A data sharing policy is a rule set by a research funder, an institution, or a journal that specifies whether, when, and how the data underlying funded or published research must be made available. It is a top-down mandate that applies to a whole category of research — every grant a funder makes, every manuscript a journal accepts — rather than an agreement negotiated between two specific parties about one specific dataset. That distinction matters because a data sharing policy and a data sharing agreement (DSA) are frequently confused, but they operate at different levels and solve different problems. This guide orients research administrators and researchers on what a data sharing policy actually requires, walks through the major real-world examples, and clarifies exactly where policy compliance ends and a bilateral DSA begins.
What a data sharing policy actually governs
A data sharing policy typically addresses some combination of the following, though the specifics vary considerably by issuer:
- Whether sharing is required at all, and for what kinds of data (e.g. all scientific data generated by the award, only data underlying published findings, only certain data types).
- When a data management and sharing plan must be submitted — usually at the proposal or application stage, before data even exists.
- Where data must be deposited — a named repository, a category of acceptable repositories (e.g. one meeting certification criteria), or the researcher’s choice within stated constraints.
- Timing — how soon after generation, or after publication, data must become available, and whether an embargo period is permitted.
- Exceptions and limits — legitimate reasons not to share (human-subjects privacy, Indigenous data sovereignty, proprietary/national-security restrictions, technical infeasibility) and how those exceptions must be documented rather than simply asserted.
- Consequences of non-compliance — ranging from a request to revise the plan to withholding of future funding.
What a data sharing policy does not typically do is specify the operational, party-to-party terms under which a particular dataset moves between two named institutions — permitted uses, security safeguards, publication rights, indemnification, retention and destruction schedules. That is the job of a Data Sharing Agreement (DSA), covered in more detail below.
Major examples of data sharing policy
NIH Data Management and Sharing (DMS) Policy
The NIH Data Management and Sharing Policy (NOT-OD-21-013) took effect January 25, 2023, and requires a Data Management and Sharing Plan for essentially all NIH-funded research that generates scientific data, submitted at the application stage and subject to review as part of funding decisions. It is a distinct obligation from the NIH Public Access Policy, which governs deposit of peer-reviewed manuscripts rather than underlying data — satisfying one does not satisfy the other. As of May 2026, NIH piloted an abbreviated DMS Plan format (yes/no questions on sharing practices, a capped-length explanation for any limited sharing, and a short table of anticipated data types and repositories) in place of the original two-page narrative, though the underlying policy obligation is unchanged. See CASRAI’s Data Management Plan (DMP) entry and the NIH vs. NSF DMP comparison guide for how the planning document itself is structured.
NSF data sharing requirements
NSF does not run a single, centralized data-sharing policy in the way NIH does. Instead, NSF’s foundation-wide grant conditions require a data management plan for essentially every proposal, but individual NSF directorates set their own supplementary expectations for what that plan must contain, reflecting how differently data behaves across disciplines (e.g. large shared physical-science datasets vs. small qualitative social-science datasets). Separately, NSF’s Public Access Plan governs deposit of peer-reviewed publications and juried conference papers into NSF-PAR, which is a publication-access policy, not a data-sharing policy — the same NIH-style distinction applies. As of April 2026, NSF moved DMP submission from an uploaded PDF to a structured Research.gov webform tailored to the proposal’s primary directorate.
Journal and publisher data availability policies
Journals and publishers layer a third kind of data sharing policy on top of funder requirements, enforced at the point of manuscript submission or acceptance rather than at the grant stage. The International Committee of Medical Journal Editors (ICMJE) requires a data sharing statement for clinical trial reports, and many journals across disciplines now require a data availability statement describing where underlying data can be found (or explaining why it cannot be shared) as a condition of publication. These policies are enforced independently of whatever a funder required at proposal stage — a dataset can be fully compliant with an NIH DMS Plan and still need a separate, journal-specific data availability statement to get published.
Institutional data sharing policies
Universities and research institutions frequently maintain their own data sharing/data management policies that sit alongside funder and journal requirements — setting default expectations for data retention, specifying which office (research data services, IRB, sponsored programs) reviews sharing plans, and clarifying how the institution expects researchers to satisfy funder mandates using institutionally supported repositories and infrastructure. An institutional policy typically incorporates funder requirements by reference rather than replacing them; researchers with external funding are usually bound by whichever policy — funder or institutional — is more restrictive on a given point.
Data sharing policy vs. Data Sharing Agreement (DSA): how they relate
These two concepts are often used loosely as if interchangeable, but they operate at different levels and get confused in practice often enough to be worth stating plainly:
| Data sharing policy | Data Sharing Agreement (DSA) |
|---|---|
| A rule set by a funder, institution, or journal, applying broadly to a category of research | A bilateral or multilateral contract between named parties, applying to one specific dataset or collaboration |
| Answers: must this data be shared, and under what general conditions? | Answers: exactly how will this specific data move between these specific parties? |
| Typically satisfied by depositing data in a repository and/or filing a plan | Typically satisfied by both parties signing a negotiated document |
| Example: NIH DMS Policy, NSF directorate DMP requirements, ICMJE data sharing statement requirement | Example: a signed agreement between University A and University B governing a shared clinical dataset |
In practice, complying with a funder’s data sharing policy often requires executing one or more DSAs along the way — for instance, if a multi-site study needs to move identifiable or restricted-access data between collaborating institutions before final deposit in a public repository, that transfer is usually governed by a DSA (or a data use agreement, for tightly access-controlled data), even though the overarching obligation to eventually share data in some form comes from the funder’s policy. The policy sets the destination and general conditions; the agreement, where one is needed, sets the terms of the specific route to get there. See CASRAI’s comparison of a Data Sharing Agreement vs. Data Processing Agreement and the guide on structuring a DSA between collaborators and institutions for the agreement side of this relationship in depth.
Why research administrators need to track both
A research administration office is usually the party accountable for demonstrating policy compliance to a funder (through the submitted DMP and any subsequent reporting) while also being the office that negotiates or reviews the DSA when a specific data transfer requires one. Treating these as the same task risks two failure modes: assuming a signed DSA alone satisfies a funder’s broader sharing mandate (it typically doesn’t, since the DSA governs one transfer, not the eventual public/repository deposit the policy requires), or assuming a compliant DMP eliminates the need for a DSA when data must move between named institutional parties before that final deposit (it doesn’t, since the DMP describes intent at the funder level, not the enforceable terms between the specific parties handling the data).
Frequently asked questions
What is an example of a data sharing policy?
The NIH Data Management and Sharing Policy (effective January 25, 2023) is one of the most widely referenced examples in the United States: it requires nearly all NIH-funded research generating scientific data to have a data management and sharing plan submitted at the application stage. NSF directorate-level DMP requirements and ICMJE’s clinical trial data sharing statement requirement are two other commonly cited examples.
Is a data sharing policy the same as a data sharing agreement?
No. A data sharing policy is a broad rule set by a funder, institution, or journal that applies to a whole category of research. A Data Sharing Agreement (DSA) is a specific contract between named parties governing one dataset or collaboration. Complying with a policy sometimes requires executing a DSA, but the two are not interchangeable.
What happens if a researcher doesn’t comply with a funder’s data sharing policy?
Consequences vary by funder but can include a request to revise the data management and sharing plan, delayed or reduced funding, and, in cases of sustained non-compliance, effects on future funding eligibility. Institutional research administration offices typically monitor compliance as part of award management, since the institution, not just the individual investigator, is accountable to the funder.
Do journal data sharing policies apply on top of funder policies?
Yes. A journal’s data availability statement requirement is enforced independently at manuscript submission or acceptance, regardless of what a funder already required at the proposal stage. Researchers often need to satisfy both.







