A data use agreement governs how an external party can share, use, and protect data—often research data, student records, or other sensitive institutional information. Review focuses on scope (exactly what data is covered and for what purpose), permitted-use restrictions, security and storage requirements, re-disclosure limits, and how the agreement handles breach notification.
DUAs carry more institutional risk than a typical vendor contract because the underlying data is often subject to regulatory protection, which makes consistent review against a fixed set of institutional standards essential.
Every one-off review of each DUA increases the odds that a permissive term slips through, which is why it’s so important for universities to adopt a contract review tool with pre-built and customizable playbooks.