CDA Review Agreement
What the CDA Review Agreement Is and When It Applies
Why a Clear CDA Review Agreement Matters
A well-drafted CDA Review Agreement limits legal and operational risk by setting the scope of permitted review, protecting trade secrets and regulated data, and clarifying each party’s responsibilities under U.S. law such as ESIGN and applicable privacy rules.
Who commonly completes a CDA Review Agreement
Organizations and individuals use CDAs when exchanging proprietary material for evaluation, due diligence, or regulatory review.
- Corporations and business development teams sharing product roadmaps or proposals with potential partners or investors.
- Research institutions and life‑science companies exchanging protocol details, patient‑level or de‑identified clinical data.
- Legal and procurement teams coordinating vendor evaluations, redlines, and contract review prior to execution.
Parties should select signatories with authority to bind the organization, and include technical contacts for secure data transfer and retention coordination.
Who signs and why
Research Director
Usually serves as the primary signatory for academic or clinical providers, confirming institutional review and acceptable data use; coordinates secure transfer and tracks retention obligations across collaborators.
General Counsel
Legal counsel or corporate officers commonly sign on behalf of a company to accept confidentiality terms, allocate liability, and confirm that the agreement aligns with corporate policies and regulatory requirements.
Step-by-step: Completing a CDA Review Agreement
-
01Identify parties: Enter full legal names and roles for each party.
-
02Define scope: Describe exactly what materials are covered and permitted uses.
-
03Set term: Specify confidentiality period and an effective date.
-
04Specify remedies: Include return/destruction procedures and liability limits.
How to configure an online CDA review workflow
| Field | Configuration |
|---|---|
| Signer Order | Define signing sequence by role or email to ensure correct execution. |
| Authentication | Choose email link, SMS code, or stronger KBA where needed for identity assurance. |
| Attachments | Allow only approved file types and apply redaction controls when necessary. |
| Audit Trail | Capture timestamps, IP addresses, and action history for each signer. |
Digital signing and submission considerations
Ensure the platform you use supports required authentication, audit trails, and data protection for the CDA Review Agreement.
- Authentication: Email, SMS, KBA options
- Integrations: CRM and cloud storage
- Formats: PDF, DOCX, HTML
Use platforms with encryption in transit and at rest, auditability, and HIPAA‑capable controls where health data or regulated information is involved.
Where to send and how the signed CDA circulates
-
Upload: Sender uploads the CDA to the signing platform.
-
Place fields: Add signature, date, and initial fields as required.
-
Notify signers: Platform emails signers with a secure signing link.
-
Store copies: Each party receives a signed PDF and audit trail.
Typical timelines and processing expectations
Request to sign:
Immediate — many reviewers expect a 24–72 hour turnaround.
Standard review period:
Often 30–90 days depending on project complexity.
Return or destruction:
Typically 30–90 days after request or upon termination.
Audit preservation:
Retain execution records per retention policy.
Amendments:
Treat as instant if all parties consent in writing.
Key milestones in CDA review processing
Drafting Complete
Agreement finalized and prepared for signatures.
Signatory Review
Legal and operational reviews completed.
Execution
All parties sign and receive certified copies.
Data Exchange
Confidential materials delivered under agreed controls.
Common preparation mistakes to avoid
- Vague scope definitions that fail to list covered materials and permitted uses, leading to disputes over disclosure boundaries.
- Incorrect or inconsistent party names that create enforcement challenges or delay signatory acceptance and tax reporting.
- Missing return or destruction provisions that leave uncertainty about how long recipients may retain confidential materials.
- Insufficient authentication or audit trail details that weaken admissibility of electronic execution under ESIGN or UETA.
Risks and potential consequences of an incorrect CDA
Real examples of CDA use in practice
Brian Fitzgibbons — Optica Ventures LLC
A venture firm needed a rapid evaluation protocol for startup data under time pressure
- They used a standard CDA with explicit scope and destruction terms
- The firm reported streamlined diligence cycles and clearer handoffs between legal, technical, and investment teams while preserving confidentiality.
Kodi‑Marie Evans — Xerox
A large enterprise required vendor demonstrations involving proprietary integrations
- The CDA limited use to evaluation and required return of test artifacts
- This reduced accidental IP exposure and clarified post‑trial obligations for both parties and integrations teams.
Comparing eSignature providers for CDA Review Agreement execution
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
Frequently asked questions about CDA Review Agreements
-
Can a CDA be signed electronically?
Yes. Electronic signatures meet U.S. legal standards under the ESIGN Act (15 U.S.C. ch. 96) and UETA where adopted, provided intent, consent, attribution, and retention are established.
-
Is HIPAA affected by a CDA?
When CDA covers protected health information, include a Business Associate Agreement and specific HIPAA safeguards; mishandling can trigger 45 CFR §164.500‑§164.534 obligations.
-
Do I need a notary or witnesses?
Most CDAs do not require notarization or witnesses, but state or industry rules may impose extra steps for certain documents; verify state requirements for deeds or statutory instruments.
-
What happens if a signer’s name is wrong?
Incorrect party names can impede enforcement. Correct errors before execution or include a confirming amendment signed by both parties to avoid ambiguity.
-
How long should we retain execution records?
Retain signed agreements and audit trails for the active term plus at least three to seven years depending on regulatory or contractual obligations and the type of data exchanged.
-
Can a CDA be amended after signing?
Yes. Amendments require clear written consent by all parties; document the effective date and attach the amendment to the original executed agreement.