Register
Forgotten password?

Data sharing agreement (unilateral)

The function of this data sharing agreement is to provide protection for personal data disclosed by one business to another, in line with the General Data Protection Regulation (GDPR) in both its EU and UK forms, taking account of the guidance on data sharing issued by the UK Information Commissioner's Office.

The data sharing agreement is intended for use in relation to controller-to-controller data sharing - in other words, where both the sharer and the recipient will use the personal data for their own purposes and via their own means.

The agreement assumes that the controllers are independent, and not joint controllers.

The core provisions of the data sharing contract cover: (i) obligations to share personal data and to ensure that the data meets identified quality requirements; (ii) a prohibition on sharing especially sensitive data (known as special categories of personal data in the GDPR); (iii) the identification of the parties as independent controllers; (iv) data protection compliance obligations; (v) onward disclosures and international transfers of the personal data; and (vi) responses to the actions of supervisory authorities and data subjects.

The agreement includes a standard confidentiality clause covering the shared data, as well as some basic warranties, indemnities and limitations of liability.

The template data sharing agreement does not include a licensing clause, and if the recipient of the data needs a licence, a separate licensing contract should be entered into. In that case, you will need to consider the relationship between the two contracts. For instance, should the termination of one lead automatically to the termination of the other?

Ask about this document

Data sharing agreement (unilateral) contents

  1. Definitions: definitions; data protection terms.
  2. Term: commencement of term; end of term.
  3. Obligations to share Personal Data: obligation on 
    Supplier
     to share personal data.
  4. Data quality:
    Supplier
    to ensure data quality.
  5. No special categories: no special categories of personal data to be shared by 
    Supplier
    ; no criminal conviction data to be shared by first party.
  6. Parties acting as controllers: each party is independent controller of
    Supplier
    personal data; legal bases of sharing
    Supplier
    personal data (independent controllers); document does not apply to all personal data disclosed by 
    Supplier
    .
  7. Compliance with Data Protection Laws: compliance with data protection laws with respect to
    Supplier
    personal data;
    Supplier
    personal data collected in accordance with law; requirements relating to consent-based processing of personal data;
    Supplier
     responsible for meeting data protection transparency requirements; assistance in relation to compliance with data protection laws.
  8. Further disclosure of
    Supplier
    Personal Data:
    Recipient
    must not disclose personal data; obligations on disclosure of
    Supplier
    personal data; section does not prevent disclosure of anonymised data; section does not prevent disclosure of personal data to processors.
  9. International transfers of 
    Supplier
    Personal Data
    :
    prohibition on third country transfers of
    Supplier
    personal data; exceptions to prohibition on third country transfers of
    Supplier
    personal data; approved international transfer clauses take precedence over 
    Agreement
    .
  10. Supplier
    Personal Data
    and supervisory authorities:
    communications from supervisory authorities about 
    Supplier
    personal data; cooperation in relation to supervisory authority action.
  11. Supplier
    Personal Data
    and data subject rights:
    communications from data subjects about first party personal data; cooperation in relation to data subject rights.
  12. Security of
    Supplier
     Personal Data
    :
    appropriate measures to secure
    Supplier
    personal data; particular security measures for
    Supplier
    personal data.
  13. Data breaches involving
    the Supplier
    Personal Data:
    notification of data breaches involving
    Supplier
    personal data; assistance in relation to
    Supplier
    personal data breaches.
  14. Retention and deletion: retention periods for
    Supplier
    personal data; section subject to effects of termination.
  15. Compliance audit: right to audit compliance; notice of audit; cooperation in relation to audit; costs of licence audit; limits on audit right.
  16. Changes to Data Protection Laws: changes to data protection law.
  17. Recipient
     confidentiality obligations:
    Recipient
    confidentiality undertaking; disclosure of confidential information by
    Recipient
    to certain persons; exceptions to
    Recipient
     confidentiality obligations; disclosures of
    Supplier
    confidential information mandated by law etc;
    Recipient
    to stop using confidential information upon termination;
    Recipient
    confidentiality obligations after termination.
  18. Warranties: first party warranty of authority; second party warranty of authority; exclusion of implied warranties and representations.
  19. Indemnities:
    Supplier
    indemnifies
    Recipient
    upon data protection breach;
    Recipient
    indemnifies
    Supplier
     upon data protection breach.
  20. Limitations and exclusions of liability: caveats to limits of liability; interpretation of limits of liability; no liability for force majeure; per event liability cap.
  21. Termination: termination by either party without cause; termination by either party upon breach; termination upon insolvency.
  22. Effects of termination:
    Recipient
    to delete
    Supplier
    personal data; surviving provisions upon termination; termination does not affect accrued rights.
  23. Notices: contractual notices must be in writing; methods of sending contractual notices; contact details for contractual notices; substitute contact details for notices; acknowledgement of notice by email; deemed receipt of contractual notices.
  24. Data protection contacts:
    Supplier
     data protection contact;
    Recipient
    data protection contact.
  25. General: no waiver; severability; variation written and signed; no assignment without written consent; no third party rights; entire agreement; governing law; exclusive jurisdiction.
  26. Interpretation: statutory references; section headings not affecting interpretation; no ejusdem generis.

SCHEDULE 1 (DATA PROTECTION INFORMATION NOTICE)

    Prompt for 
    Recipient
    data protection information notice.

SCHEDULE 2 (FORM OF CONSENT)

    Prompt for 
    Recipient
     form of consent.

SCHEDULE 3 (INTERNATIONAL TRANSFER CLAUSES)

    Prompt for international transfer clauses.

SCHEDULE 4 (SECURITY MEASURES)

  1. Supplier
    security measures:
    prompt for details of
    Supplier
    security measures.
  2.  
    Recipient
     security measures:
    prompt for details of
    Recipient
    security measures.
Data sharing agreement (unilateral) document editor previewData sharing agreement (unilateral) document editor previewData sharing agreement (unilateral) document editor previewData sharing agreement (unilateral) document editor previewData sharing agreement (unilateral) document editor preview
This is a shortened preview of the editor interface; once you create your instance you'll be able to edit the full document in our online editor.
Data sharing agreement (unilateral) document previewData sharing agreement (unilateral) document previewData sharing agreement (unilateral) document previewData sharing agreement (unilateral) document previewData sharing agreement (unilateral) document previewData sharing agreement (unilateral) document previewData sharing agreement (unilateral) document preview
This is a shortened preview of the DOCX output; once you create your instance you'll be able to download the full document in PDF, HTML, RTF and/or DOCX (Microsoft Word) format.