Skip to content

Data use agreement checklist for release operations

A data use agreement checklist should help a team review the executed terms and then apply them to actual data use. This checklist is an operational aid, not a universal contract template or legal opinion.

What the operating record should prove

1. Identify the authority and parties

Record the full executed agreement, amendments, effective date, expiration date, parties, signatories, institutional owners, related approvals, and governing project or protocol. Verify that the copy is complete and current.

2. Confirm purpose and permitted users

Write the approved purpose in language specific enough to compare with a release request. Identify named users, eligible roles or institutions, collaborators, subcontractors, and any required institutional authorization.

3. Define the data scope

List permitted and required fields, populations, cohorts, dates, geographies, source systems, refreshes, linkages, and derived outputs. If the agreement uses definitions or exhibits, cite them directly.

1. Identify the authority and parties

Record the full executed agreement, amendments, effective date, expiration date, parties, signatories, institutional owners, related approvals, and governing project or protocol. Verify that the copy is complete and current.

  • Executed document and amendments
  • Provider and recipient legal names
  • Authorized signatories
  • Effective and expiration dates
  • Project, protocol, award, or repository identifiers
  • Agreement owner and renewal contact

2. Confirm purpose and permitted users

Write the approved purpose in language specific enough to compare with a release request. Identify named users, eligible roles or institutions, collaborators, subcontractors, and any required institutional authorization.

  • Permitted research or business purpose
  • Prohibited uses
  • Named or eligible recipients
  • User onboarding and removal
  • Training or attestation requirements
  • Library Card or committee authorization

3. Define the data scope

List permitted and required fields, populations, cohorts, dates, geographies, source systems, refreshes, linkages, and derived outputs. If the agreement uses definitions or exhibits, cite them directly.

  • Field allowlist and exclusions
  • Population predicates
  • Row-level restrictions
  • Linkage and enrichment rules
  • Query or aggregation limits
  • Derived data and output rules

4. Record handling conditions

Capture approved environment, transfer method, security requirements, access end date, maximum retention, return or destruction obligations, incident duties, publication, attribution, and redisclosure limits.

  • Approved platform or environment
  • Encryption and transfer method
  • Retention and destruction evidence
  • Publication review or embargo
  • Redisclosure and downstream recipients
  • Breach or incident notification

5. Design the release approval

Identify which conditions can be checked deterministically and which require privacy, legal, security, data-owner, or committee judgment. Define approval order, quorum, exception authority, and required evidence before the first request arrives.

6. Preserve evidence and manage change

For every release, retain the agreement version, proposed purpose and recipient, artifact hashes, findings, approvals, exceptions, policy state, and final evidence. Amendments, changed payloads, new users, and expired approvals should trigger revalidation.

Why this page exists

Keep decisions human and evidence explicit.

Practical guidance that connects policy documents to observable release controls.

Primary references

Confirm requirements against current source material.

Requirements and vendor capabilities change. Confirm the current source and your approved QC plan before changing a production process.

From evidence to conclusion

Put the guidance inside a reproducible release record.

Run five release preflights with the source terms, artifacts, checks, approvals, exceptions, and evidence kept together.

Start free See public pricing