Establishing secure connection…Loading editor…Preparing document…

DataShare Agreement Template

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA SHARE AGREEMENT

This Data Share Agreement ("Agreement") is entered into as of Effective Date: by and between Data Provider Name: with principal place of business at (hereafter "Provider"), and Data Recipient Name: with principal place of business at (hereafter "Recipient"). Provider and Recipient are each a "Party" and collectively the "Parties."

RECITALS

WHEREAS, Provider possesses certain data, datasets, and related information described below and has the authority to disclose such data under the terms set forth in this Agreement; and

WHEREAS, Recipient desires to obtain and use the Provider's data for the Permitted Uses defined in this Agreement, and Provider is willing to disclose such data subject to the terms, conditions, and restrictions of this Agreement; and

WHEREAS, the Parties intend by this Agreement to define their respective rights and obligations with respect to the sharing, use, security, and protection of the shared data.

NOW, THEREFORE, in consideration of the mutual covenants and promises contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:

1. DEFINITIONS

1.1 "Data" means the information, records, datasets, metadata, and any derivative works specifically identified in Section 2 that Provider makes available to Recipient under this Agreement. "Personal Data" means Data that relates to an identified or identifiable natural person.

2. DESCRIPTION OF DATA AND PURPOSE

2.1 The Recipient shall use the Data solely for the Permitted Uses set forth above and shall not use, disclose, or permit access to the Data for any other purpose without the prior written consent of Provider.

3. DATA TRANSFER; FORMAT

3.1 Provider will transfer Data to Recipient by the methods agreed in writing. Delivery format, frequency, and technical specifications are as follows:

4. DATA SECURITY AND PRIVACY OBLIGATIONS

4.1 Recipient shall implement and maintain administrative, physical and technical safeguards appropriate to the sensitivity of the Data to protect against unauthorized access, use, alteration, or disclosure. Such safeguards shall include, at a minimum, the security measures described below and compliance with all applicable privacy laws and industry standards.

4.2 In the event Recipient becomes aware of any unauthorized access, use, or disclosure of the Data (a "Security Incident"), Recipient will: (a) notify Provider promptly and without undue delay; (b) investigate and take immediate steps to mitigate the incident; and (c) provide Provider with a written report of the incident and remediation steps taken.

5. RESTRICTIONS ON USE; PROHIBITED ACTIONS

5.1 Recipient shall not (a) attempt to re-identify Personal Data; (b) sell, lease, license, or otherwise commercially exploit the Data; or (c) disclose the Data to any third party except as expressly permitted in this Agreement. Any subcontracting or delegation of data processing activities requires Provider's prior written consent and a written agreement that imposes substantially the same obligations on the subcontractor as those imposed on Recipient hereunder.

6. CONFIDENTIALITY

6.1 The Parties acknowledge that the Data may constitute Confidential Information. Each Party agrees to hold in confidence and not disclose to any third party any Confidential Information of the other Party except as necessary to perform under this Agreement or as required by law, provided that the disclosing Party is given prompt notice to the extent permitted by law.

7. INTELLECTUAL PROPERTY

7.1 Provider retains all right, title and interest in and to the Data and any derivatives derived therefrom, except that Recipient may create derivative analyses or aggregated results that do not contain Provider's Confidential Information or personally identifiable data, in which case Recipient shall own such derivative analyses. No license or transfer of ownership in any intellectual property of Provider is granted except as expressly set forth in this Agreement.

8. TERM AND TERMINATION

8.1 This Agreement commences on the Effective Date and shall continue in effect for a term of unless earlier terminated in accordance with this Section.

8.2 Either Party may terminate this Agreement for convenience upon thirty (30) days' prior written notice. Provider may immediately suspend or terminate delivery of Data if Recipient materially breaches its obligations and fails to cure such breach within fifteen (15) days after written notice.

9. RETURN AND DESTRUCTION

9.1 Upon expiration or termination of this Agreement, Recipient shall, at Provider's option, return or securely destroy all Data and certify in writing that such return or destruction has been completed within .

10. AUDIT RIGHTS

10.1 Provider may, upon reasonable prior written notice and during regular business hours, audit Recipient's compliance with the terms of this Agreement, including physical and technical safeguards. Any such audit shall be conducted in a manner that minimizes disruption to Recipient's operations. Recipient shall remedy any non-compliance identified by the audit within a reasonable period.

11. INDEMNIFICATION; LIMITATION OF LIABILITY

11.1 Recipient shall indemnify, defend and hold harmless Provider from and against any losses, liabilities, damages, costs and expenses arising out of Recipient's breach of this Agreement, negligent or willful misuse of the Data, or violation of applicable law in connection with the Data, provided that Provider gives prompt written notice and reasonable cooperation in the defense.

11.2 EXCEPT FOR LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR BREACH OF CONFIDENTIALITY OBLIGATIONS, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR INCIDENTAL, PUNITIVE, SPECIAL, OR CONSEQUENTIAL DAMAGES; THE AGGREGATE LIABILITY OF EACH PARTY ARISING OUT OF OR RELATED TO THIS AGREEMENT SHALL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY RECIPIENT TO PROVIDER UNDER THIS AGREEMENT DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY.

12. INSURANCE

12.1 Recipient shall maintain commercially reasonable insurance coverage appropriate to the nature of the Data and the activities contemplated hereunder, including cyber liability insurance where applicable, and shall provide evidence of such insurance upon Provider's reasonable request.

13. NOTICES

13.1 All notices required or permitted under this Agreement shall be in writing and delivered to the addresses below by hand delivery, nationally recognized overnight courier, or certified mail (return receipt requested). Notices shall be effective upon receipt.

14. AMENDMENT; WAIVER; COUNTERPARTS

14.1 No amendment or modification of this Agreement shall be effective unless made in writing and signed by authorized representatives of both Parties. No waiver of any provision shall be effective unless in writing. This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument.

15. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

15.1 This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified below, without regard to conflict of law principles.

15.2 This Agreement constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings, whether written or oral. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

16. MISCELLANEOUS

16.1 Each Party represents and warrants that it has the full corporate or organizational power and authority to enter into and perform its obligations under this Agreement and that the person signing on its behalf is duly authorized to bind such Party.

16.2 The obligations of confidentiality and security set forth in this Agreement shall survive the termination or expiration of this Agreement for a period of .

Data Provider:

By:

Date:

Data Recipient:

By:

Date:

Enter text✕

What the DataShare Agreement Template Is

A DataShare Agreement Template is a standardized contract that defines terms for exchanging, using, and protecting data between parties. It sets scope, permitted uses, security controls, retention rules, liability limits, and data breach responsibilities. The template speeds negotiation by providing reusable clauses for confidentiality, permitted recipients, transfer methods, and permitted processing activities while preserving flexibility for industry-specific addenda and state-law variations.

Why use a DataShare Agreement Template

A template ensures consistent legal and technical controls across recurring data exchanges, reduces drafting time, and makes compliance easier by presetting security, retention, and breach response terms aligned with U.S. regulatory frameworks.

Why use a DataShare Agreement Template

Organizations and roles that commonly use this template

Typical users include legal teams, privacy officers, IT managers, and contracting teams responsible for recurring data transfers.

  • In-house legal or contracts teams negotiating recurring B2B data sharing arrangements across departments and vendors.
  • Privacy or compliance officers enforcing HIPAA, FERPA, or state privacy requirements in data exchange settings.
  • IT and security teams specifying technical controls, encryption, and audit requirements for data recipients.

Use the template as a starting point and add industry clauses, state-specific language, or operational exhibits as needed.

Primary signers and approvers

Legal Counsel

In-house or outside counsel reviews and negotiates contract terms, confirms indemnity and limitation of liability language, and ensures the agreement aligns with applicable state and federal law, such as ESIGN and UETA considerations for electronic execution.

Data Officer

Chief Privacy Officer or Data Protection Officer approves technical and organizational measures, defines permitted uses, authorizes data categories shared, and confirms retention and deletion schedules meet regulatory obligations.

Essential clauses to include in a professional DataShare Agreement Template

A robust template balances legal protections with operational clarity. Include clauses that address purpose, scope, security, breach handling, and governance to reduce negotiation cycles.

Scope of Sharing

Define data categories, permitted recipients, and allowed processing activities. Narrow scope reduces misuse and clarifies compliance obligations for both parties.

Purpose Limitation

Specify the business purpose for which data may be used, prohibiting secondary uses without prior written authorization to reduce regulatory and privacy risk.

Security Measures

List technical and organizational controls such as encryption, access controls, logging, and vulnerability management that recipients must maintain.

Breach Notification

Set timelines, required content, and escalation procedures for notifying the disclosing party and affected individuals where applicable under HIPAA or state breach laws.

Retention & Deletion

State retention periods, deletion obligations after purpose ends, and rules for backups and archival copies to support compliance and e-discovery readiness.

Liability & Indemnity

Allocate responsibility for breaches, data misuse, and third-party claims. Clearly define caps, exclusions, and insurance expectations.

Step-by-step: completing and executing the template

Follow these sequential steps to prepare, approve, sign, and implement a DataShare Agreement with minimal rework.

  • 01
    Draft: Insert parties, data categories, and purpose; include technical exhibits.
  • 02
    Review: Legal and privacy review contract language and risk allocations.
  • 03
    Authorize: Obtain internal approvals from data owner and security teams.
  • 04
    Execute: Sign electronically or in writing and distribute executed copies.

How to set up an online DataShare approval workflow

Configure routing and fields in your eSignature platform to match internal approval steps and technical exhibits.

Field Configuration
Signature Order Set role-based signing sequence: Discloser, Recipient, Legal
Required Fields Make Effective Date, Retention Period, and Data Categories mandatory
Authentication Use email + SMS code or stronger authentication for sensitive exchanges
Audit Trail Enable full logging of IP, timestamps, and document versions

Typical eSignature and data transfer workflow

A clear signing and transfer flow reduces friction and preserves an audit trail for compliance and dispute resolution.

  • Upload Template: Sender uploads agreement and attaches exhibits
  • Place Fields: Add signature, initials, and metadata fields
  • Send to Signers: Distribute in role order or via a secure link
  • Record Transfer: Log the handoff and secure transmission method used

Technical and platform requirements for secure eExecution

Choose a platform that supports necessary authentication, audit logging, and file formats for long-term retention.

  • File Formats: PDF, DOCX supported
  • Integrations: Connectors to CRM, cloud storage, and DLP
  • Authentication: Email+SMS or stronger options

Verify platform compliance (ESIGN, UETA) and any industry controls such as HIPAA or 21 CFR Part 11 before approving use for regulated data.

Security and compliance details to include

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Audit Trail: Immutable logs with timestamps and IP addresses
Certifications: SOC 2 Type II, ISO 27001 available
HIPAA: BAA required for protected health data
Esign Laws: Compliant with ESIGN and UETA standards
21 CFR: Supports 21 CFR Part 11 controls where required

Common penalties and legal risks to address

Breach Liability: Potential statutory fines and breach costs
Invalid Execution: Improper signing can void obligations
Regulatory Fines: HIPAA or state privacy penalties possible
Contractual Damages: Indemnity claims for misuse
Data Loss: Operational and reputational harm
I-9-like Violations: Recordkeeping failures can incur fines

Frequent preparation mistakes to avoid

  • Using vague data categories such as 'all customer data' instead of defined fields, which creates ambiguity and compliance exposure.
  • Failing to align retention language with legal and business requirements, leading to over-retention or premature deletion.
  • Neglecting to require a BAA or equivalent when sharing protected health information, risking HIPAA violations.
  • Relying on weak signer authentication for sensitive transfers, which can undermine evidentiary strength in disputes.

Key timing considerations and deadlines

Set clear dates and notice periods in the template to avoid disputes and ensure timely operational handoffs.

Effective Date:

When obligations and permissions commence

Execution Deadline:

Date by which all parties must sign

Data Transfer Window:

Permitted timeframe for initial data transfer

Breach Notice Period:

Timeframe for notifying the discloser of incidents

Retention Start:

Date used to calculate retention clock

Typical milestone timeline for a DataShare engagement

A milestone view helps coordinate legal, technical, and operational tasks from negotiation to data handoff.

01

Drafting

Prepare base template and exhibits for review

02

Internal Review

Legal and security teams approve language and controls

03

Execution

Parties sign and store executed agreement

04

Data Handoff

Secure transmission and logging of transferred data

eSignature vendor comparison for executing DataShare agreements

Compare common eSignature providers on price and core capabilities relevant to DataShare Agreement execution; signNow appears first per platform conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Varies by plan Varies by plan Varies by plan Varies by plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Varies by plan Varies by plan Varies by plan Varies by plan
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Frequently asked questions about using the template

Answers to common legal, technical, and process questions when preparing, signing, and storing DataShare agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users