Commissioned Data Processing Agreement Template for Switzerland
Generate a bespoke document
What is a Commissioned Data Processing Agreement?
The Commissioned Data Processing Agreement is a critical legal instrument required under Swiss data protection law when one organization (the processor) processes personal data on behalf of another organization (the controller). This agreement is mandatory under the Federal Act on Data Protection (FADP/DSG) whenever external data processing occurs. It serves to establish clear responsibilities, obligations, and security requirements for both parties, ensuring compliance with Swiss data protection regulations. The document becomes particularly important in contexts involving sensitive data, cross-border transfers, or complex processing operations. It must reflect the requirements of the revised FADP/DSG that came into force in 2023, while potentially accommodating GDPR requirements for organizations dealing with EU data subjects.
About the Commissioned Data Processing Agreement
A Commissioned Data Processing Agreement is a legally binding contract that governs the relationship between a data controller and a data processor under Swiss law. When your organization needs to engage external service providers to handle personal data, this agreement ensures compliance with the Federal Act on Data Protection (FADP/DSG) while protecting both parties' interests.
When do you need this document?
You need a Commissioned Data Processing Agreement whenever your organization engages a third party to process personal data on your behalf. This includes situations such as outsourcing payroll services, using cloud storage providers, engaging marketing agencies to handle customer data, or working with IT support companies that access employee information. The agreement is also essential when appointing sub-processors, transferring data across borders, or when your processing activities involve sensitive personal data categories. Under Swiss law, any commissioned processing arrangement without a proper agreement constitutes a violation of data protection regulations.
Key legal considerations
The agreement must clearly define the scope and purpose of data processing, specify security measures, and establish procedures for data subject rights. Critical clauses include data retention periods, breach notification procedures, and termination obligations. You must ensure the processor can demonstrate compliance with Swiss data protection principles and implement appropriate technical and organizational measures. The agreement should address liability allocation, indemnification terms, and audit rights. Special attention is required for international data transfers, which may need additional safeguards such as standard contractual clauses or adequacy decisions.
Legal requirements in Switzerland
Under the revised FADP/DSG effective from September 2023, commissioned data processing agreements must meet specific mandatory requirements. The agreement must be concluded in writing and include detailed instructions for data processing, security measures, and procedures for exercising data subject rights. Swiss law requires processors to maintain records of processing activities and report data breaches within 72 hours. The controller remains liable for ensuring the processor's compliance and must conduct regular assessments of the processor's security measures. For cross-border transfers, additional requirements apply, including ensuring adequate protection levels and implementing supplementary measures where necessary. The agreement must also comply with Swiss Code of Obligations provisions regarding service contracts and establish clear contractual obligations for both parties.
GOVERNING LAW
Applicable law
This Commissioned Data Processing Agreement is drafted to comply with Switzerland law. Key legislation includes:
Swiss Code of Obligations (OR): Contains the fundamental principles of Swiss contract law, including provisions on service agreements and contractual obligations that form the basis of the processing agreement.
EU General Data Protection Regulation (GDPR): While not directly applicable in Switzerland, it's relevant for cross-border data transfers and ensuring compliance when processing data of EU residents or when Swiss companies act as processors for EU controllers.
Swiss Federal Ordinance to the Federal Act on Data Protection (FODP): Implementing ordinance that provides detailed requirements for data processing, including specific security measures and documentation requirements.
Swiss Federal Act on International Private Law (IPRG): Relevant for determining applicable law and jurisdiction in cases involving international data transfers or foreign contracting parties.
Swiss Criminal Code: Contains provisions on professional secrecy and confidentiality obligations that might be relevant for data processing activities.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it