Direct comparison
CoC vs. Data Use Agreement: What Differs
A Certificate of Confidentiality shields against legal disclosure of participant identity; a DUA governs data-sharing terms. Compare both, side by side.
Side-by-side comparison
| Dimension | Certificate of Confidentiality (CoC) | Data Use Agreement (DUA) |
|---|---|---|
| What it is | A federal statutory legal-process protection under Section 301(d) of the Public Health Service Act (42 U.S.C. § 241(d)) | A negotiated contract between a data provider and a data recipient governing use of a specific dataset |
| What it protects against | Being legally compelled (subpoena, court order, legislative/administrative demand) to disclose a research participant's identity or identifying information | Unauthorized or out-of-scope use, re-disclosure, re-identification attempts, or indefinite retention of a shared dataset |
| How it's obtained | Automatic for qualifying NIH-funded research since October 1, 2017 (NOT-OD-17-109); no application, no document issued. A separate, non-automatic application exists for non-NIH-funded research | Drafted and negotiated between the parties (or their institutional signing officials) before data access is granted; mandatory under 45 CFR § 164.514(e) for HIPAA limited datasets |
| Who signs it / who it binds | Nobody signs anything — it is a standing term of the NIH award, not a bilateral agreement | Institutionally authorized officials on both sides; typically binds the recipient institution, not just the individual researcher |
| Does data need to move between institutions to apply | No — applies regardless of how many institutions are involved or whether data is shared at all | Yes — a DUA exists specifically because a dataset is being accessed or transferred to a named recipient |
| Is the data itself changed | No — data can remain fully identifiable; the CoC changes what can be legally compelled, not what the data contains | No, unless the DUA itself specifies de-identification or a limited-dataset construction as a condition of access |
| Does it cover data breaches or insider disclosure | No — offers no protection against a breach, hack, or voluntary/insider disclosure outside a legal proceeding | Partially — a well-drafted DUA requires security safeguards and breach notification, but breach itself is a contract violation, not something the DUA prevents outright |
| Typical use case | An NIH-funded study on a sensitive topic (substance use, mental health, illegal conduct, genomic data) needing protection from a subpoena seeking participant identity | A researcher requesting restricted-access data from dbGaP, CMS, or a collaborating institution's limited dataset |
| What happens if the terms are violated | Not applicable in the same sense — the CoC is a legal shield the CoC holder relies on, not a set of obligations the holder can violate | Contract remedies (data-access revocation, institutional sanctions, referral for legal action) depending on the DUA's own enforcement terms |
Common questions
FAQ
Does a Certificate of Confidentiality mean a research team doesn't also need a Data Use Agreement?+
No. A CoC only shields against compelled legal disclosure of participant identity; it says nothing about the terms under which a dataset may be shared with a collaborating institution or external recipient. If data is genuinely moving between parties, a DUA (or a comparable data-sharing instrument) is still needed regardless of whether a CoC also applies to the study.
If a study has a Certificate of Confidentiality, can the data still be shared under a Data Use Agreement?+
Yes. The two are not in tension — a CoC does not restrict data sharing, it restricts what a court or other legal process can compel. A study can have an active CoC and simultaneously share its data through one or more DUAs; the DUA's own terms (not the CoC) govern what the recipient may do with the data.
Who decides whether a project needs a Certificate of Confidentiality versus just a Data Use Agreement?+
For NIH-funded research meeting the automatic-issuance criteria, a CoC applies without anyone deciding to seek one. Whether additional protection is worth pursuing for non-NIH-funded research, and whether/how a DUA is required for a given data-sharing arrangement, are questions typically assessed by the IRB during protocol review and by institutional legal or data-governance offices during data-sharing negotiation — not a determination an individual researcher makes alone.
Can a Data Use Agreement provide the same legal protection as a Certificate of Confidentiality?+
No. A DUA is a contract between the parties to it; it cannot bind a court, prosecutor, or other party outside the agreement, and it creates no immunity from legal process. Only a CoC (or a comparable statutory protection) can shield against a subpoena or court order compelling disclosure of participant identity.
Going deeper







