Examples
Worked examples
- Is an instance
A health-services researcher requesting Medicare claims data from CMS executes a DUA committing to a defined cell-suppression threshold and approved secure-enclave use.
- Is an instance
A genomics laboratory accessing controlled-access cases from dbGaP signs a Data Use Certification through the institutional signing official before download is permitted.
Counter-examples
Looks similar, but isn't
- Not an instance
Access to a fully public, de-identified, freely downloadable dataset under an open licence does not require a DUA.
- Not an instance
Use of internally generated data that never leaves the originating institution is governed by internal data-governance policy rather than an inter-institutional DUA.
Editorial commentary
DUAs are most commonly used for HIPAA limited datasets (where the agreement is mandatory under 45 CFR §164.514(e)), for restricted-use data from federal statistical agencies, and for controlled-access datasets from repositories such as dbGaP and the UK Data Service. For university-to-university transfers of research data, many U.S. institutions instead start from the standard FDP Data Transfer and Use Agreement (DTUA). The agreement is signed by institutionally authorised officials on both sides and binds the recipient institution, not the individual researcher. Standard provisions include a defined research purpose, listed authorised users, no-attempt-to-re-identify language, prohibition on onward transfer, secure-storage and access-control requirements, and an obligation to destroy or return data on study completion.
DUA vs. MTA vs. DTUA vs. BAA
A DUA is distinct from a Material Transfer Agreement (MTA), which governs physical biological or chemical materials rather than data; from a HIPAA Business Associate Agreement (BAA), which governs a vendor or contractor performing a function on a covered entity’s behalf using protected health information, rather than a research recipient using a limited or de-identified dataset for its own study; and from the FDP DTUA, which is a specific standardised template commonly used for university-to-university transfers rather than a distinct legal category — most DTUAs are, functionally, a form of DUA. A broader Collaborative Research Agreement (CRA) often has one or more DUAs executed underneath it to cover the specific datasets exchanged within a larger multi-institution project.
What a DUA typically negotiates
Beyond the core elements above, negotiated DUA terms commonly include: the specific security controls required to hold the data (ranging from general “reasonable safeguards” language up to a named framework such as NIST SP 800-171 for higher-sensitivity government or controlled data); breach or unauthorised-disclosure notification timelines and responsibilities; whether the recipient may link the dataset to other data sources (often prohibited or requiring separate written approval, since linkage can re-identify an otherwise de-identified dataset); publication and pre-print review rights where the source data provider wants to review outputs before release; and audit rights allowing the data provider to verify compliance.
Practical implication for research offices
Because a DUA binds the institution rather than the individual investigator, a lab that changes personnel, moves institutions, or adds a new authorised user typically needs an amendment (or a fresh listing of authorised personnel) rather than being able to simply substitute one researcher for another informally — unauthorised use by someone not named on the agreement is itself a compliance breach, independent of whether any data was actually misused.
References
- HIPAA Privacy Rule 45 CFR §164.514(e) limited data set and data use agreement
- NIH Genomic Data Sharing Policy and dbGaP Data Use Certification
- ICPSR Restricted Data Use Agreement template
Related: HIPAA Privacy Rule · PHI Exemptions From the HIPAA Privacy Rule · Material Transfer Agreement (MTA) · Collaborative Research Agreement (CRA) · Data safe haven.
Also known as
DUA · data access agreement · restricted-use data agreement
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Data Use Agreement (DUA)"
vocab-term-identifier="https://casrai.org/dictionary/term/data-use-agreement" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/data-use-agreement",
"name": "Data Use Agreement (DUA)",
"identifier": "https://casrai.org/dictionary/term/data-use-agreement",
"description": "A contractual instrument required before a recipient may access an identifiable, restricted, or limited dataset that defines permitted uses, security obligations, re-disclosure prohibitions, destruction requirements, and breach-notification duties.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/data-use-agreement",
"sameAs": [
"DUA",
"data access agreement",
"restricted-use data agreement"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-05-21T02:22:52",
"dateModified": "2026-08-22T12:18:10",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







