Data Use Agreements

Overview

A Data Use Agreement (DUA) is a legal agreement that governs the sharing of data between Georgetown University and external entities. DUAs are essential for protecting data confidentiality, ensuring ethical research conduct, and complying with applicable legal, funding, and institutional requirements.

To request a DUA, the PI and/or a project team member, must initiate and submit their request through the DUA module in GU-PASS. The DUA Intake Form is submitted within the module, along with any supporting documents (e.g., draft agreement from external entity for incoming data, data description, IRB info). Guidance on how to submit a request for a DUA in the DUA module in GU-PASS can be found here.

If you have any questions about the DUA process or issues accessing the DUA module, please contact the Joint Office of Research Administration (JORA) at JORA@georgetown.edu and/or Robyn Sutton, Senior Pre-Award Grant Administrator for DUAs at robyn.sutton@georgetown.edu.

DUA Requirement Criteria

A DUA is typically needed when:

IRB Considerations

If you plan to conduct human subjects research, you must submit to the Georgetown IRB and receive approval prior to beginning any research. Please refer to Georgetown’s IRB website for information on how to submit an IRB request. Please note, JORA cannot fully execute any DUAs until the GU IRB has been approved. Researchers should consult directly with Georgetown’s IRB office to ensure compliance.

Common Data Types

Centers for Medicare & Medicaid Services (CMS) Data

Access to certain Centers for Medicare & Medicaid Services (CMS) research data is subject to CMS data use, privacy, and information security requirements. Depending on the type of data requested and the approved method of access, investigators may be required to access the data through the CMS Virtual Research Data Center (VRDC) or use an approved Georgetown computing environment that meets applicable CMS security requirements.

For CMS data that will be accessed, stored, or maintained within a Georgetown managed environment, additional information security review and documentation may be required, including an applicable Data Management Plan Self-Attestation Questionnaire (DMP SAQ) and Investigators will need to work with Georgetown’s University Information Security (UIS) team to get this set up.

Investigators requesting CMS data should submit a DUA request through GU-Pass and provide information regarding the specific CMS data requested and the proposed method for accessing and storing the data. JORA will coordinate with UIS and other appropriate Georgetown offices, as needed, to confirm that the proposed data environment and applicable CMS requirements have been reviewed before the DUA is finalized.

Important: Investigators should not download, transfer, or store CMS data in a Georgetown system or other computing environment unless that environment has been reviewed and approved by UIS for the applicable CMS data and DUA requirements.

Federal and NIH Controlled-Access Data Repositories

Some federal and NIH data repositories contain both publicly available information and controlled-access datasets. Although a repository, study, or dataset may be publicly searchable or viewable online, this does not necessarily mean that the underlying individual-level data are open-access or available for unrestricted use. The NIH has implemented Requirements for NIH Controlled-Access Data Repositories and Users, that may include institutional certification or approval and compliance with NIH information security requirements, including NIST SP 800-171, when applicable.

If you are requesting controlled-access data from NDA, dbGaP, or another federal or NIH repository, please submit a DUA request through GU-Pass for review of the applicable institutional terms and requirements. JORA will coordinate with UIS and other appropriate Georgetown offices, as needed, to confirm that the proposed data environment and applicable NIH requirements have been reviewed and approved before the DUA is submitted.

Important: Public availability of a repository or dataset description should not be interpreted as unrestricted access to the underlying data. Investigators should confirm whether the specific data requested are open-access or controlled-access before determining that a DUA or institutional review is not required.

Frequently Asked Questions – FAQ

Q: When do I need to obtain a DUA?

A: A DUA should be requested and entered into before there is any use or disclosure of a data set to an external entity

Q: Do DUAs require IRB approval?

A: Typically, yes, especially if the project involves human subjects research or identifiable/coded data. Fully de-identified data that prevents the re-identification of the individual is not considered human subjects research and typically does not require IRB approval, however, please consult with the GU IRB office to make that determination. Also, please note that JORA cannot fully execute a DUA until the GU IRB has been approved, if required.

Q: How long does DUA review take?

A: Timelines vary depending on completeness of the GU-PASS record submission, complexity of DUA terms, and required internal stakeholder reviews that may be needed (University Information Services, Office of General Counsel, IRB, Office of Technology Commercialization, Office of Research Oversight)

Q: Can I sign a DUA myself?

A: No – only an authorized signatory official in JORA may execute DUAs on behalf of Georgetown.

Q: Can I start analyzing data before the DUA is fully executed?

A: No – data cannot be transferred or used until the DUA is fully executed.