Scope: this guidance is meant to help you determine what type of agreement is necessary when data / human tissue is exchanged between two parties. The guidance assumes the appropriate consent has been given for secondary use of this data/material. It is also limited to exchanging between two parties (from A to B) and not multi-party (e.g. from A to B to C). The size of the parties involved can range from two to large collaborations, such as public/private partnerships. This tool should be used as a guidance; it is still crucial to check with local legal experts, especially regarding specific content of the necessary agreement!
For valorisation, check with your local Technology Transfer Office (TTO); for Amsterdam UMC this is the IXA For privacy, check your local privacy officers.
REMARKS
- When transferring data and/or material between two parties, an agreement between them is a must and in some cases even required by legislation. By setting up an agreement you 1) can prove that you are taking safety of the data seriously; and 2) you can setup the rules about what may and may not be done with the data by the receiving party.
- The General Data Protection Regulation (GDPR) applies to personal data. Hence, any data with personal data, is affected by the GDPR and should therefore address it.
- Data Sharing, Usage, Access, Transfer and Exchange Agreements are identical; in the chart we use Data Sharing Agreement.
- Intellectual Property is part of the Data Sharing Agreement
- Please be advised that in the end the name of the agreement is not that relevant; the content is.
- Your data may be valuable. Always consult experts before engaging in an agreement!
- If you plan on making your own data Open Access, please consult an expert first!
GLOSSARY
- Controller: The data controller determines the purposes for which and the means by which personal data is processed [1].
- Open access (OA): Refers to research outputs which are distributed online and free of cost or other barriers. There is some flexibility about which permission barriers to remove. For example, some OA providers permit commercial re-use and some do not [2,3].
- Processor: The data processor processes personal data only on behalf of the controller. The data processor is usually a third party external to the company [1].
- Recipient: A natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not [4].
SOURCES
- https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/obligations/controllerprocessor/what-data-controller-or-data-processor_en
- https://en.wikipedia.org/wiki/O pen_access
- https://legacy.earlham.edu/~peters/fos/overview.htm
- https://gdpr-info.eu/art-4-gdpr/