Establishing secure connection…Loading editor…Preparing document…

Data Use Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Data Use Agreement

This Data Use Agreement (the Agreement) is made and entered into as of by and between Provider Name: with principal place of business at ("Provider"), and Recipient Name: with principal place of business at ("Recipient").

RECITALS

WHEREAS, Provider has collected or assembled certain data and datasets described below (the Data) that Provider is willing to disclose to Recipient subject to the terms of this Agreement; and

WHEREAS, Recipient requires access to the Data to carry out research, analysis, or other legitimate business purposes subject to the restrictions set forth herein; and

WHEREAS, the parties seek to protect the confidentiality, integrity, and lawful handling of the Data and to define the rights and obligations of each party with respect to such Data.

NOW THEREFORE, in consideration of the mutual covenants and promises contained herein, the parties agree as follows.

1. Definitions

1.1 "Data" means the datasets, files, records and associated metadata provided by Provider to Recipient under this Agreement and described as:

1.2 "Permitted Purpose" means the specific use(s) of the Data by Recipient as limited in Section 2 and described as:

1.3 "Authorized Personnel" means Recipient's employees, contractors, agents, and subcontractors who have a legitimate need to access the Data to perform the Permitted Purpose and who are bound by confidentiality obligations at least as protective as those in this Agreement.

2. Grant of Access and Use Restrictions

2.1 Provider hereby grants Recipient a non-exclusive, non-transferable, revocable license to access and use the Data solely for the Permitted Purpose during the Term of this Agreement. Recipient shall not use the Data for any other purpose without the prior written consent of Provider.

2.2 Recipient shall not (a) attempt to re-identify or contact any person whose information is contained in the Data, (b) sell, rent, sublicense, distribute, or otherwise disclose the Data to any third party except as expressly permitted by this Agreement, or (c) use the Data to develop products or services for direct commercialization unless expressly authorized in writing by Provider.

2.3 Recipient shall ensure that all Authorized Personnel accessing the Data are informed of and agree to abide by the restrictions in this Agreement and maintain records of such persons for inspection by Provider pursuant to Section 7.

3. Data Security and Breach Notification

3.1 Recipient shall implement and maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the Data, including encryption of Data at rest and in transit, access controls, logging, and secure disposal practices. Minimum required controls and handling procedures are described as:

3.2 In the event of an actual or suspected security incident or unauthorized disclosure affecting the Data, Recipient shall (a) promptly take all reasonable steps to contain and mitigate the incident, and (b) notify Provider without undue delay and in any event within hours of discovery, providing sufficient details for Provider to assess the incident.

4. Data Retention and Destruction

4.1 Recipient shall retain the Data only for the period necessary to accomplish the Permitted Purpose and in accordance with the retention schedule below. At the earlier of expiration of the retention period or termination of this Agreement, Recipient shall, at Provider's election, securely return or destroy the Data and all copies.

Retention period or date:

4.2 Upon Provider's request, Recipient shall certify in writing that the Data has been returned or destroyed in accordance with this Agreement.

5. Ownership; Intellectual Property

5.1 Provider retains all right, title and interest in and to the Data, including any intellectual property rights therein. Nothing in this Agreement transfers ownership of the Data to Recipient. Recipient shall acquire no rights in the Data except the limited license expressly granted herein.

5.2 Analyses, reports, and aggregated results derived from the Data (Derived Materials) shall be owned by subject to Provider's rights to require that such results be produced in de-identified or aggregated form that does not permit re-identification.

6. Confidentiality

6.1 Each party shall maintain the confidentiality of Confidential Information received from the other party and shall not disclose such Confidential Information except as expressly permitted in this Agreement or required by law. Confidential Information includes the Data and any non-public information regarding the Data.

6.2 The obligations in this Section shall survive termination or expiration of this Agreement for a period of unless a longer period is required by law.

7. Audit and Inspection

7.1 Provider may, upon reasonable prior notice to Recipient, conduct reasonable audits or inspections to verify Recipient's compliance with this Agreement. Such audits shall be conducted during normal business hours and in a manner that minimizes disruption to Recipient's operations.

Notice period for audits: days.

8. Representations; Warranties

8.1 Each party represents and warrants that it has the full corporate or organizational power and authority to enter into and perform this Agreement and to grant the rights and assume the obligations set forth herein.

8.2 Provider represents that, to Provider's knowledge, disclosure of the Data to Recipient as permitted by this Agreement does not violate any contract or third-party right; provided, however, that Provider makes no warranty that the Data is error-free or suitable for Recipient's specific purposes.

9. Indemnification and Limitation of Liability

9.1 Recipient shall indemnify, defend, and hold harmless Provider and its officers, directors, and employees from and against any third-party claims, liabilities, damages, losses, and expenses (including reasonable attorneys' fees) arising out of Recipient's breach of this Agreement or misuse of the Data.

9.2 Except for liability resulting from willful misconduct, gross negligence, or breaches of confidentiality or data protection obligations, neither party's aggregate liability under this Agreement shall exceed .

10. Term and Termination

10.1 This Agreement shall commence on the Effective Date and shall continue for the period specified below or until earlier terminated as provided herein.

Term (if fixed):

10.2 Either party may terminate this Agreement for material breach by the other party if the breach is not cured within days after written notice. Provider may suspend access to the Data immediately upon suspected misuse.

11. Notices

12. Governing Law; Miscellaneous

12.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the state of without regard to its conflicts of law principles.

12.2 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior and contemporaneous agreements and understandings.

12.3 Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be invalid or unenforceable, the remainder of this Agreement shall remain in full force and effect and the parties shall negotiate in good faith a valid substitute provision that most closely effects the parties' intent.

12.4 Amendments; Waiver. No amendment, modification or waiver of any provision of this Agreement shall be effective unless made in writing and signed by authorized representatives of both parties. No failure or delay by either party in exercising any right shall operate as a waiver of such right.

12.5 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument. Facsimile or electronic signatures shall be binding.

Signatures

Provider:

By:

Date:

Recipient:

By:

Date:

Enter text✕

What a Data Use Agreement Is and when it applies

A Data Use Agreement (DUA) is a written contract that governs the access, use, disclosure, and protection of nonpublic or controlled data shared between parties. DUAs define permitted purposes, data elements, security controls, retention and disposal requirements, and any restrictions on redisclosure. They are commonly used for research data transfers, vendor analytics, shared healthcare datasets, and collaborative projects where privacy, confidentiality, or regulatory obligations (for example HIPAA) apply.

Why a clear Data Use Agreement matters

A DUA reduces legal and compliance risk by setting explicit boundaries for data handling, demonstrating due diligence under federal rules, and documenting technical and administrative safeguards required by regulators.

Why a clear Data Use Agreement matters

Typical organizations and roles that rely on DUAs

DUAs are used by organizations that share controlled or sensitive data and need contractual assurances and auditability.

  • Academic research offices and institutional review boards sharing deidentified or limited datasets for studies
  • Healthcare providers and business associates exchanging PHI under HIPAA-limited authorizations or data use terms
  • Vendors and analytics teams receiving customer data for processing, model training, or reporting

Use a DUA when data recipients require written terms for permitted use, security controls, breach notification, or regulatory compliance.

Core components to include in a professional DUA

A well-crafted DUA balances precision with operational clarity. Include clauses that cover scope, permitted uses, data elements, security measures, breach handling, and termination to avoid ambiguity.

Parties

Identify data provider and recipient with legal entity names and contact information.

Data Description

Specify dataset contents, formats, identifiers removed or retained, and whether PHI is involved.

Permitted Uses

List allowed purposes and prohibit reidentification, resale, or unrelated analysis.

Security Controls

Define administrative, technical, and physical safeguards and minimum standards.

Breach Notification

Set timelines, required notifications, and remediation responsibilities for incidents.

Retention & Disposal

State retention period, secure destruction methods, and certification of deletion.

Security and compliance elements to reference

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Access Controls: Role-based accounts and MFA required
Audit Trails: Detailed logging of access and actions
BAA Requirement: HIPAA-covered exchanges require a BAA
Regulatory Standards: SOC 2 Type II and ISO 27001 recognized
Retention Practices: Secure archival and tamper-evident storage

Step-by-step: completing a Data Use Agreement

Follow these steps to prepare, review, and finalize a DUA so it is enforceable and operationally clear for both parties.

  • 01
    Gather details: Collect dataset description, source, sensitivity level, and legal basis for sharing.
  • 02
    Define permitted uses: Specify allowed analyses, prohibited actions, and secondary use restrictions.
  • 03
    Set security terms: List encryption, access controls, incident response, and audit requirements.
  • 04
    Sign and retain: Obtain authorized signatures and store executed copies under retention rules.

Configuring an online DUA workflow

Set up a reproducible and auditable signing workflow to reduce errors and ensure compliance across repeat exchanges.

Field Configuration
Effective Date Field Auto-fill with contract start date; MM/DD/YYYY
Signature Field Require signer name, title, and date entries
Conditional Clauses Show additional security clauses when PHI is selected
Audit Trail Capture IP, timestamp, and authentication method

Typical routing and submission flow for a DUA

A clear routing sequence ensures correct approvals and preserves an auditable record for compliance and future audits.

  • Drafting: Data owner prepares DUA draft with dataset and purpose details.
  • Legal Review: Counsel reviews for regulatory and contractual risk alignment.
  • Signatures: Authorized signers execute; consider witness or notarization if required.
  • Distribution: Provide executed copies to all parties and store centrally.

Digital signing and technical considerations

Use an eSignature workflow that captures intent, attribution, and a reproducible record to support enforceability under U.S. law.

  • Authentication: Email plus optional SMS/KBA or advanced signer verification
  • Auditability: Timestamped audit trail and tamper-evident PDF output
  • Integrations: Connectors to document storage and contract repositories

Confirm the chosen platform supports required compliance features (for example HIPAA BAA, 21 CFR Part 11 where relevant) and provides retrievable audit logs for regulatory review.

Timelines, response windows, and processing expectations

Specify clear deadlines in the DUA for data delivery, review, incident reporting, and approval cycles to avoid operational delays.

Data Delivery:

Specify delivery date or window (for example within 30 days after signing).

Review Period:

Allow a defined review window (commonly 10–30 business days) for legal and technical checks.

Breach Notification:

Require notification within 72 hours of discovering a reportable incident.

Renewal Notice:

Set advance notice for renewal or termination (commonly 30–90 days).

Data Access Revocation:

Define when access will be revoked after termination (immediately or within specified days).

Common preparation mistakes to avoid

  • Failing to precisely define the dataset contents, which leads to disputes over scope and permitted analysis.
  • Not specifying security minimums or a BAA where PHI is involved, creating compliance gaps under HIPAA.
  • Using vague purpose clauses like 'research' without limitations, allowing unintended secondary uses.
  • Missing authorized signatory authority or relying on informal approvals that are not enforceable.

Principal risks and regulatory consequences

HIPAA Fines: Civil and criminal penalties; corrective action plans possible
Data Breach Costs: Notification, remediation, and potential class-action exposure
Contract Liability: Breach remedies and indemnification obligations
Tax/Reporting Penalties: Incorrect reporting penalties under IRC rules
Loss of Access: Provider may suspend or revoke data access
Reputational Harm: Public disclosure can damage stakeholder trust

Sample eSignature vendor comparison for DUAs (signNow first)

Basic vendor pricing and capability markers to evaluate platforms for DUA signing and secure sharing. Use vendor sites or sales contacts to verify plan details for procurement.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/yr Varies Varies Varies

Real-world examples of DUAs in practice

Practical examples illustrate how organizations use DUAs to balance data sharing with compliance and operational needs.

Optica Ventures (COO)

Optica prepared a concise DUA to share investment data with advisors

  • The emphasis was on clear permitted uses
  • The company highlights the interface was easy for customers and staff to use while protecting sensitive deal information and access controls were strictly defined for each recipient.

Fertility Centers of Illinois (Founder)

A healthcare provider used a DUA to share deidentified patient outcomes with a research partner

  • The DUA required a BAA and strict retention rules
  • The organization reported responsive vendor support and secure integrations were essential to meet HIPAA requirements and internal review board conditions.

Frequently asked questions about Data Use Agreements

Answers to common questions that arise when preparing, signing, and enforcing DUAs in the United States.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users