Direct comparison
CoC vs. Data Use Agreement: What Differs
A Certificate of Confidentiality shields against legal disclosure of participant identity; a DUA governs data-sharing terms. Compare both, side by side.
Ask about CoC vs. Data Use Agreement: What Differs
Answers are drawn from this comparison and the rest of the CASRAI corpus, with a link to every source.
Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this
How do Certificate of Confidentiality (CoC), Data Use Agreement (DUA) compare side by side?
The table below compares Certificate of Confidentiality (CoC), Data Use Agreement (DUA) across 9 procurement-relevant dimensions, from what it is through what happens if the terms are violated.
Side-by-side comparison
| Dimension | Certificate of Confidentiality (CoC) | Data Use Agreement (DUA) |
|---|---|---|
| What it is | A federal statutory legal-process protection under Section 301(d) of the Public Health Service Act (42 U.S.C. § 241(d)) | A negotiated contract between a data provider and a data recipient governing use of a specific dataset |
| What it protects against | Being legally compelled (subpoena, court order, legislative/administrative demand) to disclose a research participant's identity or identifying information | Unauthorized or out-of-scope use, re-disclosure, re-identification attempts, or indefinite retention of a shared dataset |
| How it's obtained | Automatic for qualifying NIH-funded research since October 1, 2017 (NOT-OD-17-109); no application, no document issued. A separate, non-automatic application exists for non-NIH-funded research | Drafted and negotiated between the parties (or their institutional signing officials) before data access is granted; mandatory under 45 CFR § 164.514(e) for HIPAA limited datasets |
| Who signs it / who it binds | Nobody signs anything — it is a standing term of the NIH award, not a bilateral agreement | Institutionally authorized officials on both sides; typically binds the recipient institution, not just the individual researcher |
| Does data need to move between institutions to apply | No — applies regardless of how many institutions are involved or whether data is shared at all | Yes — a DUA exists specifically because a dataset is being accessed or transferred to a named recipient |
| Is the data itself changed | No — data can remain fully identifiable; the CoC changes what can be legally compelled, not what the data contains | No, unless the DUA itself specifies de-identification or a limited-dataset construction as a condition of access |
| Does it cover data breaches or insider disclosure | No — offers no protection against a breach, hack, or voluntary/insider disclosure outside a legal proceeding | Partially — a well-drafted DUA requires security safeguards and breach notification, but breach itself is a contract violation, not something the DUA prevents outright |
| Typical use case | An NIH-funded study on a sensitive topic (substance use, mental health, illegal conduct, genomic data) needing protection from a subpoena seeking participant identity | A researcher requesting restricted-access data from dbGaP, CMS, or a collaborating institution's limited dataset |
| What happens if the terms are violated | Not applicable in the same sense — the CoC is a legal shield the CoC holder relies on, not a set of obligations the holder can violate | Contract remedies (data-access revocation, institutional sanctions, referral for legal action) depending on the DUA's own enforcement terms |
Common questions
Common questions about Certificate of Confidentiality (CoC) vs Data Use Agreement (DUA)
Does a Certificate of Confidentiality mean a research team doesn't also need a Data Use Agreement?
+
No. A CoC only shields against compelled legal disclosure of participant identity; it says nothing about the terms under which a dataset may be shared with a collaborating institution or external recipient. If data is genuinely moving between parties, a DUA (or a comparable data-sharing instrument) is still needed regardless of whether a CoC also applies to the study.
If a study has a Certificate of Confidentiality, can the data still be shared under a Data Use Agreement?
+
Yes. The two are not in tension — a CoC does not restrict data sharing, it restricts what a court or other legal process can compel. A study can have an active CoC and simultaneously share its data through one or more DUAs; the DUA's own terms (not the CoC) govern what the recipient may do with the data.
Who decides whether a project needs a Certificate of Confidentiality versus just a Data Use Agreement?
+
For NIH-funded research meeting the automatic-issuance criteria, a CoC applies without anyone deciding to seek one. Whether additional protection is worth pursuing for non-NIH-funded research, and whether/how a DUA is required for a given data-sharing arrangement, are questions typically assessed by the IRB during protocol review and by institutional legal or data-governance offices during data-sharing negotiation — not a determination an individual researcher makes alone.
Can a Data Use Agreement provide the same legal protection as a Certificate of Confidentiality?
+
No. A DUA is a contract between the parties to it; it cannot bind a court, prosecutor, or other party outside the agreement, and it creates no immunity from legal process. Only a CoC (or a comparable statutory protection) can shield against a subpoena or court order compelling disclosure of participant identity.
Going deeper







