Establishing secure connection…Loading editor…Preparing document…

CDA Review Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

CDA REVIEW AGREEMENT

This CDA Review Agreement (the Agreement) is made as of Effective Date: by and between Company Name: , a(n) with principal place of business at (Company), and Reviewer Name: , a(n) with principal place of business at (Reviewer).

RECITALS

WHEREAS, Company and one or more third parties are parties to one or more Confidential Disclosure Agreements and possess Confidential Information related to certain research, business, clinical or technical matters (the CDA Materials); and

WHEREAS, Company desires to engage Reviewer to perform an independent review of the CDA Materials and provide a written assessment and recommendations regarding confidentiality terms, obligations, and risk; and

WHEREAS, Reviewer has the requisite experience and expertise to perform such review under the terms and protections set forth herein.

NOW, THEREFORE, in consideration of the mutual covenants set forth below, the parties agree as follows:

1. SCOPE OF REVIEW

1.1 Services. Reviewer shall review the CDA Materials delivered by Company and provide a written report identifying material confidentiality, disclosure, confidentiality period, restriction, and return/destruction provisions, together with suggested revisions and a summary of material risk items (Deliverables). The scope of Documents to be reviewed is:

1.2 Timing. Reviewer shall deliver the Deliverables by Review Due Date: or within days after receipt of complete CDA Materials, unless extended in writing.

2. CONFIDENTIALITY

2.1 Definition. "Confidential Information" means non-public information disclosed by Company to Reviewer that is identified as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, including the CDA Materials and any third-party terms.

2.2 Non-Disclosure and Use. Reviewer shall (a) not disclose Confidential Information to any person except as expressly permitted herein; (b) use Confidential Information solely to perform the review services; and (c) apply at least the same degree of care to protect Confidential Information as Reviewer uses to protect its own confidential information but in no event less than a reasonable standard of care.

2.3 Permitted Disclosures. Reviewer may disclose Confidential Information to its employees, consultants, or advisors who have a need to know and who are bound by confidentiality obligations at least as protective as those in this Agreement. Reviewer shall remain liable for any breach by such persons.

2.4 Exclusions. Confidential Information does not include information that: (a) is or becomes generally available to the public other than by a breach of this Agreement; (b) was lawfully known to Reviewer prior to disclosure; (c) is received from a third party without breach of an obligation of confidentiality; or (d) is independently developed by Reviewer without use of or reference to the Confidential Information.

2.5 Return or Destruction. Upon Company’s written request following termination or expiration of this Agreement, Reviewer shall return or certify destruction of Confidential Information within days.

2.6 Duration. The obligations of confidentiality under this Section 2 shall continue for a period of following disclosure, unless otherwise required by applicable law.

3. DELIVERABLES & INTELLECTUAL PROPERTY

3.1 Deliverables. Reviewer shall provide the Deliverables in writing and in a format reasonably acceptable to Company. Deliverables shall expressly identify any assumptions made by Reviewer in performing the review.

3.2 Ownership. Company shall own all right, title and interest in and to the Deliverables including any analyses, notes and written reports created specifically for Company under this Agreement, and Reviewer hereby assigns and agrees to assign all such rights to Company. Reviewer retains ownership of Reviewer’s pre-existing ideas, know-how, templates and methodologies, provided no Confidential Information of Company is disclosed in a manner inconsistent with this Agreement.

3.3 Limited License. To the extent any intellectual property rights of Reviewer are incorporated in the Deliverables, Reviewer hereby grants Company a perpetual, irrevocable, royalty-free, worldwide license to use, reproduce and modify such materials as required for Company’s internal purposes.

4. COMPENSATION & EXPENSES

4.1 Fees. Company shall pay Reviewer a fee of $ for the services described herein, payable in accordance with Section 4.2.

4.3 Expenses. Company shall reimburse Reviewer for reasonable pre-approved out-of-pocket expenses incurred in connection with the review upon receipt of substantiating documentation.

5. TERM AND TERMINATION

5.1 Term. This Agreement commences on the Effective Date and continues until completion of the Deliverables unless earlier terminated in accordance with this Section 5.

5.2 Termination. Either party may terminate this Agreement for convenience upon days’ prior written notice to the other party. Either party may terminate immediately upon written notice if the other party materially breaches this Agreement and fails to cure within 15 days of notice of the breach.

5.3 Effect of Termination. Upon termination, Reviewer shall cease use of Confidential Information and, at Company’s option, return or destroy Confidential Information as provided in Section 2.5. Termination shall not relieve Company of the obligation to pay for services performed and expenses incurred through the effective date of termination.

6. REPRESENTATIONS, WARRANTIES AND DISCLAIMERS

6.1 Mutual Representations. Each party represents and warrants that it has full power and authority to enter into this Agreement and to perform its obligations hereunder.

6.2 Reviewer Warranty. Reviewer represents that it will perform services in a professional and workmanlike manner in accordance with generally accepted industry standards. Reviewer does not warrant the legal sufficiency of any third-party CDA or the outcome of any negotiation based on the Deliverables.

6.3 Disclaimer. EXCEPT AS EXPRESSLY PROVIDED IN SECTION 6.2, THE DELIVERABLES ARE PROVIDED "AS IS" AND COMPANY ACKNOWLEDGES THAT REVIEWER MAKES NO OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

7. LIMITATION OF LIABILITY

To the maximum extent permitted by law, neither party shall be liable for special, incidental, consequential, punitive or exemplary damages, and each party's aggregate liability for any and all claims arising out of or in connection with this Agreement shall not exceed the total fees paid by Company to Reviewer under this Agreement in the twelve (12) month period preceding the event giving rise to the claim.

8. INDEMNIFICATION

Reviewer shall indemnify, defend and hold harmless Company and its officers, directors and affiliates from and against any claims, losses or liabilities arising from Reviewer’s gross negligence or willful misconduct in performing the services. Company shall indemnify, defend and hold harmless Reviewer from claims arising out of Company’s breach of Section 2 or misuse of the Deliverables.

9. NOTICES

Notices shall be in writing and shall be deemed given upon personal delivery, confirmed delivery by commercial courier, or three (3) business days after deposit in the U.S. mail, postage prepaid, to the addresses set forth above or such other address as a party may designate by notice.

10. GOVERNING LAW; MISCELLANEOUS

10.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of , without regard to conflict of laws principles.

10.2 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, proposals and communications, whether oral or written.

10.3 Amendments. Any amendment or modification of this Agreement must be in writing and signed by authorized representatives of both parties.

10.4 Waiver. No waiver of any term or condition shall be deemed a continuing waiver or a waiver of any other provision, and no waiver shall be binding unless in writing and signed by the waiving party.

10.5 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect and the parties shall negotiate in good faith to replace the invalid provision with a valid provision that achieves, to the extent possible, the original economic, legal and commercial objectives.

10.6 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument. A signed copy transmitted by electronic means shall be deemed an original for all purposes.

10.7 Assignment. Neither party may assign this Agreement without the prior written consent of the other party, except that Company may assign this Agreement in connection with a merger or sale of substantially all of its assets.

Company:

By:

Date:

Reviewer:

By:

Date:

Enter text✕

What the CDA Review Agreement Is and When It Applies

A CDA Review Agreement is a legal confidentiality arrangement used when one party shares confidential information with another for the purpose of review, evaluation, or limited collaboration. It defines permitted uses, disclosure restrictions, data handling requirements, duration of confidentiality, and return or destruction obligations. In many contexts the CDA covers sensitive business plans, clinical or research data, technical specifications, or proprietary processes. The document may also address data security measures, permitted recipients, and consequences for unauthorized disclosure.

Why a Clear CDA Review Agreement Matters

A well-drafted CDA Review Agreement limits legal and operational risk by setting the scope of permitted review, protecting trade secrets and regulated data, and clarifying each party’s responsibilities under U.S. law such as ESIGN and applicable privacy rules.

Why a Clear CDA Review Agreement Matters

Who commonly completes a CDA Review Agreement

Organizations and individuals use CDAs when exchanging proprietary material for evaluation, due diligence, or regulatory review.

  • Corporations and business development teams sharing product roadmaps or proposals with potential partners or investors.
  • Research institutions and life‑science companies exchanging protocol details, patient‑level or de‑identified clinical data.
  • Legal and procurement teams coordinating vendor evaluations, redlines, and contract review prior to execution.

Parties should select signatories with authority to bind the organization, and include technical contacts for secure data transfer and retention coordination.

Who signs and why

Research Director

Usually serves as the primary signatory for academic or clinical providers, confirming institutional review and acceptable data use; coordinates secure transfer and tracks retention obligations across collaborators.

General Counsel

Legal counsel or corporate officers commonly sign on behalf of a company to accept confidentiality terms, allocate liability, and confirm that the agreement aligns with corporate policies and regulatory requirements.

Step-by-step: Completing a CDA Review Agreement

Follow these steps to fill, review, and execute a CDA Review Agreement efficiently and consistently.

  • 01
    Identify parties: Enter full legal names and roles for each party.
  • 02
    Define scope: Describe exactly what materials are covered and permitted uses.
  • 03
    Set term: Specify confidentiality period and an effective date.
  • 04
    Specify remedies: Include return/destruction procedures and liability limits.

How to configure an online CDA review workflow

Typical online workflows reduce manual steps and preserve an audit trail required for enforceability and compliance.

Field Configuration
Signer Order Define signing sequence by role or email to ensure correct execution.
Authentication Choose email link, SMS code, or stronger KBA where needed for identity assurance.
Attachments Allow only approved file types and apply redaction controls when necessary.
Audit Trail Capture timestamps, IP addresses, and action history for each signer.

Digital signing and submission considerations

Ensure the platform you use supports required authentication, audit trails, and data protection for the CDA Review Agreement.

  • Authentication: Email, SMS, KBA options
  • Integrations: CRM and cloud storage
  • Formats: PDF, DOCX, HTML

Use platforms with encryption in transit and at rest, auditability, and HIPAA‑capable controls where health data or regulated information is involved.

Where to send and how the signed CDA circulates

Follow an ordered routing path and preserve a copy for each party and for compliance records.

  • Upload: Sender uploads the CDA to the signing platform.
  • Place fields: Add signature, date, and initial fields as required.
  • Notify signers: Platform emails signers with a secure signing link.
  • Store copies: Each party receives a signed PDF and audit trail.

Typical timelines and processing expectations

Understand common timing expectations to avoid lapses in protection and to meet review deadlines.

Request to sign:

Immediate — many reviewers expect a 24–72 hour turnaround.

Standard review period:

Often 30–90 days depending on project complexity.

Return or destruction:

Typically 30–90 days after request or upon termination.

Audit preservation:

Retain execution records per retention policy.

Amendments:

Treat as instant if all parties consent in writing.

Key milestones in CDA review processing

A sequential view of milestones helps coordinate legal review, technical handoff, and secure data transfer.

01

Drafting Complete

Agreement finalized and prepared for signatures.

02

Signatory Review

Legal and operational reviews completed.

03

Execution

All parties sign and receive certified copies.

04

Data Exchange

Confidential materials delivered under agreed controls.

Common preparation mistakes to avoid

  • Vague scope definitions that fail to list covered materials and permitted uses, leading to disputes over disclosure boundaries.
  • Incorrect or inconsistent party names that create enforcement challenges or delay signatory acceptance and tax reporting.
  • Missing return or destruction provisions that leave uncertainty about how long recipients may retain confidential materials.
  • Insufficient authentication or audit trail details that weaken admissibility of electronic execution under ESIGN or UETA.

Risks and potential consequences of an incorrect CDA

Contract Voidance: Ambiguous terms can render protections unenforceable.
Data Breach Liability: Failure to secure data increases regulatory exposure.
Regulatory Penalties: HIPAA fines possible for PHI mishandling.
Civil Damages: Injunctive relief or money damages.
Tax Consequences: Incorrect payee info can trigger withholding.
Reputational Harm: Disclosure incidents damage trust and relationships.

Security, compliance, and technical requirements to include

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Audit Trail: Timestamps, IPs, and action history
HIPAA: BAA required for protected health information
ESIGN/UETA: Electronic execution validity in the U.S.
Access Controls: Role-based access and MFA for privileged users
Certifications: SOC 2 Type II and ISO 27001 available

Real examples of CDA use in practice

These concise customer scenarios show how organizations used CDAs to protect data during review and negotiation.

Brian Fitzgibbons — Optica Ventures LLC

A venture firm needed a rapid evaluation protocol for startup data under time pressure

  • They used a standard CDA with explicit scope and destruction terms
  • The firm reported streamlined diligence cycles and clearer handoffs between legal, technical, and investment teams while preserving confidentiality.

Kodi‑Marie Evans — Xerox

A large enterprise required vendor demonstrations involving proprietary integrations

  • The CDA limited use to evaluation and required return of test artifacts
  • This reduced accidental IP exposure and clarified post‑trial obligations for both parties and integrations teams.

Comparing eSignature providers for CDA Review Agreement execution

Common pricing and capability criteria when choosing an eSignature provider; signNow appears first per table requirements.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Frequently asked questions about CDA Review Agreements

Answers to common execution, validity, and data handling questions about CDA Review Agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users