03 · What You Need to Know
A Transfer Is More Than Sending a File
Start with the purpose of the transfer
Before deciding how to transfer data, establish why the receiving institution needs them.
Perhaps another university is conducting statistical analysis, laboratory testing, transcription, qualitative coding, long-term archiving, independent validation, or a defined part of a multicenter study. The purpose should be sufficiently specific that you can determine what information the recipient actually requires.
This matters because the purpose drives many of the decisions that follow: which records are needed, which variables are relevant, whether identifiers are necessary, who should have access, how long the recipient should retain the data, and whether onward sharing is permitted.
Being part of the research team does not automatically authorize access
A collaborator may be a co-investigator, co-author, statistician, laboratory partner, or named member of a consortium without needing every participant-level field held by the originating institution.
Access should follow the person's and institution's legitimate role in the project. Before transferring participant information, establish whether the collaborator actually needs access to those data.
The distinction becomes particularly important when a project contains separate datasets such as participant contact information, consent records, raw recordings, clinical measurements, reidentification keys, and pseudonymized analytical files. Different collaborators may need different parts.
Determine the legal and governance roles of the institutions
Two collaborating institutions do not necessarily have identical data-protection roles.
Under GDPR-style frameworks, institutions might act as separate controllers, joint controllers, or in some circumstances one party might process particular data on behalf of another. Under the Philippine Data Privacy Act framework, relevant roles include personal information controller and personal information processor.
The correct classification depends on what each institution actually decides and does. If both jointly determine the purposes and essential means of particular processing, that may indicate joint controllership under a framework that recognizes that role. If one organization processes information only according to another's instructions, the relationship may instead be controller-to-processor.
Resolve who controls, manages, and processes the research data before drafting an agreement around incorrect assumptions.
Confirm that the disclosure itself is lawful and ethically consistent
A technically secure transfer can still be inappropriate if the recipient should not have received the information in the first place.
Check the applicable legal basis or other lawful conditions for the disclosure and subsequent processing. If sensitive or specially protected categories of information are involved, additional conditions may apply.
Also review what participants were told, what the ethics application described, what the protocol permits, and whether funder, sponsor, contractual, repository, or institutional restrictions apply.
The Philippine National Privacy Commission treats data sharing as processing of personal data. Current NPC guidance explains that data sharing between personal information controllers must have an appropriate lawful basis under the Data Privacy Act and should be governed in accordance with applicable data-sharing requirements.
Do not transfer the master dataset merely because it already exists
Suppose the originating institution holds 80 variables, including participant names, contact information, exact dates of birth, recruitment records, and a reidentification key. The receiving statistician needs 17 research variables and a study ID.
The transfer should begin with those 17 variables, not with the convenient observation that the full spreadsheet is already sitting on someone's desktop.
Apply data minimization to the transfer itself. Consider whether records can be excluded, direct identifiers removed, precision reduced, dates generalized, or information pseudonymized before leaving the originating institution.
ICO data-sharing guidance similarly advises organizations to identify what information is being shared, restrict access to authorized personnel, and share information securely with the correct recipient.
Pseudonymization can reduce risk without making the data anonymous
Where the receiving institution does not need participant identities, pseudonymization may allow researchers to transfer study IDs and research variables while the identifying key remains with the originating institution.
This can substantially reduce disclosure risk. However, pseudonymized information generally remains personal data under GDPR-style frameworks when reidentification remains possible using additional information.
Researchers should therefore continue to apply appropriate security and governance rather than labeling a coded dataset "anonymous" merely because names have been removed.
Decide what happens after the recipient receives the data
Secure transmission is only one moment in the data lifecycle. The receiving institution may download, store, analyze, copy, back up, transform, combine, archive, or share the information.
Before transfer, establish where the data will be stored, who can access them, whether local copies are permitted, whether they may be combined with other information, whether subprocessors or additional collaborators may receive them, and what happens when the agreed work is complete.
ICO guidance recommends that data-sharing arrangements address what happens to information at every stage, the organizations and personnel involved, security arrangements, retention and deletion, rights requests, and termination of the sharing arrangement.
The receiving institution's security matters too
The sender should not focus exclusively on encrypting the journey while ignoring the destination.
If a sensitive dataset is transferred through an excellent encrypted system and then downloaded to an unencrypted personal laptop, the overall arrangement remains weak. Reasonable due diligence may therefore include understanding the recipient's storage environment, authentication, access controls, encryption, incident procedures, and other safeguards relevant to the data.
Current ICO guidance emphasizes taking reasonable steps to ensure that shared personal information will continue to receive adequate security at the recipient organization.
Choose the transfer mechanism after deciding what may be transferred
Possible mechanisms include an institutionally managed secure file-transfer service, authenticated cloud environment, encrypted transfer system, approved encrypted email, or controlled portable media. The appropriate method depends on the data and institutional requirements.
The previous decision is more fundamental: what information may this recipient receive?
If email is proposed, separately assess whether email is an appropriate transfer method. If portable media are proposed, assess the controls required for research data on removable media.
A data-sharing agreement can turn assumptions into explicit responsibilities
A written data-sharing arrangement can document the parties, purposes, datasets, roles, security requirements, authorized users, retention, deletion, participant rights, incident procedures, and restrictions on onward disclosure.
Under current Philippine NPC guidance, data sharing between personal information controllers may be covered by a data-sharing agreement or similar document containing the terms and conditions of the arrangement. NPC guidance recommends such documentation as a matter of accountability and good practice even where the governing rule uses permissive language.
ICO guidance likewise describes data-sharing agreements as good practice because they clarify purposes, roles, responsibilities, standards, and what happens to information throughout the sharing lifecycle.
Whether your particular transfer requires such an agreement, and what kind, is a separate question that should be resolved under the applicable framework. Do not assume that every transfer uses the same document.
A research collaboration agreement is not necessarily a data-sharing agreement
A memorandum of understanding, grant consortium agreement, authorship agreement, or collaboration contract may address scientific responsibilities without adequately specifying personal-data processing.
It may say who recruits participants and who analyzes the data but say nothing about security standards, authorized users, breach reporting, retention, deletion, participant rights, or onward sharing.
Review the actual provisions rather than the document title. If the necessary data-governance terms are already included, another document may be unnecessary. If they are absent, the existence of a signed collaboration agreement does not fill the gap by itself.
Changes in purpose require another look
Suppose University B originally receives data to perform a prespecified analysis. Six months later, its researchers identify a different question and want to reuse the dataset for another project.
The original transfer does not automatically authorize every scientifically interesting secondary use. The parties should determine whether the new processing is compatible with the original arrangements, whether another lawful basis or approval is required, whether participants were informed appropriately, and whether ethics or contractual amendments are needed.
Before You Transfer
Do not send participant data while the institutions are still trying to determine their roles, permitted purposes, or security responsibilities. Resolve the governance arrangement first; the file transfer should be the implementation of that decision, not the event that forces everyone to make it afterward.