When two or more institutions actually exchange data with each other — not just plan for it, but move a real dataset from one legal entity’s custody to another’s — a data sharing agreement (DSA) is usually the instrument that governs it. It is a signed, legally binding contract between the parties, distinct from a Data Management Plan (a funder-facing planning document) and from a Material Transfer Agreement (which governs physical or biological materials, not data). This guide covers what a DSA typically contains, when you need one, how it differs from adjacent agreement types, and who actually signs it.
What a data sharing agreement typically covers
Terms vary by institution, jurisdiction, and the sensitivity of the data involved, but a DSA that will hold up in practice generally addresses five core areas:
- Ownership. Who retains title to the original dataset, and what happens to any new data, analyses, or derivatives created from it. Ownership of underlying data and ownership of a downstream publication or database are treated as separate questions — a DSA should say so explicitly rather than leave it implied.
- Permitted use. The specific research purpose(s) the data may be used for, whether re-use for a different project requires a new agreement or an amendment, and whether the recipient may sub-license or pass the data to a third party (onward transfer). Silence on this point is a common source of later disputes.
- Security and privacy obligations. Technical and organizational safeguards the receiving party must maintain (encryption at rest/in transit, access controls, secure-enclave requirements for restricted-access data), plus breach-notification duties and timelines. Where the data includes personal data subject to the GDPR, the agreement typically needs to satisfy controller-to-processor or joint-controller obligations under GDPR Article 28, and — if data is moving outside the EU/EEA — an Article 46 transfer mechanism such as the current Standard Contractual Clauses. See CASRAI’s entries on GDPR and data subject rights under GDPR for the underlying framework, and the HIPAA Privacy Rule where US health data is involved.
- Publication rights. Whether the receiving party may publish results derived from the shared data, any pre-publication review period the providing institution retains, and how both parties should be credited or cited. This is the same clause type that, in a materials-transfer context, is often negotiated as a fixed review window before submission — see the MTA entry for a worked example of that mechanism.
- Retention and destruction terms. How long the recipient may retain the data, whether it must be destroyed or returned at the end of the project or upon request, and what counts as acceptable proof of destruction (a certificate of destruction, a deletion log). CASRAI’s retention period entry covers the same concept as it appears in a Data Management Plan; in a DSA the retention clause is a contractual obligation between named parties rather than a planning statement.
Well-drafted agreements also assign a named data steward or equivalent point of contact at each institution, and specify liability/indemnification if the shared data is misused or a security obligation is breached.
When you need a data sharing agreement instead of — or in addition to — a Data Management Plan
These two documents are often confused because both concern how research data is handled, but they serve different functions and usually have different audiences:
- A Data Management Plan is a planning document, typically required by a funder as part of a grant application, describing how data will be collected, stored, described, shared, and preserved across a project’s lifecycle. It is usually not a contract between named parties and does not by itself create enforceable obligations between institutions.
- A DSA is a bilateral or multilateral contract, executed when data will actually move from one legal entity to another. It exists to allocate legal responsibility — who is liable for a breach, who owns what, what happens if a party wants out.
In practice: if your project involves multiple institutions and any of them will receive a copy of, or ongoing access to, another party’s dataset, you need a DSA (or one of the related instruments below) regardless of what your DMP says. The DMP can — and often should — reference the existence of the DSA and summarize its key terms, but it does not substitute for it. NIH’s Data Management and Sharing Policy (effective 25 January 2023) and NSF’s Data Management and Sharing Plan requirement (renamed from “Data Management Plan” effective 22 January 2026, PAPPG 24-1 Supplement 2) both require a plan at the application stage; neither replaces a separate data sharing agreement once an actual multi-institutional transfer needs to happen. See CASRAI’s NIH vs. NSF Data Management Plans comparison for how the two funders’ planning requirements differ.
Data sharing agreement vs. data use agreement vs. Material Transfer Agreement
These three agreement types are related — all three are contracts that govern the movement of research data or materials between institutions — but they are not interchangeable, and using the wrong one (or the wrong template) is a common source of delay in a sponsored-programs or research-contracts office:
- Data Sharing Agreement (DSA) — governs bidirectional or multilateral exchange of data, appropriate for consortia, federated studies, or any arrangement where more than one party is both a source and a recipient of data.
- Data Use Agreement (DUA) — governs unidirectional access: a single recipient obtaining an identifiable, restricted, or limited dataset from a single source (for example, a researcher accessing controlled-access genomic data from dbGaP, or Medicare claims data from CMS). NIH’s Genomic Data Sharing Policy uses a related mechanism, the Institutional Certification, which the submitting Principal Investigator and the institution’s Signing Official both sign before large-scale human genomic data can be deposited.
- Material Transfer Agreement (MTA) — governs tangible research materials — cell lines, reagents, biological specimens, physical samples — not data at all. If your collaboration involves shipping a mouse line, a plasmid, or a tissue sample alongside a dataset, you likely need both an MTA for the material and a DSA or DUA for the data; they are not substitutes for each other. Standard MTA templates include the Uniform Biological Material Transfer Agreement (UBMTA) and the NIH Simple Letter Agreement.
A useful rule of thumb: if what’s moving is information, you’re in DSA/DUA territory; if what’s moving is a physical thing, you need an MTA regardless of what data or metadata travels alongside it.
Who negotiates and signs it
A DSA is normally executed at the institutional level, not between individual researchers — the same pattern as an MTA or DUA. Typically a Principal Investigator initiates the request, and an institution’s research-contracts, sponsored-programs, or general counsel’s office negotiates and countersigns on the institution’s behalf, binding the institution rather than the individual researcher. Where the underlying research involves human subjects, an IRB or equivalent ethics body typically needs to confirm that the proposed data sharing is consistent with the original participants’ informed consent before the agreement is finalized — see CASRAI’s IRB/REC Approval Process guide for how that review fits into the broader timeline. Multi-party consortium projects sometimes fold data-sharing terms into a broader consortium agreement governing the whole collaboration rather than executing a free-standing DSA — check your project’s governance documents before assuming a separate agreement is needed.
Templates and standard clauses — what actually varies
There is no single, universal data sharing agreement template that works across institutions, funders, and jurisdictions — despite real search demand for one. That’s a genuine gap, not an oversight: the right template depends on factors a generic form can’t account for, including whether personal data is involved (triggering GDPR Article 28/46 or HIPAA obligations), whether the data will cross a national border, the funder’s specific data-sharing policy, and each institution’s own contracting standards. What does vary predictably by context:
- Personal or health data pulls in GDPR controller/processor obligations or HIPAA Privacy Rule requirements, and typically needs review by a privacy office, not just a contracts office.
- Cross-border transfers of personal data out of the EU/EEA require an Article 46 safeguard — currently the modernized Standard Contractual Clauses adopted by the European Commission — layered on top of the ordinary DSA terms.
- Deposit in a repository rather than a bilateral exchange is a different scenario entirely: depositing to a trusted digital repository (one holding CoreTrustSeal certification, for example) or a sensitive-data repository is usually governed by the repository’s own deposit terms and an embargo period if applicable, not a bespoke DSA between institutions. See CASRAI’s guide to choosing an open data repository if that’s the scenario you’re actually in.
- Confidential but non-personal data (proprietary methods, unpublished results shared for peer feedback) is sometimes covered by a simpler confidentiality agreement (NDA) instead of a full DSA, if no restricted-use or retention obligations are needed beyond confidentiality itself.
The practical starting point is your institution’s research-contracts or sponsored-programs office — most maintain a starting template they adapt per agreement rather than using a public generic form, precisely because the variables above change what the agreement needs to say.
Frequently asked questions
Is a data sharing agreement the same as a data use agreement?
No. A DSA typically covers bidirectional or multilateral data exchange among consortium partners, where each party may be both a source and a recipient. A Data Use Agreement covers one-directional access — a single recipient obtaining a dataset from a single source, commonly for restricted-access or identifiable data. See CASRAI’s DSA and DUA dictionary entries for the full operational distinction.
Do I need a data sharing agreement if I already have a Data Management Plan?
Usually yes, if data is actually moving between institutions. A DMP is a planning document, typically produced for a funder, describing intended data practices across a project’s lifecycle — it does not itself create a binding legal obligation between the institutions involved. A DSA is the contract that does that. Projects with multiple institutional partners commonly need both: a DMP for the funder, and a DSA (or DUA) governing the actual data transfers between partners.
How is a data sharing agreement different from a Material Transfer Agreement?
A DSA governs data — datasets, records, information. A Material Transfer Agreement governs tangible research materials — biological specimens, cell lines, reagents, physical samples. If a collaboration involves both a physical shipment and an associated dataset, both agreements may be needed; neither substitutes for the other.
Is there a standard data sharing agreement template?
No single universal template exists. The right agreement depends on whether personal or health data is involved, whether data crosses a national border, funder-specific policy requirements, and each institution’s own contracting standards. Most research institutions’ contracts or sponsored-programs offices maintain their own starting template rather than relying on a generic public form, and adapt it per agreement.
Does GDPR require specific terms in a data sharing agreement?
Where the shared data includes personal data and the agreement is within GDPR’s scope, Article 28 requires a written contract between controller and processor covering, at minimum, the subject matter and duration of processing, its nature and purpose, the types of personal data, and the categories of data subjects. If the data is also transferred outside the EU/EEA, Article 46 requires an additional safeguard — currently the European Commission’s modernized Standard Contractual Clauses — layered on top of those Article 28 terms.
Who signs a data sharing agreement — the researcher or the institution?
The institution, not the individual researcher. A Principal Investigator typically initiates the request, but the agreement is negotiated and countersigned by each institution’s research-contracts, sponsored-programs, or general counsel’s office, binding the institution as the contracting party. This mirrors how MTAs and DUAs are signed.
For the broader research data management landscape this fits into, see CASRAI’s Research Data Management cluster hub.







