Skills
Data Processing Agreement Art. 28 GDPR
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
Domain skillsBy Oliver Schmidt-PrietzPublished on Lawvable
What this skill does
Review, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or prepare a Joint Controller Arrangement under Art. 26 GDPR (basic). Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and two review depths — quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring).
- Data
- Processing
- Agreement
Get this skill on Lawvable
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Oliver Schmidt-Prietz
- DPIA SentinelGDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklists/whitelists. Covers threshold assessment, multi-jurisdictional blacklist checks (DE, FR, IE, BE, NL, IT, PL), 5x5 risk scoring, necessity/proportionality analysis, mitigation mapping, Art. 36 prior consultation, AI dual-phase analysis, an
- GDPR Breach SentinelIncident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Covers breach risk assessment using ENISA severity methodology, Controller vs Processor obligations, 72-hour notification clock management, EDPB case matching, cross-border Lead SA determination, AI Act Art. 62 intersection, mitigation playbooks, and audit-ready .docx document generation.
- EU AI Act System ClassifierDetermine whether a technology qualifies as an AI system under Art. 3(1) and classify its risk tier (prohibited, high-risk, GPAI with systemic risk, limited risk, minimal risk). Covers scope exclusions (Art. 2), AI system definition test (7 criteria), prohibited practice screening (Art. 5), high-risk assessment (Annex I + III with Art. 6(3) exception), GPAI check, and Art. 50 transparency triggers.
- EU AI Act High-Risk ClassifierDepth assessment of whether an AI system is high-risk under Art. 6 of the EU AI Act, grounded in the Commission's draft Art. 6(5) classification guidelines (general principles + Annex I + Annex III). Covers the Annex I product-safety route, all eight Annex III areas with worked examples, the Art. 6(3) exception and its profiling re-exception, and the Art. 25 quasi-provider trap. Outputs a structured decision block, a practitioner memo, and a JSON interchange artefact.
- EU AI Act Knowledge BaseAuthoritative regulatory Q&A grounded in 70 official EU source documents, including the 2026 Commission draft guidelines on Art. 6 high-risk classification. Answers any EU AI Act question with article-level citations from the full regulation text, Commission guidelines, EDPB/EDPS opinions, codes of practice, harmonised standards, FRIA guides, and sector-specific guidance — covering penalties, timelines, GPAI obligations, high-risk and prohibited practices, and the AI Act / GDPR interplay.
- EU AI Act Obligations MapperMap the full set of legal obligations based on role and risk tier under the EU AI Act, producing an actionable compliance matrix with RACI assignments, implementation priorities, GDPR cross-references, and a phased implementation roadmap.
Skills that do related work
- EU Data ActPractitioner skill for EU Regulation 2023/2854 (Data Act). Covers Chapters II-VII (IoT data access, mandatory B2B sharing, unfair contract terms, public-sector
- EU Data ActA working tool for lawyers advising on the EU Data Act (Regulation (EU) 2023/2854). Hand it the facts of a matter and it returns a classification memo, a drafti
- EU Data Act Compliance AssessmentAssess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data sharing, cloud switching, B2B fairness
- Legal Data HunterInstall and set up the Legal Data Hunter MCP server. Use when the user wants to connect their AI agent to legal data, install legal-data-hunter, add a legal sea
- Settlement Agreement ReviewReviews or drafts the agreement that pays an employee to settle their claims — and flags the statutory conditions that decide whether it actually binds them. Wo
- Agent Authority Charter BuilderCreates an Agent Authority Charter for enterprise or regulated AI agents before deployment. Use this Skill when a user needs to define what an AI agent is allow