Data Sharing Policy Requirements: GDPR, HIPAA, and State Laws

Data sharing policy requirements come from several places at once: the core contract terms every transfer needs, the security and breach rules layered on top, and the specific statutes that govern whichever type of data you are moving. A workable policy names the parties, limits the purpose, restricts the data to what the recipient actually needs, sets retention and destruction rules, mandates encryption and access controls, assigns breach notification duties, and then satisfies whichever framework applies, whether that is the GDPR, HIPAA, the Gramm-Leach-Bliley Act, COPPA, FTC Section 5, or one of the state privacy laws now in force in more than 20 states.

What Every Policy Must Contain

Start with scope. The policy needs to identify which datasets are eligible for external transfer and which stay in-house. Most organizations sort information into tiers: data that directly identifies a person (names, government ID numbers, biometric data) and de-identified datasets stripped of those markers. That line drives everything downstream, from encryption strength to notification duties.

Name the parties and their roles. The entity providing the data and the entity receiving it carry different obligations, and ambiguity is where disputes begin. Spell out the specific organizations involved, their authorized contacts, and whether the recipient can bring in subcontractors. If a vendor plans to pass data to its own service provider, the policy has to say whether that is permitted and on what conditions.

Lock in purpose limitation. If you share customer records with a logistics partner for order fulfillment, the partner cannot repurpose that data for its own marketing without separate authorization. This restriction appears in virtually every major privacy framework, and violating it is one of the fastest paths to enforcement.

Apply data minimization. Under the GDPR, personal data must be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.”1General Data Protection Regulation (GDPR). Art. 5 GDPR – Principles Relating to Processing of Personal Data Translate that into concrete policy language: a payment processor gets transaction data, not full customer profiles. Over-sharing creates liability without adding value.

Close with retention and destruction. State how long the recipient may keep the data and what happens when the arrangement ends. The standard options are return of the data or a certificate of destruction confirming permanent deletion. Without these terms, your data lives on someone else’s servers indefinitely, accumulating risk you no longer control.

Security Terms That Belong in the Policy

Technical safeguards protect data both in transit and at rest. Policies commonly mandate AES-256 encryption for stored data and TLS for data in motion. Organizations handling government information or operating under federal contracts often need to meet FIPS 140-3 standards, which define tiered security requirements for cryptographic modules ranging from basic software protections up to hardware resistant to physical tampering.

Access controls carry equal weight. Require role-based access so only authorized personnel on the recipient’s side can see or manipulate shared data. Multi-factor authentication, audit logging, and automatic session timeouts are standard. Many policies also require regular security assessments, either through third-party penetration testing or compliance audits, to confirm the recipient still meets the standards that existed when the agreement was signed.

Name the approved transfer method. Whether the data moves via APIs, secure file transfer protocols, or encrypted cloud storage, prohibit alternatives in writing. Letting a recipient download data to an unencrypted laptop because the API was temporarily down is exactly the kind of workaround that produces breaches.

Breach Notification Terms

A policy that ignores breaches is incomplete. All 50 states, the District of Columbia, and U.S. territories have breach notification laws requiring businesses to notify affected individuals when personal information is compromised. Deadlines vary; some jurisdictions require notice within 30 days of discovery.

Under HIPAA, covered entities and business associates must notify the U.S. Department of Health and Human Services of any breach of unsecured protected health information. Breaches affecting 500 or more individuals must be reported without unreasonable delay and no later than 60 calendar days from discovery. Smaller breaches may be reported annually, though nothing prevents earlier reporting.2U.S. Department of Health and Human Services. Submitting Notice of a Breach to the Secretary

The GDPR runs on a tighter clock. Controllers must notify their supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to threaten individuals’ rights. Late notifications require an explanation for the delay.3General Data Protection Regulation (GDPR). Art. 33 GDPR – Notification of a Personal Data Breach to the Supervisory Authority In the contract, assign responsibility for detection and reporting, and set the processor-to-controller notification window short enough that the controller can still meet its 72-hour deadline.

GDPR Requirements

The GDPR applies to any organization that processes data belonging to individuals in the European Union, regardless of where the organization itself sits. Four areas shape the policy: joint controller arrangements, processor contracts, international transfers, and impact assessments.

Joint Controllers and Processor Contracts

When two organizations jointly decide why and how personal data gets processed, the GDPR treats them as joint controllers. Article 26 requires a transparent arrangement spelling out each party’s responsibilities, particularly around informing individuals and handling their rights requests, with the essence of the arrangement made available to the people whose data is involved.4General Data Protection Regulation (GDPR). Art. 26 GDPR – Joint Controllers

When one organization processes data on behalf of another, Article 28 requires a written contract binding the processor to the controller’s instructions. The contract must cover the subject matter and duration of processing, the categories of personal data involved, and the processor’s obligation to act only on documented instructions from the controller.5General Data Protection Regulation (GDPR). Art. 28 GDPR – Processor The absence of that contract is itself a violation, separate from any mishandling of the data.

International Transfers

Moving personal data outside the European Economic Area triggers Articles 44 through 49. The default rule: transfers may proceed only if the destination country provides an adequate level of protection through a formal adequacy decision, or if the parties implement approved safeguards.6General Data Protection Regulation (GDPR). Art. 44 GDPR – General Principle for Transfers The most common safeguard is Standard Contractual Clauses, pre-approved templates organizations incorporate into their data sharing agreements to legitimize cross-border transfers.7General Data Protection Regulation (GDPR). Art. 46 GDPR – Transfers Subject to Appropriate Safeguards

Violations of the transfer rules, core processing principles, or data subject rights carry fines of up to €20 million or four percent of total worldwide annual turnover from the prior fiscal year, whichever is higher.8General Data Protection Regulation (GDPR). Art. 83 GDPR – General Conditions for Imposing Administrative Fines

Data Protection Impact Assessments

Before launching a high-risk arrangement, the GDPR requires a Data Protection Impact Assessment. Article 35 lists three situations where an assessment is mandatory: automated profiling that produces legal effects on individuals, large-scale processing of sensitive categories like health or criminal records, and systematic monitoring of publicly accessible areas on a large scale.9General Data Protection Regulation (GDPR). Art. 35 GDPR – Data Protection Impact Assessment In practice, any new project involving personal information at scale should at least trigger a preliminary risk evaluation. Skipping a required assessment can draw fines on its own.

U.S. Sector Laws That Trigger Specific Clauses

There is no single federal statute covering all data sharing. Which law applies depends on the type of data and the industry.

HIPAA

Any covered entity that shares protected health information with a service provider must have a Business Associate Agreement in place before the first disclosure. The agreement must establish the permitted uses of the information, require the business associate to use appropriate safeguards, and require the associate to report any unauthorized use or disclosure, including breaches of unsecured health data.10eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements These duties flow downstream: subcontractors who touch the data need their own agreements with the same restrictions.

A separate instrument applies to limited data sets, meaning health information stripped of most direct identifiers such as names, phone numbers, and Social Security numbers. For research, public health, or healthcare operations purposes, a covered entity may share a limited data set if the recipient signs a Data Use Agreement establishing who can access the data, what they can do with it, and prohibiting any attempt to re-identify individuals.11eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information A Business Associate Agreement covers identifiable health information; a Data Use Agreement covers limited data sets. Using the wrong instrument exposes both parties to enforcement.

Gramm-Leach-Bliley Act

Financial institutions sharing nonpublic personal information with nonaffiliated third parties must first provide a clear notice of their information-sharing practices and give the customer an opportunity to opt out.12Office of the Law Revision Counsel. 15 USC 6802 – Obligations With Respect to Disclosures of Personal Information If the third party performs services on behalf of the institution, an exception allows sharing without opt-out rights, but only if the institution enters a contract requiring the third party to maintain confidentiality.

COPPA

Websites and online services directed at children under 13, or those with actual knowledge that they are collecting information from a child, must comply with the Children’s Online Privacy Protection Act. Operators must post a clear notice about what information they collect from children and how it is used, and must obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information.13Office of the Law Revision Counsel. 15 USC 6502 – Regulation of Unfair and Deceptive Acts and Practices in Connection With the Collection and Use of Personal Information From and About Children on the Internet Parents retain the right to review the data collected, request its deletion, and stop future collection.

FTC Section 5

Even when no sector-specific law applies, the Federal Trade Commission can act against organizations whose data sharing practices are unfair or deceptive under Section 5 of the FTC Act.14Office of the Law Revision Counsel. 15 USC 45 – Unfair Methods of Competition Unlawful; Prevention by Commission If your published policy says one thing and your actual practices do another, the FTC treats that gap as a deceptive act. The agency has brought enforcement actions resulting in settlements of tens of millions of dollars against companies that failed to live up to their own stated privacy commitments.15Federal Trade Commission. Privacy and Security Enforcement The policy is a binding representation, not a marketing document.

State Privacy Laws

More than 20 states have enacted comprehensive consumer privacy laws that impose their own data sharing requirements. While specifics vary, they generally require businesses to disclose what categories of personal information are collected and shared, grant consumers the right to opt out of the sale or sharing of their data, and authorize civil penalties for noncompliance. Penalty ranges across states typically fall between roughly $2,500 and $7,500 per violation, with some states adjusting these amounts for inflation annually and imposing higher fines for violations involving children’s data.

A policy written to satisfy only one jurisdiction will almost certainly fall short in others. Most state laws reach any business that processes data belonging to that state’s residents regardless of where the business is located, so organizations with multi-state customers should build to the strictest applicable requirement. Tracking which laws apply, and updating the policy as new statutes take effect, is an ongoing compliance obligation.

Building and Maintaining the Policy

A functional policy starts with a data inventory. Map every piece of information eligible for external transfer: where it originates, where it flows, how it is stored, and who currently has access. Organizations that skip this step end up with policies that sound comprehensive on paper but miss whole data categories in practice.

Document the full legal names and contact information of every third-party recipient, including vendors, contractors, and research partners. For each recipient, record the specific purpose of the sharing, the categories of data involved, and the technical method of transfer, whether that is an API connection, secure file transfer protocol, or an encrypted cloud storage environment. Those details drive the security language and determine which legal frameworks apply.

Define retention periods for each category of shared data. HIPAA, GLBA, and various state laws impose their own retention floors, and your policy should reflect the longest applicable requirement for each data type, along with a clear rule for when and how the data must be purged once that period expires. If the arrangement involves high-risk processing under the GDPR, complete the Data Protection Impact Assessment before finalizing the policy; regulators expect to see the DPIA as evidence that risks were considered before data started moving.

Publish the finalized policy where users and regulators can find it, typically in the legal or privacy section of your public website, and distribute it internally to the employees who handle shared data. For business partnerships, secure written acknowledgment from each party. For consumer-facing policies, notify registered users of the new terms and display the effective date prominently.

Version control is where organizations most often fail. Timestamp every revision, assign a version number, and archive previous versions alongside the current one. Regulators and auditors expect access to the complete version history so they can determine exactly which terms were in effect during any given period. Maintain a log recording which version was active on each date, when notifications were sent, and which recipients acknowledged the terms. That paper trail is often the difference between demonstrating compliance and reconstructing it after the fact.