Scope of Sharing
Define data categories, permitted recipients, and allowed processing activities. Narrow scope reduces misuse and clarifies compliance obligations for both parties.
A template ensures consistent legal and technical controls across recurring data exchanges, reduces drafting time, and makes compliance easier by presetting security, retention, and breach response terms aligned with U.S. regulatory frameworks.
Typical users include legal teams, privacy officers, IT managers, and contracting teams responsible for recurring data transfers.
Use the template as a starting point and add industry clauses, state-specific language, or operational exhibits as needed.
In-house or outside counsel reviews and negotiates contract terms, confirms indemnity and limitation of liability language, and ensures the agreement aligns with applicable state and federal law, such as ESIGN and UETA considerations for electronic execution.
Chief Privacy Officer or Data Protection Officer approves technical and organizational measures, defines permitted uses, authorizes data categories shared, and confirms retention and deletion schedules meet regulatory obligations.
Define data categories, permitted recipients, and allowed processing activities. Narrow scope reduces misuse and clarifies compliance obligations for both parties.
Specify the business purpose for which data may be used, prohibiting secondary uses without prior written authorization to reduce regulatory and privacy risk.
List technical and organizational controls such as encryption, access controls, logging, and vulnerability management that recipients must maintain.
Set timelines, required content, and escalation procedures for notifying the disclosing party and affected individuals where applicable under HIPAA or state breach laws.
State retention periods, deletion obligations after purpose ends, and rules for backups and archival copies to support compliance and e-discovery readiness.
Allocate responsibility for breaches, data misuse, and third-party claims. Clearly define caps, exclusions, and insurance expectations.
| Field | Configuration |
|---|---|
| Signature Order | Set role-based signing sequence: Discloser, Recipient, Legal |
| Required Fields | Make Effective Date, Retention Period, and Data Categories mandatory |
| Authentication | Use email + SMS code or stronger authentication for sensitive exchanges |
| Audit Trail | Enable full logging of IP, timestamps, and document versions |
Choose a platform that supports necessary authentication, audit logging, and file formats for long-term retention.
Verify platform compliance (ESIGN, UETA) and any industry controls such as HIPAA or 21 CFR Part 11 before approving use for regulated data.
When obligations and permissions commence
Date by which all parties must sign
Permitted timeframe for initial data transfer
Timeframe for notifying the discloser of incidents
Date used to calculate retention clock
Prepare base template and exhibits for review
Legal and security teams approve language and controls
Parties sign and store executed agreement
Secure transmission and logging of transferred data
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |