56,"props":1368,"children":1369},{},[1370],{"type":49,"value":1371},"If the privacy policy names specific subprocessor categories — does the DPA subprocessor list match?",{"type":44,"tag":120,"props":1373,"children":1374},{},[1375],{"type":49,"value":1376},"Flag mismatches. They're usually the privacy policy being stale, not the DPA being wrong, but someone needs to fix one of them.",{"type":44,"tag":113,"props":1378,"children":1380},{"id":1379},"redline-granularity",[1381],{"type":49,"value":1382},"Redline granularity",{"type":44,"tag":120,"props":1384,"children":1385},{},[1386,1391],{"type":44,"tag":124,"props":1387,"children":1388},{},[1389],{"type":49,"value":1390},"Edit at the smallest possible granularity.",{"type":49,"value":1392}," A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals \"we threw out your drafting\" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal \"we have specific asks\" and are faster to read, understand, and accept.",{"type":44,"tag":120,"props":1394,"children":1395},{},[1396],{"type":49,"value":1397},"Default to the smallest edit that achieves the playbook position:",{"type":44,"tag":235,"props":1399,"children":1400},{},[1401,1413,1424,1436,1447],{"type":44,"tag":56,"props":1402,"children":1403},{},[1404,1406,1411],{"type":49,"value":1405},"Replace a ",{"type":44,"tag":124,"props":1407,"children":1408},{},[1409],{"type":49,"value":1410},"word",{"type":49,"value":1412}," before a phrase. (\"twelve (12)\" → \"twenty-four (24)\")",{"type":44,"tag":56,"props":1414,"children":1415},{},[1416,1417,1422],{"type":49,"value":1405},{"type":44,"tag":124,"props":1418,"children":1419},{},[1420],{"type":49,"value":1421},"phrase",{"type":49,"value":1423}," before a sentence. (\"paid by the Buyer\" → \"paid and payable by the Buyer\")",{"type":44,"tag":56,"props":1425,"children":1426},{},[1427,1429,1434],{"type":49,"value":1428},"Restructure a ",{"type":44,"tag":124,"props":1430,"children":1431},{},[1432],{"type":49,"value":1433},"subclause",{"type":49,"value":1435}," before replacing the sentence. (Add \"(a)\" and \"(b)\" to split a compound condition.)",{"type":44,"tag":56,"props":1437,"children":1438},{},[1439,1440,1445],{"type":49,"value":1405},{"type":44,"tag":124,"props":1441,"children":1442},{},[1443],{"type":49,"value":1444},"sentence",{"type":49,"value":1446}," before replacing the clause.",{"type":44,"tag":56,"props":1448,"children":1449},{},[1450,1452,1457],{"type":49,"value":1451},"Only replace a ",{"type":44,"tag":124,"props":1453,"children":1454},{},[1455],{"type":49,"value":1456},"whole clause",{"type":49,"value":1458}," when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: \"We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta.\"",{"type":44,"tag":120,"props":1460,"children":1461},{},[1462],{"type":49,"value":1463},"When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.",{"type":44,"tag":113,"props":1465,"children":1467},{"id":1466},"output",[1468],{"type":49,"value":1469},"Output",{"type":44,"tag":120,"props":1471,"children":1472},{},[1473,1475,1480,1482,1487,1489,1495],{"type":49,"value":1474},"Prepend the work-product header from ",{"type":44,"tag":62,"props":1476,"children":1478},{"className":1477},[],[1479],{"type":49,"value":67},{"type":49,"value":1481}," ",{"type":44,"tag":62,"props":1483,"children":1485},{"className":1484},[],[1486],{"type":49,"value":304},{"type":49,"value":1488}," (it differs by user role — see ",{"type":44,"tag":62,"props":1490,"children":1492},{"className":1491},[],[1493],{"type":49,"value":1494},"## Who's using this",{"type":49,"value":1496},").",{"type":44,"tag":91,"props":1498,"children":1502},{"className":1499,"code":1500,"language":1501,"meta":99,"style":99},"language-markdown shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n\n# DPA Review: [Counterparty]\n\n**Direction:** [We are processor \u002F We are controller]\n**Reviewed:** [date]\n**Attached to:** [MSA \u002F standalone]\n\n---\n\n## Bottom line\n\n[Two sentences. Can we sign? What has to change?]\n\n**Issues:** [N]🟢 [N]🟡 [N]🟠 [N]🔴\n\n---\n\n## Term-by-term\n\n[For each core term, use a standard deviation-memo format: what the\ncounterparty's DPA says, what our playbook says, the gap, the risk, and the\nproposed redline language. Keep each term to a short self-contained block so a\nreviewer can skim.]\n\n---\n\n## Privacy policy consistency\n\n[🟢 Consistent | 🟡 Flags: list]\n\n---\n\n## Recommended redlines\n\n[Consolidated — ready to send back]\n\n---\n\n## If they won't move\n\n[For each issue: the fallback from the config CLAUDE.md, or escalation routing if no\nfallback exists]\n","markdown",[1503],{"type":44,"tag":62,"props":1504,"children":1505},{"__ignoreMap":99},[1506,1517,1527,1559,1567,1592,1622,1644,1652,1661,1669,1683,1691,1700,1708,1794,1802,1810,1818,1831,1839,1848,1857,1866,1875,1883,1891,1899,1912,1920,1929,1937,1945,1953,1966,1974,1983,1991,1999,2007,2020,2028,2037],{"type":44,"tag":375,"props":1507,"children":1510},{"class":1508,"line":1509},"line",1,[1511],{"type":44,"tag":375,"props":1512,"children":1514},{"style":1513},"--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8",[1515],{"type":49,"value":1516},"[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n",{"type":44,"tag":375,"props":1518,"children":1520},{"class":1508,"line":1519},2,[1521],{"type":44,"tag":375,"props":1522,"children":1524},{"emptyLinePlaceholder":1523},true,[1525],{"type":49,"value":1526},"\n",{"type":44,"tag":375,"props":1528,"children":1530},{"class":1508,"line":1529},3,[1531,1537,1543,1548,1554],{"type":44,"tag":375,"props":1532,"children":1534},{"style":1533},"--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF",[1535],{"type":49,"value":1536},"# ",{"type":44,"tag":375,"props":1538,"children":1540},{"style":1539},"--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B",[1541],{"type":49,"value":1542},"DPA Review: ",{"type":44,"tag":375,"props":1544,"children":1545},{"style":1533},[1546],{"type":49,"value":1547},"[",{"type":44,"tag":375,"props":1549,"children":1551},{"style":1550},"--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D",[1552],{"type":49,"value":1553},"Counterparty",{"type":44,"tag":375,"props":1555,"children":1556},{"style":1533},[1557],{"type":49,"value":1558},"]\n",{"type":44,"tag":375,"props":1560,"children":1562},{"class":1508,"line":1561},4,[1563],{"type":44,"tag":375,"props":1564,"children":1565},{"emptyLinePlaceholder":1523},[1566],{"type":49,"value":1526},{"type":44,"tag":375,"props":1568,"children":1570},{"class":1508,"line":1569},5,[1571,1577,1583,1587],{"type":44,"tag":375,"props":1572,"children":1574},{"style":1573},"--shiki-light:#39ADB5;--shiki-light-font-weight:bold;--shiki-default:#89DDFF;--shiki-default-font-weight:bold;--shiki-dark:#89DDFF;--shiki-dark-font-weight:bold",[1575],{"type":49,"value":1576},"**",{"type":44,"tag":375,"props":1578,"children":1580},{"style":1579},"--shiki-light:#E53935;--shiki-light-font-weight:bold;--shiki-default:#F07178;--shiki-default-font-weight:bold;--shiki-dark:#F07178;--shiki-dark-font-weight:bold",[1581],{"type":49,"value":1582},"Direction:",{"type":44,"tag":375,"props":1584,"children":1585},{"style":1573},[1586],{"type":49,"value":1576},{"type":44,"tag":375,"props":1588,"children":1589},{"style":1513},[1590],{"type":49,"value":1591}," [We are processor \u002F We are controller]\n",{"type":44,"tag":375,"props":1593,"children":1595},{"class":1508,"line":1594},6,[1596,1600,1605,1609,1614,1618],{"type":44,"tag":375,"props":1597,"children":1598},{"style":1573},[1599],{"type":49,"value":1576},{"type":44,"tag":375,"props":1601,"children":1602},{"style":1579},[1603],{"type":49,"value":1604},"Reviewed:",{"type":44,"tag":375,"props":1606,"children":1607},{"style":1573},[1608],{"type":49,"value":1576},{"type":44,"tag":375,"props":1610,"children":1611},{"style":1533},[1612],{"type":49,"value":1613}," [",{"type":44,"tag":375,"props":1615,"children":1616},{"style":1550},[1617],{"type":49,"value":379},{"type":44,"tag":375,"props":1619,"children":1620},{"style":1533},[1621],{"type":49,"value":1558},{"type":44,"tag":375,"props":1623,"children":1625},{"class":1508,"line":1624},7,[1626,1630,1635,1639],{"type":44,"tag":375,"props":1627,"children":1628},{"style":1573},[1629],{"type":49,"value":1576},{"type":44,"tag":375,"props":1631,"children":1632},{"style":1579},[1633],{"type":49,"value":1634},"Attached to:",{"type":44,"tag":375,"props":1636,"children":1637},{"style":1573},[1638],{"type":49,"value":1576},{"type":44,"tag":375,"props":1640,"children":1641},{"style":1513},[1642],{"type":49,"value":1643}," [MSA \u002F standalone]\n",{"type":44,"tag":375,"props":1645,"children":1647},{"class":1508,"line":1646},8,[1648],{"type":44,"tag":375,"props":1649,"children":1650},{"emptyLinePlaceholder":1523},[1651],{"type":49,"value":1526},{"type":44,"tag":375,"props":1653,"children":1655},{"class":1508,"line":1654},9,[1656],{"type":44,"tag":375,"props":1657,"children":1658},{"style":1533},[1659],{"type":49,"value":1660},"---\n",{"type":44,"tag":375,"props":1662,"children":1664},{"class":1508,"line":1663},10,[1665],{"type":44,"tag":375,"props":1666,"children":1667},{"emptyLinePlaceholder":1523},[1668],{"type":49,"value":1526},{"type":44,"tag":375,"props":1670,"children":1672},{"class":1508,"line":1671},11,[1673,1678],{"type":44,"tag":375,"props":1674,"children":1675},{"style":1533},[1676],{"type":49,"value":1677},"## ",{"type":44,"tag":375,"props":1679,"children":1680},{"style":1539},[1681],{"type":49,"value":1682},"Bottom line\n",{"type":44,"tag":375,"props":1684,"children":1686},{"class":1508,"line":1685},12,[1687],{"type":44,"tag":375,"props":1688,"children":1689},{"emptyLinePlaceholder":1523},[1690],{"type":49,"value":1526},{"type":44,"tag":375,"props":1692,"children":1694},{"class":1508,"line":1693},13,[1695],{"type":44,"tag":375,"props":1696,"children":1697},{"style":1513},[1698],{"type":49,"value":1699},"[Two sentences. Can we sign? What has to change?]\n",{"type":44,"tag":375,"props":1701,"children":1703},{"class":1508,"line":1702},14,[1704],{"type":44,"tag":375,"props":1705,"children":1706},{"emptyLinePlaceholder":1523},[1707],{"type":49,"value":1526},{"type":44,"tag":375,"props":1709,"children":1711},{"class":1508,"line":1710},15,[1712,1716,1721,1725,1729,1733,1738,1743,1747,1751,1755,1760,1764,1768,1772,1777,1781,1785,1789],{"type":44,"tag":375,"props":1713,"children":1714},{"style":1573},[1715],{"type":49,"value":1576},{"type":44,"tag":375,"props":1717,"children":1718},{"style":1579},[1719],{"type":49,"value":1720},"Issues:",{"type":44,"tag":375,"props":1722,"children":1723},{"style":1573},[1724],{"type":49,"value":1576},{"type":44,"tag":375,"props":1726,"children":1727},{"style":1533},[1728],{"type":49,"value":1613},{"type":44,"tag":375,"props":1730,"children":1731},{"style":1550},[1732],{"type":49,"value":636},{"type":44,"tag":375,"props":1734,"children":1735},{"style":1533},[1736],{"type":49,"value":1737},"]",{"type":44,"tag":375,"props":1739,"children":1740},{"style":1513},[1741],{"type":49,"value":1742},"🟢 ",{"type":44,"tag":375,"props":1744,"children":1745},{"style":1533},[1746],{"type":49,"value":1547},{"type":44,"tag":375,"props":1748,"children":1749},{"style":1550},[1750],{"type":49,"value":636},{"type":44,"tag":375,"props":1752,"children":1753},{"style":1533},[1754],{"type":49,"value":1737},{"type":44,"tag":375,"props":1756,"children":1757},{"style":1513},[1758],{"type":49,"value":1759},"🟡 ",{"type":44,"tag":375,"props":1761,"children":1762},{"style":1533},[1763],{"type":49,"value":1547},{"type":44,"tag":375,"props":1765,"children":1766},{"style":1550},[1767],{"type":49,"value":636},{"type":44,"tag":375,"props":1769,"children":1770},{"style":1533},[1771],{"type":49,"value":1737},{"type":44,"tag":375,"props":1773,"children":1774},{"style":1513},[1775],{"type":49,"value":1776},"🟠 ",{"type":44,"tag":375,"props":1778,"children":1779},{"style":1533},[1780],{"type":49,"value":1547},{"type":44,"tag":375,"props":1782,"children":1783},{"style":1550},[1784],{"type":49,"value":636},{"type":44,"tag":375,"props":1786,"children":1787},{"style":1533},[1788],{"type":49,"value":1737},{"type":44,"tag":375,"props":1790,"children":1791},{"style":1513},[1792],{"type":49,"value":1793},"🔴\n",{"type":44,"tag":375,"props":1795,"children":1797},{"class":1508,"line":1796},16,[1798],{"type":44,"tag":375,"props":1799,"children":1800},{"emptyLinePlaceholder":1523},[1801],{"type":49,"value":1526},{"type":44,"tag":375,"props":1803,"children":1805},{"class":1508,"line":1804},17,[1806],{"type":44,"tag":375,"props":1807,"children":1808},{"style":1533},[1809],{"type":49,"value":1660},{"type":44,"tag":375,"props":1811,"children":1813},{"class":1508,"line":1812},18,[1814],{"type":44,"tag":375,"props":1815,"children":1816},{"emptyLinePlaceholder":1523},[1817],{"type":49,"value":1526},{"type":44,"tag":375,"props":1819,"children":1821},{"class":1508,"line":1820},19,[1822,1826],{"type":44,"tag":375,"props":1823,"children":1824},{"style":1533},[1825],{"type":49,"value":1677},{"type":44,"tag":375,"props":1827,"children":1828},{"style":1539},[1829],{"type":49,"value":1830},"Term-by-term\n",{"type":44,"tag":375,"props":1832,"children":1834},{"class":1508,"line":1833},20,[1835],{"type":44,"tag":375,"props":1836,"children":1837},{"emptyLinePlaceholder":1523},[1838],{"type":49,"value":1526},{"type":44,"tag":375,"props":1840,"children":1842},{"class":1508,"line":1841},21,[1843],{"type":44,"tag":375,"props":1844,"children":1845},{"style":1513},[1846],{"type":49,"value":1847},"[For each core term, use a standard deviation-memo format: what the\n",{"type":44,"tag":375,"props":1849,"children":1851},{"class":1508,"line":1850},22,[1852],{"type":44,"tag":375,"props":1853,"children":1854},{"style":1513},[1855],{"type":49,"value":1856},"counterparty's DPA says, what our playbook says, the gap, the risk, and the\n",{"type":44,"tag":375,"props":1858,"children":1860},{"class":1508,"line":1859},23,[1861],{"type":44,"tag":375,"props":1862,"children":1863},{"style":1513},[1864],{"type":49,"value":1865},"proposed redline language. Keep each term to a short self-contained block so a\n",{"type":44,"tag":375,"props":1867,"children":1869},{"class":1508,"line":1868},24,[1870],{"type":44,"tag":375,"props":1871,"children":1872},{"style":1513},[1873],{"type":49,"value":1874},"reviewer can skim.]\n",{"type":44,"tag":375,"props":1876,"children":1878},{"class":1508,"line":1877},25,[1879],{"type":44,"tag":375,"props":1880,"children":1881},{"emptyLinePlaceholder":1523},[1882],{"type":49,"value":1526},{"type":44,"tag":375,"props":1884,"children":1886},{"class":1508,"line":1885},26,[1887],{"type":44,"tag":375,"props":1888,"children":1889},{"style":1533},[1890],{"type":49,"value":1660},{"type":44,"tag":375,"props":1892,"children":1894},{"class":1508,"line":1893},27,[1895],{"type":44,"tag":375,"props":1896,"children":1897},{"emptyLinePlaceholder":1523},[1898],{"type":49,"value":1526},{"type":44,"tag":375,"props":1900,"children":1902},{"class":1508,"line":1901},28,[1903,1907],{"type":44,"tag":375,"props":1904,"children":1905},{"style":1533},[1906],{"type":49,"value":1677},{"type":44,"tag":375,"props":1908,"children":1909},{"style":1539},[1910],{"type":49,"value":1911},"Privacy policy consistency\n",{"type":44,"tag":375,"props":1913,"children":1915},{"class":1508,"line":1914},29,[1916],{"type":44,"tag":375,"props":1917,"children":1918},{"emptyLinePlaceholder":1523},[1919],{"type":49,"value":1526},{"type":44,"tag":375,"props":1921,"children":1923},{"class":1508,"line":1922},30,[1924],{"type":44,"tag":375,"props":1925,"children":1926},{"style":1513},[1927],{"type":49,"value":1928},"[🟢 Consistent | 🟡 Flags: list]\n",{"type":44,"tag":375,"props":1930,"children":1932},{"class":1508,"line":1931},31,[1933],{"type":44,"tag":375,"props":1934,"children":1935},{"emptyLinePlaceholder":1523},[1936],{"type":49,"value":1526},{"type":44,"tag":375,"props":1938,"children":1940},{"class":1508,"line":1939},32,[1941],{"type":44,"tag":375,"props":1942,"children":1943},{"style":1533},[1944],{"type":49,"value":1660},{"type":44,"tag":375,"props":1946,"children":1948},{"class":1508,"line":1947},33,[1949],{"type":44,"tag":375,"props":1950,"children":1951},{"emptyLinePlaceholder":1523},[1952],{"type":49,"value":1526},{"type":44,"tag":375,"props":1954,"children":1956},{"class":1508,"line":1955},34,[1957,1961],{"type":44,"tag":375,"props":1958,"children":1959},{"style":1533},[1960],{"type":49,"value":1677},{"type":44,"tag":375,"props":1962,"children":1963},{"style":1539},[1964],{"type":49,"value":1965},"Recommended redlines\n",{"type":44,"tag":375,"props":1967,"children":1969},{"class":1508,"line":1968},35,[1970],{"type":44,"tag":375,"props":1971,"children":1972},{"emptyLinePlaceholder":1523},[1973],{"type":49,"value":1526},{"type":44,"tag":375,"props":1975,"children":1977},{"class":1508,"line":1976},36,[1978],{"type":44,"tag":375,"props":1979,"children":1980},{"style":1513},[1981],{"type":49,"value":1982},"[Consolidated — ready to send back]\n",{"type":44,"tag":375,"props":1984,"children":1986},{"class":1508,"line":1985},37,[1987],{"type":44,"tag":375,"props":1988,"children":1989},{"emptyLinePlaceholder":1523},[1990],{"type":49,"value":1526},{"type":44,"tag":375,"props":1992,"children":1994},{"class":1508,"line":1993},38,[1995],{"type":44,"tag":375,"props":1996,"children":1997},{"style":1533},[1998],{"type":49,"value":1660},{"type":44,"tag":375,"props":2000,"children":2002},{"class":1508,"line":2001},39,[2003],{"type":44,"tag":375,"props":2004,"children":2005},{"emptyLinePlaceholder":1523},[2006],{"type":49,"value":1526},{"type":44,"tag":375,"props":2008,"children":2010},{"class":1508,"line":2009},40,[2011,2015],{"type":44,"tag":375,"props":2012,"children":2013},{"style":1533},[2014],{"type":49,"value":1677},{"type":44,"tag":375,"props":2016,"children":2017},{"style":1539},[2018],{"type":49,"value":2019},"If they won't move\n",{"type":44,"tag":375,"props":2021,"children":2023},{"class":1508,"line":2022},41,[2024],{"type":44,"tag":375,"props":2025,"children":2026},{"emptyLinePlaceholder":1523},[2027],{"type":49,"value":1526},{"type":44,"tag":375,"props":2029,"children":2031},{"class":1508,"line":2030},42,[2032],{"type":44,"tag":375,"props":2033,"children":2034},{"style":1513},[2035],{"type":49,"value":2036},"[For each issue: the fallback from the config CLAUDE.md, or escalation routing if no\n",{"type":44,"tag":375,"props":2038,"children":2040},{"class":1508,"line":2039},43,[2041],{"type":44,"tag":375,"props":2042,"children":2043},{"style":1513},[2044],{"type":49,"value":2045},"fallback exists]\n",{"type":44,"tag":113,"props":2047,"children":2049},{"id":2048},"international-transfers-note",[2050],{"type":49,"value":2051},"International transfers note",{"type":44,"tag":120,"props":2053,"children":2054},{},[2055,2057,2062],{"type":49,"value":2056},"If the DPA contemplates cross-border data transfers, ",{"type":44,"tag":124,"props":2058,"children":2059},{},[2060],{"type":49,"value":2061},"research the currently operative transfer mechanism requirements",{"type":49,"value":2063}," for the applicable corridor(s). For each origin\u002Fdestination pair, identify: the applicable regime, whether any adequacy decision is in force, which transfer mechanism is required or available (e.g., Standard Contractual Clauses and their applicable version\u002Fmodule, UK Addendum or IDTA, BCRs, derogations), whether a transfer impact assessment or equivalent is required, and what supplementary measures may be needed. Cite primary sources (regulation, Commission decision, regulator guidance, controlling case law) with pinpoint cites and verify currency — adequacy decisions, SCC versions, and required supplementary measures change through new Commission decisions, court rulings, and regulator guidance. Flag uncertainty for attorney verification.",{"type":44,"tag":120,"props":2065,"children":2066},{},[2067],{"type":49,"value":2068},"If a transfer mechanism is missing and there is an international transfer, that is a 🔴 — there is no lawful transfer mechanism.",{"type":44,"tag":113,"props":2070,"children":2072},{"id":2071},"gate-signing-a-dpa",[2073],{"type":49,"value":2074},"Gate: signing a DPA",{"type":44,"tag":120,"props":2076,"children":2077},{},[2078,2080,2085],{"type":49,"value":2079},"Reviewing a DPA is research. ",{"type":44,"tag":592,"props":2081,"children":2082},{},[2083],{"type":49,"value":2084},"Signing",{"type":49,"value":2086}," it — or instructing someone to countersign on our behalf — is the consequential act.",{"type":44,"tag":120,"props":2088,"children":2089},{},[2090,2095,2097,2102,2104,2109],{"type":44,"tag":124,"props":2091,"children":2092},{},[2093],{"type":49,"value":2094},"Before proceeding to sign or countersign a DPA (including returning an executed version, consenting to automatic execution on a counterparty platform, or instructing a signatory to execute):",{"type":49,"value":2096}," Read ",{"type":44,"tag":62,"props":2098,"children":2100},{"className":2099},[],[2101],{"type":49,"value":1494},{"type":49,"value":2103}," in ",{"type":44,"tag":62,"props":2105,"children":2107},{"className":2106},[],[2108],{"type":49,"value":67},{"type":49,"value":2110},". If the Role is Non-lawyer:",{"type":44,"tag":366,"props":2112,"children":2113},{},[2114,2119,2127],{"type":44,"tag":120,"props":2115,"children":2116},{},[2117],{"type":49,"value":2118},"Signing a DPA is a legal act — it binds the company to specific data-protection obligations that flow to regulators and data subjects. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:",{"type":44,"tag":120,"props":2120,"children":2121},{},[2122],{"type":44,"tag":375,"props":2123,"children":2124},{},[2125],{"type":49,"value":2126},"Generate a 1-page summary: counterparty, direction (we are processor \u002F controller), the terms that deviate from the playbook and how they were resolved, any open fallback decisions, and the three things to ask the attorney before executing.",{"type":44,"tag":120,"props":2128,"children":2129},{},[2130],{"type":49,"value":2131},"If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA\u002FBar Standards Board in England & Wales, Law Society in Scotland\u002FNI\u002FIreland\u002FCanada\u002FAustralia, or your jurisdiction's equivalent).",{"type":44,"tag":120,"props":2133,"children":2134},{},[2135],{"type":49,"value":2136},"Do not proceed past this gate without an explicit yes.",{"type":44,"tag":113,"props":2138,"children":2140},{"id":2139},"close-with-the-next-steps-decision-tree",[2141],{"type":49,"value":2142},"Close with the next-steps decision tree",{"type":44,"tag":120,"props":2144,"children":2145},{},[2146,2148,2153],{"type":49,"value":2147},"End with the next-steps decision tree per CLAUDE.md ",{"type":44,"tag":62,"props":2149,"children":2151},{"className":2150},[],[2152],{"type":49,"value":304},{"type":49,"value":2154},". Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.",{"type":44,"tag":113,"props":2156,"children":2158},{"id":2157},"what-this-skill-does-not-do",[2159],{"type":49,"value":2160},"What this skill does not do",{"type":44,"tag":235,"props":2162,"children":2163},{},[2164,2169,2174],{"type":44,"tag":56,"props":2165,"children":2166},{},[2167],{"type":49,"value":2168},"It doesn't draft a DPA from scratch. If the answer is \"use our template,\" pull the template from the seed docs path in the config CLAUDE.md.",{"type":44,"tag":56,"props":2170,"children":2171},{},[2172],{"type":49,"value":2173},"It doesn't do the Transfer Impact Assessment itself — it flags when one is needed.",{"type":44,"tag":56,"props":2175,"children":2176},{},[2177],{"type":49,"value":2178},"It doesn't decide whether to accept terms outside the fallbacks. It routes those per the escalation table.",{"type":44,"tag":2180,"props":2181,"children":2182},"style",{},[2183],{"type":49,"value":2184},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"items":2186,"total":2282},[2187,2201,2216,2233,2245,2256,2267],{"slug":2188,"name":2188,"fn":2189,"description":2190,"org":2191,"tags":2192,"stars":26,"repoUrl":27,"updatedAt":2200},"ai-inventory","track AI systems for EU AI Act","EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says \"ai inventory\", \"add an ai system\", \"what systems do we have\", \"classify this ai system\", \"eu ai act register\", or \"ai system registry\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2193,2196,2199],{"name":2194,"slug":2195,"type":16},"Compliance","compliance",{"name":2197,"slug":2198,"type":16},"Governance","governance",{"name":21,"slug":22,"type":16},"2026-05-14T06:02:19.677579",{"slug":2202,"name":2202,"fn":2203,"description":2204,"org":2205,"tags":2206,"stars":26,"repoUrl":27,"updatedAt":2215},"ai-tool-handoff","manage handoff to bulk legal review tools","Detects when Luminance, Kira, or a similar bulk-review tool is in use, hands off the high-volume clause extraction to it, and QAs its output per the trust level in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fcorporate-legal\u002FCLAUDE.md`. Use when user says \"send to Luminance\", \"bulk review\", \"AI extraction\", or when diligence-issue-extraction hits a high-volume category.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2207,2210,2211,2212],{"name":2208,"slug":2209,"type":16},"Automation","automation",{"name":18,"slug":19,"type":16},{"name":21,"slug":22,"type":16},{"name":2213,"slug":2214,"type":16},"QA","qa","2026-05-14T06:01:31.00555",{"slug":2217,"name":2217,"fn":2218,"description":2219,"org":2220,"tags":2221,"stars":26,"repoUrl":27,"updatedAt":2232},"aia-generation","run AI impact assessments","Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fai-governance-legal\u002FCLAUDE.md`. Use when user says \"impact assessment for\", \"assess this AI use case\", \"run an AIA\", \"generate an AIA\", \"we need to document this AI system\", \"AI risk assessment for X\", or follows a conditional triage result.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2222,2223,2226,2229],{"name":21,"slug":22,"type":16},{"name":2224,"slug":2225,"type":16},"Policy","policy",{"name":2227,"slug":2228,"type":16},"Regulatory Compliance","regulatory-compliance",{"name":2230,"slug":2231,"type":16},"Risk Assessment","risk-assessment","2026-05-13T06:03:19.61029",{"slug":2234,"name":2234,"fn":2235,"description":2236,"org":2237,"tags":2238,"stars":26,"repoUrl":27,"updatedAt":2244},"amendment-history","trace contract amendment history","Trace how a contract has changed across its base agreement and all amendments — either a summary of all changes over time, or a provision trace for a specific clause. Use when the user says \"what changed in this contract over time\", \"show me the amendment history\", \"where's the latest [clause]\", \"how has [provision] evolved\", or uploads multiple versions of an agreement.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2239,2240,2243],{"name":18,"slug":19,"type":16},{"name":2241,"slug":2242,"type":16},"Documents","documents",{"name":21,"slug":22,"type":16},"2026-05-13T06:03:34.070339",{"slug":2246,"name":2246,"fn":2247,"description":2248,"org":2249,"tags":2250,"stars":26,"repoUrl":27,"updatedAt":2255},"auto-updater","check for community skill updates","Check installed community skills for updates. Shows a diff and requires explicit approval before applying. Use when the user says \"check for updates\", \"update my skills\", \"anything new for my installed skills\", or when invoked from the registry-sync agent.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2251,2252],{"name":2208,"slug":2209,"type":16},{"name":2253,"slug":2254,"type":16},"Plugin Development","plugin-development","2026-05-13T06:02:55.642269",{"slug":2257,"name":2257,"fn":2258,"description":2259,"org":2260,"tags":2261,"stars":26,"repoUrl":27,"updatedAt":2266},"bar-prep-questions","provide bar exam practice questions","Bar prep questions — MBE or essay, targeted at your weak subjects and bar jurisdiction. Tracks misses and comes back to patterns. Use when the user says \"bar prep\", \"MBE questions\", \"practice essay\", or \"test me for the bar\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2262,2265],{"name":2263,"slug":2264,"type":16},"Education","education",{"name":21,"slug":22,"type":16},"2026-07-24T05:41:43.01243",{"slug":2268,"name":2268,"fn":2269,"description":2270,"org":2271,"tags":2272,"stars":26,"repoUrl":27,"updatedAt":2281},"board-minutes","draft board and committee meeting minutes","Drafts board or committee meeting minutes in your house format. Auto-detects upcoming board and committee meetings from your calendar, asks for the agenda and any slides or pre-read materials, and produces a complete draft in the format learned from your seed minutes. Also handles written consents in lieu of meetings. Trigger: \"board minutes\", \"draft minutes\", \"upcoming board meeting\", \"committee minutes\", \"written consent\", or calendar detection of an upcoming board or committee event.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2273,2276,2277,2278],{"name":2274,"slug":2275,"type":16},"Documentation","documentation",{"name":2197,"slug":2198,"type":16},{"name":21,"slug":22,"type":16},{"name":2279,"slug":2280,"type":16},"Meetings","meetings","2026-05-14T06:01:29.792942",118,{"items":2284,"total":2466},[2285,2306,2320,2332,2351,2362,2380,2400,2414,2429,2437,2450],{"slug":2286,"name":2286,"fn":2287,"description":2288,"org":2289,"tags":2290,"stars":2303,"repoUrl":2304,"updatedAt":2305},"algorithmic-art","create algorithmic art with p5.js","Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2291,2294,2297,2300],{"name":2292,"slug":2293,"type":16},"Creative","creative",{"name":2295,"slug":2296,"type":16},"Design","design",{"name":2298,"slug":2299,"type":16},"Generative Art","generative-art",{"name":2301,"slug":2302,"type":16},"JavaScript","javascript",161831,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills","2026-04-06T17:56:15.455818",{"slug":2307,"name":2307,"fn":2308,"description":2309,"org":2310,"tags":2311,"stars":2303,"repoUrl":2304,"updatedAt":2319},"brand-guidelines","apply Anthropic brand colors and typography","Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2312,2315,2316],{"name":2313,"slug":2314,"type":16},"Branding","branding",{"name":2295,"slug":2296,"type":16},{"name":2317,"slug":2318,"type":16},"Typography","typography","2026-04-06T17:56:05.042852",{"slug":2321,"name":2321,"fn":2322,"description":2323,"org":2324,"tags":2325,"stars":2303,"repoUrl":2304,"updatedAt":2331},"canvas-design","create posters and visual art as PNG or PDF","Create beautiful visual art in .png and .pdf documents using design philosophy. You should use this skill when the user asks to create a poster, piece of art, design, or other static piece. Create original visual designs, never copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2326,2327,2328],{"name":2292,"slug":2293,"type":16},{"name":2295,"slug":2296,"type":16},{"name":2329,"slug":2330,"type":16},"PDF","pdf","2026-04-06T17:56:03.794732",{"slug":2333,"name":2333,"fn":2334,"description":2335,"org":2336,"tags":2337,"stars":2303,"repoUrl":2304,"updatedAt":2350},"claude-api","build apps with the Claude API","Reference for the Claude API \u002F Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration.\nTRIGGER — read BEFORE opening the target file; don't skip because it \"looks like a one-liner\" — whenever: the prompt names Claude\u002FAnthropic in any form (Claude, Anthropic, Fable, Opus, Sonnet, Haiku, `anthropic`, `@anthropic-ai`, `claude-*`, `us.anthropic.*`, `[1m]`); the user asks about an LLM (pricing\u002Fmodel choice\u002Flimits\u002Fcaching) — never answer from memory; OR the task is LLM-shaped with provider unstated (agent\u002FMCP\u002Ftool-definition\u002Fmulti-agent\u002FRAG\u002FLLM-judge\u002Fcomputer-use; generate\u002Fsummarize\u002Fextract\u002Fclassify\u002Frewrite\u002Fconverse over NL; debugging refusals\u002Fcutoffs\u002Fstreaming\u002Ftool-calls\u002Ftokens).\nSKIP only when another provider is being worked on (overrides all triggers): OpenAI\u002FGPT\u002FGemini\u002FLlama\u002FMistral\u002FCohere\u002FOllama named in the query; OR `grep -rE 'openai|langchain_openai|google.generativeai|genai|mistralai|cohere|ollama'` over the project hits (run this grep FIRST if no provider named — don't Read the file).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2338,2341,2342,2345,2347],{"name":2339,"slug":2340,"type":16},"Agents","agents",{"name":9,"slug":8,"type":16},{"name":2343,"slug":2344,"type":16},"Anthropic SDK","anthropic-sdk",{"name":2346,"slug":2333,"type":16},"Claude API",{"name":2348,"slug":2349,"type":16},"LLM","llm","2026-07-28T05:36:08.213335",{"slug":2352,"name":2352,"fn":2353,"description":2354,"org":2355,"tags":2356,"stars":2303,"repoUrl":2304,"updatedAt":2361},"doc-coauthoring","co-author documentation and technical specs","Guide users through a structured workflow for co-authoring documentation. Use when user wants to write documentation, proposals, technical specs, decision docs, or similar structured content. This workflow helps users efficiently transfer context, refine content through iteration, and verify the doc works for readers. Trigger when user mentions writing docs, creating proposals, drafting specs, or similar documentation tasks.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2357,2358],{"name":2274,"slug":2275,"type":16},{"name":2359,"slug":2360,"type":16},"Technical Writing","technical-writing","2026-04-06T17:56:14.18897",{"slug":2363,"name":2363,"fn":2364,"description":2365,"org":2366,"tags":2367,"stars":2303,"repoUrl":2304,"updatedAt":2379},"docx","create and edit Word documents","Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2368,2369,2371,2374,2377],{"name":2241,"slug":2242,"type":16},{"name":2370,"slug":2363,"type":16},"DOCX",{"name":2372,"slug":2373,"type":16},"Office","office",{"name":2375,"slug":2376,"type":16},"Templates","templates",{"name":2378,"slug":1410,"type":16},"Word","2026-07-18T05:16:23.136271",{"slug":2381,"name":2381,"fn":2382,"description":2383,"org":2384,"tags":2385,"stars":2303,"repoUrl":2304,"updatedAt":2399},"frontend-design","design production-grade frontend interfaces","Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2386,2387,2390,2393,2396],{"name":2295,"slug":2296,"type":16},{"name":2388,"slug":2389,"type":16},"Frontend","frontend",{"name":2391,"slug":2392,"type":16},"React","react",{"name":2394,"slug":2395,"type":16},"Tailwind CSS","tailwind-css",{"name":2397,"slug":2398,"type":16},"UI Components","ui-components","2026-04-06T17:56:16.723469",{"slug":2401,"name":2401,"fn":2402,"description":2403,"org":2404,"tags":2405,"stars":2303,"repoUrl":2304,"updatedAt":2413},"internal-comms","write internal company communications","A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2406,2409,2410],{"name":2407,"slug":2408,"type":16},"Communications","communications",{"name":2375,"slug":2376,"type":16},{"name":2411,"slug":2412,"type":16},"Writing","writing","2026-04-06T17:56:20.695522",{"slug":2415,"name":2415,"fn":2416,"description":2417,"org":2418,"tags":2419,"stars":2303,"repoUrl":2304,"updatedAt":2428},"mcp-builder","build MCP servers","Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node\u002FTypeScript (MCP SDK).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2420,2421,2424,2425],{"name":2339,"slug":2340,"type":16},{"name":2422,"slug":2423,"type":16},"API Development","api-development",{"name":2348,"slug":2349,"type":16},{"name":2426,"slug":2427,"type":16},"MCP","mcp","2026-04-06T17:56:10.357665",{"slug":2330,"name":2330,"fn":2430,"description":2431,"org":2432,"tags":2433,"stars":2303,"repoUrl":2304,"updatedAt":2436},"read edit and manipulate PDF files","Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text\u002Ftables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting\u002Fdecrypting PDFs, extracting images, and OCR on scanned PDFs to make them searchable. If the user mentions a .pdf file or asks to produce one, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2434,2435],{"name":2241,"slug":2242,"type":16},{"name":2329,"slug":2330,"type":16},"2026-04-06T17:56:02.483316",{"slug":2438,"name":2438,"fn":2439,"description":2440,"org":2441,"tags":2442,"stars":2303,"repoUrl":2304,"updatedAt":2449},"pptx","create and edit PowerPoint presentations","Use this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying, or updating existing presentations; combining or splitting slide files; working with templates (.potx), layouts, speaker notes, or comments. Trigger whenever the user mentions \"deck,\" \"slides,\" \"presentation,\" or references a .pptx or .potx filename, regardless of what they plan to do with the content afterward. If a .pptx or .potx file needs to be opened, created, or touched, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2443,2446],{"name":2444,"slug":2445,"type":16},"PowerPoint","powerpoint",{"name":2447,"slug":2448,"type":16},"Presentations","presentations","2026-07-18T05:16:24.1471",{"slug":2451,"name":2451,"fn":2452,"description":2453,"org":2454,"tags":2455,"stars":2303,"repoUrl":2304,"updatedAt":2465},"skill-creator","create and optimize agent skills","Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2456,2457,2458,2461,2464],{"name":2339,"slug":2340,"type":16},{"name":2274,"slug":2275,"type":16},{"name":2459,"slug":2460,"type":16},"Evals","evals",{"name":2462,"slug":2463,"type":16},"Performance","performance",{"name":2359,"slug":2360,"type":16},"2026-04-19T06:45:40.804",490]