Definition
A legally binding written instrument between a data provider and a data recipient that specifies permitted uses of a dataset, confidentiality and security obligations, restrictions on redistribution, retention and destruction requirements, responsibilities for compliance, and remedies or sanctions for breach.

Principle

Principle
A DUA converts legal, ethical and contractual constraints on data (privacy, confidentiality, proprietary rights) into operational obligations and restrictions on recipients; lawful and enforceable limits are defined by the agreement subject to applicable external law which remains binding.

Demonstration

Demonstration
Illustrative scenario: A research data repository grants a university team access to a dataset under a DUA that restricts use to a named project, prohibits re‑identification and public redistribution, requires specified encryption during storage, and mandates deletion after project completion. The repository audits logs and, on evidence of prohibited sharing, follows the DUA’s sanctions process.

Misapplication

Misapplication
Assuming a DUA can authorize uses that violate applicable statutory privacy law or that it automatically allows unrestricted secondary research or public release; this mistake conflates contractual permissions with legal adequacy and ignores overriding legal or ethical constraints.

Consequence

Consequence
A DUA enables controlled data sharing by reducing uncertainty about permitted uses and by allocating compliance responsibilities; it can increase data availability for legitimate purposes while imposing obligations (technical, administrative, legal) that increase transaction costs and may restrict downstream reuse.

Reversal

Reversal
When datasets are in the public domain, explicitly licensed for unrestricted reuse, or when applicable law imposes stricter conditions (e.g., mandatory reporting obligations, criminal prohibitions) the DUA’s permissive provisions may not apply; conversely, effective de‑identification under agreed standards can reduce some DUA restrictions but does not eliminate all legal or ethical obligations.

Boundary

Boundary
Clearly within: a bilateral or multilateral written contract defining permitted uses, security measures, retention/destruction rules and enforcement for shared datasets. Boundary case: a license to use software that incidentally contains data but does not address user‑level data reuse obligations. Clearly outside: public datasets released without contractual restrictions or purely informational data provenance statements that do not impose use restrictions.

Semantic Tension

Semantic Tension
Openness and reuse (maximizing scientific or public value) ↔ Confidentiality, privacy and legal compliance (limiting risk and protecting subjects or rights holders).

Synthesis

Synthesis
A Data Use Agreement is the contractual mechanism that operationalizes legal and ethical constraints on shared data into specific, enforceable obligations for recipients, balancing access against risk and compliance costs.