Data Processor Privacy Notice Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Processor Privacy Notice?

The Data Processor Privacy Notice is a crucial document required for organizations processing personal data on behalf of others under Swiss law. This document becomes necessary when an entity acts as a data processor, handling personal data according to the instructions of data controllers. The notice must comply with the Swiss Federal Data Protection Act (FADP/DSG) and should address key aspects such as processing purposes, security measures, and data subject rights. While primarily focused on Swiss legal requirements, the notice often needs to consider international data protection standards, particularly when handling cross-border data transfers. The document serves both as a compliance tool and as a transparency mechanism, helping processors meet their obligations while providing clear information to controllers and data subjects about their processing activities.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Processor Privacy Notice

When your organization processes personal data on behalf of other companies or entities, you need a comprehensive Data Processor Privacy Notice to comply with Swiss data protection law. This document establishes transparency about your processing activities and demonstrates compliance with the Swiss Federal Data Protection Act (FADP/DSG), which governs how personal data must be handled when you act as a processor rather than the primary data controller.

When do you need this document?

You need a Data Processor Privacy Notice whenever your organization processes personal data according to instructions from data controllers. This commonly occurs in cloud computing services, payroll processing, IT support services, marketing agencies handling client data, or any outsourced business process involving personal information. The notice becomes essential when signing data processing agreements with clients, responding to data subject inquiries, or demonstrating compliance during regulatory audits. You also need this document when processing data for multiple controllers simultaneously or when engaging sub-processors to handle data on your behalf.

Key legal considerations

Your privacy notice must clearly define your role as a data processor and distinguish it from data controller responsibilities. The document should specify the categories of personal data you process, the purposes of processing as instructed by controllers, and the technical and organizational security measures you implement. You must address data retention periods, procedures for data deletion or return upon contract termination, and your policies for engaging sub-processors. The notice should explain how you handle data subject rights requests, including access, rectification, erasure, and data portability rights. International data transfer provisions are crucial if you transfer data outside Switzerland, requiring adequate protection measures or appropriate safeguards. You must also include contact information for your Data Protection Officer if appointed, and procedures for data breach notification to controllers and potentially to the Swiss Federal Data Protection and Information Commissioner.

Legal requirements in Switzerland

Under the revised Swiss FADP, data processors must implement appropriate technical and organizational measures to ensure data security and demonstrate compliance through documentation. You must process personal data only according to documented instructions from the data controller and notify them immediately of any data breaches that pose risks to data subjects. Swiss law requires that your processing activities be governed by a written contract or legal act that specifies the subject matter, duration, nature, and purpose of processing. You cannot engage sub-processors without prior written authorization from the data controller, and you must ensure sub-processors provide the same level of protection. The notice must be available in the official languages relevant to your operations and accessible to data subjects whose information you process. Regular updates to the notice are required when processing activities change significantly or when legal requirements evolve.

GOVERNING LAW

Applicable law

This Data Processor Privacy Notice is drafted to comply with Switzerland law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it