Skip to main content
v2026.11,772 entries · CC-BY 4.0
Dictionary termTrack DStablev2026.2

Data Use Agreement (DUA)

A contractual instrument required before a recipient may access an identifiable, restricted, or limited dataset that defines permitted uses, security obligations, re-disclosure prohibitions, destruction requirements, and breach-notification duties.

ByCASRAI Editorial Board
· Last updated 22 Aug 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about Data Use Agreement (DUA)

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    A health-services researcher requesting Medicare claims data from CMS executes a DUA committing to a defined cell-suppression threshold and approved secure-enclave use.

  • Is an instance

    A genomics laboratory accessing controlled-access cases from dbGaP signs a Data Use Certification through the institutional signing official before download is permitted.

Counter-examples

Looks similar, but isn't

  • Not an instance

    Access to a fully public, de-identified, freely downloadable dataset under an open licence does not require a DUA.

  • Not an instance

    Use of internally generated data that never leaves the originating institution is governed by internal data-governance policy rather than an inter-institutional DUA.

Editorial commentary

DUAs are most commonly used for HIPAA limited datasets (where the agreement is mandatory under 45 CFR §164.514(e)), for restricted-use data from federal statistical agencies, and for controlled-access datasets from repositories such as dbGaP and the UK Data Service. For university-to-university transfers of research data, many U.S. institutions instead start from the standard FDP Data Transfer and Use Agreement (DTUA). The agreement is signed by institutionally authorised officials on both sides and binds the recipient institution, not the individual researcher. Standard provisions include a defined research purpose, listed authorised users, no-attempt-to-re-identify language, prohibition on onward transfer, secure-storage and access-control requirements, and an obligation to destroy or return data on study completion.

DUA vs. MTA vs. DTUA vs. BAA

A DUA is distinct from a Material Transfer Agreement (MTA), which governs physical biological or chemical materials rather than data; from a HIPAA Business Associate Agreement (BAA), which governs a vendor or contractor performing a function on a covered entity’s behalf using protected health information, rather than a research recipient using a limited or de-identified dataset for its own study; and from the FDP DTUA, which is a specific standardised template commonly used for university-to-university transfers rather than a distinct legal category — most DTUAs are, functionally, a form of DUA. A broader Collaborative Research Agreement (CRA) often has one or more DUAs executed underneath it to cover the specific datasets exchanged within a larger multi-institution project.

What a DUA typically negotiates

Beyond the core elements above, negotiated DUA terms commonly include: the specific security controls required to hold the data (ranging from general “reasonable safeguards” language up to a named framework such as NIST SP 800-171 for higher-sensitivity government or controlled data); breach or unauthorised-disclosure notification timelines and responsibilities; whether the recipient may link the dataset to other data sources (often prohibited or requiring separate written approval, since linkage can re-identify an otherwise de-identified dataset); publication and pre-print review rights where the source data provider wants to review outputs before release; and audit rights allowing the data provider to verify compliance.

Practical implication for research offices

Because a DUA binds the institution rather than the individual investigator, a lab that changes personnel, moves institutions, or adds a new authorised user typically needs an amendment (or a fresh listing of authorised personnel) rather than being able to simply substitute one researcher for another informally — unauthorised use by someone not named on the agreement is itself a compliance breach, independent of whether any data was actually misused.

References

  • HIPAA Privacy Rule 45 CFR §164.514(e) limited data set and data use agreement
  • NIH Genomic Data Sharing Policy and dbGaP Data Use Certification
  • ICPSR Restricted Data Use Agreement template

Related: HIPAA Privacy Rule · PHI Exemptions From the HIPAA Privacy Rule · Material Transfer Agreement (MTA) · Collaborative Research Agreement (CRA) · Data safe haven.

Also known as

DUA · data access agreement · restricted-use data agreement

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data Use Agreement (DUA)"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-use-agreement" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-use-agreement",
  "name": "Data Use Agreement (DUA)",
  "identifier": "https://casrai.org/dictionary/term/data-use-agreement",
  "description": "A contractual instrument required before a recipient may access an identifiable, restricted, or limited dataset that defines permitted uses, security obligations, re-disclosure prohibitions, destruction requirements, and breach-notification duties.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/data-use-agreement",
  "sameAs": [
    "DUA",
    "data access agreement",
    "restricted-use data agreement"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-05-21T02:22:52",
  "dateModified": "2026-08-22T12:18:10",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.