Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Direct comparison

CoC vs. Data Use Agreement: What Differs

A Certificate of Confidentiality shields against legal disclosure of participant identity; a DUA governs data-sharing terms. Compare both, side by side.

Side-by-side comparison

DimensionCertificate of Confidentiality (CoC)Data Use Agreement (DUA)
What it isA federal statutory legal-process protection under Section 301(d) of the Public Health Service Act (42 U.S.C. § 241(d))A negotiated contract between a data provider and a data recipient governing use of a specific dataset
What it protects againstBeing legally compelled (subpoena, court order, legislative/administrative demand) to disclose a research participant's identity or identifying informationUnauthorized or out-of-scope use, re-disclosure, re-identification attempts, or indefinite retention of a shared dataset
How it's obtainedAutomatic for qualifying NIH-funded research since October 1, 2017 (NOT-OD-17-109); no application, no document issued. A separate, non-automatic application exists for non-NIH-funded researchDrafted and negotiated between the parties (or their institutional signing officials) before data access is granted; mandatory under 45 CFR § 164.514(e) for HIPAA limited datasets
Who signs it / who it bindsNobody signs anything — it is a standing term of the NIH award, not a bilateral agreementInstitutionally authorized officials on both sides; typically binds the recipient institution, not just the individual researcher
Does data need to move between institutions to applyNo — applies regardless of how many institutions are involved or whether data is shared at allYes — a DUA exists specifically because a dataset is being accessed or transferred to a named recipient
Is the data itself changedNo — data can remain fully identifiable; the CoC changes what can be legally compelled, not what the data containsNo, unless the DUA itself specifies de-identification or a limited-dataset construction as a condition of access
Does it cover data breaches or insider disclosureNo — offers no protection against a breach, hack, or voluntary/insider disclosure outside a legal proceedingPartially — a well-drafted DUA requires security safeguards and breach notification, but breach itself is a contract violation, not something the DUA prevents outright
Typical use caseAn NIH-funded study on a sensitive topic (substance use, mental health, illegal conduct, genomic data) needing protection from a subpoena seeking participant identityA researcher requesting restricted-access data from dbGaP, CMS, or a collaborating institution's limited dataset
What happens if the terms are violatedNot applicable in the same sense — the CoC is a legal shield the CoC holder relies on, not a set of obligations the holder can violateContract remedies (data-access revocation, institutional sanctions, referral for legal action) depending on the DUA's own enforcement terms

Common questions

FAQ

Does a Certificate of Confidentiality mean a research team doesn't also need a Data Use Agreement?+

No. A CoC only shields against compelled legal disclosure of participant identity; it says nothing about the terms under which a dataset may be shared with a collaborating institution or external recipient. If data is genuinely moving between parties, a DUA (or a comparable data-sharing instrument) is still needed regardless of whether a CoC also applies to the study.

If a study has a Certificate of Confidentiality, can the data still be shared under a Data Use Agreement?+

Yes. The two are not in tension — a CoC does not restrict data sharing, it restricts what a court or other legal process can compel. A study can have an active CoC and simultaneously share its data through one or more DUAs; the DUA's own terms (not the CoC) govern what the recipient may do with the data.

Who decides whether a project needs a Certificate of Confidentiality versus just a Data Use Agreement?+

For NIH-funded research meeting the automatic-issuance criteria, a CoC applies without anyone deciding to seek one. Whether additional protection is worth pursuing for non-NIH-funded research, and whether/how a DUA is required for a given data-sharing arrangement, are questions typically assessed by the IRB during protocol review and by institutional legal or data-governance offices during data-sharing negotiation — not a determination an individual researcher makes alone.

Can a Data Use Agreement provide the same legal protection as a Certificate of Confidentiality?+

No. A DUA is a contract between the parties to it; it cannot bind a court, prosecutor, or other party outside the agreement, and it creates no immunity from legal process. Only a CoC (or a comparable statutory protection) can shield against a subpoena or court order compelling disclosure of participant identity.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →