Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should You Consider Before Transferring Research Data Between Institutions?

A research collaboration does not automatically authorize one institution to send participant data to another. Before transferring data, clarify the purpose, recipient, legal roles, minimum dataset, safeguards, agreements, and what happens after receipt.

317
Research Data Transfers Between Institutions Guide 317 of 398
01 · The Question

Your Collaborator Needs the Data. Can You Send It?

A research project involves two universities. One institution recruits participants and collects the data; researchers at the other institution will conduct part of the analysis. Everyone is named on the protocol, and everyone considers themselves part of the same research team.

Can the first university simply send the participant dataset to the second?

Not automatically. A scientific collaboration explains why researchers are working together, but it does not by itself establish what personal data may be disclosed, who may receive them, how they may be used, which institution is responsible for which processing, or what safeguards must govern the transfer.

02 · The Short Answer

Establish the Data Relationship Before Moving the Data

In Brief

Before transferring research data between institutions, determine why the transfer is necessary, what data the recipient actually needs, whether the disclosure is authorized, what role each institution has, how the data will be transferred and protected, and what the recipient may do with them afterward.

A collaboration agreement or ethics approval does not necessarily answer every data-protection question. Depending on the arrangement and jurisdiction, a data-sharing agreement, processing agreement, data-transfer agreement, or other documented governance arrangement may also be appropriate or required.

03 · What You Need to Know

A Transfer Is More Than Sending a File

Start with the purpose of the transfer

Before deciding how to transfer data, establish why the receiving institution needs them.

Perhaps another university is conducting statistical analysis, laboratory testing, transcription, qualitative coding, long-term archiving, independent validation, or a defined part of a multicenter study. The purpose should be sufficiently specific that you can determine what information the recipient actually requires.

This matters because the purpose drives many of the decisions that follow: which records are needed, which variables are relevant, whether identifiers are necessary, who should have access, how long the recipient should retain the data, and whether onward sharing is permitted.

Being part of the research team does not automatically authorize access

A collaborator may be a co-investigator, co-author, statistician, laboratory partner, or named member of a consortium without needing every participant-level field held by the originating institution.

Access should follow the person's and institution's legitimate role in the project. Before transferring participant information, establish whether the collaborator actually needs access to those data.

The distinction becomes particularly important when a project contains separate datasets such as participant contact information, consent records, raw recordings, clinical measurements, reidentification keys, and pseudonymized analytical files. Different collaborators may need different parts.

Determine the legal and governance roles of the institutions

Two collaborating institutions do not necessarily have identical data-protection roles.

Under GDPR-style frameworks, institutions might act as separate controllers, joint controllers, or in some circumstances one party might process particular data on behalf of another. Under the Philippine Data Privacy Act framework, relevant roles include personal information controller and personal information processor.

The correct classification depends on what each institution actually decides and does. If both jointly determine the purposes and essential means of particular processing, that may indicate joint controllership under a framework that recognizes that role. If one organization processes information only according to another's instructions, the relationship may instead be controller-to-processor.

Resolve who controls, manages, and processes the research data before drafting an agreement around incorrect assumptions.

Confirm that the disclosure itself is lawful and ethically consistent

A technically secure transfer can still be inappropriate if the recipient should not have received the information in the first place.

Check the applicable legal basis or other lawful conditions for the disclosure and subsequent processing. If sensitive or specially protected categories of information are involved, additional conditions may apply.

Also review what participants were told, what the ethics application described, what the protocol permits, and whether funder, sponsor, contractual, repository, or institutional restrictions apply.

The Philippine National Privacy Commission treats data sharing as processing of personal data. Current NPC guidance explains that data sharing between personal information controllers must have an appropriate lawful basis under the Data Privacy Act and should be governed in accordance with applicable data-sharing requirements.

Do not transfer the master dataset merely because it already exists

Suppose the originating institution holds 80 variables, including participant names, contact information, exact dates of birth, recruitment records, and a reidentification key. The receiving statistician needs 17 research variables and a study ID.

The transfer should begin with those 17 variables, not with the convenient observation that the full spreadsheet is already sitting on someone's desktop.

Apply data minimization to the transfer itself. Consider whether records can be excluded, direct identifiers removed, precision reduced, dates generalized, or information pseudonymized before leaving the originating institution.

ICO data-sharing guidance similarly advises organizations to identify what information is being shared, restrict access to authorized personnel, and share information securely with the correct recipient.

Pseudonymization can reduce risk without making the data anonymous

Where the receiving institution does not need participant identities, pseudonymization may allow researchers to transfer study IDs and research variables while the identifying key remains with the originating institution.

This can substantially reduce disclosure risk. However, pseudonymized information generally remains personal data under GDPR-style frameworks when reidentification remains possible using additional information.

Researchers should therefore continue to apply appropriate security and governance rather than labeling a coded dataset "anonymous" merely because names have been removed.

Decide what happens after the recipient receives the data

Secure transmission is only one moment in the data lifecycle. The receiving institution may download, store, analyze, copy, back up, transform, combine, archive, or share the information.

Before transfer, establish where the data will be stored, who can access them, whether local copies are permitted, whether they may be combined with other information, whether subprocessors or additional collaborators may receive them, and what happens when the agreed work is complete.

ICO guidance recommends that data-sharing arrangements address what happens to information at every stage, the organizations and personnel involved, security arrangements, retention and deletion, rights requests, and termination of the sharing arrangement.

The receiving institution's security matters too

The sender should not focus exclusively on encrypting the journey while ignoring the destination.

If a sensitive dataset is transferred through an excellent encrypted system and then downloaded to an unencrypted personal laptop, the overall arrangement remains weak. Reasonable due diligence may therefore include understanding the recipient's storage environment, authentication, access controls, encryption, incident procedures, and other safeguards relevant to the data.

Current ICO guidance emphasizes taking reasonable steps to ensure that shared personal information will continue to receive adequate security at the recipient organization.

Choose the transfer mechanism after deciding what may be transferred

Possible mechanisms include an institutionally managed secure file-transfer service, authenticated cloud environment, encrypted transfer system, approved encrypted email, or controlled portable media. The appropriate method depends on the data and institutional requirements.

The previous decision is more fundamental: what information may this recipient receive?

If email is proposed, separately assess whether email is an appropriate transfer method. If portable media are proposed, assess the controls required for research data on removable media.

A data-sharing agreement can turn assumptions into explicit responsibilities

A written data-sharing arrangement can document the parties, purposes, datasets, roles, security requirements, authorized users, retention, deletion, participant rights, incident procedures, and restrictions on onward disclosure.

Under current Philippine NPC guidance, data sharing between personal information controllers may be covered by a data-sharing agreement or similar document containing the terms and conditions of the arrangement. NPC guidance recommends such documentation as a matter of accountability and good practice even where the governing rule uses permissive language.

ICO guidance likewise describes data-sharing agreements as good practice because they clarify purposes, roles, responsibilities, standards, and what happens to information throughout the sharing lifecycle.

Whether your particular transfer requires such an agreement, and what kind, is a separate question that should be resolved under the applicable framework. Do not assume that every transfer uses the same document.

A research collaboration agreement is not necessarily a data-sharing agreement

A memorandum of understanding, grant consortium agreement, authorship agreement, or collaboration contract may address scientific responsibilities without adequately specifying personal-data processing.

It may say who recruits participants and who analyzes the data but say nothing about security standards, authorized users, breach reporting, retention, deletion, participant rights, or onward sharing.

Review the actual provisions rather than the document title. If the necessary data-governance terms are already included, another document may be unnecessary. If they are absent, the existence of a signed collaboration agreement does not fill the gap by itself.

Changes in purpose require another look

Suppose University B originally receives data to perform a prespecified analysis. Six months later, its researchers identify a different question and want to reuse the dataset for another project.

The original transfer does not automatically authorize every scientifically interesting secondary use. The parties should determine whether the new processing is compatible with the original arrangements, whether another lawful basis or approval is required, whether participants were informed appropriately, and whether ethics or contractual amendments are needed.

Before You Transfer

Do not send participant data while the institutions are still trying to determine their roles, permitted purposes, or security responsibilities. Resolve the governance arrangement first; the file transfer should be the implementation of that decision, not the event that forces everyone to make it afterward.

04 · A Practical Example

Sharing Data With a Collaborating University

Hypothetical Example

A multicenter education study

University A recruits 1,200 students and holds the identifiable master dataset. University B will conduct a prespecified statistical analysis examining the relationship between study behaviors and academic outcomes.

Define the purpose University B requires participant-level research variables for the agreed analysis but has no role in recruitment or participant follow-up.
Reduce the dataset University A removes names, email addresses, student numbers, contact information, and variables unrelated to the agreed analysis. Study IDs are retained where analytically necessary.
Clarify institutional roles The institutions determine their respective data-protection roles based on the actual processing arrangement rather than assuming that "collaborator" is a legal category.
Document the arrangement The appropriate institutional agreement specifies the permitted purpose, dataset, authorized users, security, retention, incident procedures, and restrictions on further sharing.
Transfer securely University A uses the institutionally approved authenticated transfer system. The dataset is made available only to authorized University B personnel.
Close the transfer lifecycle At the end of the agreed work, University B follows the documented return, deletion, retention, or archival arrangement rather than keeping the dataset indefinitely because another analysis might eventually be interesting.

The collaboration justified a legitimate reason to share data, but it did not determine the dataset, access rights, transfer mechanism, or future uses automatically. Those decisions required their own justification.

05 · What Researchers Often Get Wrong

Common Mistakes in Interinstitutional Data Transfers

Misconception

If Both Institutions Are Named on the Study, Can They Freely Exchange the Data?

No. Participation in the same research project does not automatically determine which personal data each institution may receive. Access should reflect the authorized purpose, actual roles, ethics arrangements, applicable law, and data-governance requirements.

Misconception

If Ethics Approval Mentions the Collaborator, Is the Transfer Fully Covered?

Not necessarily. Ethics approval may be important, but separate data protection, contractual, security, institutional, or transfer requirements can still apply.

Misconception

Should You Send the Full Dataset So the Collaborator Can Decide What They Need?

Usually not. Determine the authorized purpose first and construct the dataset around that purpose. Sending unnecessary identifiers or variables increases exposure without improving the agreed analysis.

Misconception

Does Encrypting the Transfer Solve the Governance Problem?

No. Encryption can protect the data during transmission or storage, but it does not establish whether the recipient is authorized, whether the disclosure is lawful, what the recipient may do afterward, or how long the information may be retained.

Misconception

Does a Data-Sharing Agreement Make Any Transfer Lawful?

No. An agreement documents and governs an otherwise legitimate arrangement; it does not manufacture a lawful basis for an impermissible disclosure. The underlying processing still needs to satisfy applicable legal, ethical, and institutional requirements.

06 · What This Means for You

Treat the Recipient Institution as Part of the Data Lifecycle

Before transferring research data, map what will happen on both sides of the transfer. The sender's responsibility does not end at the upload button, and the recipient's responsibility does not begin only when analysis starts.

A simple decision framework

If the recipient does not need participant-level data
Consider providing aggregate or genuinely anonymous information instead.
If participant-level data are necessary
Transfer only the records, variables, precision, and identifiers needed for the defined purpose.
If another institution will determine its own purposes or jointly make processing decisions
Clarify the relevant controller relationship and document the sharing arrangement appropriately.
If the institution will process data only on your organization's instructions
Determine whether a controller-to-processor arrangement and corresponding processing terms are required.
If the receiving institution is in another country
Add the applicable international-transfer analysis before releasing access or sending the data.

If the relationship requires formal documentation, determine which type of data-sharing or transfer agreement fits the arrangement rather than treating every document with "data" in its title as interchangeable.

07 · A Quick Checklist

Before Transferring Data to Another Institution

Confirm:
The specific purpose for which the receiving institution needs the data.
The disclosure and subsequent processing have an appropriate legal, ethical, and institutional basis.
The respective controller, joint-controller, processor, or other applicable roles have been determined from the actual arrangement.
Only the records, variables, identifiers, and precision necessary for the recipient's purpose will be transferred.
The receiving institution's authorized users, storage environment, access controls, and security arrangements are appropriate.
The required sharing, processing, transfer, confidentiality, or collaboration documentation is in place before the transfer.
An institutionally approved secure transfer mechanism has been selected.
Retention, deletion, return, onward sharing, secondary use, and incident-reporting responsibilities are documented.
Any additional international-transfer requirements have been addressed if the recipient or access location is outside the relevant jurisdiction.
08 · Frequently Asked Questions

Common Questions About Transfers Between Research Institutions

Can two universities share participant data if they are collaborating on the same study?

Potentially, but collaboration alone is not sufficient. The institutions should establish the purpose, applicable legal basis, ethics and participant commitments, respective roles, necessary dataset, security arrangements, and any required agreements before sharing.

Do research data need to be anonymized before transfer?

Not necessarily. Some legitimate research requires participant-level personal data. However, if the purpose can be achieved using genuinely anonymous or appropriately pseudonymized information, reducing identifiability can substantially reduce risk and may simplify the governance requirements.

Do we always need a data-sharing agreement?

Requirements depend on the jurisdiction and relationship. Current ICO guidance treats data-sharing agreements as good practice, while Philippine NPC rules provide a specific framework for data sharing between personal information controllers and strongly support appropriate documentation for accountability. Determine what your actual arrangement requires.

Can a collaboration agreement double as a data-sharing agreement?

Potentially, if it contains the provisions required for the applicable data-sharing arrangement. The title of the document matters less than whether it adequately addresses purposes, roles, data, safeguards, access, retention, incidents, rights, and other required terms.

Can the receiving institution reuse the data for another study?

Not automatically. A new purpose should be assessed against the original authorization, participant information, ethics arrangements, applicable data protection principles, agreements, and institutional requirements before secondary processing begins.

Who is responsible if the receiving institution has a data breach?

That depends on the parties' legal roles, applicable law, and circumstances of the breach. The sharing arrangement should identify incident-reporting responsibilities in advance so that containment and legal assessment do not begin with everyone trying to determine who was supposed to call whom.

09 · The Bottom Line

A Collaboration Explains Why You Work Together, Not Automatically What Data You May Share

The Bottom Line

Before transferring research data between institutions, establish the purpose, authority, institutional roles, minimum necessary dataset, recipient safeguards, transfer method, and rules governing what happens to the data after receipt.

Do that work before the file moves. A secure transfer mechanism protects data in transit; a well-designed data-sharing arrangement protects the research relationship around it.

10 · Sources and Further Reading

Authoritative Sources on Interinstitutional Data Sharing

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes