Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

When Is a Data-Sharing or Data-Transfer Agreement Needed?

Not every movement of research data requires the same agreement. The appropriate document depends on who is sharing the data, why they are receiving it, whether they act as controllers or processors, and whether international-transfer rules apply.

320
Data-Sharing and Transfer Agreements Guide 320 of 398
01 · The Question

Do You Need a DSA, DTA, DPA, or Something Else?

A collaborator asks for participant data. Your research office asks whether there is a data-sharing agreement. Someone else calls it a data-transfer agreement. The cloud provider sends a data-processing addendum. The collaboration contract already has a confidentiality clause.

Are these different names for the same document?

No. Data-sharing, data-transfer, and data-processing agreements can serve different purposes, and the terminology is not completely standardized across institutions and jurisdictions. The right starting point is not the acronym. It is the actual relationship between the parties and what each party will do with the data.

02 · The Short Answer

The Agreement Should Match the Data Relationship

In Brief

A formal data agreement is generally needed when law, institutional policy, contract, funder requirements, or the parties' processing relationship requires responsibilities for shared or transferred data to be documented; the correct agreement depends on whether data are shared between controllers, processed on another party's behalf, or transferred under additional cross-border rules.

Do not assume every research transfer requires a standalone document called a "Data Transfer Agreement." Sometimes the necessary terms can appear in a collaboration agreement, processing contract, joint-controller arrangement, data-sharing agreement, or another instrument, provided it satisfies the applicable requirements.

03 · What You Need to Know

Identify the Relationship Before Choosing the Agreement

"Data-sharing agreement" does not have one universal meaning

Researchers frequently use data-sharing agreement as a generic label for any document governing data movement. Legal and regulatory frameworks can use the term more precisely.

Current ICO guidance, for example, focuses its data-sharing code on sharing personal data between organizations acting as controllers. It explicitly distinguishes this from a controller using a processor, which is governed by processor-contract requirements under Article 28 of the UK GDPR.

The Philippine National Privacy Commission also distinguishes data sharing from outsourcing. Under NPC Circular No. 2020-03, data sharing concerns personal data under a personal information controller's custody being shared, disclosed, or transferred to one or more other personal information controllers. A processor relationship is conceptually different.

That distinction matters because putting the wrong label on the agreement can hide the more important error: misunderstanding what the recipient is actually allowed to do.

Controller-to-controller sharing may call for a data-sharing arrangement

Suppose University A provides participant data to University B, and University B will use those data for an agreed research purpose for which it exercises its own controller-level decision-making.

This is different from University B merely performing a technical service according to University A's instructions. Under controller-to-controller sharing, the parties may need to document why data are shared, what each controller may do, how participants' rights are handled, security requirements, retention, onward disclosure, incident management, and other responsibilities.

ICO guidance describes data-sharing agreements as a useful accountability framework that records the purpose of sharing, what happens to information at each stage, and the standards the participating organizations must follow. It also emphasizes that an agreement does not itself make an unlawful disclosure lawful.

Philippine data-sharing agreements specifically concern PIC-to-PIC sharing

NPC Circular No. 2020-03 defines a data-sharing agreement as a contract, joint issuance, or similar document containing the terms and conditions of a data-sharing arrangement between two or more parties acting as personal information controllers.

Recent NPC guidance reiterates that only PICs are parties to a DSA under this framework and that a DSA need not necessarily be a standalone contract. A policy, memorandum of agreement, joint issuance, or similar document may perform the function if it contains the necessary terms. The NPC nevertheless strongly recommends appropriate documentation as a matter of accountability and good practice.

This is an important nuance for research collaborations. A memorandum of agreement can potentially contain the required data-sharing terms. The research team does not necessarily need to generate another document solely because nobody has yet placed the letters "DSA" on the cover.

A processor relationship requires a different kind of contract

Suppose a university sends interview recordings to a transcription company that processes the files only according to the university's instructions. The company does not independently decide to use the recordings for its own research.

That is conceptually a controller-to-processor relationship rather than controller-to-controller data sharing.

Under UK GDPR Article 28, a written contract is required whenever a controller uses a processor. The contract must address specified matters, including processing instructions, confidentiality, security, subprocessors, assistance with compliance, return or deletion of data, and audit-related obligations.

The Philippine framework likewise distinguishes outsourcing to a personal information processor from data sharing between PICs. NPC materials explain that a processor acts according to the PIC's instructions and does not process the information for an independent purpose.

Controller-to-controller sharing Each controller has responsibility for its own processing purposes and activities; a data-sharing arrangement may govern the disclosure and subsequent use.
Controller-to-processor processing The processor handles personal data on the controller's instructions; processor or outsourcing contractual requirements apply.

A data-transfer agreement is often an institutional or contractual label

Data Transfer Agreement, often abbreviated DTA, is widely used in universities and research organizations, but it is not a single globally standardized legal instrument.

An institution may use a DTA to govern transfer of research datasets, including confidential or non-personal research information. Another institution may use a data-use agreement, data-access agreement, material and data transfer agreement, or collaboration agreement for substantially similar purposes.

The document might address permitted research use, publication, confidentiality, security, intellectual property, attribution, retention, destruction, onward sharing, and liability in addition to privacy requirements.

Therefore, do not assume that a document called a DTA automatically satisfies a legally required DSA or processor contract. Read what it actually contains.

Not every research dataset contains personal data

A transfer agreement can still be useful when data protection law is not the main issue. Research datasets may contain confidential commercial information, unpublished results, proprietary algorithms, culturally sensitive information, intellectual property, restricted-access database content, or information governed by funder or repository conditions.

A contractual DTA or data-use agreement can therefore govern research data even when the dataset is genuinely anonymous or contains no personal data at all.

This is another reason the generic question "Do I need a DSA?" can be misleading. Privacy law is only one possible reason to document a transfer.

A confidentiality agreement is not automatically a data-sharing agreement

A nondisclosure or confidentiality agreement may prohibit unauthorized disclosure but say little about why participant data may be processed, which variables may be used, who can access them, what happens after the project, how data-subject requests are handled, or how security incidents are reported.

Confidentiality can be one provision within a broader data arrangement, but it does not necessarily replace the rest of the required governance.

An ethics approval is not a data contract

An ethics committee may approve a protocol describing data sharing. That approval can be essential to the research, but it does not necessarily establish contractual obligations between two universities or satisfy processor-contract requirements under data protection law.

This follows the broader distinction between research ethics and data protection compliance. The two processes may examine the same transfer from different perspectives.

What should a data-sharing agreement actually address?

The exact required terms depend on the jurisdiction and arrangement, but useful data-sharing documentation commonly addresses the parties, purpose, categories of data, authorized processing, security, access, retention, deletion, rights, onward disclosure, incident response, and termination.

ICO guidance recommends identifying the controllers involved, precise purposes, information to be shared, lawful basis, access arrangements, information governance standards, retention, deletion, security, individual rights, and what happens when the sharing arrangement ends.

Philippine NPC materials similarly identify matters including the purpose of sharing, types of personal data, participating parties, processing arrangements, security measures, duration, retention or disposal, data-subject remedies, online access where applicable, and secure return, destruction, or disposal.

The agreement should describe the actual data flow

A generic template saying that the recipient will "maintain appropriate security" is much less useful if nobody has identified what data are transferred, who can access them, where they will be stored, or whether they can be shared onward.

Before drafting, map the data flow. Determine what happens when the data move between the institutions and make the agreement reflect that reality.

International transfers may require additional documentation

If personal data cross national borders, ordinary data-sharing or processing terms may not be sufficient. The applicable data protection framework may require an additional international-transfer mechanism or contractual safeguards.

The EU GDPR, UK GDPR, and Philippine Data Privacy Act frameworks approach international transfers differently. A research collaboration should therefore not use "DTA signed" as shorthand for "all international transfer requirements satisfied."

Before an overseas transfer, separately assess the requirements for international research data transfers.

The agreement should exist before the transfer it governs

A familiar research sequence goes like this: send the data because the analysis is urgent, discover during manuscript preparation that an agreement was required, then ask the research office to date paperwork around a transfer that already happened.

That sequence defeats much of the purpose of the agreement.

The document is supposed to establish what may happen before access or transfer begins. It allows privacy, legal, research governance, information security, and the collaborating institutions to resolve responsibilities while the data are still under control.

Do Not Start With the Template

First determine the parties' roles and the proposed processing. Then select the agreement that fits. Starting with whichever DSA or DTA template someone used on the previous project can produce a beautifully formatted description of the wrong legal relationship.

A signed agreement does not make an inappropriate transfer appropriate

Contracts document obligations. They do not override data protection law, participant rights, ethics requirements, institutional restrictions, or a lack of legitimate purpose.

ICO guidance explicitly notes that a data-sharing agreement can support compliance but does not provide immunity from breaches of data protection law.

Similarly, Philippine NPC guidance requires data-sharing arrangements to remain consistent with the Data Privacy Act, its implementing rules, and applicable issuances.

The agreement should memorialize a defensible transfer, not attempt to manufacture one.

04 · A Practical Example

Three Recipients, Three Different Relationships

Hypothetical Example

A university research project uses several external organizations

University A holds identifiable interview and survey data. It works with University B on a joint analysis, hires Company C to transcribe recordings, and later provides a research dataset to University D in another country for an approved secondary study.

University B The institutions determine that both make controller-level decisions about the agreed collaborative processing. The appropriate controller-to-controller or joint-controller documentation is established according to the applicable framework.
Company C The transcription company processes recordings only according to University A's instructions. A controller-to-processor agreement containing the required processing and security terms is used rather than pretending that Company C independently shares the university's research purpose.
University D University D will conduct its own approved research using a defined dataset. The institutions establish the appropriate sharing or data-use arrangement and separately address any international-transfer mechanism required by the governing law.

The data may leave University A in all three scenarios, but the relationships are not identical. Calling every document a DTA would conceal those differences rather than simplify them.

05 · What Researchers Often Get Wrong

Common Misunderstandings About Research Data Agreements

Misconception

Does Every Research Data Transfer Require a Standalone DTA?

No. The required documentation depends on the data, parties, roles, jurisdiction, and institutional requirements. Appropriate terms may sometimes be incorporated into another agreement rather than placed in a separately titled DTA.

Misconception

Are a DSA and a Processor Agreement the Same Thing?

No. Controller-to-controller sharing and controller-to-processor outsourcing involve different relationships. Both UK and Philippine regulatory frameworks distinguish these arrangements.

Misconception

If We Already Have a Collaboration Agreement, Do We Definitely Need Another Contract?

Not necessarily. Review whether the existing agreement contains all data-governance terms required for the actual relationship. A single document can potentially serve several functions if it satisfies the relevant requirements.

Misconception

Does Signing a DSA Authorize Any Research Use of the Data?

No. The agreement should define and restrict permitted purposes. New secondary uses may require additional assessment, authorization, ethics review, or amendment rather than being absorbed automatically into the original agreement.

Misconception

Is a Confidentiality Agreement Enough?

Not necessarily. Confidentiality addresses disclosure but may not cover processing purposes, legal roles, participant rights, access, retention, security incidents, deletion, onward sharing, or other required provisions.

Misconception

Can We Transfer the Data First and Complete the Agreement Later?

That should not be the default approach. Where an agreement is required, it should normally govern the transfer before data are disclosed or access is provided. Urgent situations may have separate legal procedures, but ordinary research deadlines are not emergencies.

06 · What This Means for You

Ask What the Recipient Will Do Before Asking Which Agreement to Sign

A simple agreement framework

If another controller will receive personal data for its own or jointly determined authorized purpose
Assess the applicable data-sharing or joint-controller documentation requirements.
If another organization processes personal data only on your controller's instructions
Use the required processor or outsourcing contractual arrangement rather than treating the relationship as ordinary controller-to-controller sharing.
If non-personal but confidential or restricted research data are transferred
Determine whether a DTA, data-use agreement, collaboration agreement, confidentiality agreement, repository terms, or another contractual instrument is required by the institutions.
If personal data will be accessed or transferred internationally
Add the international-transfer mechanism and safeguards required by the applicable jurisdiction.
If an existing collaboration agreement already contains the necessary terms
Ask the responsible institutional office whether it can govern the data relationship without creating a redundant standalone agreement.

Researchers generally should not make the final contractual determination alone. Privacy, legal, research governance, technology-transfer, contracts, or data protection offices may need to establish which instrument is appropriate and who has authority to sign it on behalf of the institution.

07 · A Quick Checklist

Before Signing or Requesting a Research Data Agreement

Identify:
Exactly which organizations or individuals will disclose, receive, access, or process the data.
Whether personal data, confidential non-personal data, or both are involved.
The specific research or processing purpose for which the recipient needs the information.
Whether the parties act as separate controllers, joint controllers, controller and processor, or another relationship under the applicable framework.
Whether law, institutional policy, funder conditions, contracts, ethics arrangements, or repository rules require particular documentation.
Whether an existing agreement already contains all required data-governance terms.
The agreement addresses permitted data, purposes, authorized users, security, retention, deletion, onward sharing, secondary use, rights, and incident responsibilities as applicable.
Any additional international-transfer mechanism or contractual safeguard has been addressed separately where required.
The appropriate institutional representative, rather than an unauthorized individual researcher, will execute the agreement where institutional signature is required.
08 · Frequently Asked Questions

Common Questions About Data-Sharing and Transfer Agreements

Does every research collaboration need a data-sharing agreement?

No universal rule requires every collaboration to use a standalone document with that title. The need and form depend on the data, institutional roles, jurisdiction, and applicable policies. Where personal data are shared between controllers, documented sharing arrangements are often required or strongly recommended.

What is the difference between a DSA and a DTA?

Terminology varies. A DSA commonly governs data sharing between parties, particularly controllers, while DTA is often an institutional contractual label for transferring research data. A DTA may also cover non-personal research data. Always examine the document's function and required terms rather than relying on its acronym.

What is the difference between a DSA and a data-processing agreement?

A DSA generally governs sharing between organizations that have controller-level roles, while a processor agreement governs processing performed on a controller's behalf and instructions. The distinction is recognized in both UK GDPR guidance and Philippine NPC materials.

Is a data-sharing agreement mandatory in the Philippines?

The answer depends on the sharing arrangement and applicable rule. NPC Circular No. 2020-03 provides the current DSA framework, while recent NPC guidance notes that although its language may permit data sharing to be covered by a DSA or similar document in relevant situations, executing such documentation is highly recommended for accountability. Specific statutory or regulatory contexts may impose additional requirements.

Can a memorandum of agreement serve as the data-sharing agreement?

Potentially. Philippine NPC guidance expressly recognizes that a DSA can take the form of a contract, joint issuance, or similar document. What matters is whether the instrument contains the appropriate terms and satisfies the requirements for the actual arrangement.

Do anonymous data need a data-sharing agreement?

Data protection requirements may no longer apply if the information is genuinely anonymous under the applicable standard, but contractual restrictions, confidentiality, intellectual property, funder conditions, repository rules, or institutional policies may still justify or require a data-use or transfer agreement.

Who should sign a research data agreement?

That depends on institutional authority. Principal investigators are not necessarily authorized to bind their university or organization contractually. Check with the relevant research, legal, contracts, privacy, or technology-transfer office before signing on behalf of the institution.

Does a signed DSA mean we can start transferring data immediately?

Only if the other applicable requirements are also satisfied. Ethics approval, legal basis, security controls, participant information, international-transfer rules, institutional approvals, and technical arrangements may still need to be completed.

09 · The Bottom Line

Choose the Agreement From the Relationship, Not the Acronym

The Bottom Line

A research data agreement is needed when the applicable law, institutional requirements, or processing relationship requires the parties' responsibilities to be documented, but the correct instrument depends on what each party actually does with the data.

Determine first whether you have controller-to-controller sharing, processing on another party's behalf, a contractual transfer of non-personal research data, an international transfer, or some combination of these. Then document that relationship before the data move. The acronym comes last.

10 · Sources and Further Reading

Authoritative Sources on Data-Sharing and Processing Agreements

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes