Data Use Agreement For Research Template for England and Wales

Generate a bespoke document

What is a Data Use Agreement For Research?

A Data Use Agreement For Research is essential when organizations need to share data for research purposes while maintaining legal compliance and data protection standards. This agreement, governed by English and Welsh law, is particularly crucial in today's data-driven research environment where proper handling of sensitive information is paramount. It addresses key requirements under UK GDPR and the Data Protection Act 2018, specifying how data can be used, stored, and protected throughout the research process. The agreement is designed to protect both the data provider's interests and the researcher's ability to conduct meaningful research while maintaining appropriate data protection standards.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Use Agreement For Research

A Data Use Agreement For Research is a specialized contract that governs how data can be shared, used, and protected when organizations collaborate on research projects. Under England and Wales law, these agreements are essential for ensuring compliance with data protection legislation while enabling valuable research activities that benefit society.

When do you need this document?

You need this agreement whenever your organization plans to share data for research purposes with external parties. This includes collaborations between universities and pharmaceutical companies for clinical trials, sharing anonymized patient data between NHS trusts and academic institutions, or when contract research organizations access proprietary datasets from sponsors. The agreement is particularly crucial when handling personal data, commercially sensitive information, or data subject to specific regulatory requirements. Research institutions increasingly require these agreements before approving data sharing proposals, and funding bodies often mandate their use as a condition of grant approval.

Key legal considerations

The agreement must clearly define the scope of permitted data use, ensuring it aligns with the original purpose for which data was collected under data protection principles. Purpose limitation clauses prevent data being used beyond agreed research objectives, while data minimization provisions ensure only necessary data is shared. Security obligations must specify technical and organizational measures for protecting data, including encryption, access controls, and breach notification procedures. Intellectual property clauses should address ownership of research outputs and any resulting publications or patents. The agreement should include provisions for data retention periods, secure deletion requirements, and procedures for handling data subject rights requests. Liability and indemnification clauses protect parties from potential breaches or misuse of shared data.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, data sharing for research purposes requires a lawful basis, typically legitimate interests or explicit consent depending on the data type. The agreement must demonstrate compliance with data protection principles, including lawfulness, fairness, transparency, and accountability. Special category data, such as health information, requires additional safeguards and may need explicit consent or substantial public interest grounds. The Freedom of Information Act 2000 may apply to publicly funded research, requiring consideration of transparency obligations. Common law duty of confidentiality applies when sharing confidential information, particularly in healthcare research contexts. For clinical trials, compliance with Clinical Trials Regulation and Good Clinical Practice guidelines is mandatory. The agreement should specify the legal basis for processing, include privacy impact assessment requirements, and ensure appropriate technical and organizational measures meet UK standards for data security and protection.

GOVERNING LAW

Applicable law

This Data Use Agreement For Research is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: UK General Data Protection Regulation - The primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles for data processing, security, and subject rights

Data Protection Act 2018: The UK's implementation of data protection law that works alongside UK GDPR, providing specific provisions for certain types of data processing including research

Freedom of Information Act 2000: Legislation that provides public right of access to information held by public authorities, which may impact research data sharing and transparency requirements

Common Law Duty of Confidentiality: Legal obligation to keep personal information confidential when obtained in circumstances where a duty of confidence is expected

Clinical Trials Regulation: Regulations governing clinical trials and research, including specific requirements for data handling in medical research contexts

Human Tissue Act 2004: Legislation regulating the storage and use of human tissue, including associated data in research contexts

Health Research Authority Requirements: Regulatory framework specific to health research in the UK, including guidelines for data protection in research studies

ICO Guidelines: Information Commissioner's Office guidance on data protection compliance, including specific provisions for research data

Research Ethics Committee Requirements: Standards and requirements set by ethics committees for conducting research, including data protection and subject privacy

Caldicott Principles: Guidelines for handling patient-identifiable information in healthcare settings, including research contexts

Industry Codes of Practice: Sector-specific guidelines and best practices for data handling in research contexts

International Data Transfer Requirements: Regulations governing the transfer of research data across international borders, including adequacy decisions and appropriate safeguards

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it