Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Data Transfer Agreement (DTA)

A contract governing the mechanics of transferring a dataset between institutions -- authorised senders and recipients, transmission and security method, and destruction-or-return terms -- distinct from a Data Use Agreement's downstream use restrictions and a Material Transfer Agreement's coverage of physical materials.

ByCASRAI Editorial Board
· Last updated 18 Jul 2026

Examples

Worked examples

  • Is an instance

    A university sends HIPAA limited-dataset clinical trial records to a collaborating institution via an encrypted secure file transfer under a DTA specifying the approved transmission method and a five-year destruction date.

  • Is an instance

    A US-based research consortium transferring genomic data to a European partner institution executes a DTA incorporating EU Standard Contractual Clauses to satisfy GDPR's international-transfer requirement.

Counter-examples

Looks similar, but isn't

  • Not an instance

    Downloading a fully public, de-identified dataset released under an open licence from a public repository does not require a DTA, since there is no confidentiality or transfer-security risk to manage.

  • Not an instance

    Shipping a biological specimen such as a cell line between labs is governed by a Material Transfer Agreement, not a DTA, since no data is being transferred.

Editorial commentary

A Data Transfer Agreement (DTA) is the contract that governs the mechanics of physically or electronically moving a dataset from one institution to another: who is authorised to send and receive it, what transmission or storage method is required, what security safeguards apply in transit and at rest, and what happens to the data (destruction, return, or continued retention) once the transfer’s purpose is complete. It is one of three commonly confused research agreement types, and institutions frequently use “DTA” and “Data Use Agreement (DUA)” interchangeably in practice, or combine both sets of terms into a single document. Where they are treated as separate instruments, the distinction is one of emphasis: a DTA is oriented toward the transfer event itself (custody, transmission security, liability for loss or breach during the handoff), while a DUA is oriented toward the recipient’s downstream obligations once they hold the data (permitted research purposes, authorised users, re-identification prohibitions, publication restrictions). Many transfers require both, executed as a single combined document or as companion agreements.

A DTA is also distinct from a Material Transfer Agreement (MTA), which governs the opposite category of research property: tangible physical materials such as reagents, cell lines, biospecimens, plasmids, or lab animals, rather than data. The two are sometimes needed together on the same project — for example, a biospecimen shipped under an MTA that arrives with an accompanying dataset of clinical annotations requires a DTA (or DUA) for the data component in addition to the MTA covering the physical specimen — but they are governed by different institutional offices in many universities (sponsored programs or technology transfer for MTAs; privacy, data governance, or IRB-adjacent offices for DTAs/DUAs) and address entirely different risks: chain-of-custody and biosafety for materials versus confidentiality, re-identification, and breach liability for data.

When institutions require a DTA

A DTA is typically required whenever identifiable, restricted, or otherwise sensitive research data crosses an institutional boundary: between two universities on a collaborative grant, from an institution to an industry partner or contract research organisation, from a health system to an academic investigator, or across a national border where data-protection law (for example, the EU/UK GDPR’s restrictions on transfers outside the European Economic Area) imposes an additional transfer-mechanism requirement on top of any use restrictions. A DTA is generally not required for fully public, de-identified, open-licence datasets, since there is no confidentiality or re-identification risk to manage in the handoff itself — though an open data licence or terms of use may still apply to how the data is subsequently used.

Typical required clauses

  • Transmission and security method — the approved transfer mechanism (encrypted secure file transfer, a designated secure enclave, physical media with encryption at rest) and prohibition on ad hoc methods such as unencrypted email.
  • Custody and liability — which party bears responsibility for a breach or loss occurring during transmission versus after receipt, and breach-notification timelines and obligations.
  • Permitted use and authorised recipients — often overlapping with DUA territory: the specific research purpose the data may be used for and the named individuals or roles permitted to access it.
  • Security safeguards at the receiving institution — access controls, storage requirements, and prohibition on further disclosure or onward transfer to a third party without consent.
  • Destruction or return terms — a defined end date or triggering event (study completion, award closeout) after which the recipient must destroy the data (with certification) or return it to the source, and retention exceptions where a repository deposit or regulatory retention requirement overrides the default.
  • Governing law and dispute resolution, and, for cross-border transfers, the specific international transfer mechanism relied on (for example, EU Standard Contractual Clauses or an adequacy decision) where GDPR or an equivalent regime applies.

Because the DTA/DUA/MTA distinction is applied inconsistently across institutions, the safest approach for a research administrator handling a new data transfer is to identify which risks are actually present (transfer security, downstream use restrictions, physical materials, or a combination) and confirm with the receiving institution’s contracts or privacy office which single document, or combination of documents, they expect — rather than assuming a specific label controls scope. See the Data Use Agreement Template guide for clause-level worked examples of the use-restriction side of this pairing, and the Material Transfer Agreement guide for the physical-materials process.

References

  • NIH guidance on data sharing and data use agreements for controlled-access data
  • HIPAA Privacy Rule 45 CFR §164.514(e) (limited data set and accompanying data use agreement)
  • EU/UK GDPR Chapter V (international transfer mechanisms: adequacy decisions, Standard Contractual Clauses)

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data Transfer Agreement (DTA)"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-transfer-agreement" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-transfer-agreement",
  "name": "Data Transfer Agreement (DTA)",
  "identifier": "https://casrai.org/dictionary/term/data-transfer-agreement",
  "description": "A contract governing the mechanics of transferring a dataset between institutions -- authorised senders and recipients, transmission and security method, and destruction-or-return terms -- distinct from a Data Use Agreement's downstream use restrictions and a Material Transfer Agreement's coverage of physical materials.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/data-transfer-agreement",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-18T06:30:56",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →