Parties and Scope
Identify each party, describe the categories of data shared, and specify purposes and permitted downstream uses.
A DSA reduces legal exposure by documenting permitted uses, security measures, and breach responsibilities; it clarifies liability, supports regulatory compliance, and creates an operational playbook for data handling between parties.
DSAs are commonly used across industries whenever data is exchanged between entities; the following examples indicate who typically prepares or signs these agreements.
Identify stakeholders early — legal counsel, privacy officers, data custodians, and the operational owner should be engaged before final execution.
Identify each party, describe the categories of data shared, and specify purposes and permitted downstream uses.
State any legal bases for sharing sensitive data (consent, contract, legitimate interest) and cite applicable statutes such as HIPAA when relevant.
Specify encryption, access controls, authentication, incident response, and the standard of care required of recipients.
Define retention periods, secure deletion methods, and responsibilities on termination or expiration.
Include audit rights, evidence retention obligations, reporting frequency, and obligations to cooperate with regulators or independent assessors.
Allocate risk, limit liability where appropriate, and set indemnity and insurance minimums to cover breaches or misuse.
| Field | Configuration |
|---|---|
| Approver Order | Sequential routing: data owner → security → legal → executive signatory |
| Authentication | Enable email link with optional SMS code or SSO for higher assurance |
| Conditional Fields | Show security clauses only for regulated data categories |
| Audit Trail | Capture timestamps, IPs, and action logs for every signer |
Choose a platform that supports secure eSignatures, audit trails, access controls, and integrations with your contract repository.
Verify that the chosen provider supports your regulatory obligations (for example HIPAA BAA) and provides a complete audit trail for enforcement and dispute resolution.
MM/DD/YYYY; starts obligations and retention clocks
Annual or biennial security and purpose review
Contractual period for notices (e.g., 72 hours recommended)
30–90 days before expiration to negotiate continuation
Post-termination deletion window per clause, typically 30–90 days
| Document Type | Primary Focus | Typical Use |
|---|---|---|
| Data Sharing Agreement | access and use limits | cross-entity operational data exchange |
| Non-Disclosure Agreement | confidentiality only | protects secret information, not technical controls |
| Data Processing Agreement | processor obligations | required under data protection regimes for processors |
| Business Associate Agreement | hipaa-covered functions | required between covered entities and hipaa bas |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes (premium tier) | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA available) | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
A hospital shares de‑identified patient data with a university for a clinical study
A software vendor accesses customer transaction logs to provide analytics
A senior executive (e.g., CEO, CFO, or authorized VP) with delegated contract authority signs on behalf of the entity. Legal counsel should confirm the signatory has authority consistent with corporate bylaws or delegated signing thresholds.
Designated contract managers or procurement officers can sign DSAs if empowered by a board resolution or documented delegation. Maintain a roster of authorized signers to prevent enforceability issues.