Skip to content
Built here

DPA draft with subprocessors

/legal--dpa-gen

/legal--dpa-gen is a Claude Code skill in the Business section. Drafts a Data Processing Agreement with the subprocessor list and annexes built from the stack your code actually uses.

Author's description

Draft a DPA skeleton with a subprocessor list built from your actual stack

Use it when

  • You sell a SaaS and a customer asks you to sign a DPA
  • You need to list the subprocessors you really use
  • You want data and security annexes grounded in your code

Not for

  • Replacing the advice of a lawyer
  • Reviewing a vendor DPA: contract review is the better fit

What you get

A legal/DPA_DRAFT.md file following the GDPR Art. 28 structure, with processing, security and subprocessor annexes, plus a gap list in the chat.

How to ask for it

  • /legal--dpa-gen draft a DPA for my SaaS with my current subprocessors
  • /legal--dpa-gen I need the data processing agreement based on my real stack
  • /legal--dpa-gen generate the subprocessor list and base DPA

Install

curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash

After installing with the script, type /legal--dpa-gen. Using Cursor, Windsurf or Codex? Platform guides

Questions about this skill

How does it know which subprocessors I use?
It infers them from dependencies, SDKs, env vars and infrastructure files. It keeps only services that receive personal data, and marks region [CONFIRM] when the code does not reveal it.
Does it work if I am the controller, not the processor?
It asks your role, since obligations flip. To review a vendor DPA it suggests the contract review skill instead.
Is the result ready to sign?
No. It is a skeleton with [PLACEHOLDER] markers for anything unverifiable and needs legal review.

Demo coming soon

↑↓ move · Enter open · Esc close