What is a Safety Data Exchange Agreement (SDEA)?

A comprehensive guide to Safety Data Exchange Agreements, responsibilities, reporting obligations, vendor oversight and inspection readiness.

Audio Lesson 8 min

What is a Safety Data Exchange Agreement (SDEA)?

Introduction

Modern pharmacovigilance systems depend heavily upon collaboration.

Medicinal products are frequently developed, licensed, marketed and supported through relationships involving:

When multiple organisations participate in activities affecting pharmacovigilance, responsibilities must be clearly defined.

Without clear responsibilities, important safety information may:

Safety Data Exchange Agreements exist to reduce these risks.

What Is an SDEA?

A Safety Data Exchange Agreement (SDEA) is a formal document that defines how pharmacovigilance and safety information will be exchanged between organisations.

The agreement typically describes:

A useful way to think about an SDEA is:

An SDEA defines who is responsible for what, when, and how regarding safety information.

The agreement helps ensure that all parties understand their obligations.

Why SDEAs Exist

Pharmacovigilance systems often involve multiple organisations.

Consider a licensing arrangement.

One company may hold the marketing authorisation.

Another company may market the product.

A third party may process safety reports.

Without clear agreements, questions arise.

Examples include:

An SDEA helps answer these questions before problems occur.

The Regulatory Perspective

Regulators expect organisations to maintain control of pharmacovigilance responsibilities. When activities are distributed across entities, those obligations must remain demonstrably clear. Inspectors will evaluate whether:

Key regulatory sources include EMA GVP Modules (I, II, III), Directive 2001/83/EC and implementing regulations, ICH E2 series (including E2A, E2D, E2B formats), and local legislation. SDEAs should reference applicable regional obligations and be drafted to support compliance across the territories covered.

Common Situations Requiring an SDEA

SDEAs are needed in many contexts, for example:

Across these situations, the need for clarity and traceability is constant.

What Problems Do SDEAs Solve?

SDEAs primarily reduce ambiguity and operational risk, preventing:

Typical Components of an SDEA

Most robust SDEAs include the following elements:

The SDEA should be consistent with the PSMF, SOPs, and operational practice.

The Most Important Principle

Clarity is paramount. An agreement must reflect operational reality and be used as an active governance tool rather than a static contract. Inspectors will expect to see evidence that the SDEA directs everyday activities and that deviations are addressed via governance and CAPA.

SDEAs and Accountability

An SDEA can allocate responsibilities operationally but cannot remove legal obligations. The Marketing Authorisation Holder (MAH) typically retains ultimate responsibility for pharmacovigilance compliance in the territories where it holds authorisation. This principle should be stated explicitly and implemented through governance, oversight and documented delegation.

SDEAs and Vendor Oversight

An SDEA is one element of vendor governance. Effective oversight requires:

Inspectors expect oversight artifacts and performance data mapped back to the SDEA.

SDEAs and the PSMF

The Pharmacovigilance System Master File (PSMF) must accurately reflect the pharmacovigilance system, including outsourced activities and SDEAs. Inspectors commonly correlate PSMF content with SDEAs, SOPs and operational records; inconsistencies suggest governance weaknesses.

How Inspectors Review SDEAs

Inspectors assess agreements in context:

The goal is to verify control, not merely the existence of paperwork.

Common SDEA Inspection Findings

Frequent findings include:

Most findings point to governance and oversight shortcomings rather than contractual language alone.

Characteristics of a Strong SDEA

Strong SDEAs are:

The QPPV Perspective

QPPVs rely on SDEAs for visibility of distributed responsibilities and risk management. A structured approach to review includes verifying contractual terms, governance evidence, reconciliation outputs, KPIs and audit trails to demonstrate that delegated activities meet regulatory expectations.

For additional information see: [[psmf-qppv-oversight]]


Inspection-ready SDEA Checklist

The following checklist is written for organisations preparing for pharmacovigilance inspection or internal review. It lists documentary and operational evidence inspectors typically request and that an organisation should maintain in an inspection-ready state. Organise documents for rapid retrieval and ensure version control and cross-references are clear.

Note: adapt the checklist to the specific regulatory jurisdiction(s) and the product lifecycle stage.

  1. Agreement documentation
  2. Fully executed SDEA (PDF with signatures), including version number, effective date, renewal/expiry date.
  3. Amendment history and change control log (who approved what and why).
  4. Distribution list and contact details (names, roles, escalation contacts).
  5. Scope and mapping
  6. Product/indication list and covered territories explicitly listed.
  7. Activities mapping (see sample mapping table below) showing which party performs and which party is accountable.
  8. PSMF section referencing the SDEA and describing outsourced activities.
  9. Regulatory references and timelines
  10. SDEA clause listing applicable regulatory requirements by territory (e.g., EMA GVP, national guidance, ICH E2 series).
  11. Operational timelines aligned to regulatory requirements and internal SOPs; evidence of compliance (timestamped entries, submission receipts).
  12. Data exchange and IT evidence
  13. Technical specification document: data formats (e.g., ICH E2B(R3) XML mapping), transmission methods (secure FTP, gateway, portal), and validation tests.
  14. Test logs and validation evidence for data transfers.
  15. Sample transmission logs and receipts (e.g., EudraVigilance acknowledgements, FDA correspondence).
  16. Case processing evidence
  17. Sample ICSRs with audit trail demonstrating receipt time, database entry time, assessment, follow-up, and regulatory submission.
  18. Records of initial serious/unexpected assessments and causality determinations.
  19. Reconciliation and metrics
  20. Reconciliation SOP and latest reconciliation reports (case matching, discrepancies, resolutions).
  21. KPI metric reports and trend analyses (timeliness, completeness, duplicate rate).
  22. Evidence of governance meetings where KPIs were reviewed (minutes, actions, owners, deadlines).
  23. Escalation and signal management
  24. Escalation matrix (contacts, thresholds, timelines) and sample escalations.
  25. Signal meeting minutes, logs showing escalation to MAH/QPPV when required.
  26. Audit and oversight
  27. Audit reports of the vendor and internal follow-up/CAPA tracking and closure evidence.
  28. Vendor qualification documents, training records for vendor personnel performing PV tasks.
  29. Training and SOPs
  30. Copies of SOPs referenced by the SDEA and training logs demonstrating staff awareness and competence.
  31. Business continuity and breach management
    • Business continuity plans, contingency arrangements for safety data processing failures.
    • Breach/incident logs with root cause analysis and CAPA.
  32. Confidentiality and data protection
    • Data protection clauses and evidence of compliance with GDPR or other local privacy laws (Data Processing Agreement, DPIA if applicable).
  33. Legal and financial
    • Audit-rights confirmation in the SDEA and evidence of exercising those rights if audits occurred.
    • Liability and indemnity clauses and documentation of any disputes or claims.
  34. Inspection pack assembly
    • A single indexed inspection pack or binder cross-referencing PSMF sections, SOPs, the SDEA and operational evidence.
    • A cover sheet summarising contractual responsibilities and a one-page process map showing information flows for the product(s) under the SDEA.

Inspection relevance: For each item, have a traceable path from the clause in the SDEA to the SOP and to an executed case or report. Inspectors expect to see "paper to practice" linkage.


Sample SDEA Template

Below is a comprehensive, inspection-focused SDEA template intended for practical use. It includes headings and suggested clause language to support operationalisation, auditing and inspection. Replace bracketed placeholders with company-specific details.

Note: This template is illustrative. Legal review is required before execution. It is presented here to demonstrate the depth of content inspectors expect.

Title: Safety Data Exchange Agreement (SDEA) Version: [vX.Y] Effective date: [YYYY-MM-DD] Parties: [MAH] and [Partner/Vendor/Distributor/CRO] Products and indications: [List products/brand/generic names, indications] Territories: [List covered countries/regions] Term and termination - Effective date and expiry - Renewal process - Termination for convenience and for cause - Transition obligations on termination (data transfer, case ownership) Definitions - Define key terms: ICSR, SAE, SUSAR, MAH, PV Database, E2B(R3), Serious, Unexpected, etc. Scope - Activities covered (e.g., case intake, data entry, medical review, expedited reporting, literature screening, aggregate reporting, signal detection) Roles and responsibilities - Detailed mapping (see sample mapping table below) - Statement of MAH ultimate responsibility Reporting obligations and timelines - Reference applicable regulations per territory - Operational timelines for internal handoffs and regulatory submissions Data exchange specifications - Required minimum data elements for case transfer - Data format (E2B(R3) XML preferred where applicable) and version - Transmission methods (secure portal, SFTP, API, manual forms) and proof of delivery - File naming conventions and validation rules Escalation and communication - Escalation matrix by issue type and severity with timelines - Routine communications: governance meetings, frequency, attendees, agenda templates Reconciliation - Reconciliation scope (cases, submissions, literature findings) - Frequency (e.g., monthly), matching fields, thresholds for discrepancies - Dispute resolution procedure and timeline to close discrepancies Audit, inspection and access rights - Right to audit (frequency, notice periods, remote/on-site) - Cooperation during regulatory inspections and access to records Quality and oversight - KPIs and SLAs (timeliness, completeness, duplicate reporting rates, reconciliation metrics) - Root cause analysis and CAPA expectations Change control and amendments - Amendment process (change request, impact assessment, approval) - Regulatory-driven changes (e.g., new law) and implementation timelines Training and personnel - Training requirements and qualification records to be maintained - Access controls and segregation of duties Confidentiality and data protection - Confidentiality clauses - Data Processing Agreement (if personal data processed) and compliance with GDPR/local law Record retention and archiving - Retention periods per territory (e.g., per regulation or longer if required) Business continuity and disaster recovery - Minimum recovery time objectives and contingency arrangements for processing safety data Subcontracting - Restrictions and approval process for subcontractors Liability and indemnity - Liability caps, indemnity clauses, insurance requirements Performance management - KPI definitions, reporting frequency, remediation plan for missed targets Dispute resolution - Governing law, escalation path, mediation/arbitration clauses Signatures - Name, title, date for authorised signatories on both parties

Appendices A. Contact details and escalation matrix (operational and executive) B. Data transfer specification and example E2B(R3) mapping C. SOP cross-reference table (SDEA clause → SOP ID) D. Reconciliation template and discrepancy log format E. KPI definitions and sample report layout F. Sample case transfer form (if manual transfer required)


Sample Mapping Table: Activities to Accountable Parties and Timelines

The table below is a worked example mapping common pharmacovigilance activities to the accountable party and suggested operational timelines. Final timelines must be aligned with applicable regulatory requirements and internal SOPs. Use this table as a starting point to create the activity matrix in your SDEA and PSMF.

Activity Accountable Party (Responsibility) Performing Party (May be same or delegated) Regulatory Timeline (example) Operational SDEA Requirement (example) Inspection Evidence
Receipt of initial adverse event report (source: HCP, patient) Receiving party per territory (e.g., local affiliate or MAH) — MAH remains ultimately accountable Local affiliate / PV vendor / MAH N/A (regulatory timelines start upon MAH awareness) Acknowledge receipt to sender within 24 hours; enter case into Safety Database within 24–48 hours of receipt Case intake logs, timestamped database entry, email acknowledgements
Triage and initial assessment (seriousness, expectedness) Performing party; MAH accountable for adequacy of assessment PV vendor / Local PV team Immediate assessment on receipt; escalations per regulations Assessment documented in database within 24 hours; escalate potential serious/unexpected cases to MAH/QPPV within 24 hours Case file showing assessment, escalation emails, meeting minutes
Expedited regulatory reporting (post-marketing contexts) MAH (responsible for submission) PV vendor may prepare submission on MAH’s behalf Per territory (e.g., follow national/EU/US requirements) — see SDEA references MAH notified of case for submission within 24 hours of initial assessment; MAH (or delegated party) submits in required format within regulatory timelines Submission receipt (acknowledgement), SDEA clause delegating submission, SOPs
SUSAR reporting (clinical trials) Sponsor/MAH (sponsor for clinical trials) CRO or vendor may prepare report ICH timelines (e.g., 7 days for fatal/life-threatening SUSARs; 15 days for other serious SUSARs for clinical trial reporting) CRO notifies sponsor within 24 hours of becoming aware; sponsor (or delegate) submits to regulatory authorities within regulatory timelines SUSAR forms, timestamps, submission confirmations
Literature monitoring and case identification MAH (accountable) PV vendor / MAH safety team Continuous; periodic inventory per SOP Literature screening performed [e.g., weekly]; potential cases forwarded to MAH within 48 hours of identification Literature logs, screening reports, forwarded case records
Aggregate reporting (PBRER, PSUR, DSUR inputs) MAH overall (accountable for content and submission) PV vendor / MAH medical safety team Submission timelines per regional regulations Vendor provides aggregate data and analysis input per agreed schedule (e.g., 3 months before submission) Draft deliverables, meeting minutes, final submission documents
Signal detection and evaluation MAH (accountable) MAH PV team / PV vendor analytics As per company SOPs and GVP guidance Routine signal detection frequency (e.g., weekly for high-risk products, monthly otherwise); signal assessments documented and escalated per thresholds Signal detection reports, safety review minutes, action plans
Case reconciliation (cases transferred between parties) Both parties share responsibility; MAH accountable for final reconciliation MAH & Vendor Monthly or frequency agreed Formal reconciliation monthly; discrepancies investigated and closed within 30 days Reconciliation reports, discrepancy logs, closure evidence
Medical review and causality assessment MAH or delegated medically-qualified person (accountable) MAH medical team / Vendor medical reviewer Per SOP; expedited for serious cases Medical review completed within 72 hours for serious cases; documented rationale in case record Medical review notes, credentials of reviewer, escalation evidence
Data retention and archiving MAH (accountable) Performing party as agreed Per regulations (e.g., minimum years specified by territory) Records retained and accessible per clause; immediate access for inspections Archive index, retrieval logs, retention policy
Audit and inspection cooperation MAH (accountable to regulators) Vendor must cooperate N/A Vendor must provide access within [X] business days per SDEA clause Audit reports, inspection packs, correspondence with authorities

Notes: - "Accountable" denotes the party legally responsible or ultimately owning compliance for the activity. - "Performing party" may be a delegate; the SDEA must specify delegation and the MAH must ensure adequate oversight. - Tailor regulatory timelines to the territories covered; include explicit references to the applicable statutes/regulations in the SDEA.


Practical Implementation Details

This section outlines pragmatic steps to implement an SDEA and operationalise the mapping table and governance clauses so the arrangement is demonstrably compliant and inspection-ready.

  1. Contract development and alignment
  2. Draft the SDEA with input from PV, legal, IT, QA, business owners and the QPPV.
  3. Include PSMF and SOP references; map each SDEA activity to an SOP.
  4. Ensure the SDEA cites specific regulatory frameworks applicable to each territory.

  5. Operationalisation

  6. Create an activity matrix (the mapping table) and include it as an appendix to the SDEA.
  7. Produce SOPs or work instructions reflecting the SDEA operational timelines and handoffs.
  8. Configure the PV database and interfaces according to the Data Transfer Specification and validate transfers (test cycles and production cutover).

  9. Governance and oversight

  10. Establish a governance cadence: monthly operational reviews, quarterly business reviews, and annual contract reviews.
  11. Define KPIs, thresholds and escalation triggers (e.g., >5% missed timeliness incidents triggers root cause analysis).
  12. Record meeting minutes, assigned actions, owners and closure dates in a governance tracker.

  13. Reconciliation process

  14. Agree reconciliation fields (case ID, suspect drug, reaction, reporting source, date of receipt, regulatory submission status).
  15. Use a standard reconciliation template with version control.
  16. Perform reconciliations at least monthly (more frequent for high volume or risk products).
  17. Maintain a discrepancy log that records investigation, root cause, remediation and closure.

  18. Audit and inspection preparation

  19. Maintain an inspection pack aligned to the checklist above.
  20. Conduct periodic readiness exercises and mock inspections focusing on SDEA fulfilment.
  21. For each SDEA clause, maintain at least one operational artifact showing how the clause is implemented.

  22. Change control and continuous improvement

  23. Treat SDEA amendments like regulated change: impact assessment, approval and update of related SOPs and PSMF.
  24. Track regulatory changes and proactively update SDEA timelines and procedures.

  25. Training and competence

  26. Maintain training matrices for MAH and vendor staff on SDEA obligations, SOPs and systems.
  27. Record training and competency assessments; include records in inspection pack.

  28. Data protection and privacy

  29. Execute a Data Processing Agreement where personal data is processed.
  30. Implement technical and organisational controls to secure transmissions and storage.
  31. Ensure logs of access and transfers are maintained for inspection.

  32. Incident management and breach response

  33. Define incident severity levels and required notifications.
  34. Include contractual timelines for notification of breaches to the MAH and regulators if required.
  35. Keep incident reports, root cause analyses, and CAPA records accessible.

Governance Discussion: Roles, Oversight and the QPPV

Governance should be tiered and transparent:

Key governance tasks: - Confirm that the SDEA accurately reflects delegation and non-delegable responsibilities. - Review reconciliation outputs and unresolved discrepancies. - Approve CAPAs and ensure timely completion. - Ensure inspection readiness: maintain the inspection pack, prepare spokespeople, and rehearse likely inspector requests.

Inspection relevance: Inspectors will look for evidence of active governance — meeting minutes, actions assigned and closed, trend analyses and demonstration that the QPPV and MAH can intervene when vendor performance jeopardises compliance.


Inspection Scenarios and Evidence Examples

Inspectors commonly test scenarios such as:

Preparing these bundles in advance, cross-referencing clauses to operational evidence, and labelling all artifacts improves inspection efficiency and reduces findings.


Concluding Notes

An SDEA is a central governance instrument for distributed pharmacovigilance responsibilities. To be inspection-ready, an SDEA must be clear, operational, supported by SOPs, observed in day-to-day practice, and evidenced by records (reconciliations, KPIs, audit reports, submission acknowledgements). The materials provided here — the inspection-ready checklist, sample SDEA template, activity-to-accountability mapping and practical implementation guidance — are intended to help organisations convert contractual obligations into demonstrable compliance.

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH E2 series (E2A, E2D, E2B(R3), E2E) and ICH E6.

Last reviewed: 2026-06-11