Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Direct comparison

DSA vs DPA: Which GDPR Agreement Applies?

A DSA covers research collaborators sharing data as joint/independent controllers. A DPA is the GDPR Art. 28 contract for engaging a data processor.

Side-by-side comparison

DimensionData Sharing Agreement (DSA)Data Processing Agreement (DPA)
What it governsData moving between research collaborators or institutionsPersonal data handed to a third-party processor acting on a controller’s behalf
Legal triggerContractual choice — not mandated by a specific statuteMandatory under GDPR Article 28 whenever a controller uses a processor
Relationship between partiesJoint controllers or independent controllers, each with their own purposeController-to-processor — the processor acts only on documented instructions
Typical counterparty in researchA collaborating university, institute, or investigatorA vendor: cloud/storage provider, survey or EDC platform, transcription or analytics service
Applies only to personal data?No — also used for non-personal research data; GDPR terms apply only if personal data is includedYes — a DPA exists specifically because personal data is being processed
Mandatory contentNo fixed statutory list — negotiated: permitted use, security, publication rights, retention, IP, liabilityFixed by GDPR Art. 28(3): subject-matter, duration, nature/purpose, data types, data-subject categories, controller’s rights, plus 8 processor duties (Art. 28(3)(a)-(h))
Can the recipient set its own purpose for the data?Yes — each party typically has its own research purposeNo — the processor has no independent purpose (Art. 28(3)(a))
Sub-sharing / sub-processingGoverned by whatever onward-sharing clauses are negotiatedProcessor cannot engage a sub-processor without the controller’s prior written authorisation (Art. 28(2))
On terminationRetention/destruction terms as negotiated (e.g. destroy after study closeout)Processor must delete or return all personal data at the end of the engagement (Art. 28(3)(g))
Off-the-shelf model textInstitution- or funder-specific templates; no single universal templateEU Standard Contractual Clauses for controller-processor relationships (Commission Implementing Decision (EU) 2021/915, under Art. 28(7))
Geographic scopeUsed globally regardless of whether GDPR appliesGDPR Art. 28 itself is EU/EEA law; UK GDPR retains an equivalent Article 28 obligation post-Brexit

Common questions

FAQ

Do we need both a DSA and a DPA for the same project?+

Often, yes — but for different counterparties. A DSA covers the terms between research collaborators who each use the data for their own purposes; a DPA covers any third-party vendor (cloud storage, survey platform, analytics service) that processes personal data purely on your institution’s instructions. A project can need one, the other, or both at once.

Is a DPA required if two institutions are joint controllers rather than controller and processor?+

No. Joint controllership is a different relationship, addressed by GDPR Article 26, not Article 28. Two institutions each deciding their own purposes for shared data should use a data sharing agreement (with GDPR joint-controller terms where relevant), not a DPA — a DPA specifically covers a controller instructing a processor with no independent purpose of its own.

Does GDPR require the document to be titled “Data Processing Agreement”?+

No. What matters is that the mandatory terms in Article 28(3) appear in a binding written contract between the controller and the processor — whether that is a standalone DPA, an addendum to a master services agreement, or a data-processing clause embedded in a broader contract. The underlying controller-processor relationship is what triggers Article 28, not the document’s title.

Who signs a DPA in a university research context?+

Typically the institution’s legal, privacy, or procurement office signs on behalf of the controller, with the vendor (or its authorised signatory) as processor. Individual researchers usually aren’t the signing party, though they often trigger the need for one by selecting a new tool or vendor.

Does a DPA apply if the shared dataset has been anonymised?+

If data is genuinely and irreversibly anonymised, it falls outside GDPR’s definition of personal data and Article 28 does not apply. Pseudonymised or coded data is not the same as anonymised — GDPR still treats pseudonymised data as personal data, so a DPA (or DSA with GDPR terms) is still required for it.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →