03 · What You Need to Know
Identify the Relationship Before Choosing the Agreement
"Data-sharing agreement" does not have one universal meaning
Researchers frequently use data-sharing agreement as a generic label for any document governing data movement. Legal and regulatory frameworks can use the term more precisely.
Current ICO guidance, for example, focuses its data-sharing code on sharing personal data between organizations acting as controllers. It explicitly distinguishes this from a controller using a processor, which is governed by processor-contract requirements under Article 28 of the UK GDPR.
The Philippine National Privacy Commission also distinguishes data sharing from outsourcing. Under NPC Circular No. 2020-03, data sharing concerns personal data under a personal information controller's custody being shared, disclosed, or transferred to one or more other personal information controllers. A processor relationship is conceptually different.
That distinction matters because putting the wrong label on the agreement can hide the more important error: misunderstanding what the recipient is actually allowed to do.
Controller-to-controller sharing may call for a data-sharing arrangement
Suppose University A provides participant data to University B, and University B will use those data for an agreed research purpose for which it exercises its own controller-level decision-making.
This is different from University B merely performing a technical service according to University A's instructions. Under controller-to-controller sharing, the parties may need to document why data are shared, what each controller may do, how participants' rights are handled, security requirements, retention, onward disclosure, incident management, and other responsibilities.
ICO guidance describes data-sharing agreements as a useful accountability framework that records the purpose of sharing, what happens to information at each stage, and the standards the participating organizations must follow. It also emphasizes that an agreement does not itself make an unlawful disclosure lawful.
Philippine data-sharing agreements specifically concern PIC-to-PIC sharing
NPC Circular No. 2020-03 defines a data-sharing agreement as a contract, joint issuance, or similar document containing the terms and conditions of a data-sharing arrangement between two or more parties acting as personal information controllers.
Recent NPC guidance reiterates that only PICs are parties to a DSA under this framework and that a DSA need not necessarily be a standalone contract. A policy, memorandum of agreement, joint issuance, or similar document may perform the function if it contains the necessary terms. The NPC nevertheless strongly recommends appropriate documentation as a matter of accountability and good practice.
This is an important nuance for research collaborations. A memorandum of agreement can potentially contain the required data-sharing terms. The research team does not necessarily need to generate another document solely because nobody has yet placed the letters "DSA" on the cover.
A processor relationship requires a different kind of contract
Suppose a university sends interview recordings to a transcription company that processes the files only according to the university's instructions. The company does not independently decide to use the recordings for its own research.
That is conceptually a controller-to-processor relationship rather than controller-to-controller data sharing.
Under UK GDPR Article 28, a written contract is required whenever a controller uses a processor. The contract must address specified matters, including processing instructions, confidentiality, security, subprocessors, assistance with compliance, return or deletion of data, and audit-related obligations.
The Philippine framework likewise distinguishes outsourcing to a personal information processor from data sharing between PICs. NPC materials explain that a processor acts according to the PIC's instructions and does not process the information for an independent purpose.
Controller-to-controller sharing
Each controller has responsibility for its own processing purposes and activities; a data-sharing arrangement may govern the disclosure and subsequent use.
Controller-to-processor processing
The processor handles personal data on the controller's instructions; processor or outsourcing contractual requirements apply.
A data-transfer agreement is often an institutional or contractual label
Data Transfer Agreement, often abbreviated DTA, is widely used in universities and research organizations, but it is not a single globally standardized legal instrument.
An institution may use a DTA to govern transfer of research datasets, including confidential or non-personal research information. Another institution may use a data-use agreement, data-access agreement, material and data transfer agreement, or collaboration agreement for substantially similar purposes.
The document might address permitted research use, publication, confidentiality, security, intellectual property, attribution, retention, destruction, onward sharing, and liability in addition to privacy requirements.
Therefore, do not assume that a document called a DTA automatically satisfies a legally required DSA or processor contract. Read what it actually contains.
Not every research dataset contains personal data
A transfer agreement can still be useful when data protection law is not the main issue. Research datasets may contain confidential commercial information, unpublished results, proprietary algorithms, culturally sensitive information, intellectual property, restricted-access database content, or information governed by funder or repository conditions.
A contractual DTA or data-use agreement can therefore govern research data even when the dataset is genuinely anonymous or contains no personal data at all.
This is another reason the generic question "Do I need a DSA?" can be misleading. Privacy law is only one possible reason to document a transfer.
A confidentiality agreement is not automatically a data-sharing agreement
A nondisclosure or confidentiality agreement may prohibit unauthorized disclosure but say little about why participant data may be processed, which variables may be used, who can access them, what happens after the project, how data-subject requests are handled, or how security incidents are reported.
Confidentiality can be one provision within a broader data arrangement, but it does not necessarily replace the rest of the required governance.
An ethics approval is not a data contract
An ethics committee may approve a protocol describing data sharing. That approval can be essential to the research, but it does not necessarily establish contractual obligations between two universities or satisfy processor-contract requirements under data protection law.
This follows the broader distinction between research ethics and data protection compliance. The two processes may examine the same transfer from different perspectives.
What should a data-sharing agreement actually address?
The exact required terms depend on the jurisdiction and arrangement, but useful data-sharing documentation commonly addresses the parties, purpose, categories of data, authorized processing, security, access, retention, deletion, rights, onward disclosure, incident response, and termination.
ICO guidance recommends identifying the controllers involved, precise purposes, information to be shared, lawful basis, access arrangements, information governance standards, retention, deletion, security, individual rights, and what happens when the sharing arrangement ends.
Philippine NPC materials similarly identify matters including the purpose of sharing, types of personal data, participating parties, processing arrangements, security measures, duration, retention or disposal, data-subject remedies, online access where applicable, and secure return, destruction, or disposal.
The agreement should describe the actual data flow
A generic template saying that the recipient will "maintain appropriate security" is much less useful if nobody has identified what data are transferred, who can access them, where they will be stored, or whether they can be shared onward.
Before drafting, map the data flow. Determine what happens when the data move between the institutions and make the agreement reflect that reality.
International transfers may require additional documentation
If personal data cross national borders, ordinary data-sharing or processing terms may not be sufficient. The applicable data protection framework may require an additional international-transfer mechanism or contractual safeguards.
The EU GDPR, UK GDPR, and Philippine Data Privacy Act frameworks approach international transfers differently. A research collaboration should therefore not use "DTA signed" as shorthand for "all international transfer requirements satisfied."
Before an overseas transfer, separately assess the requirements for international research data transfers.
The agreement should exist before the transfer it governs
A familiar research sequence goes like this: send the data because the analysis is urgent, discover during manuscript preparation that an agreement was required, then ask the research office to date paperwork around a transfer that already happened.
That sequence defeats much of the purpose of the agreement.
The document is supposed to establish what may happen before access or transfer begins. It allows privacy, legal, research governance, information security, and the collaborating institutions to resolve responsibilities while the data are still under control.
Do Not Start With the Template
First determine the parties' roles and the proposed processing. Then select the agreement that fits. Starting with whichever DSA or DTA template someone used on the previous project can produce a beautifully formatted description of the wrong legal relationship.
A signed agreement does not make an inappropriate transfer appropriate
Contracts document obligations. They do not override data protection law, participant rights, ethics requirements, institutional restrictions, or a lack of legitimate purpose.
ICO guidance explicitly notes that a data-sharing agreement can support compliance but does not provide immunity from breaches of data protection law.
Similarly, Philippine NPC guidance requires data-sharing arrangements to remain consistent with the Data Privacy Act, its implementing rules, and applicable issuances.
The agreement should memorialize a defensible transfer, not attempt to manufacture one.