DPA red-flag review

Use case · Compliance

← All use cases
§

DPA red-flag review

Compliance

Scan a vendor Data Processing Agreement for GDPR/CCPA red flags — sub-processors, international transfers, breach SLAs, audit rights, deletion — and suggest redlines.

The routing recipe
Job typeComplex reasoningPolicyBest qualityConstraintsctx ≥ 128k
routes to
NVIDIA Nemotron 3 Ultra 550B-A55B nvidia
nvidia:nvidia/nemotron-3-ultra-550b-a55b
93.7
match score
96.5
task fit
100
cost
59.5
speed
Why this model from benchmarks & capabilities
  • "Complex reasoning" leans hardest on reasoning; NVIDIA Nemotron 3 Ultra 550B-A55B scores 100/100 there — top-1 of 40 chat models.
  • Strength on this class of work shows up on GPQA Diamond, MMLU-Pro, BIG-Bench Hard, where NVIDIA models are competitive.
  • Cost: runs on NVIDIA free credits / self-hostable NIM — effectively $0 marginal. Speed: ~70 tok/s (estimated).
  • Chosen over DeepSeek V4 Pro for cheaper & faster.
Capability the job needsWeightNVIDIA Nemotron 3 Ultra 550B-A55BCatalog rank
reasoning1.00100#1 of 40
math0.6099#3 of 40
knowledge0.5092#4 of 40
Relevant benchmarksGPQA Diamond MMLU-Pro BIG-Bench Hard LiveBench (reasoning) EconomicsCost: runs on NVIDIA free credits / self-hostable NIM — effectively $0 marginal.
Speed: ~70 tok/s (estimated).
vs runner-upChosen over DeepSeek V4 Pro for cheaper & faster. (DeepSeek V4 Pro, score 91.8)
Example result
Sample input ▾
DPA §7: "Processor may engage sub-processors at its discretion and will maintain a list available on request." §9: "Processor shall notify Controller of a personal data breach without undue delay, and in any case within 30 days."
Sub-processors — RISK: "at its discretion" removes your consent right. Quote §7. Redline: "…with 30 days' prior written notice and a right to object." Breach SLA — RISK: 30 days is far outside GDPR Art. 33 (72h to the regulator). Quote §9. Redline: "…without undue delay and no later than 48 hours after becoming aware." Transfers — GAP: no transfer mechanism named. Add: "International transfers rely on the EU SCCs (2021/914) Module 2." Top 3 must-fix: (1) breach SLA → 48h; (2) sub-processor prior-notice + objection; (3) name SCCs + deletion-on-termination clause.
Test it on your own data
Sign in to continue

LLM Switchboard is private — sign in with Authlee to access the control room.

Sign in with Authlee
← Back to home