Data Sharing Agreement
A data sharing agreement is a written agreement between two or more parties that sets out what data will be shared, why it is being shared, and how it may be used. It clarifies each party's responsibilities and the standards they must follow at each stage of the data sharing, whether the exchange happens once or on an ongoing basis. It is a governance and accountability tool rather than a guarantee of legal compliance on its own.
A data sharing agreement (DSA) is a documented arrangement between two or more parties that governs a one-time or enduring exchange of, or access to, data. Per ICO guidance under the UK GDPR framework, it typically states the purpose of the sharing, describes what happens to the data at each stage, sets applicable standards, and allocates responsibilities among the parties. A DSA is primarily a governance and accountability instrument that helps parties demonstrate how sharing is managed and constrains permitted uses of the shared data; it does not by itself establish a lawful basis for processing, determine controller or processor status, or ensure compliance, all of which depend on the underlying facts, jurisdiction, and implementation. This entry does not address cross-border transfer mechanisms, retention rules, security controls, or the distinct question of whether shared data qualifies as personal, special category, or non-personal data; treatment of DSAs also differs across regimes such as the EU GDPR, CCPA and CPRA, and HIPAA, and generic model templates should not be assumed to satisfy any specific regulatory obligation.
Why it matters
A data sharing agreement gives the parties to a data exchange a documented, shared understanding of what is being shared, why, and how the data may be used. In governance terms, this matters because accountability frameworks generally require organizations to demonstrate how data handling is managed rather than simply assert that it is under control. A DSA that records the purpose of the sharing, describes what happens to the data at each stage, sets applicable standards, and allocates responsibilities among the parties provides evidence of that management and constrains permitted uses of the shared data.
Just as important is understanding what a DSA does not do. On its own it does not establish a lawful basis for processing, determine controller or processor status, or ensure compliance; those questions depend on the underlying facts, the applicable jurisdiction, and how the sharing is actually implemented. Treating a signed agreement as a compliance guarantee is a common and consequential mistake. Generic or model templates, such as those published for research or public-sector contexts, should not be assumed to satisfy any specific regulatory obligation without review against the relevant regime.
Treatment of data sharing agreements also differs across regulatory regimes. The ICO's data sharing guidance sits within the UK GDPR framework, while the EU GDPR, the CCPA and CPRA, and HIPAA each frame sharing arrangements differently. A DSA is best understood as a governance and accountability instrument that supports, but does not replace, the separate legal analysis each regime requires.
Who it's relevant to
Inside DSA
Common questions
Answers to the questions practitioners most commonly ask about DSA.