Data Sharing Agreement
A data sharing agreement governs a defined exchange of data between parties and specifies lawful purpose, permitted users, quality, security, onward disclosure, linkage, retention, publication, and deletion.
Direct answer
What is the purpose of Data Sharing Agreement?
Use a data sharing agreement when parties exchange data for their own or joint purposes and analyze privacy roles, confidentiality, licensing, ethics, and sector rules before transfer.
01
What Data Sharing Agreement does
A data sharing agreement governs a defined exchange of data between parties and specifies lawful purpose, permitted users, quality, security, onward disclosure, linkage, retention, publication, and deletion.
A useful document turns the parties' actual arrangement into measurable duties, approvals, timing, remedies, and a reliable execution record. Its terms should be reconciled to the transaction rather than copied from an unrelated form.
02
When this agreement is commonly used
- Organizations exchange datasets for research, benchmarking, fraud prevention, or service coordination
- Affiliates or partners share customer, operational, or de-identified information
- A data provider licenses a dataset with use and redistribution restrictions
03
When another document or professional review may be better
The document name alone does not determine the right structure. Consider a different instrument or qualified legal review when any of these conditions applies:
- Do not call data anonymous or de-identified without a defensible method and controls against reidentification.
- Do not use a sharing agreement to bypass consent, notice, research, confidentiality, competition, or statutory restrictions.
04
Information to collect before drafting
Record exact facts before clauses are written. Names, authority, dates, amounts, defined terms, dependencies, and incorporated materials should be verifiable and consistent.
- Provider, recipient, privacy roles, authority, purposes, and approved users
- Datasets, fields, formats, quality, sensitivity, provenance, and update schedule
- Transfer method, access controls, linkage, onward disclosure, outputs, and publication
- Retention, correction, incident response, individual rights, audit, deletion, and derived data
05
Key decisions to make
These decisions shape the allocation of responsibility and should not be left for boilerplate to decide:
- Which purposes and users are authorized
- Whether personal, confidential, proprietary, or regulated data is included
- Whether data may be linked, modeled, published, or redistributed
- Who corrects source data and controls derived outputs after termination
06
Provisions the agreement commonly addresses
- Purpose, authority, roles, and data description
- Transfer, access, permitted uses, linkage, and prohibited uses
- Quality, correction, security, incidents, and confidentiality
- Onward disclosure, outputs, publication, IP, and attribution
- Retention, deletion, audit, suspension, and termination
Every provision should use the same parties, dates, standards, defined terms, and document hierarchy. A clause that is reasonable by itself can still create a conflict when it is not reconciled with payment, default, termination, or another exhibit.
07
How to prepare a Data Sharing Agreement
- 01Describe the intended result and the relationship in plain language.
- 02Confirm parties, authority, governing jurisdiction, dates, money, property, services, and approvals.
- 03Resolve the key decisions and identify every schedule, exhibit, disclosure, consent, or filing.
- 04Draft the provisions as one consistent system, then review the complete execution set before signature.
08
Material risks and source-backed checks
Purpose creep, reidentification, poor provenance, unlawful onward disclosure, and competitively sensitive exchanges can turn a useful dataset into major regulatory and reputational exposure.
09
Supporting documents and the complete package
The main agreement may establish the framework while schedules, exhibits, disclosures, consents, or operational records supply transaction-specific details.
- Dataset and field dictionary
- Privacy, ethics, or security assessment
- Transfer, access-control, and deletion procedure
Each incorporated document should be identified precisely, use the same names and effective date, and follow a stated order of precedence if terms conflict.
10
Review and execution checklist
Approve the exact field dictionary, complete legal and ethical review, use secure transfer and named access groups, log exports, review use periodically, and certify deletion when access ends.
- Confirm legal names, roles, capacity, addresses, and signing authority
- Reconcile dates, amounts, definitions, cross-references, schedules, and exhibits
- Confirm that duties, deadlines, approvals, acceptance standards, and payment triggers are measurable
- Check that default, termination, remedies, and surviving obligations work together
- Complete jurisdiction-specific forms, notices, witnesses, notarization, filings, or professional review when applicable
- Deliver and preserve the complete signed package with its incorporated documents
11
Authoritative references and further reading
These sources provide federal, state-resource, regulatory, or institutional context. They do not replace checking the law and required forms applicable to the parties, transaction, and governing jurisdiction.
Source 1
Privacy FrameworkNational Institute of Standards and Technology. Institutional framework for managing privacy risk.
Source 2
Data SecurityFederal Trade Commission. Federal business guidance for reasonable data-security practices.
Source 3
De-identification of Protected Health InformationU.S. Department of Health and Human Services. Official guidance on HIPAA de-identification methods.
Source 4
Dealings with CompetitorsFederal Trade Commission. Current federal competition guidance on joint ventures, information sharing, and other dealings among competitors.
Frequently asked questions
Questions about Data Sharing Agreement
What does a Data Sharing Agreement establish?
A data sharing agreement governs a defined exchange of data between parties and specifies lawful purpose, permitted users, quality, security, onward disclosure, linkage, retention, publication, and deletion.
When is a Data Sharing Agreement usually the wrong document?
Do not call data anonymous or de-identified without a defensible method and controls against reidentification. Do not use a sharing agreement to bypass consent, notice, research, confidentiality, competition, or statutory restrictions.
Is de-identified data outside every privacy law?
No. Standards differ, some laws regulate pseudonymous or reasonably linkable data, and contractual and technical controls may be required to maintain de-identified status.
Which decisions should be settled before drafting a Data Sharing Agreement?
Before drafting, the parties should resolve these agreement-specific questions: Which purposes and users are authorized; Whether personal, confidential, proprietary, or regulated data is included; Whether data may be linked, modeled, published, or redistributed; Who corrects source data and controls derived outputs after termination. They should reconcile those choices with the governing jurisdiction and the verified intake facts, including: Provider, recipient, privacy roles, authority, purposes, and approved users.
What may need to accompany a Data Sharing Agreement?
The execution package may include Dataset and field dictionary, Privacy, ethics, or security assessment, Transfer, access-control, and deletion procedure. The parties should attach only the materials that apply and identify each one by name, date, or version.
Related contract guides