Establishing secure connection…Loading editor…Preparing document…

Data Sharing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA SHARING AGREEMENT

This Data Sharing Agreement (the Agreement) is made effective as of Effective Date: by and between Party A: , with principal place of business at (hereinafter "Data Provider"), and Party B: , with principal place of business at (hereinafter "Data Recipient").

RECITALS

WHEREAS, Data Provider possesses certain data, records and datasets described herein that are necessary to accomplish the Purpose set forth below; and

WHEREAS, Data Recipient seeks access to such data for the limited and lawful purposes described below and represents that it has the technical and organizational measures necessary to protect such data; and

WHEREAS, the Parties desire to set forth the terms and conditions governing the transfer, access, use, protection, retention and disposition of the Shared Data.

NOW, THEREFORE

In consideration of the mutual promises and covenants contained herein, the Parties agree as follows:

1. DEFINITIONS

1.1 "Shared Data" means all information, data files, reports and datasets described in Section 2 and provided by Data Provider to Data Recipient under this Agreement. Shared Data includes Personal Data where indicated.

1.2 "Personal Data" means any information relating to an identified or identifiable natural person to the extent included in the Shared Data.

1.3 "Security Breach" means any unauthorized access to, acquisition of, or disclosure of Shared Data that compromises the confidentiality, integrity or availability of the Shared Data.

2. SCOPE OF DATA TO BE SHARED

2.1 Description of Shared Data: The categories and fields of data to be shared are described below. The Parties acknowledge that the description below controls the permissible content of any transfer.

Yes No

3. PURPOSE AND PERMITTED USE

3.1 Purpose: Data Recipient shall use the Shared Data solely for the following purpose: . Any other use is prohibited unless expressly agreed in writing.

3.2 Use Restrictions: Data Recipient shall not, and shall ensure its personnel and subcontractors do not, (a) sell or transfer Shared Data to third parties for marketing or commercial resale; (b) attempt to re-identify anonymized data; or (c) use Shared Data to discriminate unlawfully against any individual.

4. SECURITY AND CONFIDENTIALITY

4.1 Security Measures: Data Recipient shall implement and maintain administrative, technical and physical safeguards appropriate to the sensitivity of the Shared Data, including encryption in transit and at rest, access controls based on least privilege, secure authentication, logging of access to Shared Data and regular vulnerability management.

4.2 Confidentiality: Each Party shall treat Shared Data as confidential information and shall not disclose such data to any third party except as permitted by this Agreement or as required by law. Access shall be limited to employees, contractors or agents who have a documented need to know and who are bound by confidentiality obligations at least as protective as those in this Agreement.

5. DATA SUBJECT RIGHTS

5.1 Assistance: To the extent applicable, the Parties shall cooperate to enable each Party to comply with rights requests from data subjects (such as access, correction, deletion or portability) and to provide reasonable assistance in responding to such requests within the timeframes required by applicable law.

5.2 Allocation of Responsibility: The Parties shall document and agree, in writing, which Party is responsible for responding to a particular data subject request prior to responding to the data subject.

6. SECURITY BREACH NOTIFICATION

6.1 Notification: In the event of a Security Breach affecting Shared Data, the Party discovering the breach shall notify the other Party without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware. Notification shall include a description of the nature, scope and remediation steps taken.

6.2 Mitigation: Each Party shall reasonably cooperate in investigating the Security Breach, mitigating harm and fulfilling regulatory or data subject notification obligations.

7. AUDIT RIGHTS AND RECORDS

7.1 Audit: Upon reasonable prior written notice, Data Provider may audit Data Recipient's compliance with this Agreement no more than once per calendar year, during normal business hours and subject to confidentiality protections. Audits shall be conducted at Data Provider's expense unless material noncompliance is identified.

7.2 Records: Each Party shall maintain records of processing activities and technical and organizational measures relevant to the Shared Data and shall retain such records for the term of this Agreement and for a reasonable period thereafter to satisfy legal obligations.

8. LIABILITY AND INDEMNIFICATION

8.1 Indemnification: Each Party (Indemnifying Party) shall indemnify, defend and hold harmless the other Party and its affiliates and their respective officers, directors and employees (Indemnified Parties) from and against any third-party claims, liabilities, losses, damages and expenses arising from the Indemnifying Party's breach of this Agreement, negligence or willful misconduct.

8.2 Limitation: Except for liability arising from a Party's gross negligence, willful misconduct, or breach of confidentiality or data protection obligations, neither Party shall be liable to the other for consequential, special, incidental or punitive damages.

9. INSURANCE

Each Party shall maintain, at its own expense, commercially reasonable insurance coverage appropriate to the processing and risk involved, including cyber liability and errors and omissions insurance, and shall provide evidence of such coverage upon reasonable request.

10. TERM AND TERMINATION

10.1 Term: This Agreement shall commence on the Effective Date and shall continue for a period of years unless earlier terminated in accordance with this Agreement.

10.2 Termination for Convenience: Either Party may terminate this Agreement for convenience upon thirty (30) days' prior written notice to the other Party.

10.3 Termination for Cause: Either Party may terminate this Agreement immediately if the other Party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days after receipt of written notice specifying the breach.

11. RETURN OR DESTRUCTION

Upon termination or expiration of this Agreement, Data Recipient shall, at Data Provider's election, securely return or destroy all Shared Data in its possession and certify in writing within thirty (30) days that such return or destruction has been completed, except to the extent retention is required by applicable law.

12. NOTICES

All notices required or permitted under this Agreement shall be in writing and delivered to the addresses below by hand, courier, or certified mail, or by electronic mail with confirmation of receipt.

13. AMENDMENTS, WAIVER AND COUNTERPARTS

13.1 Amendment: No amendment to this Agreement shall be effective unless in writing and signed by authorized representatives of both Parties.

13.2 Waiver: Failure or delay by either Party to exercise any right shall not constitute a waiver of that right unless expressly waived in writing.

13.3 Counterparts: This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument. Signatures transmitted by electronic means shall be valid and binding.

14. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

14.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction chosen by the Parties:

14.2 Entire Agreement: This Agreement constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings.

14.3 Severability: If any provision of this Agreement is held to be invalid or unenforceable, the remainder of this Agreement shall remain in full force and effect and the Parties shall negotiate in good faith a valid substitute provision that achieves the original intent as closely as possible.

15. MISCELLANEOUS PROVISIONS

15.1 Subprocessors and Third Parties: Data Recipient shall not engage subprocessors to process Shared Data without the prior written consent of Data Provider. Where consent is granted, Data Recipient shall enter into a written agreement with each subprocessor imposing data protection obligations no less protective than those in this Agreement.

15.2 Export Controls and Compliance: Each Party shall comply with all applicable laws, regulations and rules governing data protection, export controls and the handling of the Shared Data.

Party A (Data Provider) - Printed Name:

By:

Date:

Party B (Data Recipient) - Printed Name:

By:

Date:

Enter text✕

What a Data Sharing Agreement Is and When it Applies

A Data Sharing Agreement (DSA) is a written contract that sets terms, responsibilities, and controls for transferring or accessing data between parties. It defines permitted uses, data categories, security and privacy safeguards, retention and deletion obligations, and breach notification processes. DSAs are used when personal, proprietary, or regulated data crosses organizational boundaries — for example between a service provider and a healthcare organization or between business partners exchanging customer records. In the United States, DSAs must align with ESIGN and UETA for electronic execution and with sector rules such as HIPAA or FERPA when those laws apply.

Why a Data Sharing Agreement Matters for Legal and Operational Risk

A DSA reduces legal exposure by documenting permitted uses, security measures, and breach responsibilities; it clarifies liability, supports regulatory compliance, and creates an operational playbook for data handling between parties.

Why a Data Sharing Agreement Matters for Legal and Operational Risk

Typical Organizations and Roles That Use a Data Sharing Agreement

DSAs are commonly used across industries whenever data is exchanged between entities; the following examples indicate who typically prepares or signs these agreements.

  • Healthcare providers and vendors exchanging patient information under HIPAA.
  • Research institutions and universities sharing educational or study data.
  • Technology companies and SaaS vendors integrating customer data flows.

Identify stakeholders early — legal counsel, privacy officers, data custodians, and the operational owner should be engaged before final execution.

Core Sections to Include in a Professional Data Sharing Agreement

A complete DSA organizes obligations clearly so signatories can comply and auditors can verify controls. The following components form the backbone of a robust agreement.

Parties and Scope

Identify each party, describe the categories of data shared, and specify purposes and permitted downstream uses.

Legal Basis

State any legal bases for sharing sensitive data (consent, contract, legitimate interest) and cite applicable statutes such as HIPAA when relevant.

Data Security

Specify encryption, access controls, authentication, incident response, and the standard of care required of recipients.

Data Retention & Deletion

Define retention periods, secure deletion methods, and responsibilities on termination or expiration.

Audit & Compliance

Include audit rights, evidence retention obligations, reporting frequency, and obligations to cooperate with regulators or independent assessors.

Liability & Indemnity

Allocate risk, limit liability where appropriate, and set indemnity and insurance minimums to cover breaches or misuse.

Step-by-Step: Fill Out a Data Sharing Agreement

Follow this sequential checklist to prepare, review, and execute a DSA efficiently while involving the right stakeholders.

  • 01
    Draft: Populate parties, scope, data categories, and purpose with operational input.
  • 02
    Security Review: Have IT or security validate technical controls and encryption requirements.
  • 03
    Legal Review: Request legal review for liability, indemnity, and regulatory language.
  • 04
    Execution: Sign electronically or with notarization if required by jurisdiction or policy.

Configuring an Online DSA Workflow

Set up a repeatable electronic workflow to streamline approvals, signatures, and secure distribution for DSAs.

Field Configuration
Approver Order Sequential routing: data owner → security → legal → executive signatory
Authentication Enable email link with optional SMS code or SSO for higher assurance
Conditional Fields Show security clauses only for regulated data categories
Audit Trail Capture timestamps, IPs, and action logs for every signer

Where to Send, Store, and Monitor a Completed DSA

A clear routing plan ensures the agreement is available to operations, compliance, and auditors while minimizing unauthorized access.

  • Send to Parties: Deliver executed copies to all signatories and their legal representatives
  • Store Securely: Retain master copies in encrypted document storage with access logs
  • Register in Contract Repository: Record metadata (effective date, term, owner, renewal) for lifecycle management
  • Monitor Controls: Schedule periodic compliance reviews and technical audits

Technology and Platform Considerations for eSigning a DSA

Choose a platform that supports secure eSignatures, audit trails, access controls, and integrations with your contract repository.

  • eSignature Standards: Must comply with ESIGN and UETA; consider PKI/digital signatures for higher assurance
  • Security: TLS1.2/1.3 in transit; AES-256 at rest; BAA available for HIPAA needs
  • Integrations: Support for SSO, CRM, cloud storage, and API-based automation

Verify that the chosen provider supports your regulatory obligations (for example HIPAA BAA) and provides a complete audit trail for enforcement and dispute resolution.

Typical Timelines and Deadlines to Track for a DSA

Track key dates to ensure compliance with retention, renewal, and audit obligations that affect operational and regulatory timelines.

Effective Date:

MM/DD/YYYY; starts obligations and retention clocks

Review Cycle:

Annual or biennial security and purpose review

Breach Notification:

Contractual period for notices (e.g., 72 hours recommended)

Renewal Notice:

30–90 days before expiration to negotiate continuation

Data Deletion:

Post-termination deletion window per clause, typically 30–90 days

Common Preparation Errors to Avoid

  • Using vague purpose language that permits unanticipated secondary uses.
  • Failing to align technical controls with contractual security commitments.
  • Omitting retention and deletion details tied to applicable law.
  • Not confirming signatory authority or required notarization in the jurisdiction.

Risks and Legal Consequences of an Incomplete or Incorrect DSA

Regulatory Fines: Violations of HIPAA or sector rules can trigger fines and corrective action
Contract Liability: Indemnity and breach clauses may expose parties to damages
Data Breach Costs: Remediation, notification, and reputational harm are likely after breaches
Operational Disruption: Loss of access to shared data or paused integrations
Tax or Reporting Penalties: Noncompliance with record retention could affect IRS or SEC obligations
Enforceability Issues: Improper signatures or missing consent can render the agreement void

How a Data Sharing Agreement Differs from Related Documents

Compare DSAs with NDAs, Business Associate Agreements, and Data Processing Agreements to choose the right instrument for your data exchange.

Document Type Primary Focus Typical Use
Data Sharing Agreement access and use limits cross-entity operational data exchange
Non-Disclosure Agreement confidentiality only protects secret information, not technical controls
Data Processing Agreement processor obligations required under data protection regimes for processors
Business Associate Agreement hipaa-covered functions required between covered entities and hipaa bas

Comparing Common eSignature Providers for Data Sharing Agreements

Basic vendor differences are shown here to inform platform selection. signNow is listed first as the comparison baseline; pricing and feature availability vary by plan and deployment model.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (premium tier) Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Frequently Asked Questions About Data Sharing Agreements

Answers to common procedural and legal questions about preparing, signing, and managing DSAs in a U.S. context.


Need help? Contact support

Real-World Examples of Data Sharing Agreements in Use

Two short illustrative examples show common DSA scenarios and practical clauses to consider.

Healthcare Research

A hospital shares de‑identified patient data with a university for a clinical study

  • Data use restricted to IRB‑approved protocols
  • The DSA required data security controls, a BAA for PHI, and annual audit access for the hospital.

SaaS Integration

A software vendor accesses customer transaction logs to provide analytics

  • Access limited to specified API endpoints and purposes
  • Agreement included encryption standards, deletion on termination, and indemnity for unauthorized disclosures.

Who Is Authorized to Sign a Data Sharing Agreement

Company Officer

A senior executive (e.g., CEO, CFO, or authorized VP) with delegated contract authority signs on behalf of the entity. Legal counsel should confirm the signatory has authority consistent with corporate bylaws or delegated signing thresholds.

Authorized Contract Signer

Designated contract managers or procurement officers can sign DSAs if empowered by a board resolution or documented delegation. Maintain a roster of authorized signers to prevent enforceability issues.

How to Amend or Revise an Existing Data Sharing Agreement

Use a controlled amendment process to change scope, security, or retention without creating conflicting obligations.

01

Identify Change:

Document the precise clause or operational change requiring amendment.
02

Impact Assessment:

Assess legal, security, and privacy impacts, and whether regulatory notice is required.
03

Draft Amendment:

Prepare clear amendment language referencing the original DSA and effective date.
04

Obtain Approvals:

Route amendment to same stakeholders as original DSA: security, legal, and signatory.
05

Execute:

Have all original parties sign the amendment using the agreed execution method.
06

Record:

Store amendment with the master agreement and update contract metadata.
be ready to get more
Join over 28 million airSlate SignNow users