Extension: The anatomy of a data transfer agreement for health research
Technical interoperability does not settle an institutional relation. Swales, Gooden, and Thaldar reach the same boundary through a scoping review of twenty-four data transfer agreements. The agreements identify the parties, state the purpose of the transfer, allocate duties, restrict processing, provide for audit, assign liability, and specify termination and dispute resolution. These clauses do more than document an exchange. They determine who acts, what the recipient may do, how compliance is assessed, who bears loss, and what follows from breach. The evidence independently extends Kaal's claim: a new integration needs a governance settlement before data or authority crosses the boundary. The evidence is narrower than Kaal's claim. The review studies English-language agreements for health research. It treats the identity of legal parties rather than authentication of software components. It does not test sovereign agent runtimes or automated remedies. The institutional mechanism nevertheless transfers. A runtime should translate the agreement into executable fields: verified component identity, delegated authority, purpose and duration limits, assigned responsibility, audit rights, termination, and redress. An unset field is not a harmless implementation gap. It leaves a material term unresolved. The integration gate should therefore refuse execution until each field names an accountable actor and an enforceable consequence. Technical compatibility can open a channel. Only the prior settlement makes its use institutionally defensible.
institutional-designgovernance-designai-and-agentsdata-governanceidentityauthorityaccountabilityremedy