The Problem with One-Off Data Sharing Agreements
Many organisations find themselves trapped in a cycle of drafting new data sharing agreements for every new project or service. This approach is not only time-consuming but also creates significant governance risks. Each agreement is negotiated from scratch, leading to slow implementation of important initiatives.
Worse, this method often results in a collection of contradictory documents. One agreement might define security standards differently from another, creating confusion and compliance gaps. This fragmented approach makes it nearly impossible to maintain a clear, central view of all data sharing activities, a core requirement of the UK GDPR’s accountability principle.
The traditional method of creating separate agreements for each activity is inefficient and carries unnecessary risk. For organisations that collaborate frequently, such as those in primary care, one-off data sharing agreements stop working effectively. A more structured, proportionate, and risk-based approach is needed.
Introducing the Data Sharing Framework Model
A data sharing framework offers a practical and robust alternative. It separates the unchanging rules of data sharing from the specific activities that use them. Think of it as a master rulebook for a partnership. The core principles are agreed upon once by all parties, providing a stable foundation.
New projects or services are then added quickly through short, specific documents known as 'activity schedules'. This model ensures consistency, speeds up collaboration, and provides a clear audit trail. It is a tangible way to demonstrate accountability, a cornerstone of the UK General Data Protection Regulation (UK GDPR).
This approach aligns directly with guidance from the Information Commissioner's Office (ICO), which encourages organisations to have clear and systematic processes for sharing data. The ICO data sharing guidance emphasises the importance of documented procedures that protect individuals' information.
The Three-Layer Structure of an Effective Data Sharing Framework
An effective framework is typically built in three distinct layers. Once these are in place, adding a new service becomes a simple administrative task, rather than a lengthy legal negotiation. This structure brings clarity to roles, responsibilities, and processes.
Layer One: The Master Framework Agreement
The master agreement is the constitution for all data sharing activities conducted under the framework. It is signed once by the main parties, for instance, a GP federation and a local NHS trust. This document sets out the terms that apply to every activity.
Key elements covered in the master agreement include:
- Roles and Responsibilities: Clearly defining each party's role as a controller or processor.
- Security Expectations: Establishing baseline technical and organisational security measures, often referencing standards like the NHS Data Security Standards.
- Confidentiality and Lawful Basis: Confirming that each party is responsible for its own lawful basis and that confidential patient information is handled correctly.
- Breach Handling: A unified procedure for managing and reporting data breaches.
- Audit and Review: The rights of each party to audit compliance and the agreed frequency for reviewing the framework itself.
By settling these core terms once, organisations can focus their resources on assessing the specifics of each new data sharing activity.
Layer Two: Onboarding Parties and Defining Authority
This layer governs how new organisations join the framework. For example, individual GP practices can sign up to the master agreement established by their federation. In doing so, a practice formally becomes a party to the framework.
Crucially, the practice also authorises its federation to sign specific activity schedules on its behalf, but only within carefully defined limits. This authority is not a blank cheque. A practice can set boundaries, such as approving certain categories of activity while excluding others, or requiring prior notification before a schedule is signed. This ensures practices retain control over their data while avoiding the need to sign dozens of individual agreements.
Layer Three: The Activity Schedule
Each new data sharing initiative is documented in an activity schedule. This is a concise document that describes only the specifics of that single activity. It does not repeat the general terms from the master agreement, which keeps it short and focused.
An activity schedule typically details:
- The purpose of the data processing.
- The specific data categories involved.
- The lawful basis each party is relying on.
- Data retention periods for that activity.
- Any specific security arrangements required.
The schedule only takes effect once it has been assessed for risk and signed by the relevant parties. This structure ensures that speed does not come at the expense of safety and proper diligence.
Integrating Risk Assessment into the Process
One of the most powerful features of a data sharing framework is the integration of the Data Protection Impact Assessment (DPIA) directly into the activity schedule. In traditional models, the DPIA is often a separate document, created at a different time and sometimes poorly aligned with the final agreement.
By combining the two, the risk assessment is completed as the activity is being defined. This means the risks identified can shape the data sharing arrangements from the start, rather than being documented as an afterthought. This proactive approach to risk management is fundamental to UK GDPR compliance. For those new to the process, our guide on how to conduct a Data Protection Impact Assessment provides a clear, step-by-step method.
This combined form can also be proportionate. A low-risk data quality exercise does not require the same depth of assessment as a large-scale research project. The template can include a screening stage to determine the necessary level of scrutiny, ensuring the process remains efficient and risk-based.
The Practical Benefits of a Data Sharing Framework
Implementing a data sharing framework brings tangible benefits that strengthen governance and enable better collaboration.
- A Single View of Sharing: The framework maintains a central register of all active schedules. This gives organisations a complete, up-to-date overview of what data is being shared, with whom, and for what purpose. This is invaluable for audits and responding to ICO enquiries.
- Efficiency and Speed: A new service that might have taken months to approve can be onboarded in days, as only the activity-specific details need to be agreed.
- Consistency and Control: All sharing activities are held to the same high standards defined in the master agreement, eliminating contradictions and compliance gaps. Answering critical questions for patient data sharing becomes a standardised process.
- Simplified Management: The lifecycle of a service—from addition to amendment to retirement—is managed cleanly through the schedules, without ever needing to reopen the master agreement.
Myth vs Fact: Common Misconceptions
Myth: A framework reduces the level of scrutiny for new projects.
Fact: It allows for more focused and effective scrutiny. With the general rules already settled, the assessment process concentrates entirely on the specific risks and particulars of the new activity, ensuring nothing is overlooked.
Myth: The lead organisation, like a GP federation, takes on all the data protection risk.
Fact: A well-drafted framework clarifies the roles and responsibilities of each party. It ensures that each organisation remains the data controller for its own data and is accountable for its own compliance, which is a key part of managing UK GDPR processor risk effectively.
Frequently Asked Questions (FAQ)
Does this model only work in the NHS?
While the primary care example is common, this model is highly effective for any sector where multiple organisations collaborate regularly. This includes local authorities, academic research partnerships, and charitable networks.
How are existing agreements handled?
Existing bilateral agreements are not discarded. They can be migrated into the framework one by one, typically as they come up for renewal. Each old agreement becomes a new activity schedule under the single master agreement.
Who is responsible for maintaining the framework?
One organisation usually takes the lead in administering the framework and maintaining the central register of schedules. However, responsibility for compliance remains with each participating organisation as defined in the master agreement.
Moving from ad-hoc agreements to a structured data sharing framework is a significant step towards mature information governance. It replaces a slow, fragmented, and risky process with one that is efficient, consistent, and demonstrably compliant with UK GDPR.
This approach provides the clarity and assurance needed to share data confidently and responsibly, protecting individuals while enabling the vital work that relies on collaboration. If your organisation is considering how to improve its data sharing practices, developing a framework provides a clear path forward.