When data stewards decide to share institutional data, they may need to formally document the decision and accompanying requirements in a Memorandum of Understanding (MOU) or a Data Sharing Agreement (DShA).
Memorandum of Understanding (MOU)
MOUs are documents that record the mutual understanding of requester responsibilities and appropriate data use. MOUs are used in situations where formal documentation of expectations is prudent.
MOU Template coming soon.
Data Sharing Agreement (DShA)
The DShA is a binding agreement that governs data sharing terms and is signed by an individual with delegated signature authority. It is required in higher-risk or external sharing scenarios. Note: This is not a data security agreement (DSA).
DShA Template coming soon.
When to Use Data Agreements
Requests for low-sensitivity data do not require MOU or DShA, but appropriate documentation in the data request system is strongly recommended.
Requests for data of moderate or higher sensitivity must be well-documented and are subject to the following guidance based on the requestor’s affiliation with the university:
U-M Faculty and Staff
| Scenario | Agreement | Considerations |
|---|---|---|
| Ongoing use for operations | None | Provide system access and review periodically. Training is likely necessary. |
| One-time use for research or operations | MOU recommended | Consider data sensitivity level, consider IRB involvement, consult with ITS Information Assurance and OGC as needed. |
U-M Students
| Scenario | Agreement | Considerations |
|---|---|---|
| Class/research project (supervised by faculty) | MOU required | Seek MOU approval from faculty; consider IRB involvement. |
| U-M sponsored student org | MOU recommended | Consider data sensitivity level, consider IRB involvement, consult with ITS Information Assurance and OGC as needed. Data Steward determines sharing conditions. IRB may need to be involved. |
| Non-UM or voluntary student org or business venture | DShA required | Involve the Data Steward. |
External Partners
| Scenario | Agreement | Considerations |
|---|---|---|
| Third-party vendor (ongoing or one-time) | Contract and Data Security Agreement required | Consult with Procurement Services and ITS Information Assurance, depending on data sensitivity. |
| Ongoing use by non-UM researcher | DShA required | Involve the Data Steward. Seek IRB approval. |
| One-time use by non-UM researcher | DShA preferred, binding MOU acceptable | Involve the Data Steward. Seek IRB approval. |
Signed agreements must be maintained by the data steward in an organized repository that is appropriately protected and allows access to authorized individuals.