Controller To Controller Data Processing Agreement Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Controller To Controller Data Processing Agreement?

A Controller To Controller Data Processing Agreement is essential when two organizations, each acting as independent data controllers, need to share personal data in Switzerland. This agreement is specifically designed to comply with the Swiss Federal Act on Data Protection (FADP/nFADP 2022) and becomes necessary when both parties independently determine the purposes and means of processing personal data they share with each other. The document outlines mutual obligations, security requirements, data subject rights handling, and breach notification procedures. It's particularly relevant for cross-organizational data sharing, joint ventures, or collaborative projects where both parties maintain separate control over data processing activities. The agreement should address Swiss legal requirements while considering potential international data protection standards, especially when dealing with cross-border data transfers or EU-based partners.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Controller To Controller Data Processing Agreement

When your organization needs to share personal data with another company in Switzerland, where both parties will independently control how that data is processed, you need a Controller To Controller Data Processing Agreement. This specialized contract ensures compliance with Swiss data protection laws while protecting both organizations from regulatory and legal risks associated with shared data processing activities.

When do you need this document?

You'll need this agreement when establishing business partnerships, joint ventures, or collaborative projects where personal data flows between organizations. Common scenarios include mergers and acquisitions where due diligence requires data sharing, research collaborations between universities and corporations, marketing partnerships involving customer data exchange, and strategic alliances where operational data must be shared. The agreement is also essential when Swiss companies work with international partners, particularly those in the EU, as it ensures compliance with both Swiss FADP requirements and potential GDPR obligations for cross-border data transfers.

Key legal considerations

Your agreement must clearly define each party's role as independent data controllers and specify the categories of personal data being shared, processing purposes, and retention periods. Critical clauses should address data security measures, including technical and organizational safeguards that both parties must implement. You'll need provisions covering data subject rights, including how individuals can exercise access, rectification, and deletion rights across both organizations. The agreement should establish clear breach notification procedures, ensuring both parties can meet the 72-hour notification requirement under Swiss law. Include liability allocation clauses to protect against regulatory fines and civil claims, and ensure termination provisions address data return or destruction obligations.

Legal requirements in Switzerland

Under the Swiss Federal Act on Data Protection (FADP/nFADP 2022), your agreement must demonstrate lawful basis for data processing and ensure adequate protection levels for shared personal data. The contract must comply with Swiss Code of Obligations requirements for contract validity and enforceability. When transferring data internationally, you'll need to verify adequate protection levels in destination countries or implement appropriate safeguards like standard contractual clauses. Your agreement should address data localization requirements and specify whether data will be stored within Switzerland or transferred abroad. For organizations dealing with EU data subjects, consider GDPR compliance requirements alongside Swiss law. The Federal Ordinance to the FADP provides detailed implementation guidelines that your agreement should reflect, particularly regarding data security standards and individual rights procedures.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it