DPA Agreement Template for Switzerland
Generate a bespoke document
What is a DPA Agreement?
This DPA Agreement is essential when a company (controller) engages another party (processor) to process personal data on its behalf under Swiss jurisdiction. The agreement is required under the Swiss Federal Data Protection Act (FADP/DSG) and becomes particularly important when organizations handle personal data of Swiss residents or operate within Switzerland. It details the scope of data processing, security requirements, confidentiality obligations, and compliance measures. The document should be used whenever there's a controller-processor relationship, especially in cases involving systematic data processing, sensitive personal information, or cross-border data transfers. The agreement helps organizations demonstrate compliance with Swiss data protection laws while providing a framework for secure and lawful data processing operations.
Trusted by high-performance teams
About the DPA Agreement
A Data Processing Agreement (DPA) is a legally binding contract required under Swiss law when your organization engages a third-party service provider to process personal data on your behalf. Under the Swiss Federal Data Protection Act (FADP/DSG), this agreement establishes clear responsibilities, security requirements, and compliance obligations between data controllers and processors operating in Switzerland.
When do you need this document?
You need a DPA whenever your company acts as a data controller and engages external processors to handle personal data. Common scenarios include outsourcing IT services, using cloud storage providers, engaging marketing agencies that access customer data, or working with payroll service providers. The agreement is particularly crucial when processing involves Swiss residents' data, cross-border transfers, or sensitive personal information categories. Swiss law requires explicit contractual arrangements for any systematic processing activities performed by third parties on behalf of your organization.
Key legal considerations
Your DPA must clearly define the scope and purpose of data processing, ensuring processors only handle data for specified legitimate purposes. Security measures represent a critical component, requiring both technical and organizational safeguards appropriate to the data sensitivity level. The agreement must address data subject rights, including procedures for handling access requests, corrections, and deletions under Swiss law. Confidentiality clauses should protect against unauthorized disclosure, while data retention provisions must align with Swiss legal requirements and your organization's policies. Consider including provisions for regular audits, breach notification procedures, and termination clauses that ensure secure data return or destruction.
Legal requirements in Switzerland
Swiss FADP requires your DPA to meet specific statutory obligations for controller-processor relationships. The agreement must ensure processors implement appropriate security measures proportionate to data sensitivity and processing risks. You must include clear instructions limiting processing activities to authorized purposes only, with provisions preventing processors from using data for their own purposes. The DPA should address cross-border data transfer requirements, particularly for processors located outside Switzerland or handling data transfers to third countries. Consider GDPR compatibility requirements if your processing involves EU data subjects, as this maintains Switzerland's adequacy status. Your agreement must also specify liability allocation, ensuring clear responsibility assignment for potential data protection violations under Swiss law.
GOVERNING LAW
Applicable law
This DPA Agreement is drafted to comply with Switzerland law. Key legislation includes:
Ordinance to the Federal Act on Data Protection (FADP Ordinance): Implementing regulation that provides detailed requirements and specifications for compliance with the FADP, including technical and organizational measures.
EU General Data Protection Regulation (GDPR): While not directly applicable in Switzerland, important to consider for cross-border data transfers and maintaining adequacy status with the EU.
Swiss Code of Obligations (OR): Contains general contract law provisions that apply to the formation and execution of the DPA as a binding agreement between parties.
Federal Act on Telecommunications (FMG): Relevant when the data processing involves telecommunications services or electronic communications data.
Swiss Criminal Code: Contains provisions on data theft, unauthorized access to data processing systems, and breach of professional confidentiality.
Canton-specific Data Protection Laws: May apply if processing involves public bodies or institutions at the cantonal level.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

