Third-Party Risk & DPA Clause Classification
Scope of Project The project involved enterprise-wide annotation and classification of third-party vendor contracts and Data Processing Agreements (DPAs) across the EMEA region to support AI-driven contract review and third-party risk assessment. The dataset comprised large volumes of unstructured legal text (PDFs and Word documents), including GDPR Article 28 clauses, cross-border transfer mechanisms, breach notification terms, sub-processor provisions, retention periods and technical and organisational measures. The scope included clause-level classification, named entity recognition (e.g., jurisdictions, timelines), span annotation to highlight mandatory language, and structured risk scoring aligned to regulatory requirements. Quality standards were critical due to the regulatory context. Clear annotation guidelines were defined, with multi-stage QA review and senior validation to ensure consistency. Inter-annotator agreement measures, calibration sessions and documented edge-case