If you’ve ever dealt with personal data, whether you run a small business, a charity, or a larger organisation, you’ve probably come across terms like Data Sharing Agreement (DSA) and Data Processing Agreement (DPA). At first glance, they might seem interchangeable, but mixing them up can create confusion, unnecessary obligations, or even legal risks. Let’s break down the difference in plain English, why it matters, and what could go wrong if you don’t get it right.
What’s the Difference?
Data Sharing Agreement (DSA): Think of a DSA as a partnership. Two or more organisations agree to share personal data with each other, usually to achieve their own objectives. Each organisation typically acts as a data controller, meaning they decide how and why the data is used.
Data Processing Agreement (DPA): A DPA is more like hiring a specialist to handle data for you. One organisation, the data controller, instructs another, the data processor, to process personal data on its behalf. The processor doesn’t decide what to do with the data, it simply follows instructions.
Key Differences
Who decides how the data is used?
Data Sharing Agreement: Each party acts as a controller and decides independently how to use the data.
Data Processing Agreement: The processor follows the controller’s instructions and doesn’t make independent decisions.
Purpose of the agreement
Data Sharing Agreement: To share personal data between organisations for their own purposes.
Data Processing Agreement: To outline how a processor will handle personal data on behalf of a controller.
Legal obligations
Data Sharing Agreement: Each controller is responsible for compliance with data protection laws, including lawful processing, security, and retention.
Data Processing Agreement: The processor must implement security measures, report breaches, and only process data as instructed by the controller.
Who holds accountability?
Data Sharing Agreement: Each party is accountable for their own use of the shared data.
Data Processing Agreement: The controller remains accountable for compliance, but the processor is responsible for following instructions and safeguarding data.
When each is required
Data Sharing Agreement: When multiple organisations want to collaborate and share data for their own purposes.
Data Processing Agreement: When a business hires a third party to process data on its behalf.
Why Getting It Right Matters
Choosing the wrong type of agreement can have significant consequences:
- Legal obligations: Controllers and processors have different duties under data protection law. Misclassifying the relationship could mean you’re inadvertently taking on responsibilities you shouldn’t.
- Accountability: If a breach occurs, the wrong agreement could make it unclear who is responsible.
- Unnecessary work: You could end up creating extra compliance obligations, audits, or reports that don’t apply to your situation.
That’s why it’s really important to get it right. Having the right agreement protects you, your partners, and the people whose data you’re handling.
Real-World Examples
Example 1: Local Council and Health Services
Imagine a local council wants to share residents’ health information with a local clinic to coordinate community health programmes. Both organisations decide what data they need, why they need it, and how they will use it.
Correct agreement: Data Sharing Agreement
Why: Both parties are making independent decisions about the data, they’re controllers.
Obligations: Each must ensure data is shared lawfully, secure it appropriately, and only keep it for as long as needed.
What could go wrong: If they used a DPA instead, the council would wrongly be treated as instructing the clinic as a processor. This could restrict the clinic’s ability to use the data for its own legal purposes and create confusion about who’s responsible if something goes wrong.
Example 2: IT Support
A small business hires a company to provide IT support. The provider only follows the business’s instructions and doesn’t make decisions about the data’s use.
Correct agreement: Data Processing Agreement
Why: The provider is a processor, not a controller.
Obligations: The processor must implement security measures, notify the controller of any data breaches, and only process data as instructed.
What could go wrong: Using a DSA here could mistakenly suggest that the IT support provider is a controller, potentially making them responsible for compliance obligations they don’t control. This could lead to liability issues if data protection rules aren’t followed correctly by the small business.
Example 3: Charity Outsourcing Donor Management
Imagine a small charity hires an external company to manage its donor database and run fundraising campaigns. The charity instructs the company to contact supporters, segment donor lists, and report back on campaign performance. The charity believes it’s outsourcing the work, so it signs a Data Sharing Agreement.
What’s really happening: The external company is acting as a processor, not a controller. They are following the charity’s instructions rather than making independent decisions about how to use the data. They do not need the data beyond what the charity is asking them to do with it.
Correct agreement: Data Processing Agreement
Why: The charity remains the controller of the donor data. The company is processing data on its behalf and has no independent decision-making authority.
Obligations for the charity: Ensure the processor has appropriate security measures in place, monitor compliance, and remain accountable for any breaches.
Obligations for the processor: Follow instructions carefully, keep data secure, report any incidents immediately, and not use the data for its own purposes.
What could go wrong: If the charity mistakenly uses a Data Sharing Agreement, the company might assume it has more autonomy over the data than it actually does. This can lead to misuse, accidental non-compliance with GDPR, or even liability for the charity if the processor mishandles personal data. Charities often fall into this trap because they want to “share” responsibility, but the reality is the charity retains control and accountability.
Bottom Line
Getting your agreements right is about protecting your business, your partners, and the people whose data you handle. Using a data sharing agreement where you should have a data processing agreement (or vice versa) can create unnecessary legal obligations, confusion, and even risk your compliance with the data protection legislation.
Always be clear about your role: are you sharing data because you each need it for your own purposes, or are you hiring someone to handle it for you? Answering this simple question will point you to the right agreement and give you peace of mind.
Confused about which agreement you need? Don’t risk getting it wrong, contact us today, and we’ll help you put the right data sharing or data processing agreement in place, so you can be sure all parties’ interests are protected properly.
