¶¶Òõ¶ÌÊÓÆµ

Third Party Data Sharing Agreement Template for United States

Create a bespoke document in minutes,  or upload and review your own.

4.6 / 5
4.8 / 5

Let's create your Third Party Data Sharing Agreement

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get your first 2 documents free

Your data doesn't train Genie's AI

You keep IP ownership of your information

Key Requirements PROMPT example:

Third Party Data Sharing Agreement

"I need a Third Party Data Sharing Agreement to allow our healthcare software company to share patient data with our analytics provider in compliance with HIPAA, starting from March 2025."

Document background
The Third Party Data Sharing Agreement is essential for organizations that need to share personal, sensitive, or confidential data with third parties while maintaining compliance with U.S. privacy laws and regulations. This agreement has become increasingly important due to stricter data protection requirements and growing cyber security concerns. It specifically addresses data handling procedures, security measures, breach notifications, and compliance requirements while protecting both the data controller and processor's interests.
Suggested Sections

1. Parties: Identification and details of all parties involved in the agreement

2. Background: Context and purpose of the data sharing arrangement

3. Definitions: Key terms used throughout the agreement including data types, security measures, and compliance requirements

4. Scope of Data Sharing: Detailed description of what data will be shared, purposes of sharing, and permitted uses

5. Data Protection Obligations: Security measures, compliance requirements, and responsibilities of each party

6. Confidentiality: Obligations regarding the confidential treatment of shared data

7. Data Security: Specific security measures and protocols to be implemented

8. Data Subject Rights: Procedures for handling data subject requests and rights

9. Term and Termination: Duration of agreement, renewal terms, and termination conditions

10. Liability and Indemnification: Allocation of risk and responsibility between parties

Optional Sections

1. International Transfer Provisions: Additional provisions for cross-border data transfers and compliance with international data protection laws

2. Industry-Specific Compliance: Specific provisions for HIPAA, GLBA, FERPA, or other industry-specific regulations

3. Breach Notification Procedures: Detailed procedures for handling and reporting data breaches

4. Audit Rights: Provisions for conducting security and compliance audits

5. Data Retention and Destruction: Requirements for maintaining and destroying data after agreement termination

Suggested Schedules

1. Schedule A - Data Processing Details: Detailed description of data types, processing activities, and purposes

2. Schedule B - Security Requirements: Technical and organizational security measures to be implemented

3. Schedule C - Contact Details: Key contacts for data protection matters and breach notification

4. Schedule D - Sub-processor List: List of approved sub-processors and their roles

5. Schedule E - Compliance Checklist: Checklist of applicable regulatory requirements and compliance measures

Authors

Alex Denne

Head of Growth (Open Source Law) @ ¶¶Òõ¶ÌÊÓÆµ | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents | Serial Founder & Legal AI Author

Clauses






























Industries

Privacy Act of 1974: Federal law establishing a code of fair information practices governing the collection, maintenance, use, and dissemination of personally identifiable information maintained by federal agencies

Federal Trade Commission Act: Prohibits unfair or deceptive practices affecting commerce, including companies' privacy and data security practices

Electronic Communications Privacy Act: Extends government restrictions on wire taps to include transmitted electronic data and stored electronic communications

HIPAA: Provides data privacy and security provisions for safeguarding medical information and healthcare records

Gramm-Leach-Bliley Act: Requires financial institutions to explain their information-sharing practices and protect sensitive data

FERPA: Federal law protecting the privacy of student education records and applying to all schools receiving federal funding

COPPA: Federal law imposing requirements on operators of websites or online services directed to children under 13 years of age

CCPA/CPRA: California state laws providing consumers with rights regarding the collection and use of their personal information by businesses

Virginia Consumer Data Protection Act: Comprehensive state privacy law providing Virginia residents rights over their personal data

Colorado Privacy Act: State law providing Colorado residents with data privacy rights and imposing obligations on data controllers and processors

GDPR Compliance Requirements: EU regulation considerations for cross-border data transfers affecting US companies handling EU resident data

Privacy Shield Framework: Framework for regulating transatlantic exchanges of personal data for commercial purposes between the EU and US

NIST Cybersecurity Framework: Voluntary guidance for private sector organizations to better manage and reduce cybersecurity risk

ISO 27001: International standard for information security management systems (ISMS)

PCI DSS: Information security standard for organizations that handle branded credit cards from major card schemes

Teams

Employer, Employee, Start Date, Job Title, Department, Location, Probationary Period, Notice Period, Salary, Overtime, Vacation Pay, Statutory Holidays, Benefits, Bonus, Expenses, Working Hours, Rest Breaks,  Leaves of Absence, Confidentiality, Intellectual Property, Non-Solicitation, Non-Competition, Code of Conduct, Termination,  Severance Pay, Governing Law, Entire Agreemen

Find the exact document you need

Controller To Controller Agreement Gdpr

A US law-governed agreement establishing GDPR-compliant data sharing arrangements between independent data controllers handling EU personal data.

find out more

Personal Data Sharing Agreement

A US-compliant agreement governing the sharing of personal data between organizations, ensuring privacy law compliance and data protection.

find out more

Office Sharing Agreement

A U.S.-compliant legal agreement establishing terms for sharing office space between multiple parties, including space allocation, costs, and usage rights.

find out more

Data Exchange Agreement

A U.S.-governed agreement that establishes terms and conditions for sharing data between parties while ensuring regulatory compliance.

find out more

Third Party Data Sharing Agreement

A U.S.-compliant legal agreement governing the sharing and protection of data between organizations.

find out more

Content Sharing Agreement

A U.S.-governed agreement establishing terms for sharing and distributing digital content between parties, including rights, permissions, and compliance requirements.

find out more

Download our whitepaper on the future of AI in Legal

By providing your email address you are consenting to our Privacy Notice.
Thank you for downloading our whitepaper. This should arrive in your inbox shortly. In the meantime, why not jump straight to a section that interests you here: /our-research
Oops! Something went wrong while submitting the form.

³Ò±ð²Ô¾±±ð’s Security Promise

Genie is the safest place to draft. Here’s how we prioritise your privacy and security.

Your documents are private:

We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

Our bank-grade security infrastructure undergoes regular external audits

We are ISO27001 certified, so your data is secure

Organizational security

You retain IP ownership of your documents

You have full control over your data and who gets to see it

Innovation in privacy:

Genie partnered with the Computational Privacy Department at Imperial College London

Together, we ran a £1 million research project on privacy and anonymity in legal contracts

Want to know more?

Visit our for more details and real-time security updates.