Skip to main content
Category: International Data Transfers

Data Sharing

Also known as: Data Exchange, Data Disclosure
Simply put

Data sharing is the practice of making an organization's data available to other users, applications, teams, or external organizations so that more people can access and use that information. It can happen internally between departments or externally with partners, other investigators, or the broader public. When the data being shared includes personal data, sharing it triggers data protection obligations that depend on the applicable jurisdiction and the roles of the parties involved.

Formal definition

Data sharing is the controlled process of making the same data resources available to multiple applications, users, or organizations, encompassing the technologies, practices, and governance arrangements that enable such access. In a data governance context, it involves defining ownership, stewardship, access controls, and policy over what is disclosed, to whom, and under what conditions. Where personal data is shared, the arrangement must be assessed against the relevant legal regime (which differs across the EU GDPR, UK GDPR, CCPA and CPRA, and other frameworks) to determine each party's role and obligations; sharing personal data does not remove it from scope, and the evidence provided here does not address cross-border transfer mechanisms, lawful bases, retention rules, or the specific controller/processor allocation applicable to any given arrangement.

Why it matters

Data sharing is a foundational enabler of value across research, analytics, and inter-organizational collaboration, allowing more users and applications to access the same trusted information rather than maintaining siloed, duplicated copies. In a governance context, the same act that unlocks value also expands the surface over which ownership, stewardship, access controls, and policy must be enforced. When the data being shared includes personal data, sharing does not remove that data from the scope of data protection regimes; instead, it typically introduces obligations that turn on the applicable jurisdiction and the roles the parties assume.

The central risk is that sharing arrangements are often implemented as technical connections first and governed as legal relationships second, or not at all. Making data available to another team, application, or external partner requires a clear determination of what is disclosed, to whom, and under what conditions, and, where personal data is involved, an assessment against the relevant framework to establish each party's responsibilities. Treatment differs across the EU GDPR, the UK GDPR, and the CCPA and CPRA, among others, so a sharing arrangement that is well-characterized under one regime may be described differently under another.

Accountability under governance frameworks generally requires demonstrable evidence of these arrangements, not merely a stated intention to share responsibly. The evidence available here does not address cross-border transfer mechanisms, lawful bases for processing, retention rules, or the specific controller and processor allocation applicable to any given arrangement, so those elements must be assessed separately before a sharing arrangement is treated as compliant.

Who it's relevant to

Data protection officers and privacy leads
Where shared data includes personal data, these roles typically need to assess the arrangement against the applicable regime, which differs across the EU GDPR, UK GDPR, and CCPA and CPRA, and to confirm how each party's role and obligations are established. Sharing personal data does not take it out of scope, so this assessment is generally required rather than optional.
Data governance and stewardship teams
Data sharing depends on clear definitions of ownership, stewardship, access controls, and policy governing what is disclosed, to whom, and under what conditions. These teams are typically responsible for ensuring shared resources remain governed rather than becoming ungoverned copies once access is extended internally or externally.
Research and administrative data partners
In research and administrative contexts, sharing often means providing partners with access to information they cannot reach within their own holdings, including other investigators, research subjects, or the broader public. These parties benefit from clear conditions of access and, where personal data is involved, a defined allocation of responsibilities under the relevant framework.
Legal, compliance, and accountability owners
Because accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, these roles need documented sharing arrangements. Note that the evidence here does not resolve lawful bases, retention, cross-border transfer mechanics, or controller and processor allocation, so those must be addressed separately before an arrangement is treated as compliant.

Inside Data Sharing

Disclosing and receiving parties
Data sharing involves the transfer or provision of access to personal data between distinct organizations or, in some cases, between separate parts of the same organization. Each party must be assessed for its role: a party may act as a controller, joint controller, or processor depending on who determines the purposes and means of processing. This role determination drives the respective obligations and is not always obvious from the direction of the data flow.
Lawful basis for the sharing
Under regimes such as the EU GDPR and UK GDPR, any disclosure of personal data requires an identified lawful basis, which need not be consent and may be, for example, legitimate interests, legal obligation, or performance of a contract, depending on the circumstances. Where special category data is involved, an additional condition for processing is generally required beyond the ordinary lawful basis. Treatment differs under other regimes such as the CCPA and CPRA or HIPAA.
Governing arrangement or agreement
Data sharing is typically documented through an arrangement that defines roles, purposes, categories of data, security expectations, and responsibilities. A controller-to-processor relationship generally requires a written contract with specified terms, while a controller-to-controller or joint controller arrangement is commonly governed by a data sharing agreement setting out how respective obligations are met. The precise required contents vary by regime and are not covered exhaustively here.
Purpose limitation and scope
Shared data is generally constrained to the purpose for which it was disclosed. Re-use for a new, incompatible purpose by the receiving party may require a fresh assessment of lawful basis and, in some cases, notice to individuals. The categories of data shared should be limited to what is necessary for the stated purpose (data minimization).
Governance and security responsibilities
Data sharing sits at the intersection of governance and security. Governance elements include documenting the data flow, assigning stewardship, tracking lineage, and maintaining records of the sharing activity. Security elements include the confidentiality, integrity, and availability controls applied in transit and at rest. These are distinct disciplines that overlap in a sharing arrangement but should not be collapsed into one another.
Accountability and record-keeping
Parties are generally expected to be able to demonstrate, with evidence rather than stated intent, that the sharing is lawful, documented, and controlled. This may include records of processing activities where such an obligation applies, though such records are a documentation requirement and not the same as a data inventory tool.

Common questions

Answers to the questions practitioners most commonly ask about Data Sharing.

Does anonymizing data before sharing remove it from the scope of data protection law?
Only if the data is genuinely anonymized in an irreversible way such that individuals can no longer be identified, directly or indirectly, by any party with access. This is a high bar. Pseudonymized data, tokenized data, and encrypted data generally remain personal data because re-identification is still possible, so sharing them typically remains subject to data protection obligations. Treating reversible techniques as equivalent to anonymization is a common error; the sharing party should assess re-identification risk in context rather than assume the data has left scope.
If both organizations agree to share data, does the recipient simply take on the same obligations as the discloser?
Not automatically. The obligations that attach to a data sharing arrangement depend on the role each party holds. Where a party determines the purposes and means of processing it generally acts as a controller and bears controller obligations; where it processes only on documented instructions it generally acts as a processor. Parties may be separate controllers, joint controllers, or a controller and processor, and each configuration carries different accountability. The applicable duties also vary by regime, since the EU GDPR, UK GDPR, and other frameworks treat these roles and arrangements differently. Agreement to share does not by itself equalize responsibilities.
What should a written data sharing arrangement typically address?
Arrangements generally identify the parties and their roles, the categories of data and individuals involved, the purposes for which data may be used, the lawful basis relied on where applicable, security expectations, and how individuals' rights will be handled. Where a controller-processor relationship exists, many regimes require specific contractual terms. This entry does not enumerate the mandatory clauses of any particular regime, and requirements differ across jurisdictions, so the exact contents should be confirmed against the applicable instrument.
How does data sharing relate to cross-border transfer requirements?
Sharing data with a recipient located in, or accessible from, another jurisdiction may trigger separate cross-border transfer rules in addition to the general requirements for sharing. The mechanics of those transfer mechanisms are out of scope for this entry. Parties should assess transfer obligations independently of, and in addition to, the sharing arrangement itself, because satisfying one does not satisfy the other.
What governance evidence supports a data sharing arrangement?
Accountability under governance frameworks generally requires demonstrable evidence rather than stated intent. Relevant records may include the sharing agreement, documentation of the roles and lawful basis where applicable, records of processing activities, data lineage or catalog entries showing what is shared and with whom, and any assessment of risk conducted before sharing. Data governance concerns such as ownership, stewardship, and lineage overlap with but remain distinct from the security controls applied to protect the shared data.
Is a data protection impact assessment always required before sharing data?
No. An impact assessment is generally required only where processing is likely to result in a high risk to individuals, and the criteria for that trigger depend on the applicable regime. Some sharing activities warrant one and others do not. The assessment should be scoped to the specific sharing operation and its risks rather than performed reflexively for every arrangement, and its necessity should be evaluated against the relevant instrument.

Common misconceptions

Data sharing always requires the consent of the individuals concerned.
Consent is only one of several lawful bases. In many jurisdictions, sharing may instead rely on legitimate interests, a legal obligation, contractual necessity, or another applicable basis, depending on context. Treating consent as the default can be both unnecessary and, where consent is not freely given or is later withdrawn, operationally fragile.
Applying encryption, tokenization, or pseudonymization before sharing removes the data from data protection scope.
Pseudonymized data remains personal data because re-identification is possible, and encryption or tokenization are security measures that do not by themselves make data non-personal. Only irreversible anonymization would generally take data outside most regulatory scope, and achieving genuine anonymization is difficult to demonstrate.
The party sending the data always carries the compliance obligations, and the recipient is merely a passive processor.
Roles depend on who determines the purposes and means of processing, not on the direction of the flow. A recipient may be an independent controller with its own full set of obligations, or a joint controller sharing accountability. Mischaracterizing the recipient as a processor when it is in fact a controller misallocates responsibility.

Best practices

Determine and document the role of each party (controller, joint controller, or processor) before sharing, based on who decides the purposes and means, and reflect this in the governing agreement.
Identify and record a specific lawful basis for the disclosure, and where special category data is involved, confirm an additional processing condition applies rather than defaulting to consent.
Put in place an appropriate written arrangement that defines purposes, data categories, security expectations, and responsibilities, and align its contents to the requirements of the applicable regime.
Apply data minimization by limiting shared data to what is necessary for the stated purpose, and constrain the recipient's re-use to compatible purposes only.
Maintain demonstrable evidence of the sharing, including the flow, roles, lawful basis, and controls, so accountability can be shown rather than merely asserted.
Keep governance documentation (ownership, lineage, records of the activity) distinct from but coordinated with the security controls protecting the data in transit and at rest.