Data Sharing Agreement
_Template updated: 23 August 2026_
Template notice. This document is a starting point for a clinic and its company-associate. It does not become an agreement until both parties complete every applicable field, obtain legal and Data Protection Officer review, and sign it. It does not replace a privacy notice, consent form, lawful-basis assessment, employment or insurance advice, or a required regulatory filing.
Legal status. NPC Advisory No. 2025-01 confirms that a Data Sharing Agreement is optional, though the National Privacy Commission encourages one as evidence of accountability and good faith. A signed DSA does not create a lawful basis for sharing. Each party must identify an applicable basis under Republic Act No. 10173 before any sharing starts.
This Data Sharing Agreement (the Agreement) is made on [SIGNING DATE] between:
- [FULL REGISTERED NAME OF CLINIC], with address at [CLINIC ADDRESS] (the Clinic); and
- [FULL REGISTERED NAME OF EMPLOYER, HMO, INSURER, OR OTHER ASSOCIATED COMPANY], with address at [COMPANY ADDRESS] (the Company Associate).
The Clinic and the Company Associate are the Parties. Each Party acts as a Personal Information Controller for the personal data under its control. The Parties enter into this Agreement under Republic Act No. 10173, its Implementing Rules and Regulations, NPC Circular No. 2020-03, NPC Advisory No. 2025-01, NPC Circular No. 2016-03, the Health Privacy Code implementing Joint Administrative Order No. 2016-0002 where applicable, and other Philippine laws and professional rules that apply to the stated purpose.
1. Roles of the Parties and the solutions provider
The Clinic. The Clinic controls its patient and medical records. It decides why it collects them, which patient it associates with the Company Associate, which lawful basis permits each disclosure, and which records it may disclose for the stated purpose.
The Company Associate. The Company Associate controls the personal data it receives or creates for its employee, member, dependent, beneficiary, or covered-person functions. It decides who among its authorized personnel may use that data and remains responsible for each use, disclosure, download, copy, and retention.
ACCESS Software Solutions. ACCESS Software Solutions, DTI registration number 3377044, with registered address at San Luis, Baguio City, Philippines, operates CareClinic as the Parties' technology solutions provider. It supplies the Employer & HMO Portal, hosting, encrypted storage, access controls, audit logging, transmission, backup, maintenance, and support. To the extent that it handles personal data on a Party's documented instructions, it acts as that Party's Personal Information Processor.
ACCESS Software Solutions does not become a Party to this Agreement. NPC Circular No. 2020-03 permits only Personal Information Controllers to become parties to a DSA. The solutions provider does not select the Parties' purpose or lawful basis, approve a patient-company association, decide who should receive health information, or make employment, coverage, treatment, or benefit decisions. Its processor obligations arise under the CareClinic Terms of Use, the Privacy Policy, and any separate processing agreement signed with a Party.
The Parties shall not treat the presence of a portal field, report, or permission as proof that a disclosure is lawful or necessary.
2. Purpose and objectives
The Parties may share personal data only for this specific purpose:
[STATE THE PRECISE PURPOSE. Example: administration of the 2026 annual physical examination program for eligible employees of the Company Associate.]
The sharing has these measurable objectives:
- [OBJECTIVE 1]
- [OBJECTIVE 2]
- [OBJECTIVE 3, IF NEEDED]
Terms such as "HR purposes," "company use," "healthcare," or "insurance administration" do not define a sufficient purpose without the program, persons, decisions, and expected result. The Parties shall complete Schedule 1 before signing.
The Company Associate shall not use shared data for advertising, employee monitoring unrelated to the stated purpose, or the training of an artificial-intelligence model. It shall not use shared data for hiring, dismissal, promotion, discipline, reassignment, benefit denial, underwriting, or pricing unless Schedule 1 identifies that exact use, each Party documents a lawful basis for it, each affected data subject receives the required notice, and Philippine law permits the use.
3. Data subjects
This Agreement applies only to the following people:
[DESCRIBE THE DATA SUBJECTS. Example: current employees enrolled in the named annual physical examination program, and their participating dependants where applicable.]
The Clinic shall share data only for a person whom it has associated with the Company Associate in CareClinic. An association identifies the recipient; it does not prove a lawful basis or authorize unrelated disclosure.
4. Lawful basis and proportionality
Before the first disclosure, each Party shall document a lawful basis for every category of personal data it processes. Sensitive personal information, including health data, requires an applicable condition under section 13 of Republic Act No. 10173 or another law that authorizes the processing.
The Parties record their bases in Schedule 1:
- Clinic lawful basis: [IDENTIFY THE APPLICABLE PROVISION AND EXPLAIN WHY IT APPLIES]
- Company Associate lawful basis: [IDENTIFY THE APPLICABLE PROVISION AND EXPLAIN WHY IT APPLIES]
- Basis for sensitive personal information: [IDENTIFY THE APPLICABLE SECTION 13 CONDITION OR OTHER LAW]
The Parties shall apply transparency, legitimate purpose, and proportionality. They shall share the least amount of data needed, with the fewest authorized users, for the shortest period that can achieve the stated purpose.
If a Party relies on consent, it shall obtain a freely given, specific, informed indication of the data subject's will through written, electronic, or recorded means before the processing covered by that consent. The Party shall record when it obtained the consent, its scope, and any withdrawal.
If a data subject withdraws consent, the Clinic shall record the withdrawal in CareClinic. The portal will then refuse further Company Associate access to that person's clinic record. Each Party shall stop the processing that depended on the withdrawn consent, while retaining data only where another law requires or permits retention. Withdrawal does not invalidate processing completed before the withdrawal.
5. Personal data covered
The Parties shall select in Schedule 1 only the categories needed for the purpose. Depending on the selected portal areas, CareClinic can make the following categories available:
- identity and contact details, including name, date of birth, sex, email, phone number, and address;
- the clinic relationship and company-association reference;
- appointment or examination details, including date, type, status, clinician, and Annual Physical Examination forms or results;
- medical-record entries, including diagnosis, treatment, clinical entry notes, clinician, and date;
- prescription details, including medication, instructions, status, and prescribing clinician;
- charge and payment history, including amounts, status, receipt reference, and dates; and
- Company Associate health entries or custom fields, subject to the visibility chosen for each entry.
The platform does not expose the Clinic's patient-level insurance-information field, the Clinic's general patient medical-notes field, records held by another clinic, or records of a person who has no active association with the Company Associate.
The Company Associate shall not open, request, export, or use a portal area or data category omitted from Schedule 1. If the portal configuration cannot enforce a restriction required by Schedule 1, the Parties shall not use the portal for that sharing arrangement until they adopt an effective control.
6. Data supplied by the Company Associate
The Company Associate may give the Clinic enrollment lists, company identifiers, eligibility information, program instructions, or health entries needed for the stated purpose. It warrants that it has authority to collect and disclose that data and that it has given required notices to the affected data subjects.
A health entry created in the Company Portal belongs to the Company Associate's processing record. The user who creates it chooses whether the entry is visible to the Company Associate, the Clinic, or both. The Company Associate shall not mark an entry as visible to the Clinic unless that disclosure falls within this Agreement.
The Clinic shall not treat a Company Associate entry as a clinical finding without review by an authorized healthcare professional.
7. Method and operational details
The Parties will share data through the CareClinic Employer & HMO Portal. ACCESS Software Solutions provides the web application and secured middleware that resolve the Company Associate, verify the patient association, apply the portal's allowlisted record views, and log access before returning clinic data.
Online access follows these limits:
- Authorized recipient roles: [NAMED COMPANY ADMINISTRATORS, HR USERS, OR OTHER SPECIFIC ROLES]
- Authorized portal areas: [SELECT THE CATEGORIES FROM SECTION 5]
- Estimated number of data subjects: [NUMBER OR RANGE]
- Estimated access frequency: [PER DAY, WEEK, MONTH, OR PROGRAM CYCLE]
- Estimated volume per access or transfer: [NUMBER OR RANGE]
- Processing and storage location: [COUNTRY AND HOSTING PROVIDER, OBTAINED FROM ACCESS SOFTWARE SOLUTIONS]
- Approved exports or reports: [IDENTIFY OR WRITE NONE]
CareClinic transmits browser traffic through HTTPS using Transport Layer Security. It encrypts protected patient fields at rest with AES-256-GCM and clinic-specific key material. The application decrypts an authorized field inside an authenticated session when a permitted user opens it. The Parties acknowledge that encryption at rest does not protect information after an authorized user views, prints, photographs, downloads, or exports it.
The Parties do not grant public access. The Company Associate shall not disclose shared data to another employer, affiliate, insurer, broker, vendor, or government body unless law requires the disclosure or the Clinic and the data subject receive any notice required for a new lawful purpose. If a new recipient will act as a Personal Information Controller, the Parties shall review whether they need a new or amended sharing instrument before disclosure.
8. Transparency and notice
Before sharing begins, or at the next practical opportunity allowed by law, the Party that collected the data from the data subject shall give a clear privacy notice that identifies:
- the recipient or category of recipients;
- the purpose and objectives;
- the categories of personal data;
- the manner and extent of online access;
- the applicable data-subject rights and how to exercise them; and
- the DPO contact details of the Party responsible for the request.
Where consent supplies the lawful basis, the consent record must contain the information needed for specific and informed consent. A privacy notice does not turn invalid consent into valid consent.
An affected data subject may request a copy of the signed Agreement from either Party's DPO. The Party may redact trade secrets, confidential business information, security details, or information whose disclosure could endanger a system or personal data. The Party shall not redact the purpose, categories of data, controller identities, retention rules, data-subject procedures, or other information the data subject needs to understand the sharing.
9. Responsibilities of the Clinic
The Clinic shall:
- confirm the identity of the Company Associate and the scope of the program before creating an association;
- record the sharing basis and, where applicable, the consent date for each associated patient;
- provide accurate data and correct material errors brought to its attention;
- restrict the disclosure to the categories and purpose in Schedule 1;
- maintain its own privacy notice, DPO contact, sharing record, and required consent evidence;
- review access logs and remove an association or account access when sharing must stop; and
- retain its medical records under the laws and professional rules that govern the Clinic.
10. Responsibilities of the Company Associate
The Company Associate shall:
- limit portal accounts to identified personnel who need access for the stated purpose;
- assign the least-privileged role and review access at least every twelve months;
- train authorized users on confidentiality, appropriate use, incident reporting, and data-subject rights;
- prevent account sharing and remove access when a user changes role or leaves;
- verify the lawful basis before it uploads a roster, creates a note, downloads data, or discloses data onward;
- keep downloads and printed copies in approved locations and record permitted disclosures;
- avoid using shared health data as the sole basis for an adverse decision about a person; and
- delete or return data according to section 15 and Schedule 1.
11. Responsibilities of both Parties
Each Party shall keep its record of the sharing arrangement current, including Party and DPO contacts, legal bases, the signed Agreement, consent evidence where applicable, and the dates of consent and withdrawal.
Each Party remains responsible for data under its control or custody, including processing outsourced to ACCESS Software Solutions or another processor. A Party shall bind each processor to written data-protection duties and remain accountable for its processor's work as required by law.
The Parties shall cooperate in correcting inaccurate shared data. The Clinic remains the source of truth for its clinical record. The Company Associate remains the source of truth for its own eligibility, program, custom-field, and Company Associate health-entry data.
12. Security measures
Each Party shall maintain reasonable and appropriate organizational, physical, and technical safeguards that account for the volume and sensitivity of health information. At minimum, each Party shall:
- designate accountable personnel and enforce confidentiality duties;
- use unique accounts, strong authentication, role-based access, and session controls;
- enable multi-factor authentication for users with access to shared health data where CareClinic makes it available;
- protect workstations, mobile devices, paper files, removable media, exports, and backups;
- encrypt personal data in transit and at rest where the technology supports it;
- maintain access and security logs and review suspicious events;
- patch supported systems, manage vulnerabilities, and test restoration procedures;
- keep an incident-response process and documented breach register; and
- destroy data and media so that unauthorized persons cannot reconstruct them.
The Company Associate acknowledges that CareClinic records a Company Portal read in the Clinic's access log. The log identifies the user, company, record context, and time, but does not copy the clinical content viewed.
Security controls do not expand the permitted purpose or categories. A secure disclosure can still breach this Agreement or the law if it lacks a lawful basis or exceeds what the purpose requires.
13. Personal data breaches and security incidents
A Party that knows or reasonably believes that a security incident or personal data breach affects shared data shall notify the other Party's DPO without undue delay and no later than 24 hours after discovery. The first notice shall contain available facts and shall not wait for a completed investigation.
The reporting Party shall provide, as information becomes available:
- how and when the incident occurred and was discovered;
- the data and approximate number of people or records involved;
- likely consequences;
- containment, recovery, mitigation, and recurrence-prevention measures;
- notices already made or planned; and
- an incident contact.
Each Personal Information Controller remains responsible for deciding and making any notification required from it. Where NPC Circular No. 2016-03 requires notification, the responsible controller must notify the National Privacy Commission and affected data subjects within the applicable 72-hour period, subject to the Circular's rules on threshold, delay, exemption, and phased information. The Parties shall cooperate, preserve evidence, avoid inconsistent statements, and keep records of the assessment even where notification is not required.
ACCESS Software Solutions shall report a platform breach to the affected controller under its processor terms. The solutions provider may assist with facts, containment, and notification, but it does not assume a Party's controller duty unless law requires it to act.
14. Data-subject rights, complaints, and investigations
An affected person may exercise the rights available under Republic Act No. 10173, including rights to information, access, objection, correction, erasure or blocking, damages, and data portability where applicable.
The Clinic will address requests about the Clinic's patient and medical record. The Company Associate will address requests about its eligibility records, copies, exports, custom fields, health entries, and decisions. A Party that receives a request concerning the other Party shall send it to the correct DPO within two working days and tell the requester where it sent the request.
The Parties shall cooperate on a request that concerns both records. Neither Party may answer on behalf of the other without written authority. Nothing in this Agreement restricts a person's right to complain to the National Privacy Commission or the Commission's authority to decide responsibility for a violation.
For an NPC inquiry or investigation, the Clinic will coordinate matters involving the source clinical record and the Company Associate will coordinate matters involving its use or disclosure. Each Party shall preserve relevant records and respond for the processing it controls.
15. Retention, return, and disposal
The Company Associate shall retain shared data for [SPECIFIC RETENTION PERIOD] from [TRIGGER EVENT], unless a named law in Schedule 1 requires another period. "As long as needed" and indefinite retention do not satisfy this Agreement.
The Clinic shall retain its original medical records for the periods required by applicable health, professional, tax, insurance, and claims rules. Ending this Agreement does not require the Clinic to destroy an original record that it must keep or that remains necessary for patient care or a legal claim.
At expiry or termination, the Company Associate shall stop portal use and, within [NUMBER, MAXIMUM 30] days, return or securely destroy copies it no longer has authority to retain. It shall delete exports from user devices, shared drives, email, removable media, and active systems, then allow protected backup copies to expire under a documented backup cycle of no more than [BACKUP PERIOD]. An authorized officer shall certify completion in writing.
If law requires retention, the retaining Party shall identify the law, isolate the retained data from ordinary use, limit access, and destroy the data when the legal period ends.
ACCESS Software Solutions will revoke portal access when the Clinic removes the association, consent-dependent access is withdrawn, the Company Portal closes, or the Parties instruct it under their applicable processor terms. Platform retention and account-closure rules remain governed by the Terms of Use and Privacy Policy.
16. Term, review, and renewal
This Agreement starts on [EFFECTIVE DATE] and expires on [EXPIRY DATE]. It has no effect if the Parties leave either date blank or use an indefinite term. The expiry date must reflect the expected duration of the purpose.
The DPOs shall review the arrangement at least every twelve months and after a material incident, change in purpose, new data category, new recipient, new portal capability, or material change in law. The review shall record whether the purpose continues, whether the safeguards remain sufficient, and whether an incident requires a change.
The Parties may renew the Agreement through a written instrument signed before expiry. The renewal shall state its new fixed term, the reason for renewal, review findings, and each amendment. Continued portal access does not renew this Agreement.
17. Suspension and termination
Either Party shall suspend sharing at once where it reasonably believes that the sharing lacks a lawful basis, exceeds the purpose, threatens a data subject, or exposes data to an unacceptable security risk. The suspending Party shall notify the other DPO and document the reason.
This Agreement ends on the earliest of:
- its expiry without signed renewal;
- written agreement of the Parties;
- a material breach that the breaching Party fails to cure within [NUMBER] days after notice, where cure remains possible;
- immediate termination for an unlawful disclosure, serious security failure, or use outside the stated purpose;
- dissolution of a Party;
- completion or disappearance of the purpose; or
- an order or finding of a competent authority that requires termination.
Termination does not erase duties concerning confidentiality, incident cooperation, rights requests, liability, or retained data. Section 15 governs return and disposal.
18. Confidentiality and compelled disclosure
Each Party shall bind personnel with access to shared data to confidentiality during and after their role. The Company Associate shall treat health data as confidential and shall prevent supervisors or decision-makers from viewing it unless Schedule 1 grants access for a lawful and necessary purpose.
If law, court order, or a competent regulator requires disclosure, the receiving Party shall verify the request, disclose the minimum required, use a secure method, and document the disclosure. Where law permits, it shall notify the other Party before disclosure.
19. Accountability and responsibility
Each Party answers for its own acts, omissions, instructions, personnel, processors, and onward disclosures. No clause transfers a statutory controller obligation to the other Party or to ACCESS Software Solutions.
The Parties shall allocate investigation and remediation costs according to their legal responsibility and any final determination by a court or regulator. This Agreement does not waive a data subject's rights or remedies and does not restrict the National Privacy Commission's authority.
20. Governing law and disputes
Philippine law governs this Agreement. The DPOs shall first try to resolve an operational or privacy dispute within ten working days after written notice. This process does not delay an urgent security response, regulatory deadline, data-subject request, or application for legal relief.
The Parties submit unresolved disputes to the courts of [CITY OR PROVINCE], subject to any mandatory jurisdiction. Nothing prevents a person or Party from bringing a matter within the National Privacy Commission's jurisdiction to the Commission.
21. Amendments, assignment, and notices
The Parties may amend this Agreement only through a written instrument reviewed by both DPOs and signed by authorized representatives. A change in purpose, lawful basis, data category, recipient, online-access method, retention, or term requires review as a new sharing arrangement before the change takes effect.
Neither Party may assign this Agreement or transfer the shared data as part of a merger, acquisition, outsourcing, or corporate reorganization without assessing the new controller, giving required notices, and establishing a lawful transfer mechanism.
Formal notices under this Agreement shall go to the representatives and DPOs in Schedule 1. Email notice takes effect when the receiving system confirms delivery, except where law requires another method.
22. Entire agreement and signatures
This Agreement and its completed schedules record the entire controller-to-controller sharing arrangement for the stated purpose. The CareClinic Terms of Use and Privacy Policy govern the solutions provider's platform and processor role. If a conflict arises, the Parties shall apply Philippine law first, then the signed term that gives data subjects the greater lawful protection without requiring unlawful processing.
The Parties may sign counterparts and may use electronic signatures recognized by Philippine law. Each signatory confirms authority to bind the named Party. The DPOs sign as witnesses to the data-sharing terms and do not assume personal liability by witnessing in their official capacity.
For the Clinic
Authorized representative: [NAME]
Position: [POSITION]
Signature: ______________________________
Date: __________________
For the Company Associate
Authorized representative: [NAME]
Position: [POSITION]
Signature: ______________________________
Date: __________________
Witnessed by the Clinic DPO
Name: [NAME]
Signature: ______________________________
Date: __________________
Witnessed by the Company Associate DPO
Name: [NAME]
Signature: ______________________________
Date: __________________
Schedule 1: Details the Parties must complete
Program or arrangement name: [NAME]
Specific purpose: [PURPOSE]
Objectives: [OBJECTIVES]
Data subjects: [PRECISE GROUP]
Clinic lawful basis for personal information: [PROVISION AND ASSESSMENT]
Clinic lawful basis for sensitive personal information: [PROVISION AND ASSESSMENT]
Company Associate lawful basis for personal information: [PROVISION AND ASSESSMENT]
Company Associate lawful basis for sensitive personal information: [PROVISION AND ASSESSMENT]
Consent evidence and withdrawal process, if consent applies: [DETAILS OR NOT APPLICABLE]
Categories the Clinic may disclose: [SELECT FROM SECTION 5]
Categories the Company Associate may disclose: [SELECT FROM SECTION 6]
Authorized Company Portal roles and named teams: [ROLES AND TEAMS]
Estimated number of data subjects: [NUMBER OR RANGE]
Estimated frequency and volume: [FREQUENCY AND VOLUME]
Permitted exports: [REPORTS OR NONE]
Permitted onward disclosures: [RECIPIENT, PURPOSE, BASIS, OR NONE]
Processing and storage country and provider: [DETAILS]
Other approved processors or service providers: [NAME, PROCESSING, LOCATION, OR NONE]
Company Associate retention period and trigger: [PERIOD AND TRIGGER]
Backup deletion cycle: [PERIOD]
Return or destruction method: [METHOD]
Effective date: [DATE]
Expiry date: [DATE]
Review date: [DATE, NO LATER THAN 12 MONTHS AFTER EFFECTIVE DATE]
Venue for disputes: [CITY OR PROVINCE]
Clinic DPO: [NAME, EMAIL, PHONE, BUSINESS ADDRESS]
Company Associate DPO: [NAME, EMAIL, PHONE, BUSINESS ADDRESS]
Clinic incident contact: [NAME, EMAIL, PHONE]
Company Associate incident contact: [NAME, EMAIL, PHONE]
Schedule 2: Signing checklist
- The Parties completed all applicable fields and removed examples that do not apply.
- Each Party documented its own lawful basis for personal and sensitive personal information.
- The selected categories match what the purpose requires.
- The portal can enforce every required association, user, and category restriction.
- Each Party issued an accurate privacy notice and obtained valid consent where consent supplies the basis.
- Each Party verified the other Party's identity, DPO, security controls, retention, and incident contacts.
- The Parties obtained the current processing location and relevant provider details from ACCESS Software Solutions.
- Each Party's legal counsel and DPO reviewed the completed Agreement.
- The authorized representatives signed, and both DPOs signed as witnesses.
- Each Party stored the signed copy, lawful-basis record, and applicable consent evidence in its compliance file.