What Should a Data Sharing Agreement Include?
A clear data sharing agreement turns a proposed disclosure into an accountable operating arrangement, with defined purposes, roles, safeguards and procedures.
A data sharing agreement records the rules that apply when organisations share personal information. It helps the parties understand why the sharing takes place, who is responsible for what, how information will be protected and what happens when the arrangement changes or ends.
Did you know? A data sharing agreement can support compliance, but it does not make an excessive or otherwise unlawful disclosure permissible. The parties still need a valid lawful basis and must meet the UK GDPR principles.
Is a data sharing agreement mandatory?
A standalone agreement is not mandatory for every controller-to-controller disclosure, but the ICO describes it as good practice and an important way to demonstrate accountability. Some relationships have separate legal requirements: joint controllers must transparently determine their respective responsibilities, and controller-processor relationships require a contract containing the Article 28 terms.
Start by identifying the relationship
Before drafting, decide whether the parties are independent controllers, joint controllers or controller and processor. The label used in the contract does not determine the position; the assessment depends on who decides the purposes and essential means of the processing.
What should a data sharing agreement cover?
- Parties and roles: identify every organisation involved and the relevant data protection contacts.
- Purpose: state the specific aims, why the sharing is necessary and the expected benefit.
- Information: describe the people and data involved, including any special category or criminal offence information.
- Lawful basis: record the lawful basis used by each controller and any additional condition required for sensitive information.
- Use and access: define permitted purposes, authorised users and restrictions on onward disclosure.
- Transparency: decide what people will be told, by whom and at what point.
- Rights and complaints: allocate responsibility for handling access requests, objections, corrections and complaints.
- Security and breaches: set minimum controls, transfer methods, incident contacts and notification procedures.
- Accuracy, retention and deletion: agree how information is checked, corrected, retained, returned and securely destroyed.
- International transfers: record any transfer mechanism and supporting assessment.
- Review and termination: set review dates, change-control rules and the consequences of ending the arrangement.
A contract does not make unlawful sharing lawful
The organisations must still have a lawful basis, respect the data protection principles and provide appropriate transparency. An agreement helps evidence the decisions and implement controls, but it does not provide immunity where the underlying sharing is excessive, unfair or otherwise unlawful.
Consider a DPIA before the sharing starts
If the proposed arrangement is likely to result in a high risk to people, a DPIA may be required. Even where it is not mandatory, a proportionate risk assessment can help define safeguards and test whether the sharing is necessary.
Put the agreement into practice
Operational teams need to understand the permitted sharing and escalation routes. Configure access controls, train relevant staff, test secure transfer methods, maintain sharing logs where appropriate and make sure rights requests or incidents reach the right contact quickly.
Review the arrangement
Review the agreement regularly and whenever the purpose, parties, datasets, systems, recipients or legal basis changes. A complaint, security incident or evidence that the arrangement is not working should trigger an earlier review.
The ICO’s data sharing code provides detailed guidance and checklists.
Need a practical data sharing agreement?
WDPS can assess the parties’ roles, lawful basis and risks, then draft or review an agreement that reflects the real flow of information.
View our data-sharing service →
Frequently asked questions
Is a data sharing agreement the same as a processor contract?
No. A data sharing agreement commonly governs sharing between controllers. A controller-processor relationship requires a written contract containing the specific
Article 28 terms.
Can each party rely on a different lawful basis?
Yes. Each controller must identify and document the lawful basis that applies to its own processing. The agreement should make those decisions clear.
Should the agreement name every dataset?
It should describe the information with enough precision to prevent irrelevant or excessive disclosure. Complex arrangements may need an attached data specification.
What should happen when the arrangement ends?
The agreement should define whether information is returned, retained or securely deleted, how access is removed, and which obligations continue after termination.
Written by Clara Westbrook, solicitor and founder.
Speak to our team
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]





