Data sharing agreement: what it is and what to include

A data sharing agreement is a written contract that controls how one organization discloses data to another, fixing the purpose of the exchange, the permitted uses, the security obligations, and the length of the arrangement. It protects both sides by defining who owns the data, how it may be handled, and what must happen when the relationship ends or something goes wrong.

What a data sharing agreement is

A data sharing agreement (also called a data sharing contract, data use agreement, or data transfer agreement) is a legally binding document between a party that supplies data and a party that receives or accesses it. It records the exact terms under which specific datasets move between the organizations or become available to the recipient. Those datasets may include customer personal information, employee records, financial figures, research inputs, product telemetry, or aggregated analytics.

The agreement answers a practical question that informal handoffs leave open: once the data leaves your systems, what is the other party allowed to do with it? Rather than relying on trust or a loose email, the contract sets enforceable boundaries. It names the datasets, ties them to a defined purpose, and holds the recipient to specific standards for storage, access, and disposal. Because data often carries privacy and regulatory weight, the agreement usually cross-references applicable laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Health Insurance Portability and Accountability Act for protected health information, or the General Data Protection Regulation when European personal data is involved.

A data sharing agreement can stand alone or sit inside a larger deal. It is common to see it as a schedule to a master services agreement, a research collaboration, a vendor onboarding pack, or a joint marketing arrangement. Whatever its form, its job is the same: make the rights, duties, and limits of the data exchange explicit and provable.

Key terms and clauses to include

A strong data sharing agreement leaves little to interpretation. The following clauses form its backbone:

  • Parties and roles. Identify the data provider and the data recipient, and state each party’s legal role. Under privacy law that may mean labeling one party a controller and another a processor, or a business and a service provider.
  • Purpose and permitted use. Describe why the data is shared and the specific uses allowed. A tightly drawn purpose clause is the single most important limit in the contract, because it blocks scope creep and secondary use.
  • Data description and scope. List the datasets, fields, formats, and volumes covered. Vague references to “our data” invite disputes later.
  • Ownership and license. State who owns the data and what license, if any, the recipient receives. Ownership rarely transfers; the recipient usually gets a limited, revocable right to use the data for the stated purpose only.
  • Confidentiality. Require the recipient to keep the data confidential and to restrict access to personnel with a genuine need to know.
  • Security safeguards. Specify technical and organizational measures such as encryption in transit and at rest, access controls, logging, and personnel training. Reference a recognized standard where one applies.
  • Privacy and compliance. Allocate responsibility for meeting applicable data protection laws, including notice, consent, and individual rights handling.
  • Onward transfer and subcontracting. State whether the recipient may share the data with affiliates, subprocessors, or third parties, and on what conditions.
  • Retention and deletion. Set how long the recipient may hold the data and require certified deletion or return when the purpose ends.
  • Audit and verification. Give the provider the right to request evidence of compliance or to audit the recipient’s controls.
  • Breach notification. Require prompt notice of any security incident, with a defined timeline and required content.
  • Liability and indemnification. Allocate risk for misuse, breaches, and regulatory penalties, and set any caps or carve-outs.
  • Term and termination. Define the duration, renewal, and the grounds on which either party may end the arrangement.
  • Governing law and dispute resolution. Choose the governing law and the forum or arbitration path for disputes.

Each clause should reinforce the others. The purpose clause defines the boundary, the security and retention clauses protect the data inside that boundary, and the audit, breach, and liability clauses provide remedies when the boundary is crossed.

When you need one

You need a data sharing agreement whenever data of any sensitivity leaves your control or is opened to an outside party. Common triggers include:

  • Engaging a vendor, analytics provider, or cloud service that will process your customer or employee data.
  • Entering a partnership, joint venture, or co-marketing deal where each side contributes data.
  • Participating in research or a consortium that pools datasets across organizations.
  • Sharing data with an affiliate or subsidiary that sits under separate legal ownership.
  • Transferring personal data across borders, which often brings extra legal requirements.

Even sharing that feels routine, such as passing a lead list to a marketing agency or sending records to an auditor, deserves a written agreement. The cost of drafting one is small next to the cost of a privacy investigation, a lost dataset, or a dispute over who owned what. If personal or regulated data is involved, treat the agreement as mandatory rather than optional.

Common pitfalls

The most frequent failure is a purpose clause that is too broad. When the permitted use is written loosely, the recipient can justify almost any activity, and the provider loses the control the contract was meant to give. Draft the purpose narrowly and add an express ban on secondary use.

A second pitfall is silence on deletion. Many agreements describe how data is shared but never say when it must be destroyed. Without a deletion clause, copies linger in the recipient’s systems long after the purpose ends, expanding the attack surface and the compliance burden.

Third, parties often skip the roles analysis required by privacy law. Labeling each side correctly, whether as controller and processor or business and service provider, drives specific obligations, and getting it wrong can void other protections.

Fourth, security terms are frequently vague. “Reasonable measures” means little without concrete controls, so name the safeguards you expect. Finally, teams sign the agreement and then lose track of it. Renewal dates pass, deletion deadlines slip, and no one holds the recipient to the audit rights they negotiated.

That last pitfall is a management problem as much as a drafting one. A data sharing agreement only protects you if its obligations are tracked and enforced across its whole life. Storing every executed agreement in a central contract repository, extracting the key dates and duties, and receiving alerts before renewal or deletion deadlines turns a static document into a living control. Pactolane’s CLM platform keeps these agreements in one repository with an audit trail and renewal and deadline alerts, while PactAI can extract obligations, score risk, and surface conflicting terms so the human reviewer decides with full context. Disciplined contract management is what carries a data sharing agreement from signature to the day the data is finally, verifiably deleted.

This is general legal information, not legal advice.

Key clauses in this agreement

The clauses that carry the risk in this contract type.

Frequently asked questions

What is a data sharing agreement?

A data sharing agreement is a written contract that governs how one organization discloses data to another, setting the purpose, permitted uses, security obligations, and duration of the exchange. It defines who owns the data, how the recipient may use it, and what happens when the arrangement ends or a breach occurs. The document turns an informal handoff into an enforceable set of boundaries. This is general legal information, not legal advice.

How is a data sharing agreement different from an NDA?

An NDA mainly stops the recipient from disclosing confidential information to others, while a data sharing agreement goes further and governs how the recipient may actually use, store, secure, and dispose of specific datasets. A data sharing agreement typically covers permitted purpose, ownership, retention, deletion, audit rights, and privacy compliance in addition to confidentiality. In practice the two are often combined, with the sharing agreement carrying the detailed data terms.

When is a data sharing agreement legally required?

A data sharing agreement is prudent whenever data leaves your control, and it becomes effectively mandatory when personal or regulated data is involved. Privacy laws such as the CCPA as amended by the CPRA, HIPAA, and the GDPR often require written terms between the parties handling the data. Confirm the specific triggers that apply to your data and jurisdiction with counsel.

What clauses should a data sharing agreement include?

A data sharing agreement should include the parties and their roles, a narrow purpose and permitted-use clause, a clear description of the datasets, ownership and license terms, confidentiality, and security safeguards. It should also address privacy compliance, onward transfer, retention and deletion, audit rights, breach notification, liability, term and termination, and governing law. The purpose clause is the most important limit, because it prevents scope creep and secondary use.

Who owns the data under a data sharing agreement?

Under most data sharing agreements ownership stays with the provider, and the recipient receives only a limited, revocable license to use the data for the agreed purpose. The agreement should state ownership expressly rather than leaving it implied, because silence invites later disputes. It should also confirm that the license ends when the purpose is fulfilled or the contract terminates, triggering return or certified deletion of the data.

In the same family

Not to be confused with

Comparisons that set this agreement apart.

On the same topic

Other pages closely related to this one.

This page provides general legal information, not legal advice. Every situation is specific: for a binding contract, consult a qualified legal professional.

Manage my cookies