prompt-pack-vendor-data-protection-addendum
Installation
SKILL.md
Vendor Data Protection Addendum
When to use this
Use this skill when a company (the "controller") engages a vendor (the "processor") who will have access to personal data — and the parties need a written data processing agreement to govern that processing relationship. A DPA is not optional under GDPR, UAE PDPL, KSA PDPL, or Egypt PDPL: each statute mandates a written contract between controller and processor setting out the processor's obligations.
Common triggers:
- Engaging a SaaS vendor whose platform will process employee or customer personal data
- Outsourcing HR, payroll, IT help-desk, or CRM functions to a third-party provider
- Using a cloud storage or analytics vendor that handles company-controlled personal data
- A vendor's own standard DPA needs to be counter-proposed with company-standard terms
- An existing vendor contract lacks a DPA and the company is conducting a data protection audit
This addendum supplements the master services agreement (MSA) or other main contract; it does not replace it.