If you’re a smaller or newer business, or you just don’t share personal data very often, then it is more than likely you won’t have your own standard template data sharing agreement. Instead, you’re likely to rely on the equivalent template provided by organisations you get personal data from or sent it to.
That’s absolutely fine. Why reinvent the wheel? And having any kind of agreement is better than none (which happens a lot more than you might think).
However, in my experience a lot of data sharing agreements leave a lot to be desired. Here are the top five red-flags that I come across most often.

What is a Data Sharing Agreement?
A Data Sharing Agreement or DSA does what is says on the tin. It is an agreement between two organisations to share personal data. It is a binding contractual document that either stands alone or forms part of a wider contract. You absolutely do need a DSA if you are sharing personal between organisations. The only real exceptions are if the data sharing is ad-hoc (for example, under the vital interests lawful basis) or I you have a statutory duty to share the information (payroll data to HMRC for example).
Often , but not always, the problem with DSAs is what they DON’T include.
The controller / processor relationship is not set out.
Under the GDPR a data controller decides what personal data is collected / shared and what processing may happen. The processor receives the personal data and processes it on the controller’s instructions. Controllers have certain accountabilities for their data processors’ handling of the personal data they share. It’s therefore important that the DSA is clear who is the controller and who is the processor. Alternatively, if all parties are controllers or controllers in common, this should also be clear.
For example:
- A company wants to send marketing materials by post to existing customers. It asks another business to design, print and send the mailing and gives that business the mailing addresses of the customers to target. In this scenario the company initiating the campaign is the controller and the business printing and sending it is the processor. The controller is accountable for ensuring the processor only uses the personal data for the agreed purposes, and overseeing the processor’s GDPR compliance. The processor cannot retain or reuse the personal data one the mailing is done, but of course the controller can.
- A company is recruiting and uses a recruitment agency to seek and review applications before sending a recommended interview list to the company. The company and the agency are likely to be joint controllers because the agency will have some flexibility about deciding what and how much personal data to collect from applicants, and will make decisions about people based on that information. The agency will then pass on that personal data for further processing to the company. Crucially the recruitment agency decides what information to share with the hiring company.
What happens when the DSA ends?
Any DSA should make clear what happens to personal data on termination of the agreement. This can be when the underlying purpose for the data sharing has been successfully completed. They also have a termination clause “either party can terminate this agreement by given seven days’ notice in writing” etc. Any termination clause should also set out what happens to personal data once the data sharing agreement is no longer required or in force. This is important partly because controllers are responsible for the compliance of data processors including preventing unauthorised processing and compliance with the principles around data retention. However, too often DSAs omit this crucial information.
Sign Up Here:
This is less of an issue than it used to be but still a lot of template data sharing agreements rely on consent as the lawful basis for data processing and don’t consider the other options. This could be because a standard template has not been adapted, or because of a lingering assumption that consent is the King of Lawful Bases. It isn’t. It is just one of many. This is partly important because people’s data rights operate a little differently depending on what lawful basis you are relying on for data processing. It also impacts the controller because if someone were to withdraw consent for data processing they need to let the processor know and ensure they stop using that person’s information. That requires more vigilance and oversight than say relying on the performance of a contract as your lawful basis. Also, if the controller is a public authority and processing personal data on that basis the processor cannot rely on that and another lawful basis should be found, and set out. Finally, if relying on legitimate interests then discussing the appropriate balancing test that shows the processing is a reasonable intrusion into people’s privacy should be set out. Sometimes people enter into DSAs without consulting a relevant expert such as a Data Protection Officer (DPO). This is always a good idea because they may spot things mere mortals may not. For example, I was asked to review a DSA that contain a clause reading that the processor may reuse personal data that it has received in error and that they can share personal data received properly with “carefully selected third parties”. Neither of these are acceptable. It is an offence under s.170 of the Data Protection Act to knowingly or recklessly obtain personal data without the consent of the controller, and also to retain and process that data. The controller really should know who, if anyone, else their personal data may be shared with and why, and have control over whether this happens. In most instances such wider sharing will be completely unnecessary. And, under Article 28 of the UK GDPR, if a processor does undertake this wider sharing they risk becoming a data controller in their own right with all the responsibilities and accountabilities that involves. This is one of my favourites because it shows either the DSA template is remarkably out of date or has not been updated or drafted properly. Obviously the correct Act is the 2018 Data Protection Act and if any DSA has this kind of error my advice is to hand it back to the author/sender and say you do not intend to review the document further until these basic mistakes have been rectified. Plus six months’ free post course support to help you apply your learning “Interested in Becoming a GDPR Champion? Get The Brochure Here“ Rated 4.8 out of 5 on Trustpilot The issues described above an be avoided with some fairly simply planning: A data sharing agreement is a document that the Information Commissioner or the courts can expect to rely on in the event of a complaint, dispute between the parties or data breach so it is hugely important to ensure it is accurate and comprehensive.There is an overreliance on consent, or the lawful basis isn’t clear.
The DSA has not been reviewed by a Data Protection Officer
The DSA refers to the Data Protection Act 1998
Learn from the Experts
This GDPR training course includes the following modules:

Conclusion
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: