惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
C
Cisco Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
IT之家
IT之家
博客园 - 【当耐特】
V
V2EX
博客园_首页
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
G
Google Developers Blog
The Last Watchdog
The Last Watchdog
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 司徒正美
N
Netflix TechBlog - Medium
F
Fortinet All Blogs
Know Your Adversary
Know Your Adversary
S
Schneier on Security
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
量子位
G
GRAHAM CLULEY
T
Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cybersecurity and Infrastructure Security Agency CISA
S
Security @ Cisco Blogs
B
Blog
Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
A
About on SuperTechFans
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
S
Securelist
博客园 - 聂微东
Cloudbric
Cloudbric
N
News and Events Feed by Topic
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
H
Help Net Security
N
News | PayPal Newsroom
P
Privacy & Cybersecurity Law Blog
Schneier on Security
Schneier on Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
W
WeLiveSecurity
Martin Fowler
Martin Fowler
K
Kaspersky official blog
S
Security Affairs
TaoSecurity Blog
TaoSecurity Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
Data Sharing Agreement: What You Should Know as a Business | iubenda
Alice Perseval · 2023-06-09 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

As a business, implementing a data sharing agreement can be a good practice when sharing personal data with other parties. Before getting started, you should make sure to understand what this agreement is and why it can be useful for your business in ensuring compliance, security, and trust with your partners and customers.

👀 In this article, we explain everything that you should know about data sharing agreements, why and in what cases they can be useful. We also look at the difference with another document, the data processing agreement. Let’s get started!

📌 What is a Data Sharing Agreement?

As the name implies, a data sharing agreement may be defined as a legally-binding document or agreement, between two or more entities, which regulates how data is shared among these parties and for what purpose.

A data sharing agreement or DSA clearly defines the roles, responsibilities, and rights of all parties involved in the data exchange process.

The types of data shared may be of various types:

  • data about identified or identifiable natural persons or “personal data“;
  • data protected by intellectual property rights or another kind of property-like right;
  • data considered confidential (including trade secrets and know-how), financial data, etc.

💡 The parties to the DSA are bound to comply with obligations at two levels: mandatory rules arising from the applicable law(s); and terms and conditions of the contract itself, agreed by the parties.

👋 Have you considered a Data Privacy Impact Assessment?

🔍 A DPIA is a common organizational measure to implement. Make sure to learn more here

Why is a data sharing agreement important?

There are several reasons why it is a good practice to implement a data sharing agreement in your company:

  • Legal Compliance: Considering the privacy laws in place today, such as the GDPR in Europe, it is prudent for entities that carry out some data sharing activities to have a DSA in place. This helps to regulate data sharing and be compliant with the relevant privacy legislation.
  • Data Security: A robust data sharing agreement also protects your data’s integrity by setting out guidelines on how the data should be transmitted, mitigating the risks of data breaches.
  • Trust & Privacy: By having an explicit agreement, you’re establishing trust with your partners and customers by showing them that you are implementing privacy-friendly practices for protecting the data shared. Transparency in data handling is a critical factor in establishing and maintaining this trust.

When is it Useful?

Data sharing agreements are especially valuable when it comes to data transfers that involve a high amount of data, or data that is quite sensitive (e.g. confidential data).

They are typically used for data transfers between government agencies, for example, or in the big data industry.

In fact, big data requires a multitude and complexity of factors, data sources, flows, algorithms… For carrying safe and compliant analytics activities, it’s a good starting point to have the right agreements in place.

🔍 What does the law say about DSAs?

👉 The GDPR does not expressly state data sharing agreements as a requirement. However, when sharing data, you need to keep in mind the applicable legislation and make relevant disclosures in your agreement. For example, if you declare sharing sensitive health data in your DSA, you will have to comply with GDPR’s article 9.

👉 European Data Act: in an early draft (not in force yet), the European Data Act refers to establishing rules on “fair contractual terms for data sharing agreements”.

👉 In the US, there can be some specific disclosures to be made in a data sharing agreement, especially when it comes to certain types of data, for example for sharing military health system data.

📌 What are the Components of a Data Sharing Agreement?

A well-structured data sharing agreement should, at least, contain the following elements:

  1. Definition of parties: clearly identify all parties involved in the data sharing process. This includes the data owner (the entity providing the data), the data recipient (the entity receiving the data), and any third parties involved.
  2. Purpose of data sharing and legal basis: articulate why the data is being shared, e.g. for data analysis, for the implementation of a new program or service…
  3. Categories of data to be shared: specify the types and categories of data being shared (e.g. name, address, phone number). You can also mention subject’s rights as per the GDPR.
  4. Function of the parties: define the function of the party disclosing and the party receiving data, in relation to their purpose.
  5. Processing details: description of how data will be processed (e.g. information is sent via a secure file transfer, then stored). Mention duration and frequency.
  6. Security measures: detail the security measures in place to protect the data during transmission and storage. These include password protection, the use of unique identifiers, procedures for handling data breaches, data encryption, staff training, and data backup, including backups for VMware in virtualized environments.
  7. Retention and deletion: specify for how long the data will be kept before it is deleted.
  8. Withdrawal and termination: define the various procedures and specify how the agreement can be ended and what happens to the data after termination.

💡 Looking to use a template? A template data sharing agreement can help you get started, but always remember to tailor the agreement to your specific situation and seek professional legal advice to ensure all bases are covered.

data sharing agreement

📌 Data Sharing Agreement vs. Data Processing Agreement

Unlike data sharing agreements, data processing agreements are required under the GDPR (Article 28).

When you, as a data controller, need an external supplier to help process personal data, this “supplier”, referred to as a processor by the GDPR, will handle your client data on your behalf, not for their own interest.

According to Article 28 of the GDPR, a written “Data Processing Agreement” must be established between the data controllers and data processors.

This agreement outlines each party’s responsibilities, like:

  • following instructions from controllers;
  • implementing sufficient data protection measures; and
  • cooperating with controllers in response to user queries or actions by regulatory bodies.

💡 Controllers and processors are jointly liable to third parties. This means, if an individual believes their data has been illegally processed, they can demand compensation from either the controller or processor. The party that compensated can later seek reimbursement from the other party.

See also