Skip to main content
v2026.11,772 entries · CC-BY 4.0

Direct comparison

DSA vs DPA: Which GDPR Agreement Applies?

A DSA covers research collaborators sharing data as joint/independent controllers. A DPA is the GDPR Art. 28 contract for engaging a data processor.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · included with Regulatory Radar

Ask about DSA vs DPA: Which GDPR Agreement Applies?

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do Data Sharing Agreement (DSA), Data Processing Agreement (DPA) compare side by side?

The table below compares Data Sharing Agreement (DSA), Data Processing Agreement (DPA) across 11 procurement-relevant dimensions, from what it governs through geographic scope.

Side-by-side comparison

DimensionData Sharing Agreement (DSA)Data Processing Agreement (DPA)
What it governsData moving between research collaborators or institutionsPersonal data handed to a third-party processor acting on a controller’s behalf
Legal triggerContractual choice — not mandated by a specific statuteMandatory under GDPR Article 28 whenever a controller uses a processor
Relationship between partiesJoint controllers or independent controllers, each with their own purposeController-to-processor — the processor acts only on documented instructions
Typical counterparty in researchA collaborating university, institute, or investigatorA vendor: cloud/storage provider, survey or EDC platform, transcription or analytics service
Applies only to personal data?No — also used for non-personal research data; GDPR terms apply only if personal data is includedYes — a DPA exists specifically because personal data is being processed
Mandatory contentNo fixed statutory list — negotiated: permitted use, security, publication rights, retention, IP, liabilityFixed by GDPR Art. 28(3): subject-matter, duration, nature/purpose, data types, data-subject categories, controller’s rights, plus 8 processor duties (Art. 28(3)(a)-(h))
Can the recipient set its own purpose for the data?Yes — each party typically has its own research purposeNo — the processor has no independent purpose (Art. 28(3)(a))
Sub-sharing / sub-processingGoverned by whatever onward-sharing clauses are negotiatedProcessor cannot engage a sub-processor without the controller’s prior written authorisation (Art. 28(2))
On terminationRetention/destruction terms as negotiated (e.g. destroy after study closeout)Processor must delete or return all personal data at the end of the engagement (Art. 28(3)(g))
Off-the-shelf model textInstitution- or funder-specific templates; no single universal templateEU Standard Contractual Clauses for controller-processor relationships (Commission Implementing Decision (EU) 2021/915, under Art. 28(7))
Geographic scopeUsed globally regardless of whether GDPR appliesGDPR Art. 28 itself is EU/EEA law; UK GDPR retains an equivalent Article 28 obligation post-Brexit

Common questions

Common questions about Data Sharing Agreement (DSA) vs Data Processing Agreement (DPA)

Do we need both a DSA and a DPA for the same project?

+

Often, yes — but for different counterparties. A DSA covers the terms between research collaborators who each use the data for their own purposes; a DPA covers any third-party vendor (cloud storage, survey platform, analytics service) that processes personal data purely on your institution’s instructions. A project can need one, the other, or both at once.

Is a DPA required if two institutions are joint controllers rather than controller and processor?

+

No. Joint controllership is a different relationship, addressed by GDPR Article 26, not Article 28. Two institutions each deciding their own purposes for shared data should use a data sharing agreement (with GDPR joint-controller terms where relevant), not a DPA — a DPA specifically covers a controller instructing a processor with no independent purpose of its own.

Does GDPR require the document to be titled “Data Processing Agreement”?

+

No. What matters is that the mandatory terms in Article 28(3) appear in a binding written contract between the controller and the processor — whether that is a standalone DPA, an addendum to a master services agreement, or a data-processing clause embedded in a broader contract. The underlying controller-processor relationship is what triggers Article 28, not the document’s title.

Who signs a DPA in a university research context?

+

Typically the institution’s legal, privacy, or procurement office signs on behalf of the controller, with the vendor (or its authorised signatory) as processor. Individual researchers usually aren’t the signing party, though they often trigger the need for one by selecting a new tool or vendor.

Does a DPA apply if the shared dataset has been anonymised?

+

If data is genuinely and irreversibly anonymised, it falls outside GDPR’s definition of personal data and Article 28 does not apply. Pseudonymised or coded data is not the same as anonymised — GDPR still treats pseudonymised data as personal data, so a DPA (or DSA with GDPR terms) is still required for it.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.