Skip to content
97.5% of teams see value from GC AI before month oneSee how

Data Sharing Agreement: What It Is and What to Check


Caitlin PricePublished

Rachel Harris, General Counsel and AI Governance and Privacy Officer at the market research company Suzy, sits on the procurement side of the house. On CZ and Friends, GC AI's podcast hosted by CEO Cecilia Ziniti, she described the seat: legal review and DPA review on every procurement ticket in the pipeline. That is the data paper an in-house lawyer reads all week: processor paper. Now put a co-marketing deal on that desk. Both companies plan to email the same customer list, both decide what to do with it, and the partner's counsel sends over “the DPA.” Two clauses in, you can tell it is the wrong document, because nobody in this deal is anyone's processor. The deal needs a data sharing agreement.

The difference decides who holds the legal basis, who answers a data subject's access request, and who is on the hook when the data ends up somewhere it should not.

A data sharing agreement (DSA) is a contract between two or more organizations that each act as an independent or joint controller of the same personal data, setting the purpose, legal basis, security, transfer mechanisms, and deletion terms for sharing it. It governs controller-to-controller sharing, where both sides decide how and why the data is used.

A Data Processing Agreement (DPA) governs controller-to-processor processing, where one party only acts on the other's documented instructions. Same privacy law underneath, two different relationships, two different documents. Get the document wrong and the rest of your review is built on the wrong foundation.

A DSA arrives with a deadline attached, so the lens below is built for a fast first pass. GC AI, the enterprise-grade legal AI platform built for in-house counsel, reads the agreement inside Microsoft Word the same way you will read it here: roles first, then basis, then transfers, then deletion. It pulls the operative clause verbatim with Exact Quote, so every gap it flags arrives with the contract language attached.

Data Sharing Agreement vs DPA: The Distinction to Get Right

A data sharing agreement covers two controllers sharing personal data they each decide how to use; a DPA covers a controller handing data to a processor that acts only on instructions. The test is control, wherever the data flows.

Ask one question of the receiving party: does it get to decide why and how to use this data for its own purposes? If yes, that party is a controller and you need a data sharing agreement. If it can only do what your contract tells it to do, it is a processor and you need a DPA.

Two quick examples make the line concrete. You hire a payroll vendor to run payroll using your employee data, and the vendor does only what you tell it. That is controller-to-processor, so it needs a DPA.

You and a co-marketing partner each email a shared audience and each decide independently what to send and what to measure. That is controller-to-controller, so it needs a data sharing agreement. The payroll vendor never gets to repurpose your employee data for its own ends. The marketing partner does, which is exactly why the controls have to be heavier and explicit.

The roles also split inside the controller world, and the agreement has to name which one applies:

  • Independent controllers. Each party determines its own purposes and means separately after the share. You hand the data over, the other side decides its own uses, and each side is responsible for its own compliance. This is where commercial data shares land.
  • Joint controllers. The parties jointly determine the purposes and means of the same processing. Under GDPR Article 26, joint controllers must agree, in a transparent arrangement, who does what, especially around transparency notices and data-subject rights, and make the essence of that arrangement available to individuals.

Naming the role decides who writes the privacy notice, who fields the access request, and who indemnifies whom when something breaks. GC AI's live data protection clause page walks the controller-to-processor side in depth, including sub-processor controls and breach notification, so this page stays on the controller-to-controller relationship the DSA governs.

What to Check in a Data Sharing Agreement

The review lens for a data sharing agreement runs across eight checks: purpose limitation, legal basis, roles, security, onward and international transfers, data-subject rights, liability and indemnity, and term and deletion. Read in that order and you catch the structural problems before you get lost in defined terms. The order matters because the first three checks set up everything after them. The UK ICO's data sharing code of practice treats a written agreement as good practice for any routine sharing. The eight checks are:

  1. Purpose limitation
  2. Legal basis
  3. Roles, independent versus joint controller
  4. Security
  5. Onward transfer and international transfer
  6. Data-subject rights
  7. Liability and indemnity
  8. Term and deletion

...process the Shared Personal Data in connection with this Agreement which may include the transfer of the Shared Personal Data to Company outside of the European Economic Area (EEA); and (b) shall not, by act or omission, cause Company to violate any Data Protection Laws...

Source: data-sharing provision in an agreement filed by STAAR Surgical Company as Exhibit 10.2 to a Form 8-K, December 2022, via SEC EDGAR.

Purpose Limitation

The agreement should state, in precise terms, the specific purposes for which the data may be shared and used, and bar use for anything else. Vague purpose language (“for the parties' business purposes”) is the most common defect and the most dangerous, because it lets the receiving controller drift the data into new uses you never priced into your risk. Pin the purpose to the deal in front of you. If the co-marketing partner wants the list for one campaign, the agreement says one campaign. The redline is one line of drafting: strike “for the parties' business purposes,” write “solely for the campaign described in Schedule B,” and add that any further use needs a fresh written agreement.

Rachel Harris runs that discipline question by question on the data requests her own team sends out, and her test is the one to put to every purpose clause:

What is most important and what the regulators really intend is what is it capturing and why? And can you ask it in another way to where it's clearer for the end user, so that it's easier for the end recipient to answer, and so that both sides of the table have a better understanding of what's actually happening with the data involved.

She was describing a security questionnaire rebuild, and the same test reads straight onto the purpose clause: every category of shared data should trace to a stated purpose that both controllers could explain to a regulator without looking at their shoes.

Each controller documents its own lawful basis for the sharing, and the bases can differ between the parties. One side may rely on consent, the other on legitimate interests. If the data includes special category data, such as health or biometric data, or criminal offense data, the agreement must also identify the additional condition for processing it.

The check here is twofold: confirm a basis is stated for each party, and confirm it fits the stated purpose. A consent basis that does not cover the co-marketing use is a basis in name only.

There is a second question hiding under the first: what did your privacy notice say when you collected the list? GDPR's transparency rules make you name recipient categories at collection, so a notice that never mentioned partner sharing means updating the notice, or reworking the basis, before the data moves.

For California data, the same check runs under the CCPA. When a business sells or shares personal information with a third party, Section 1798.100(d) requires a contract that limits the recipient to specified purposes, obligates it to match the CCPA's level of protection, and gives the business the right to step in when the recipient falls short. A GDPR-shaped data sharing agreement covers much of this; confirm the California language rides along.

Consent that works on paper still has to survive the product surface. On the same CZ and Friends episode, Cecilia Ziniti told the story of a GC AI customer that runs point-of-sale machines: outside counsel sent over a CCPA disclaimer longer than the payment screen, and the customer's lawyer sat with engineering to get it down to a tap-to-consent flow of roughly five words. The lawyer who knows what the basis requires, and where it has to live in the product, is the one who keeps the deal shippable.

Roles, Independent Versus Joint Controller

The agreement should state who the controllers are at every stage, including after the share, and whether they act independently or jointly. Where the parties are joint controllers, look for the Article 26 arrangement, the allocation of responsibilities, and the requirement to make its essence available to data subjects. Where they are independent, confirm the agreement says so plainly, because silence here is where parties later argue about who owed the individual what. A role mismatch, language that calls the parties joint controllers while the operative clauses treat one as a processor, is a flag worth raising before signature.

Watch for hybrid deals, where the same partner independently markets to the shared list (a controller) and also hosts your campaign assets (a processor). Name the role per data flow; a hybrid deal papers both, with the DSA governing the shared list and a DPA governing the hosting.

Security

Both controllers stay responsible for compliance, so the agreement should set out the security measures each side applies, the standard they are measured against, and the practical guardrails that prevent over-disclosure. Look for obligations to train staff who handle the data, to share only the fields the purpose requires, and to encrypt data in transit and at rest. In a co-marketing share, the sharpest minimization move happens before the agreement: match audiences on hashed identifiers instead of handing over the raw list, because a narrower share writes a narrower clause. Tie security to breach handling. The agreement should say how quickly a party notifies the other after discovering an incident affecting the shared data, and who notifies regulators and individuals. The 72-hour clock in GDPR Article 33 starts when a controller becomes aware of a breach, so the party-to-party notice has to land fast enough to leave room inside your own deadline: ask for a number measured in hours, and confirm the clause names who calls whom. A confidentiality clause covers commercial secrecy; the personal-data security terms do a separate job. An agreement that carries one and skips the other is half done.

Onward Transfer and International Transfer

The Irish Data Protection Commission fined Meta €1.2 billion in May 2023, the largest GDPR fine on record, for EU-to-US personal data transfers that failed GDPR's transfer requirements even with SCCs in place. This is the check that sinks agreements, and the one worth running twice.

Two questions decide it. First, can either controller pass the data onward to its own third parties, and under what conditions? Second, does the data cross a border into a country without an adequacy decision? If it does, the agreement needs a valid transfer mechanism, in most cases the EU Standard Contractual Clauses (SCCs), or the UK International Data Transfer Agreement or Addendum, plus a transfer risk assessment.

A US recipient certified under the EU-U.S. Data Privacy Framework is covered by the July 2023 adequacy decision, so confirm the certification is current on the public list. An agreement that moves EU personal data to a non-adequate country with no SCCs attached is not ready to sign. Transfer rules move, so confirm the current adequacy list and the operative SCC version before you rely on them.

Data-Subject Rights

The agreement should specify which controller handles each data-subject right, access, rectification, erasure, objection, and how the parties cooperate when a request touches shared data. Independent controllers each answer for the data they hold, but they still need a mechanism to coordinate, because a deletion request honored by one side and ignored by the other is a regulator's exhibit A. For joint controllers, the rights allocation is mandatory under Article 26, and individuals can exercise their rights against either party. The allocation binds the parties. The individual keeps both doors.

Liability and Indemnity

GDPR fines for the most serious violations reach €20 million or 4% of global annual turnover, whichever is higher, under Article 83(5), and unlawful sharing sits squarely in that tier. Read who bears the loss when the shared data causes harm. Look for an indemnity that tracks fault, each controller covering the consequences of its own breach. A flat allocation leaves you carrying the other side's mistakes.

Watch the liability cap, and name the ask: a standalone cap for data-protection claims, sized against the regulatory fine and the class action, with the general commercial cap left to do its own job. Where the parties are joint controllers, remember that data subjects can claim full compensation from either party, so your indemnity is the only thing that gets you back to fault-based exposure.

Term and Deletion

The agreement should say how long each party keeps the shared data, what triggers deletion, and what happens to the data when the relationship ends. The default to push for is deletion or return on termination, with a short, defined retention tail only where a law requires it. A data sharing agreement with no deletion term is an open-ended liability, because the other controller can hold your customers' data indefinitely with no contractual obligation to let it go. Confirm the deletion obligation survives termination and covers backups.

Run the eight checks in order and the structural defects surface first: wrong document, missing basis, missing mechanism, long before the drafting details.

What a Data Sharing Agreement Template Contains

A data sharing agreement template contains nine sections: the parties and their controller roles, a data specification, purpose and lawful basis, security measures, transfer mechanisms, data-subject rights allocation, breach notification between the parties, liability and indemnity, and term and deletion. Each section maps to a check in the review lens above, so a good template is the checklist in contract form.

Template SectionWhat It DoesCheck It Answers
Parties and controller rolesNames each organization and states independent or joint controller statusRoles
Data specification (schedule)Lists the exact data categories and fields being sharedPurpose limitation
Purpose and lawful basisStates the permitted uses and each controller's legal basisPurpose limitation, legal basis
Security measuresSets the security standard, staff training, and data minimization guardrailsSecurity
Transfer mechanismsAttaches SCCs, the UK IDTA or Addendum, or confirms an adequacy basisOnward and international transfer
Data-subject rights allocationAssigns who answers access, deletion, and objection requestsData-subject rights
Breach notificationSets how fast each party notifies the other and who notifies regulatorsSecurity
Liability and indemnityTracks loss to fault and carves data claims out of a low general capLiability and indemnity
Term and deletionEnds the sharing and requires return or deletion, backups includedTerm and deletion

Read the schedules before the body. The data specification schedule defines what the parties share, so a polished body attached to a blank Schedule A commits both companies to sharing an undefined dataset. Free public templates, including the model agreements regulators publish, give you a workable skeleton, and the defaults reflect someone else's deal: rework the indemnification and limitation of liability terms against the data in your schedule. A template gets you a first draft in an hour. The review time goes into the schedule and the liability caps.

How In-House Teams Review a Data Sharing Agreement With GC AI

GC AI runs the eight checks on a data sharing agreement inside Microsoft Word. The checks are fast to list and slow to run by hand across a 14-page agreement with three schedules, so the platform compresses the first read.

You open the data sharing agreement in GC AI for Word and ask it to confirm the controller roles, locate the legal basis for each party, and flag whether a transfer mechanism is attached. It reads the document and surfaces the gaps in plain terms:

  • No SCCs despite an EU-to-US transfer
  • Language calling the parties joint controllers while the rights clause reads independent
  • No deletion term on termination

The work shifts from hunting for what is missing to deciding what to do about it. Here is the shape of the first-pass prompt:

Review this data sharing agreement. Confirm each party's controller role and flag any clause that treats a party as a processor. Locate the lawful basis stated for each party and the purposes the sharing is limited to. Identify the transfer mechanism for any cross-border flow, and flag if none is attached. Confirm a deletion or return obligation exists and survives termination.

One prompt covers the four structural checks: roles, basis, transfers, deletion. The drafting-detail checks come after, once the agreement has earned the deeper read.

Two features carry the weight here. Exact Quote pulls the operative language verbatim, every comma intact, so when you tell the partnerships lead “the agreement allows onward transfer to unnamed third parties, here is the exact clause,” you are reading the document back word for word. And because transfer rules and adequacy decisions move, GC AI Research pulls the current SCC version and adequacy status from primary and authoritative sources, with citations you can check.

Ritesh Patel, Chief Legal Officer at Viant Technology, put the research half plainly:

It's also replaced Googling. Now my first stop is GC AI. I describe the setup, get an answer with citations, and use that to brief my team or our business partners.

For a cross-border data share, that is the difference between telling marketing “I think we need SCCs” and telling them “we need the current SCC version for this EU-to-US transfer, here is the citation, here is the addendum to attach.”

The checks also become a team asset. KT Farley, Chief Privacy Officer and Associate General Counsel at Helix, described the pattern:

The ability to create and store reusable prompts and share them across the team has completely changed the work required to review standard work. Junior teammates now run the checklist prompt first and bring me the output as the predicate for my review.

Store the eight checks as a reusable prompt in GC AI's Skill Library and every DSA review starts the same way: a teammate runs the checklist, the output arrives as the predicate, and the privacy lead's time goes to the judgment calls on liability and transfers.

The fastest test of fit is an agreement you already know: drop the last DSA your team reviewed by hand into the 14-day trial and compare what the first pass surfaces.

Putting a data sharing agreement into an AI platform raises the same question the agreement itself governs, which is where the data goes. GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with its model providers wherever feasible, and AES-256 encryption.

GC AI is used by 2,200+ legal teams across 50+ countries as of September 2026, including the legal departments at TIME, Riot Games, Vercel, Gusto, Snyk, and Liquid Death, plus 300+ public companies. For teams comparing platforms for privacy work, the best legal AI tools for in-house counsel guide ranks the field from the in-house seat.

Start Your Next Data Sharing Agreement Review This Week

Pull the last data sharing agreement that crossed your desk and run the checks against it. Confirm the document type first, a DSA for controllers, a DPA for processors. Then read for purpose, legal basis, roles, security, transfers, rights, liability, and deletion, so the deal-killers surface before the defined terms eat your afternoon.

Signature is the midpoint, and three steps finish the job: record the share in your Article 30 register, confirm your privacy notice names this category of recipient, and diary the review date the agreement sets. The full picture on the processor side lives on the data protection clause page, and we teach the prompting behind this workflow in GC AI's free legal AI classes, which are California CLE-eligible.

A data sharing agreement done right protects your customers and your company in the same clause. Read it once, read it in the right order, and the next co-marketing deal that lands on your desk is a checklist run instead of a weekend.

Frequently Asked Questions

Is a Data Sharing Agreement Legally Binding?
Yes, a signed data sharing agreement is a legally binding contract, enforceable between the parties like any other commercial agreement. It also carries regulatory weight, because the agreement is the first document a regulator reads after a shared dataset leaks. The contract manages risk between the parties, and each controller still owes its own compliance duties directly under the applicable privacy law.
Who Signs a Data Sharing Agreement?
Each organization that shares data signs through a representative with contracting authority, such as a general counsel, a data protection officer, or a commercial lead with delegated signing power. Legal or privacy review comes first in larger organizations, and the signatories bind their companies to the purpose limitation, security, and liability terms. The agreement should also name a point of contact on each side for data-subject requests and incidents, which is a separate role from the signatory.
Do You Need a Data Sharing Agreement or a Non-Disclosure Agreement?
You need a data sharing agreement when personal data moves between the parties on an ongoing basis, because the arrangement has to address purpose limitation, security, transfers, and data-subject rights. A non-disclosure agreement protects confidential business information exchanged during discussions; the personal-data obligations live in the DSA. Deals that involve both use both, with the NDA covering the commercial secrets and the data sharing agreement covering the people in the dataset.
What Is the Difference Between a Joint Controller Agreement and a Data Sharing Agreement?
A joint controller agreement is the GDPR Article 26 arrangement required when two organizations jointly determine the purposes and means of processing, allocating who handles data-subject requests and transparency notices. A data sharing agreement is the broader commercial document, covering controllers acting either jointly or independently. Where the parties are joint controllers, the Article 26 arrangement sits inside or alongside the data sharing agreement, and data subjects can exercise their rights against either party.
Is a Data Sharing Agreement Needed When Group Companies Share Data Internally?
Yes, companies in the same corporate group are separate controllers under GDPR, so intragroup sharing of personal data still needs a lawful basis, safeguards, and, for cross-border entities, a transfer mechanism. GDPR Recital 48 recognizes a legitimate interest in transferring personal data within a group for internal administrative purposes, and the interest still has to be documented. An intragroup data sharing agreement records the categories shared, each entity's legal basis, and the security measures applied.
How Long Does a Data Sharing Agreement Last?
The parties set the term, and the right length follows the purpose: a share tied to one campaign or project ends when the purpose ends, while ongoing commercial data flows run on renewable terms with periodic review. Set a review date even for an open-ended arrangement, because purposes drift and the UK ICO's code treats regular review of sharing arrangements as good practice. Whatever term you pick, tie it to the deletion trigger the agreement already defines.
What Is the Difference Between a Data Sharing Agreement and a Data Use Agreement?
A data use agreement (DUA) is the common term in US research, healthcare, and government settings for a contract governing a recipient's use of a specific dataset, such as a HIPAA limited data set or data tied to federal funding conditions. A data sharing agreement is the broader commercial and privacy-law term for controller-to-controller sharing of personal data. The two overlap in substance, and the eight checks in this article apply to both.
SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Take the first step now

Let's explore about how we can make your life as an in-house lawyer a whole lot easier.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.

Keep up with the latest content