Data Sharing Agreement: What It Is and What to Check
Caitlin PricePublished
Rachel Harris, General Counsel and AI Governance and Privacy Officer at the market research company Suzy, sits on the procurement side of the house. On CZ and Friends, GC AI's podcast hosted by CEO Cecilia Ziniti, she described the seat: legal review and DPA review on every procurement ticket in the pipeline. That is the data paper an in-house lawyer reads all week: processor paper. Now put a co-marketing deal on that desk. Both companies plan to email the same customer list, both decide what to do with it, and the partner's counsel sends over “the DPA.” Two clauses in, you can tell it is the wrong document, because nobody in this deal is anyone's processor. The deal needs a data sharing agreement.
The difference decides who holds the legal basis, who answers a data subject's access request, and who is on the hook when the data ends up somewhere it should not.
A data sharing agreement (DSA) is a contract between two or more organizations that each act as an independent or joint controller of the same personal data, setting the purpose, legal basis, security, transfer mechanisms, and deletion terms for sharing it. It governs controller-to-controller sharing, where both sides decide how and why the data is used.
A Data Processing Agreement (DPA) governs controller-to-processor processing, where one party only acts on the other's documented instructions. Same privacy law underneath, two different relationships, two different documents. Get the document wrong and the rest of your review is built on the wrong foundation.
A DSA arrives with a deadline attached, so the lens below is built for a fast first pass. GC AI, the enterprise-grade legal AI platform built for in-house counsel, reads the agreement inside Microsoft Word the same way you will read it here: roles first, then basis, then transfers, then deletion. It pulls the operative clause verbatim with Exact Quote, so every gap it flags arrives with the contract language attached.
Data Sharing Agreement vs DPA: The Distinction to Get Right
A data sharing agreement covers two controllers sharing personal data they each decide how to use; a DPA covers a controller handing data to a processor that acts only on instructions. The test is control, wherever the data flows.
Ask one question of the receiving party: does it get to decide why and how to use this data for its own purposes? If yes, that party is a controller and you need a data sharing agreement. If it can only do what your contract tells it to do, it is a processor and you need a DPA.
Two quick examples make the line concrete. You hire a payroll vendor to run payroll using your employee data, and the vendor does only what you tell it. That is controller-to-processor, so it needs a DPA.
You and a co-marketing partner each email a shared audience and each decide independently what to send and what to measure. That is controller-to-controller, so it needs a data sharing agreement. The payroll vendor never gets to repurpose your employee data for its own ends. The marketing partner does, which is exactly why the controls have to be heavier and explicit.
The roles also split inside the controller world, and the agreement has to name which one applies:
- Independent controllers. Each party determines its own purposes and means separately after the share. You hand the data over, the other side decides its own uses, and each side is responsible for its own compliance. This is where commercial data shares land.
- Joint controllers. The parties jointly determine the purposes and means of the same processing. Under GDPR Article 26, joint controllers must agree, in a transparent arrangement, who does what, especially around transparency notices and data-subject rights, and make the essence of that arrangement available to individuals.
Naming the role decides who writes the privacy notice, who fields the access request, and who indemnifies whom when something breaks. GC AI's live data protection clause page walks the controller-to-processor side in depth, including sub-processor controls and breach notification, so this page stays on the controller-to-controller relationship the DSA governs.
What to Check in a Data Sharing Agreement
The review lens for a data sharing agreement runs across eight checks: purpose limitation, legal basis, roles, security, onward and international transfers, data-subject rights, liability and indemnity, and term and deletion. Read in that order and you catch the structural problems before you get lost in defined terms. The order matters because the first three checks set up everything after them. The UK ICO's data sharing code of practice treats a written agreement as good practice for any routine sharing. The eight checks are:
- Purpose limitation
- Legal basis
- Roles, independent versus joint controller
- Security
- Onward transfer and international transfer
- Data-subject rights
- Liability and indemnity
- Term and deletion
...process the Shared Personal Data in connection with this Agreement which may include the transfer of the Shared Personal Data to Company outside of the European Economic Area (EEA); and (b) shall not, by act or omission, cause Company to violate any Data Protection Laws...
Source: data-sharing provision in an agreement filed by STAAR Surgical Company as Exhibit 10.2 to a Form 8-K, December 2022, via SEC EDGAR.
Purpose Limitation
The agreement should state, in precise terms, the specific purposes for which the data may be shared and used, and bar use for anything else. Vague purpose language (“for the parties' business purposes”) is the most common defect and the most dangerous, because it lets the receiving controller drift the data into new uses you never priced into your risk. Pin the purpose to the deal in front of you. If the co-marketing partner wants the list for one campaign, the agreement says one campaign. The redline is one line of drafting: strike “for the parties' business purposes,” write “solely for the campaign described in Schedule B,” and add that any further use needs a fresh written agreement.
Rachel Harris runs that discipline question by question on the data requests her own team sends out, and her test is the one to put to every purpose clause:
What is most important and what the regulators really intend is what is it capturing and why? And can you ask it in another way to where it's clearer for the end user, so that it's easier for the end recipient to answer, and so that both sides of the table have a better understanding of what's actually happening with the data involved.
She was describing a security questionnaire rebuild, and the same test reads straight onto the purpose clause: every category of shared data should trace to a stated purpose that both controllers could explain to a regulator without looking at their shoes.
Legal Basis
Each controller documents its own lawful basis for the sharing, and the bases can differ between the parties. One side may rely on consent, the other on legitimate interests. If the data includes special category data, such as health or biometric data, or criminal offense data, the agreement must also identify the additional condition for processing it.
The check here is twofold: confirm a basis is stated for each party, and confirm it fits the stated purpose. A consent basis that does not cover the co-marketing use is a basis in name only.
There is a second question hiding under the first: what did your privacy notice say when you collected the list? GDPR's transparency rules make you name recipient categories at collection, so a notice that never mentioned partner sharing means updating the notice, or reworking the basis, before the data moves.
For California data, the same check runs under the CCPA. When a business sells or shares personal information with a third party, Section 1798.100(d) requires a contract that limits the recipient to specified purposes, obligates it to match the CCPA's level of protection, and gives the business the right to step in when the recipient falls short. A GDPR-shaped data sharing agreement covers much of this; confirm the California language rides along.
Consent that works on paper still has to survive the product surface. On the same CZ and Friends episode, Cecilia Ziniti told the story of a GC AI customer that runs point-of-sale machines: outside counsel sent over a CCPA disclaimer longer than the payment screen, and the customer's lawyer sat with engineering to get it down to a tap-to-consent flow of roughly five words. The lawyer who knows what the basis requires, and where it has to live in the product, is the one who keeps the deal shippable.
Roles, Independent Versus Joint Controller
The agreement should state who the controllers are at every stage, including after the share, and whether they act independently or jointly. Where the parties are joint controllers, look for the Article 26 arrangement, the allocation of responsibilities, and the requirement to make its essence available to data subjects. Where they are independent, confirm the agreement says so plainly, because silence here is where parties later argue about who owed the individual what. A role mismatch, language that calls the parties joint controllers while the operative clauses treat one as a processor, is a flag worth raising before signature.
Watch for hybrid deals, where the same partner independently markets to the shared list (a controller) and also hosts your campaign assets (a processor). Name the role per data flow; a hybrid deal papers both, with the DSA governing the shared list and a DPA governing the hosting.
Security
Both controllers stay responsible for compliance, so the agreement should set out the security measures each side applies, the standard they are measured against, and the practical guardrails that prevent over-disclosure. Look for obligations to train staff who handle the data, to share only the fields the purpose requires, and to encrypt data in transit and at rest. In a co-marketing share, the sharpest minimization move happens before the agreement: match audiences on hashed identifiers instead of handing over the raw list, because a narrower share writes a narrower clause. Tie security to breach handling. The agreement should say how quickly a party notifies the other after discovering an incident affecting the shared data, and who notifies regulators and individuals. The 72-hour clock in GDPR Article 33 starts when a controller becomes aware of a breach, so the party-to-party notice has to land fast enough to leave room inside your own deadline: ask for a number measured in hours, and confirm the clause names who calls whom. A confidentiality clause covers commercial secrecy; the personal-data security terms do a separate job. An agreement that carries one and skips the other is half done.
Onward Transfer and International Transfer
The Irish Data Protection Commission fined Meta €1.2 billion in May 2023, the largest GDPR fine on record, for EU-to-US personal data transfers that failed GDPR's transfer requirements even with SCCs in place. This is the check that sinks agreements, and the one worth running twice.
Two questions decide it. First, can either controller pass the data onward to its own third parties, and under what conditions? Second, does the data cross a border into a country without an adequacy decision? If it does, the agreement needs a valid transfer mechanism, in most cases the EU Standard Contractual Clauses (SCCs), or the UK International Data Transfer Agreement or Addendum, plus a transfer risk assessment.
A US recipient certified under the EU-U.S. Data Privacy Framework is covered by the July 2023 adequacy decision, so confirm the certification is current on the public list. An agreement that moves EU personal data to a non-adequate country with no SCCs attached is not ready to sign. Transfer rules move, so confirm the current adequacy list and the operative SCC version before you rely on them.
Data-Subject Rights
The agreement should specify which controller handles each data-subject right, access, rectification, erasure, objection, and how the parties cooperate when a request touches shared data. Independent controllers each answer for the data they hold, but they still need a mechanism to coordinate, because a deletion request honored by one side and ignored by the other is a regulator's exhibit A. For joint controllers, the rights allocation is mandatory under Article 26, and individuals can exercise their rights against either party. The allocation binds the parties. The individual keeps both doors.
Liability and Indemnity
GDPR fines for the most serious violations reach €20 million or 4% of global annual turnover, whichever is higher, under Article 83(5), and unlawful sharing sits squarely in that tier. Read who bears the loss when the shared data causes harm. Look for an indemnity that tracks fault, each controller covering the consequences of its own breach. A flat allocation leaves you carrying the other side's mistakes.
Watch the liability cap, and name the ask: a standalone cap for data-protection claims, sized against the regulatory fine and the class action, with the general commercial cap left to do its own job. Where the parties are joint controllers, remember that data subjects can claim full compensation from either party, so your indemnity is the only thing that gets you back to fault-based exposure.
Term and Deletion
The agreement should say how long each party keeps the shared data, what triggers deletion, and what happens to the data when the relationship ends. The default to push for is deletion or return on termination, with a short, defined retention tail only where a law requires it. A data sharing agreement with no deletion term is an open-ended liability, because the other controller can hold your customers' data indefinitely with no contractual obligation to let it go. Confirm the deletion obligation survives termination and covers backups.
Run the eight checks in order and the structural defects surface first: wrong document, missing basis, missing mechanism, long before the drafting details.
What a Data Sharing Agreement Template Contains
A data sharing agreement template contains nine sections: the parties and their controller roles, a data specification, purpose and lawful basis, security measures, transfer mechanisms, data-subject rights allocation, breach notification between the parties, liability and indemnity, and term and deletion. Each section maps to a check in the review lens above, so a good template is the checklist in contract form.
| Template Section | What It Does | Check It Answers |
|---|---|---|
| Parties and controller roles | Names each organization and states independent or joint controller status | Roles |
| Data specification (schedule) | Lists the exact data categories and fields being shared | Purpose limitation |
| Purpose and lawful basis | States the permitted uses and each controller's legal basis | Purpose limitation, legal basis |
| Security measures | Sets the security standard, staff training, and data minimization guardrails | Security |
| Transfer mechanisms | Attaches SCCs, the UK IDTA or Addendum, or confirms an adequacy basis | Onward and international transfer |
| Data-subject rights allocation | Assigns who answers access, deletion, and objection requests | Data-subject rights |
| Breach notification | Sets how fast each party notifies the other and who notifies regulators | Security |
| Liability and indemnity | Tracks loss to fault and carves data claims out of a low general cap | Liability and indemnity |
| Term and deletion | Ends the sharing and requires return or deletion, backups included | Term and deletion |
Read the schedules before the body. The data specification schedule defines what the parties share, so a polished body attached to a blank Schedule A commits both companies to sharing an undefined dataset. Free public templates, including the model agreements regulators publish, give you a workable skeleton, and the defaults reflect someone else's deal: rework the indemnification and limitation of liability terms against the data in your schedule. A template gets you a first draft in an hour. The review time goes into the schedule and the liability caps.
How In-House Teams Review a Data Sharing Agreement With GC AI
GC AI runs the eight checks on a data sharing agreement inside Microsoft Word. The checks are fast to list and slow to run by hand across a 14-page agreement with three schedules, so the platform compresses the first read.
You open the data sharing agreement in GC AI for Word and ask it to confirm the controller roles, locate the legal basis for each party, and flag whether a transfer mechanism is attached. It reads the document and surfaces the gaps in plain terms:
- No SCCs despite an EU-to-US transfer
- Language calling the parties joint controllers while the rights clause reads independent
- No deletion term on termination
The work shifts from hunting for what is missing to deciding what to do about it. Here is the shape of the first-pass prompt:
Review this data sharing agreement. Confirm each party's controller role and flag any clause that treats a party as a processor. Locate the lawful basis stated for each party and the purposes the sharing is limited to. Identify the transfer mechanism for any cross-border flow, and flag if none is attached. Confirm a deletion or return obligation exists and survives termination.
One prompt covers the four structural checks: roles, basis, transfers, deletion. The drafting-detail checks come after, once the agreement has earned the deeper read.
Two features carry the weight here. Exact Quote pulls the operative language verbatim, every comma intact, so when you tell the partnerships lead “the agreement allows onward transfer to unnamed third parties, here is the exact clause,” you are reading the document back word for word. And because transfer rules and adequacy decisions move, GC AI Research pulls the current SCC version and adequacy status from primary and authoritative sources, with citations you can check.
Ritesh Patel, Chief Legal Officer at Viant Technology, put the research half plainly:
It's also replaced Googling. Now my first stop is GC AI. I describe the setup, get an answer with citations, and use that to brief my team or our business partners.
For a cross-border data share, that is the difference between telling marketing “I think we need SCCs” and telling them “we need the current SCC version for this EU-to-US transfer, here is the citation, here is the addendum to attach.”
The checks also become a team asset. KT Farley, Chief Privacy Officer and Associate General Counsel at Helix, described the pattern:
The ability to create and store reusable prompts and share them across the team has completely changed the work required to review standard work. Junior teammates now run the checklist prompt first and bring me the output as the predicate for my review.
Store the eight checks as a reusable prompt in GC AI's Skill Library and every DSA review starts the same way: a teammate runs the checklist, the output arrives as the predicate, and the privacy lead's time goes to the judgment calls on liability and transfers.
The fastest test of fit is an agreement you already know: drop the last DSA your team reviewed by hand into the 14-day trial and compare what the first pass surfaces.
Putting a data sharing agreement into an AI platform raises the same question the agreement itself governs, which is where the data goes. GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with its model providers wherever feasible, and AES-256 encryption.
GC AI is used by 2,200+ legal teams across 50+ countries as of September 2026, including the legal departments at TIME, Riot Games, Vercel, Gusto, Snyk, and Liquid Death, plus 300+ public companies. For teams comparing platforms for privacy work, the best legal AI tools for in-house counsel guide ranks the field from the in-house seat.
Start Your Next Data Sharing Agreement Review This Week
Pull the last data sharing agreement that crossed your desk and run the checks against it. Confirm the document type first, a DSA for controllers, a DPA for processors. Then read for purpose, legal basis, roles, security, transfers, rights, liability, and deletion, so the deal-killers surface before the defined terms eat your afternoon.
Signature is the midpoint, and three steps finish the job: record the share in your Article 30 register, confirm your privacy notice names this category of recipient, and diary the review date the agreement sets. The full picture on the processor side lives on the data protection clause page, and we teach the prompting behind this workflow in GC AI's free legal AI classes, which are California CLE-eligible.
A data sharing agreement done right protects your customers and your company in the same clause. Read it once, read it in the right order, and the next co-marketing deal that lands on your desk is a checklist run instead of a weekend.






