Extension: The anatomy of a data transfer agreement for health research

Record: kaal:position:2026-08-26-009 · 2026-08-26

Technical interoperability does not settle an institutional relation. Swales, Gooden, and Thaldar reach the same boundary through a scoping review of twenty-four data transfer agreements. The agreements identify the parties, state the purpose of the transfer, allocate duties, restrict processing, provide for audit, assign liability, and specify termination and dispute resolution. These clauses do more than document an exchange. They determine who acts, what the recipient may do, how compliance is assessed, who bears loss, and what follows from breach. The evidence independently extends Kaal's claim: a new integration needs a governance settlement before data or authority crosses the boundary. The evidence is narrower than Kaal's claim. The review studies English-language agreements for health research. It treats the identity of legal parties rather than authentication of software components. It does not test sovereign agent runtimes or automated remedies. The institutional mechanism nevertheless transfers. A runtime should translate the agreement into executable fields: verified component identity, delegated authority, purpose and duration limits, assigned responsibility, audit rights, termination, and redress. An unset field is not a harmless implementation gap. It leaves a material term unresolved. The integration gate should therefore refuse execution until each field names an accountable actor and an enforceable consequence. Technical compatibility can open a channel. Only the prior settlement makes its use institutionally defensible.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

The anatomy of a data transfer agreement for health research

Scholarly basis

kaal:claim:7314479-009
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed scoping review with complete open full text
Review tier: independent substantive scholarly-growth extension
Mapping confidence: 0.94
Mapping ambiguous: false

Topics

institutional-designgovernance-designai-and-agentsdata-governanceidentityauthorityaccountabilityremedy

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-009-reviewed-v2 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: 10f0cfe7c395a1dba78c36999737123d0c77b0d9c2ce28f20fc93e50f52c5d39
curl -s https://wulfkaal.github.io/positions/2026-08-26-009.md | sha256sum