Direct comparison
DSA vs DPA: Which GDPR Agreement Applies?
A DSA covers research collaborators sharing data as joint/independent controllers. A DPA is the GDPR Art. 28 contract for engaging a data processor.
Side-by-side comparison
| Dimension | Data Sharing Agreement (DSA) | Data Processing Agreement (DPA) |
|---|---|---|
| What it governs | Data moving between research collaborators or institutions | Personal data handed to a third-party processor acting on a controller’s behalf |
| Legal trigger | Contractual choice — not mandated by a specific statute | Mandatory under GDPR Article 28 whenever a controller uses a processor |
| Relationship between parties | Joint controllers or independent controllers, each with their own purpose | Controller-to-processor — the processor acts only on documented instructions |
| Typical counterparty in research | A collaborating university, institute, or investigator | A vendor: cloud/storage provider, survey or EDC platform, transcription or analytics service |
| Applies only to personal data? | No — also used for non-personal research data; GDPR terms apply only if personal data is included | Yes — a DPA exists specifically because personal data is being processed |
| Mandatory content | No fixed statutory list — negotiated: permitted use, security, publication rights, retention, IP, liability | Fixed by GDPR Art. 28(3): subject-matter, duration, nature/purpose, data types, data-subject categories, controller’s rights, plus 8 processor duties (Art. 28(3)(a)-(h)) |
| Can the recipient set its own purpose for the data? | Yes — each party typically has its own research purpose | No — the processor has no independent purpose (Art. 28(3)(a)) |
| Sub-sharing / sub-processing | Governed by whatever onward-sharing clauses are negotiated | Processor cannot engage a sub-processor without the controller’s prior written authorisation (Art. 28(2)) |
| On termination | Retention/destruction terms as negotiated (e.g. destroy after study closeout) | Processor must delete or return all personal data at the end of the engagement (Art. 28(3)(g)) |
| Off-the-shelf model text | Institution- or funder-specific templates; no single universal template | EU Standard Contractual Clauses for controller-processor relationships (Commission Implementing Decision (EU) 2021/915, under Art. 28(7)) |
| Geographic scope | Used globally regardless of whether GDPR applies | GDPR Art. 28 itself is EU/EEA law; UK GDPR retains an equivalent Article 28 obligation post-Brexit |
Common questions
FAQ
Do we need both a DSA and a DPA for the same project?+
Often, yes — but for different counterparties. A DSA covers the terms between research collaborators who each use the data for their own purposes; a DPA covers any third-party vendor (cloud storage, survey platform, analytics service) that processes personal data purely on your institution’s instructions. A project can need one, the other, or both at once.
Is a DPA required if two institutions are joint controllers rather than controller and processor?+
No. Joint controllership is a different relationship, addressed by GDPR Article 26, not Article 28. Two institutions each deciding their own purposes for shared data should use a data sharing agreement (with GDPR joint-controller terms where relevant), not a DPA — a DPA specifically covers a controller instructing a processor with no independent purpose of its own.
Does GDPR require the document to be titled “Data Processing Agreement”?+
No. What matters is that the mandatory terms in Article 28(3) appear in a binding written contract between the controller and the processor — whether that is a standalone DPA, an addendum to a master services agreement, or a data-processing clause embedded in a broader contract. The underlying controller-processor relationship is what triggers Article 28, not the document’s title.
Who signs a DPA in a university research context?+
Typically the institution’s legal, privacy, or procurement office signs on behalf of the controller, with the vendor (or its authorised signatory) as processor. Individual researchers usually aren’t the signing party, though they often trigger the need for one by selecting a new tool or vendor.
Does a DPA apply if the shared dataset has been anonymised?+
If data is genuinely and irreversibly anonymised, it falls outside GDPR’s definition of personal data and Article 28 does not apply. Pseudonymised or coded data is not the same as anonymised — GDPR still treats pseudonymised data as personal data, so a DPA (or DSA with GDPR terms) is still required for it.
Going deeper







