Data sharing agreement template for research data
When a university gives research data to another institution for that institution's own study, neither a processing agreement nor a joint controller agreement fits. This guide explains when you need a data sharing (or data transfer) agreement, what makes the disclosure lawful, how pseudonymised data is treated, what changes when the recipient is outside the EEA, and what the agreement should contain. A free Word template is included.
The short version
- If the recipient uses the data for its own research, it is a separate controller. You need a data sharing (or data transfer) agreement, not a DPA and not a joint controller agreement.
- Each disclosure needs a legal basis, and the recipient needs its own. Further processing for research is not considered incompatible with the original purpose, provided Article 89(1) safeguards are in place (Article 5(1)(b)).
- Pseudonymised data is personal data for anyone who can re-identify it. Whether it is personal data for a recipient without the key depends on the means reasonably available to that recipient, so contractual bans on re-identification matter.
- Sharing with a recipient outside the EEA is a transfer under Chapter V. Check for an adequacy decision first; otherwise standard contractual clauses (Module One for controller to controller) with a transfer impact assessment are the usual route.
- Download the free data sharing agreement template for research data (Word), with an optional annex for transfers outside the EEA.
Contents
1. DSA, DTA, DPA or JCA: which agreement?
The name of the document matters less than the roles behind it. Universities use "data sharing agreement" (DSA) and "data transfer agreement" (DTA) for much the same thing: a contract under which one controller discloses personal data to another controller. The roles decide which agreement you need:
| Data sharing / transfer agreement | Data processing agreement (DPA) | Joint controller agreement (JCA) | |
|---|---|---|---|
| Relationship | Separate controllers. The recipient decides its own purposes and means. | Controller and processor. The recipient acts only on your instructions. | Joint controllers. The parties decide purposes and essential means together. |
| GDPR basis | No specific article. Supports Articles 5, 6, 24 and 32; Chapter V clauses if outside the EEA. | Article 28(3), with mandatory content. | Article 26, with mandatory topics and transparency to data subjects. |
| Typical research case | Giving a dataset to another university for its own study; receiving registry or cohort data. | Survey platform, transcription service, cloud storage, external statistician working to your brief. | Consortium with a jointly drafted protocol or a jointly governed database. |
| Who is responsible afterwards? | The recipient, for its own processing. | You remain the controller. | All parties, as allocated, and each towards data subjects. |
The EDPB's Guidelines 07/2020 say that exchanging data between two entities "without jointly determined purposes or jointly determined means" is a transmission between separate controllers (paragraph 70). The EDPB's Guidelines 1/2026 on scientific research, adopted on 15 April 2026 as a version for public consultation, give a research example: a public university runs a research database of pseudonymised health data, and a pharmaceutical company that accesses it for its own project is an independent controller, as is the university for operating the database (Example 22).
The University of Groningen's research guidance sums up the practical rule: a data transfer agreement is needed when data goes to a third party for independent reuse, and is advisable when you receive data in the same way. A processing agreement is needed for processors, and a joint controller agreement when purposes and means are common. If you are unsure whether partners are joint controllers, see our joint controller agreement guide.
2. Making the disclosure lawful
Two separate questions must be answered: may the university disclose, and may the recipient process?
- Your side. Disclosure is processing. The EDPB says each disclosure by a controller requires a lawful basis and an assessment of compatibility, whether the recipient is a separate or a joint controller (Guidelines 07/2020, footnote 76). Article 5(1)(b) GDPR says further processing for scientific research purposes shall "not be considered to be incompatible" with the initial purposes, in accordance with Article 89(1). Guidelines 1/2026 treat that as a presumption of compatibility, but the safeguards in Article 89(1) still apply.
- The recipient's side. The recipient needs its own legal basis under Article 6 and, for special category data, an Article 9(2) condition such as Article 9(2)(j), which requires a basis in EU or national law and suitable safeguards. National research and ethics rules may require ethics approval for the new use.
- Transparency. Participants should know about recipients. Guidelines 1/2026 list engaging new research partners that participants would not reasonably expect, especially outside the EEA, as a change that requires additional information.
- Data minimisation. Article 89(1) requires that where research purposes can be fulfilled with data that does not permit identification, they "shall be fulfilled in that manner". Guidelines 1/2026 go further: if the recipient's research does not need identifiable data, the data "must be anonymised before transmission" (paragraph 162).
Validemic's analysis Write the minimisation decision into the agreement. Annex 1 of our template asks which variables are shared, why each is needed, and why less identifiable data would not do. That record answers the most common question from data protection officers and ethics boards.
3. Pseudonymised and anonymised data
Article 4(5) GDPR defines pseudonymisation as processing so that data "can no longer be attributed to a specific data subject without the use of additional information", with that information kept separately and protected. Recital 26 says pseudonymised data that could be attributed to a person using additional information "should be considered to be information on an identifiable natural person". Anonymous information, by contrast, is outside the GDPR.
In EDPS v SRB (C-413/23 P, 4 September 2025), the Court of Justice, interpreting the parallel rules for EU institutions, held that pseudonymised data must not be regarded as personal data "in all cases and for every person". Whether a recipient can identify people depends on the means reasonably available to it. The Court added that where it cannot be ruled out that third parties to whom the data is passed on have means reasonably allowing them to attribute it, for example by cross-checking with other data, the data should be considered personal (paragraphs 85 and 86). Guidelines 1/2026 cite this judgment.
For research data sharing this has three practical consequences:
- For the university, pseudonymised data stays personal data. You hold the key, so the disclosure is processing of personal data and needs a legal basis and safeguards.
- For the recipient, it depends. Small samples, rare characteristics, free text and linkable variables make re-identification more likely. Assess, document and do not assume.
- Contracts help. Guidelines 1/2026 say legal or contractual bans on re-identification can complement technical measures when datasets are shared between research partners, and that contracts should help data subjects exercise their rights, for example by letting the controller that pseudonymised the data provide what is needed to find a participant's records (paragraph 163).
Participants should also not be misled. Guidelines 1/2026 say data subjects should not be given the impression that their data will be anonymised if it will in fact be processed in pseudonymised form (paragraph 164).
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
4. Sharing outside the EEA
Article 44 GDPR allows a transfer to a third country only if the conditions of Chapter V are met, including for onward transfers. The EDPB's Guidelines 05/2021 set three cumulative criteria for a transfer: the exporter is subject to the GDPR for the processing; it discloses or makes the data available to another controller, joint controller or processor; and the importer is in a third country or is an international organisation. Remote access from a third country and storage in a cloud outside the EEA can also be transfers when these criteria are met.
Work through the options in order:
- Adequacy (Article 45). On 7 October 2026 the European Commission's list included, among others, Switzerland, the United Kingdom (renewed in December 2025), Japan, the Republic of Korea, Canada (commercial organisations), Israel, New Zealand, Brazil (January 2026) and the United States for organisations in the EU-US Data Privacy Framework. Check the current list on the Commission's page, and for a US recipient check whether that organisation is actually listed in the Framework rather than assuming it is. See our Data Privacy Framework guide.
- Appropriate safeguards (Article 46). For a non-adequate country the usual tool is the Commission's standard contractual clauses, Implementing Decision (EU) 2021/914. Module One covers controller-to-controller transfers. It requires the parties to assess the laws and practices of the destination country (Clause 14), which is what a transfer impact assessment documents. Article 46(2)(a) also allows a legally binding and enforceable instrument between public authorities or bodies, which may be relevant between public institutions.
- Derogations (Article 49). These are for specific situations, such as explicit informed consent to the transfer or important reasons of public interest recognised in EU or national law. Article 49(3) says the consent and contract derogations do not apply to public authorities "in the exercise of their public powers". Treat derogations as exceptions, not as the default for a research programme.
Two details often trip up research offices. First, recital 7 of Decision 2021/914 says the clauses may be used only to the extent that the importer's processing does not fall within the scope of the GDPR; the Commission says it is developing additional clauses for importers directly subject to the GDPR. Second, the EU-US Data Privacy Framework was upheld by the General Court on 3 September 2025 (Latombe v Commission, T-553/23), and an appeal to the Court of Justice has been reported. Treat the Framework as in force but under review.
Our transfer mechanism tool walks through these steps for a single recipient.
5. What a research data sharing agreement contains
There is no mandatory list for sharing between separate controllers, so the content follows the risks. Drawing on the GDPR, the EDPB's research guidance and university practice, a research DSA normally covers:
- Parties and roles. A statement that each party is a separate controller, and that the recipient is not acting as your processor.
- Purpose. The recipient's specific research project, protocol and ethics approval. Guidelines 1/2026 list strict purpose limitation, "for example contractually limiting any further processing", as a safeguard.
- Description of the data. Variables, format (identifiable, pseudonymised, aggregated), number of records, special category data, and the minimisation reasoning.
- Legal basis. Your basis for disclosing and the recipient's basis for processing, including any Article 9 condition.
- Conditions of use. No re-identification, no linkage beyond what is agreed, no onward sharing without consent, publication only of results that do not identify individuals.
- Security. Minimum measures under Article 32, approved storage, access limited to named researchers, and secure transfer of the data.
- Data subject rights and transparency. How requests are passed on, and the pseudonym mechanism for finding records.
- Breaches. Notice to the provider so it can inform participants or its own authority if needed.
- International transfers. The Chapter V tool used, with the standard contractual clauses attached where relevant, and rules on onward transfers.
- Retention and end of use. Deletion or return when the project ends, with a written confirmation.
- Assurance. The right to request evidence of compliance and to suspend sharing.
- Other terms. Acknowledgement and citation, intellectual property, liability, term and governing law. These often sit in a separate material or data transfer agreement drafted by the research office.
6. A workable process
- Classify the request. Who will decide on the use? If the recipient, this is a controller disclosure.
- Check the original basis. What did participants consent to or what were they told? Does the ethics approval allow sharing?
- Minimise. Share anonymised or aggregated data where that serves the purpose; otherwise pseudonymised data with only the variables needed.
- Check the recipient's environment. Where will the data be stored and analysed, and which vendors are involved? Our guide to research data storage covers what to look for.
- Check transfers. Recipient location, its processors and any remote access.
- Sign at institutional level and record the disclosure in your record of processing activities as a recipient.
- Transfer securely and keep the transfer log.
- Diarise the end date and ask for a deletion confirmation.
7. The template
The data sharing agreement template for research data is a Word document containing:
- Instructions and a role check against DPAs and joint controller agreements.
- Clauses on roles, purpose, legal basis, conditions of use, re-identification, onward sharing, security, data subject rights, breaches, transfers, retention, assurance, publication, liability and term.
- Annex 1: description of the shared data, with a minimisation column.
- Annex 2: minimum security measures.
- Annex 3: transfers outside the EEA, pointing to the standard contractual clauses Module One and a transfer impact assessment.
- Annex 4: a data transfer log and a certificate of deletion.
The template follows the GDPR and the EDPB guidance as read on 7 October 2026. EDPB Guidelines 1/2026 were a version for public consultation on that date, and the Commission's additional clauses for importers subject to the GDPR were still being developed. National law may add requirements. The template is not legal advice.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 4(5), 5(1)(b), 9, 26, 28, 44 to 46, 49 and 89, and recital 26, Official Journal text (retrieved 7 October 2026).
- EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1 (retrieved 7 October 2026).
- EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, version for public consultation adopted 15 April 2026 (retrieved 7 October 2026).
- EDPB Guidelines 05/2021 on the interplay between Article 3 and Chapter V, version 2.0 (retrieved 7 October 2026).
- CJEU, C-413/23 P, EDPS v SRB, judgment of 4 September 2025 (retrieved 7 October 2026).
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses, recital 7, Module One and Clause 14 (retrieved 7 October 2026).
- European Commission: Standard contractual clauses (SCC) (retrieved 7 October 2026).
- European Commission: Adequacy decisions (retrieved 7 October 2026).
- General Court, T-553/23, Latombe v Commission, judgment of 3 September 2025 (retrieved 7 October 2026).
- WilmerHale: European Court of Justice to review challenge to EU-U.S. Data Privacy Framework, reporting the appeal lodged on 31 October 2025 (secondary source, retrieved 7 October 2026).
- University of Groningen Digital Competence Centre: Protocols and agreements (retrieved 7 October 2026).
About this page
Sources checked on 7 October 2026. Legislation and judgments were read in their Official Journal and Court versions; EDPB guidance in the PDFs on the EDPB website. We could not confirm the status of the Data Privacy Framework appeal on the Court of Justice's own site on the check date and rely on a secondary report for it. Statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error, or something has changed, please contact us and we will correct it.
Frequently asked questions
What is the difference between a data sharing agreement and a DPA?
A data processing agreement (Article 28 GDPR) is required when a processor handles data on your behalf and only on your instructions. A data sharing or data transfer agreement is used when the recipient becomes a controller and uses the data for its own purposes, for example its own research project.
Is a data sharing agreement required by the GDPR?
For sharing between separate controllers the GDPR does not prescribe a contract in the way Articles 26 and 28 do. It is still the usual way to document the lawful basis, limit use and set security terms, and universities such as Groningen require one when data goes to a third party for reuse. Transfers outside the EEA often need contractual clauses anyway.
Is pseudonymised research data still personal data?
For the university that holds the key, yes: recital 26 GDPR says pseudonymised data that can be attributed using additional information is personal data. In EDPS v SRB (C-413/23 P, 2025), the Court of Justice held that for a recipient without means reasonably likely to identify people, the data may not be personal data. Assess this case by case and do not assume it.
Which standard contractual clauses apply to sharing research data with a partner outside the EEA?
For a transfer from an EEA controller to a recipient controller in a third country without an adequacy decision, Module One (controller to controller) of the 2021 standard contractual clauses, Commission Implementing Decision (EU) 2021/914, is the usual tool, together with a transfer impact assessment.
Can a public university rely on consent for a transfer outside the EEA?
Article 49(3) GDPR says the consent and contract derogations in Article 49(1)(a) to (c) do not apply to activities of public authorities in the exercise of their public powers. Whether that covers a university's research depends on national law, so check with your data protection officer.