Legal playbook · AI Employee: Lex

DPA Handling

DPA turnaround < 5 days

The problem

Data Processing Agreements are the specialised contract vehicle GDPR made unavoidable. Every enterprise customer now requires one; every DPA has 20-40 pages of legal language; every DPA request costs legal-team time regardless of whether the terms are standard or non-standard. The temptation to just sign the customer's version to speed the deal is real — and dangerous.

At a glance
Trigger
Form
Approvals
Privacy counsel review on custom terms
What it does
Writes to your systems
Systems
Ironclad · DocuSign · Privacy KB
How it feels in production

An hour-by-hour walkthrough.

Priya (sales) DMs Lex: "Acme needs a DPA signed before the deal can close. Their legal team sent us their template." Lex ingests the doc. Runs a diff against our approved DPA template. Categorises the diffs: - 12 clauses match our template exactly (green) - 6 clauses have minor wording differences that don't change substance (yellow) - 3 clauses have material differences — Acme requires 72-hour breach notification (we standardly offer 96), Acme requires audit rights annually (we offer biennially), Acme lists subprocessors we don't use (removable) Lex drafts a response: "3 material items need review. The subprocessor list can be cleaned up (recommendation: strike). The breach-notification difference is negotiable (we've accepted 72h for 3 prior enterprise deals). Audit-frequency likely needs GC sign-off." Routes to Sarah (privacy counsel) with Lex's analysis + the draft response + the deal context (Priya's summary, Acme's ARR). Sarah reviews in 45 minutes. Accepts strike on subprocessors, accepts 72h breach notification, approves annual audit for this deal. Countersigns via DocuSign. Priya sends signed DPA to Acme; deal closes. Total legal-team time: 45 minutes on the actually-hard clauses. Same request pre-Lex would have consumed 3-4 hours across template diff + wording review + sign-off — days of waiting. When a DPA has too many material differences (>10 material redlines), Lex declines to draft a response and escalates directly to Sarah — some negotiations deserve full human attention.
How it works

Step by step.

  1. 01

    Ingest DPA request

    Customer's DPA (or DPA-attachment on a broader MSA) submitted via Slack, email, or DocuSign envelope. Lex reads the document and classifies as DPA.

    Slack · Email · DocuSign
  2. 02

    Match to standard or route custom

    Diff against our approved DPA template. Categorise each clause: exact match, minor wording (non-material), material difference. Recommend response for each category.

    Knowledge Studio · Diff analysis
  3. 03

    Sign or negotiate

    Standard DPAs (all clauses match or minor wording): Lex prepares countersignature + sends via DocuSign after quick attorney check. Non-standard: Lex drafts response + routes to privacy counsel with material items highlighted.

    DocuSign · Legal review queue
  4. 04

    Store record

    Signed DPA archived to Ironclad with metadata: customer, effective date, term, material variations from template, subprocessor list. Discoverable in contract search.

    Ironclad
Systems and wiring

What you connect to make this run.

Ironclad · Adobe Sign

read+write

Approved DPA template lives in Ironclad. Lex diffs incoming against template; writes signed docs back with metadata.

DocuSign

read+write

OAuth with envelope-read + envelope-create scopes. Reads inbound envelopes for auto-classification; sends countersignature envelopes.

Knowledge Studio

read

DPA template + past-negotiated variations indexed. Lex references past deals to draft recommendations grounded in precedent.

Salesforce

read

Deal context — ARR, urgency, sales-cycle stage. Enables risk-appropriate response drafting.

What changes

Before and after, honestly.

Legal-team time per DPA
Before
3-6 hours per DPA (mostly diff + wording review)
After
30-60 minutes on material items only
DPA turnaround
Before
5-10 business days
After
Under 5 business days, most under 2
Deal-cycle delay from DPA
Before
2-4 weeks added to enterprise deals
After
Under 1 week for most
Rate of non-standard clauses accepted vs. rejected
Before
Ad-hoc; no consistency across deals
After
Consistent — precedent-grounded recommendations lead to consistent outcomes
Frequently asked

Answers about this playbook.

What about DPAs from small customers with quirky templates?

Same flow. Small customers with quirky templates surface as "many material differences" and route to counsel. Often the fastest path is: "here's our standard DPA, would this work for you?" — counsel drafts that response.

How does Lex handle sub-processor changes?

Sub-processor list changes trigger notifications per DPA terms. Adjacent playbook (subprocessor-list-management) coordinates the notifications; DPA-handling captures the notification requirements per customer at signing.

What if the customer requires audit rights we can't accommodate?

Audit-rights variations are common; Lex categorises as material and routes to GC. Recommendations grounded in what we've accepted for similar-tier customers previously.

Can Lex handle EU vs. US DPAs?

Yes — jurisdiction-appropriate templates. GDPR-specific for EU customers; state-privacy-law variants for US. Lex reads customer location to select template baseline.

How does this integrate with our CLM (Ironclad)?

Ironclad is the CLM source of truth. Lex reads the customer's contract history for context, writes signed DPAs back with full metadata. Ironclad handles the ongoing lifecycle (amendments, renewals, expiration).

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.