Commissioned Data Processing Agreement Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Commissioned Data Processing Agreement?

The Commissioned Data Processing Agreement is a critical legal instrument required under Swiss data protection law when one organization (the processor) processes personal data on behalf of another organization (the controller). This agreement is mandatory under the Federal Act on Data Protection (FADP/DSG) whenever external data processing occurs. It serves to establish clear responsibilities, obligations, and security requirements for both parties, ensuring compliance with Swiss data protection regulations. The document becomes particularly important in contexts involving sensitive data, cross-border transfers, or complex processing operations. It must reflect the requirements of the revised FADP/DSG that came into force in 2023, while potentially accommodating GDPR requirements for organizations dealing with EU data subjects.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Commissioned Data Processing Agreement

A Commissioned Data Processing Agreement is a legally binding contract that governs the relationship between a data controller and a data processor under Swiss law. When your organization needs to engage external service providers to handle personal data, this agreement ensures compliance with the Federal Act on Data Protection (FADP/DSG) while protecting both parties' interests.

When do you need this document?

You need a Commissioned Data Processing Agreement whenever your organization engages a third party to process personal data on your behalf. This includes situations such as outsourcing payroll services, using cloud storage providers, engaging marketing agencies to handle customer data, or working with IT support companies that access employee information. The agreement is also essential when appointing sub-processors, transferring data across borders, or when your processing activities involve sensitive personal data categories. Under Swiss law, any commissioned processing arrangement without a proper agreement constitutes a violation of data protection regulations.

Key legal considerations

The agreement must clearly define the scope and purpose of data processing, specify security measures, and establish procedures for data subject rights. Critical clauses include data retention periods, breach notification procedures, and termination obligations. You must ensure the processor can demonstrate compliance with Swiss data protection principles and implement appropriate technical and organizational measures. The agreement should address liability allocation, indemnification terms, and audit rights. Special attention is required for international data transfers, which may need additional safeguards such as standard contractual clauses or adequacy decisions.

Legal requirements in Switzerland

Under the revised FADP/DSG effective from September 2023, commissioned data processing agreements must meet specific mandatory requirements. The agreement must be concluded in writing and include detailed instructions for data processing, security measures, and procedures for exercising data subject rights. Swiss law requires processors to maintain records of processing activities and report data breaches within 72 hours. The controller remains liable for ensuring the processor's compliance and must conduct regular assessments of the processor's security measures. For cross-border transfers, additional requirements apply, including ensuring adequate protection levels and implementing supplementary measures where necessary. The agreement must also comply with Swiss Code of Obligations provisions regarding service contracts and establish clear contractual obligations for both parties.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it