Data Sharing
Data sharing is the practice of making an organization's data available to other users, applications, teams, or external organizations so that more people can access and use that information. It can happen internally between departments or externally with partners, other investigators, or the broader public. When the data being shared includes personal data, sharing it triggers data protection obligations that depend on the applicable jurisdiction and the roles of the parties involved.
Data sharing is the controlled process of making the same data resources available to multiple applications, users, or organizations, encompassing the technologies, practices, and governance arrangements that enable such access. In a data governance context, it involves defining ownership, stewardship, access controls, and policy over what is disclosed, to whom, and under what conditions. Where personal data is shared, the arrangement must be assessed against the relevant legal regime (which differs across the EU GDPR, UK GDPR, CCPA and CPRA, and other frameworks) to determine each party's role and obligations; sharing personal data does not remove it from scope, and the evidence provided here does not address cross-border transfer mechanisms, lawful bases, retention rules, or the specific controller/processor allocation applicable to any given arrangement.
Why it matters
Data sharing is a foundational enabler of value across research, analytics, and inter-organizational collaboration, allowing more users and applications to access the same trusted information rather than maintaining siloed, duplicated copies. In a governance context, the same act that unlocks value also expands the surface over which ownership, stewardship, access controls, and policy must be enforced. When the data being shared includes personal data, sharing does not remove that data from the scope of data protection regimes; instead, it typically introduces obligations that turn on the applicable jurisdiction and the roles the parties assume.
The central risk is that sharing arrangements are often implemented as technical connections first and governed as legal relationships second, or not at all. Making data available to another team, application, or external partner requires a clear determination of what is disclosed, to whom, and under what conditions, and, where personal data is involved, an assessment against the relevant framework to establish each party's responsibilities. Treatment differs across the EU GDPR, the UK GDPR, and the CCPA and CPRA, among others, so a sharing arrangement that is well-characterized under one regime may be described differently under another.
Accountability under governance frameworks generally requires demonstrable evidence of these arrangements, not merely a stated intention to share responsibly. The evidence available here does not address cross-border transfer mechanisms, lawful bases for processing, retention rules, or the specific controller and processor allocation applicable to any given arrangement, so those elements must be assessed separately before a sharing arrangement is treated as compliant.
Who it's relevant to
Inside Data Sharing
Common questions
Answers to the questions practitioners most commonly ask about Data Sharing.