Data privacy, consent & sharing agreement templates

Ready-to-adapt consent language, a practical data use agreement (DUA) skeleton, and a step-by-step anonymization & risk-assessment checklist to help teams share research data safely, ethically, and reuse-ready.

Overview

This collection contains practical, adaptable text and checklists you can copy into study documents, DUAs, and data-handling SOPs. Use these as a starting point—tailor wording to your jurisdiction, institutional policy, funder requirements, and the specific risks of your dataset. The goal: enable responsible data sharing while protecting participant rights and preserving utility.

What's included

  • Consent language samples for common study types (clinical, observational, secondary use, biobanking).
  • Data Use Agreement (DUA) skeleton with suggested clauses: permitted uses, security, retention, attribution, liability, and audit rights.
  • An anonymization checklist + simple risk assessment steps to evaluate re-identification risk and document choices.
  • Practical guidance for adapting templates to local law and research ethics requirements.

How to use these templates

Read each clause for intent before copying. Mark any items that conflict with your institutional policy or law. When in doubt, consult your institutional review board (IRB), legal counsel, or data protection officer. Keep a short companion log that records decisions (why you removed or added clauses) so future reviewers understand the dataset’s sharing pedigree.

Sample consent language (short forms)

Use these short samples as insertion points in consent forms. Expand with study-specific details and options (e.g., tiered consent for re-contact or commercial uses).

1. Clinical trial (broad research + sharing)

By signing, you agree that information collected about you for this study, including test results and de-identified biological samples, may be shared with other researchers for future health research. Shared data will be handled securely and, whenever possible, de-identified. You will not be identified in published results. You may withdraw consent for future sharing at any time; withdrawal will not affect use of data already shared under secure agreements.

2. Observational study (limited secondary use)

We will use the information you provide for this study and may share a de-identified version of the data with approved researchers working on related health questions. Any secondary use will be limited to analyses approved by our ethics committee and governed by a data use agreement.

3. Data deposited in a controlled-access repository

Data collected in this study may be deposited in a controlled-access data repository. Access to those data will require an application and agreement to the repository’s terms, including restrictions on re-identification and a commitment to data security.

Data Use Agreement (DUA) skeleton

Below is a practical DUA structure with suggested language. Keep clauses concise and specific to avoid ambiguity.

Parties and purpose

This Data Use Agreement (DUA) is between [Data Provider] and [Data Recipient]. The Recipient will use the Dataset only for [describe permitted project/purpose].

Permitted uses and restrictions

  • Permitted uses: [e.g., analysis for X, method development].
  • Prohibited uses: re-identification attempts, commercial resale, uses outside the stated project without written permission.

Data security and access controls

The Recipient must store and process data on systems with appropriate technical and organizational measures (access controls, encryption at rest and in transit, patch management). Access must be limited to named personnel and subcontractors listed in Appendix A.

Data handling, retention, and destruction

Data will be retained only for the duration needed for the permitted research and will be securely destroyed or returned to the Provider within [X] months of project completion, unless otherwise agreed in writing.

Attribution and publications

Publications arising from the data must acknowledge the Provider and cite the dataset per [citation format]. The Recipient will share manuscripts with the Provider [X] days before submission for non-binding comment.

Audit, monitoring, and breach notification

The Provider reserves the right to audit compliance. The Recipient must notify the Provider within [Y] hours of discovering a security incident and follow agreed remediation steps.

Liability, indemnity, and legal compliance

Each party must comply with applicable laws (e.g., data protection statutes). Liability provisions should be consistent with institutional policies. Indemnity clauses should be reviewed by legal counsel.

Signatures and governance

Authorized signatories for both parties with contact details. Include a governance contact for operational questions.

Anonymization checklist & simple re-identification risk assessment

Follow these steps and document each decision in a short dataset-sharing record.

  1. Inventory: List all variables and data types (direct identifiers, quasi-identifiers, sensitive attributes, free text, images, timestamps).
  2. Remove direct identifiers: names, national IDs, exact addresses, contact details, etc.
  3. Assess quasi-identifiers: consider replacing precise dates with month/year, limiting geographic granularity, or grouping rare categories.
  4. Consider pseudonymization: replace identifiers with stable codes; keep the key separate and protected or avoid keeping it if not needed.
  5. Evaluate small cells and rare combinations: apply k-anonymity (e.g., k>=5) or combine levels to avoid unique records.
  6. Free-text and images: scan and redact obvious identifiers; consider NLP-based de-identification for large corpora and human review for high-risk items.
  7. Statistical risk check: estimate re-identification risk qualitatively (low/medium/high). For medium/high risk, apply additional perturbation (noise, generalization) or restrict access to controlled environments only.
  8. Document transformation: record every modification, rationale, and residual risks in a data-sharing log.
  9. Decide access model: open, controlled access repository, or on-site/virtual secure environment. Match the level to residual risk and consent permissions.

Adaptation & jurisdiction notes

Local law (e.g., GDPR, HIPAA) and funder policies may require additional clauses (legal basis, data protection impact assessment, data transfer safeguards such as SCCs or BCRs). Always confirm whether 'de-identification' meets the legal threshold used by your institution and regulators.

Quick checklist for a safe share

  • Consent covers the planned secondary use or repository deposit.
  • DUA specifies permitted uses, security, retention, and breach process.
  • Anonymization steps documented and residual risk assessed.
  • Access model commensurate with risk (open vs controlled).
  • Contact and governance information included for post-share questions.

Next steps & tailoring

To make this actionable for your team:

  1. Choose the consent sample that best matches your study and expand with specifics (secondary uses, re-contact, commercial use options).
  2. Fill in the DUA skeleton with project-specific details (project scope, names, timelines, named personnel).
  3. Run the anonymization checklist and record results in a dataset-sharing log for future reviewers.
  4. Obtain institutional approvals (IRB/ethics, data protection officer) before sharing.

Legal & ethical disclaimer

This resource is practical guidance, not legal advice. Consult institutional counsel, IRB, or a data protection officer to ensure compliance with applicable laws and policies before sharing data.


Discussion

Comments and conversation will live here.