International Data Transfer Addendum Template for Switzerland
Generate a bespoke document
What is a International Data Transfer Addendum?
The International Data Transfer Addendum is essential for organizations transferring personal data from Switzerland to other countries, particularly those without an adequate level of data protection as recognized by Swiss authorities. This document supplements existing service agreements or contracts, specifically addressing data protection requirements under the Swiss Federal Data Protection Act (FADP) and related regulations. It becomes necessary when Swiss entities engage with foreign service providers, establish intra-group data sharing arrangements, or outsource data processing activities internationally. The addendum includes detailed provisions on data security measures, data subject rights, breach notification procedures, and compliance monitoring mechanisms, ensuring that personal data transferred outside Switzerland maintains the level of protection required by Swiss law.
About the International Data Transfer Addendum
When you transfer personal data from Switzerland to other countries, you need an International Data Transfer Addendum to ensure compliance with Swiss data protection laws. This legal document supplements your existing contracts and establishes the necessary safeguards for cross-border data transfers, particularly when sending data to jurisdictions that Switzerland has not recognized as providing adequate data protection.
When do you need this document?
You require this addendum whenever your Swiss organization transfers personal data internationally. This includes engaging cloud service providers based outside Switzerland, outsourcing customer service operations to foreign companies, or sharing employee data with overseas subsidiaries. The document becomes particularly critical when transferring data to countries without adequacy decisions from Swiss authorities, such as the United States, India, or most Asian and Latin American jurisdictions. Even transfers within multinational corporations require this protection when crossing Swiss borders.
Key legal considerations
Your addendum must address several critical legal elements to ensure enforceability and compliance. Data processing purposes must be clearly defined and limited to what you originally collected the data for under Swiss law. You need explicit provisions covering data subject rights, including access, rectification, erasure, and data portability rights that Swiss individuals retain even after international transfer. Security measures must meet Swiss standards, including encryption requirements, access controls, and regular security assessments. The document should establish clear breach notification procedures, requiring the data importer to notify you within 72 hours of any security incidents. Additionally, you must include audit rights, allowing you or third-party auditors to verify the data importer's compliance with the agreed safeguards.
Legal requirements in Switzerland
Under the Swiss Federal Data Protection Act (FADP) that took effect in September 2023, international data transfers require adequate protection levels or appropriate safeguards. Your addendum must demonstrate these safeguards through contractual clauses that mirror Swiss data protection standards. The Swiss Federal Data Protection and Information Commissioner (FDPIC) requires that you conduct transfer impact assessments for high-risk destinations, documenting why the transfer is necessary and how you will maintain data protection. You must also ensure the data importer can comply with Swiss law requirements, including responding to data subject requests and cooperating with Swiss authorities. The addendum should reference both the Swiss FADP and the Federal Data Protection Ordinance (FDPO), establishing jurisdiction clauses that allow Swiss courts to hear disputes and Swiss law to govern the agreement.
GOVERNING LAW
Applicable law
This International Data Transfer Addendum is drafted to comply with Switzerland law. Key legislation includes:
Swiss Federal Data Protection Ordinance (FDPO): The implementing ordinance that provides detailed requirements and specifications for the FADP.
EU General Data Protection Regulation (GDPR): While not directly applicable, Swiss law closely aligns with GDPR principles, and it's relevant for international transfers involving EU entities or data subjects.
Swiss Code of Obligations: The fundamental law governing contracts in Switzerland, providing the basic framework for contractual relationships and obligations.
Swiss Federal Act on Private International Law (PILA): Governs international legal relationships in private law matters, including the choice of law and jurisdiction in international contracts.
Swiss Federal Data Protection and Information Commissioner (FDPIC) Guidelines: Official guidelines and recommendations for international data transfers, including standard contractual clauses and binding corporate rules.
Swiss Standard Contractual Clauses: Model clauses approved by the FDPIC for international data transfers to countries without adequate data protection laws.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it