← ClaudeAtlas

gdpr-ropa-dpa-enlisted

Records of processing (RoPA, GDPR Art. 30) and data processing agreement (DPA, Art. 28) review assistant. Part 1 - RoPA: builds and validates the controller register (Art. 30(1)) and processor register (Art. 30(2)), enforcing the required fields (purposes, categories of data subjects and data, recipients, transfers, erasure timelines, security measures). Part 2 - DPA: checks a processor contract against the mandatory Art. 28(3)(a)-(h) clauses (controller's instructions, confidentiality, security, sub-processing, assistance with data-subject rights, assistance with Art. 32-36, deletion/return, audits) + Chapter V transfers. Produces a draft register and a contract redline - it does NOT sign (a human act). Runs locally (GDPR-safe). Use when: "records of processing", "RoPA Art. 30", "data processing agreement", "DPA Art. 28", "processor contract review", "GDPR register".
matematicsolutions/awesome-matematic-skills-en · ★ 0 · AI & Automation · score 76
Install: claude install-skill matematicsolutions/awesome-matematic-skills-en
# GDPR RoPA + DPA EN - records of processing (Art. 30) and processor contracts (Art. 28) ## Philosophy A RoPA is a living accountability document and a processor contract is a list of mandatory clauses - both can be checked mechanically against the article. The skill drafts/redlines; signing and filing are human acts. ## Part 1 - Records of processing (Art. 30) **Controller (Art. 30(1))** - mandatory fields per activity: - name and contact details of controller / joint controller / DPO, - purposes of the processing, - categories of data subjects and categories of personal data, - categories of recipients (incl. in third countries), - transfers to third countries + safeguards (Chapter V), - envisaged erasure time limits per category, - general description of technical and organisational security measures (Art. 32). **Processor (Art. 30(2))** - narrower: categories of processing per controller, transfers + safeguards, description of measures. The skill validates completeness (a missing field is a gap, not a guess) and flags activities needing a DPIA => [[gdpr-dpia-en]]. The Art. 30(5) exemption (<250 persons) is narrow - rarely applies in practice. ## Part 2 - Processor contract review (Art. 28(3)) The contract MUST bind the processor to: - **(a)** process **only on the controller's documented instructions** (incl. transfers), - **(b)** ensure **confidentiality** of authorised persons, - **(c)** apply **security** measures (Art. 32), - **(d)** respect the conditions for