Description
The Data Protection Reviewer takes privacy policies, data processing agreements (DPAs), and technical and organizational measures (TOMs) from external vendors and assesses them systematically against GDPR. It checks completeness, rates every relevant clause with a traffic light system (green, yellow, red), and turns the findings into concrete renegotiation points. Particular focus: third country transfer clauses, which have regularly been the most critical point in such reviews since Schrems II. This explicitly includes reviews of AI tools, for example when a team wants to use ChatGPT, a new SaaS product, or an automation provider and needs to know beforehand where data travels and which commitments are missing from the fine print.
It is built for data protection officers, IT leads, compliance managers, procurement, and management at DACH small and mid-sized companies who need a structured pre-check before every new tool or vendor decision, without bringing in outside counsel for every single case.
What it deliberately does not do: it does not replace legal review, makes no legally binding statements, and does not invent processing activities that are not in the document. Where information is missing or a document is incomplete, it explicitly flags this as an assumption or a gap rather than glossing over it. Note: this tool does not constitute legal advice. Seek a qualified legal review of results with legal implications before making decisions.




