Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

CDA vs NDA vs DUA: What Each One Actually Covers in Research

CDA stands for Confidential Disclosure Agreement — functionally the same as an NDA. This guide compares CDA/NDA vs. DUA vs. MTA vs. SRA, covers mutual vs. one-way confidentiality, the HIPAA limited-data-set DUA requirements, the residuals clause, and export-control and manuscript-disclosure interactions.

Ask about CDA vs NDA vs DUA: What Each One Actually Covers in Research

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Two questions come up constantly when a researcher is handed one of these documents for the first time: what does CDA even stand for, and is it the same as an NDA? The short answer to both: CDA stands for Confidential Disclosure Agreement, and in day-to-day research administration a CDA and an NDA (Non-Disclosure Agreement) are the same instrument under two different names. “CDA” is simply the term of art favored in pharma, clinical research, and university technology-transfer offices, where AUTM (the Association of University Technology Managers) and most institutional research-contracts offices use it as their default label; “NDA” is the more generic legal and business term for the identical kind of agreement. If your institution’s template is called a CDA and a partner’s is called an NDA, you are not looking at two different legal instruments — you are looking at the same one.

A Data Use Agreement (DUA) is a genuinely different instrument, even though it gets confused with CDA/NDA constantly. A CDA/NDA governs whether information can be disclosed to a third party at all. A DUA governs how a dataset that has already been legitimately received may be used — permitted purposes, who may access it, security safeguards, and what happens to it when the project ends. Confidentiality and permitted use are related but separate problems, and conflating them is the single most common terminology mistake in this area.

CDA/NDA vs. DUA vs. MTA vs. SRA, side by side

The table below is the fast-reference version. For the full decision logic across all seven common research-contracting instruments — including subaward, subcontract, and consultant agreements — see CASRAI’s research contract types decision guide, which this page complements rather than repeats.

Instrument What it governs What’s actually transferred Who signs Typical duration Clause most likely to stall it
CDA / NDA (unilateral or mutual) Whether shared information may be disclosed to others at all, and for what limited purpose it may be used internally Ideas, technical information, and unpublished results discussed during evaluation of a possible collaboration — no material, no data transfer, no funding Institution (TTO or research contracts office), not the PI Confidentiality obligation typically runs 3–7 years from disclosure; the underlying evaluation period itself is usually much shorter, often 1–2 years An overbroad definition of “Confidential Information” that would restrict the researcher’s own prior or independently developed work; whether a residuals clause is acceptable
Data Use Agreement (DUA) Permitted uses of a specific dataset the recipient has already received — not whether it can be disclosed, but what can be done with it The dataset itself: a restricted, identifiable, or limited-data-set extract, typically one-directional (single source to single recipient) Institution (sponsored programs or privacy office), binds the institution, not the individual researcher Tied to the approved research period rather than a fixed term; typically ends with a contractual obligation to destroy or return the data on study completion Permitted secondary uses, re-identification prohibitions, and the specific security safeguards required for the data’s sensitivity level
Material Transfer Agreement (MTA) Terms under which a tangible research material can be shipped, used, and (if applicable) further shared or modified Physical material — a cell line, reagent, plasmid, antibody, or biospecimen Institution (TTO or research contracts office) Runs for the life of the study; often layered with separate terms governing what happens to unused or modified material afterward Reach-through rights on future discoveries made using the material; ownership of modifications or progeny
Sponsored Research Agreement (SRA) The full scope, funding, deliverables, and IP terms of a defined piece of collaborative research Funding, a defined scope of work, and — commonly — background confidential information the sponsor discloses to scope the work Institution (sponsored programs director, VP for research, or delegated contracts officer) Length of the funded project, typically one to three years, often renewable Publication rights and delay; ownership of resulting inventions; indemnification

Two situations regularly need more than one of these at once. A CDA is frequently executed first, purely to allow the parties to exchange enough proprietary information to negotiate an SRA or a licensing deal — the CDA covers the negotiation period itself, and a separate instrument (the SRA, the license) takes over once terms are agreed. And a collaboration that shares both data and physical material needs a DUA and an MTA; one does not substitute for the other, because they govern different things moving across the same relationship.

One-way vs. mutual: the distinction that changes what you’re agreeing to

CDAs and NDAs come in two structurally different forms, and which one you’re being asked to sign changes what obligations actually apply to your institution:

  • Unilateral (one-way). Only one party is disclosing confidential information; the other party is only receiving it and has no reciprocal disclosure obligation. This is typical when a company is sharing proprietary background technology with a university to scope a potential license or sponsored project, and the university has nothing confidential of its own to protect in that exchange.
  • Mutual (two-way). Both parties are disclosing and receiving confidential information, and both are bound by the same confidentiality obligations toward what the other side discloses. This is the more common form in genuine research collaborations, where both the university and an industry partner are sharing unpublished data, methods, or preliminary results to evaluate working together.

A mutual CDA is not automatically “fairer” or safer to sign quickly just because the obligations run both ways — the definition of what counts as confidential, the exclusions (information already public, already known, or independently developed), and the permitted-purpose language still need the same scrutiny either way. What changes is simply who is bound by what.

The HIPAA limited-data-set DUA: where “data use agreement” is a hard legal requirement, not a template choice

Most of the instruments on this page are matters of institutional practice and negotiated risk allocation. One is not: under the HIPAA Privacy Rule, a covered entity that discloses a Limited Data Set for research, public health, or health care operations is legally required to obtain a Data Use Agreement from the recipient before making the disclosure. This is codified at 45 CFR § 164.514(e), and it is the one place in this whole topic where getting the wording wrong is a regulatory compliance failure, not just a weak contract.

A limited data set is protected health information with the 16 direct identifiers listed at 164.514(e)(2) removed — names, precise geographic detail below town/city/state/ZIP, phone/fax/email, Social Security numbers, medical record and health-plan beneficiary numbers, account numbers, license/certificate numbers, vehicle and device identifiers, URLs and IP addresses, biometric identifiers, and full-face photographs. Unlike full de-identification under HIPAA’s Safe Harbor method, a limited data set is allowed to retain dates and geographic subdivisions down to town, city, state, and ZIP code — which is exactly why the DUA requirement exists: some re-identification risk remains, and the agreement is the legal control that offsets it.

Under 164.514(e)(4), the required DUA must:

  • Establish the permitted uses and disclosures of the limited data set by the recipient, consistent with the permitted purposes at 164.514(e)(3) — research, public health, or health care operations only;
  • Identify who is permitted to use or receive the limited data set;
  • Require the recipient not to use or further disclose the information other than as permitted by the agreement or as required by law;
  • Require the recipient to use appropriate safeguards to prevent unauthorized use or disclosure;
  • Require the recipient to report to the covered entity any unauthorized use or disclosure it becomes aware of;
  • Bind any agents or subcontractors the recipient uses to the same restrictions and conditions; and
  • Prohibit the recipient from attempting to re-identify the data or contact the individuals it describes.

A limited-data-set disclosure made under a compliant DUA is exempt from HIPAA’s accounting-of-disclosures requirement — a practical reason covered entities favor this route for research data sharing over case-by-case authorization. This is also the DUA pathway CASRAI’s own Data Use Agreement entry references for HIPAA data specifically; for data governed by NIH’s genomic and general data-sharing expectations rather than HIPAA, the relevant instrument is often the FDP Data Transfer and Use Agreement (DTUA), a standard template many US institutions default to for university-to-university research data exchange outside a HIPAA-covered disclosure.

Who actually signs — and why it’s never the PI

As with every instrument in the comparison table above, a CDA, NDA, or DUA is an institutional agreement: the university or research institution is the contracting party, not the individual researcher, and it is the institution that bears the resulting legal exposure if confidentiality is breached or data is misused. That means signature authority sits with a delegated institutional official — typically the sponsored programs office, the technology transfer office, or (for DUAs involving protected health information) the institutional privacy office — never with the PI. CASRAI’s research contract types guide covers the enforceability and risk-exposure reasons this rule exists in full; the short version for CDAs and DUAs specifically is that a PI generally has neither the authority to bind the institution to a confidentiality obligation nor visibility into what other agreements the institution may already have with the same counterparty that could create a conflict.

Typical term lengths and the residuals clause

A CDA/NDA’s confidentiality obligation is time-bound — commonly three to seven years from the date of disclosure, though some agreements covering genuine trade secrets specify “for as long as the information remains a trade secret” rather than a fixed number of years. A DUA, by contrast, is usually not written around a fixed confidentiality term at all; it runs for the life of the approved research use and terminates with an affirmative obligation to destroy or return the data, which is a functionally different kind of end point than an NDA’s confidentiality clock simply expiring.

One clause worth knowing by name before you see it in a draft: a residuals clause. It permits the receiving party’s personnel who were exposed to the discloser’s confidential information to later use, in their own unaided memory, general ideas, concepts, and know-how they retained — without that later use being treated as a breach of the confidentiality agreement, provided the residual use doesn’t reproduce actual trade secrets or copyrighted material verbatim. Companies with large R&D or engineering functions often push for a residuals clause because their staff move fluidly between projects and can’t practically “unlearn” what they’ve seen; universities and disclosing companies often resist it, because it can be read as quietly narrowing what the agreement actually protects. There is no single standard resolution — some institutional templates accept a narrowly drafted residuals clause, others decline it outright — and this is frequently the single line item that determines how long a CDA negotiation takes.

The export-control interaction when the discloser is foreign

A CDA or DUA doesn’t exist in a regulatory vacuum just because it’s “only” about confidentiality or data use. If the information, software, or technical data being disclosed is subject to the Export Administration Regulations (EAR) or the International Traffic in Arms Regulations (ITAR), sharing it with a foreign national researcher on the receiving team — even one lawfully working in the same US lab — can itself constitute a regulated deemed export, entirely independent of whether the confidentiality terms of the agreement are satisfied. The same issue runs the other direction: if the disclosing party is a foreign entity, or the agreement contemplates sharing controlled technical data with a foreign institution, export-control screening needs to happen before signature, not after. This is a distinct compliance question from the confidentiality terms themselves, and it’s why research-security and export-control offices are often looped into CDA and DUA review specifically when either party, or any named recipient of the data, is outside the United States. See CASRAI’s export-controlled research entry for how this screening typically fits into an institution’s broader compliance workflow.

When confidential information ends up in a manuscript

This is where CDA obligations most often collide with a researcher’s own goals, because publishing is the whole point of academic research and confidentiality is, by definition, the opposite instinct. The practical answer institutions converge on is the same shape used for publication-review clauses in sponsored research agreements: a bounded pre-submission review period — commonly 30 to 60 days — during which the disclosing party can flag its own confidential information for redaction before the manuscript is submitted or presented. What a CDA does not typically give the discloser is a veto over publishing the underlying research results once that review period has run; the redaction is limited to the counterparty’s own confidential material, not the researcher’s independently generated findings. See CASRAI’s publication delay and review clauses guide for how this same mechanism is structured and negotiated in more detail. The practical lesson for a researcher under a CDA: flag anything in a draft manuscript that came from or references the counterparty’s disclosed information before submission, rather than after a reviewer or editor has already seen it — a pre-submission gap is far easier to fix than a public retraction or amendment.

Frequently asked questions

What does CDA stand for?

Confidential Disclosure Agreement. It’s functionally the same instrument as a Non-Disclosure Agreement (NDA) — “CDA” is simply the more common label in pharma, clinical research, and university technology-transfer settings, where AUTM and most institutional templates default to that term.

What’s the actual difference between a CDA and an NDA?

In practice, none. Both govern whether and how confidential information disclosed during a negotiation or evaluation can be shared or used further. If your institution has separate templates called each, they typically cover the same legal ground; the choice of label reflects industry convention (CDA in tech transfer and pharma, NDA more broadly in business generally) rather than a substantive legal distinction.

What is a data use agreement, and how is it different from a CDA/NDA?

A data use agreement (DUA) governs the permitted use of a specific dataset the recipient has already been given lawful access to — permitted purposes, authorized users, security safeguards, and destruction obligations. A CDA/NDA governs a different question entirely: whether information can be disclosed to another party at all. A DUA can exist without any prior CDA in the picture, and a CDA is frequently signed with no data changing hands at all.

Is “data usage agreement” the same thing as a “data use agreement”?

Yes — “data usage agreement” and “data use agreement” refer to the same instrument (a DUA); “data usage agreement” is simply a less formal phrasing of the same term used in searches and casual conversation.

What is a CDA agreement used for in a research context?

Most commonly to allow a university and a prospective industry partner, sponsor, or licensee to exchange proprietary technical information, unpublished data, or trade-secret know-how while evaluating whether to move forward with a sponsored research agreement, license, or other collaboration — before either party is ready to commit to that larger, more detailed agreement.

Who signs a CDA at a university — can a PI sign it directly?

No. Like every instrument covered on this page, a CDA is an institutional agreement, and signature authority sits with a delegated official — typically the technology transfer office or research contracts office — not the individual principal investigator. See CASRAI’s research contract types guide for why this rule exists across every instrument in this space.

Does a CDA ever cover data, or only ideas and discussions?

A CDA can be drafted broadly enough to cover data shared during a negotiation, but once actual, structured datasets are being transferred for ongoing research use — rather than discussed in the abstract during a scoping conversation — most institutions move to a dedicated DUA (or, for HIPAA-covered data, a DUA is legally required) rather than relying on a general confidentiality agreement to carry that weight.

Last verified: August 2026. The HIPAA limited-data-set Data Use Agreement requirements reflect 45 CFR § 164.514(e). CDA/NDA terminology, term lengths, and residuals-clause practice reflect general US research-contracting and technology-transfer convention rather than a single codified standard, and vary by institution — confirm specific dollar thresholds, signature delegations, and template language against your own institution’s research contracts or technology transfer office.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →