International Data Transfer Addendum Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a International Data Transfer Addendum?

The International Data Transfer Addendum is essential for organizations transferring personal data from Switzerland to other countries, particularly those without an adequate level of data protection as recognized by Swiss authorities. This document supplements existing service agreements or contracts, specifically addressing data protection requirements under the Swiss Federal Data Protection Act (FADP) and related regulations. It becomes necessary when Swiss entities engage with foreign service providers, establish intra-group data sharing arrangements, or outsource data processing activities internationally. The addendum includes detailed provisions on data security measures, data subject rights, breach notification procedures, and compliance monitoring mechanisms, ensuring that personal data transferred outside Switzerland maintains the level of protection required by Swiss law.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the International Data Transfer Addendum

When you transfer personal data from Switzerland to other countries, you need an International Data Transfer Addendum to ensure compliance with Swiss data protection laws. This legal document supplements your existing contracts and establishes the necessary safeguards for cross-border data transfers, particularly when sending data to jurisdictions that Switzerland has not recognized as providing adequate data protection.

When do you need this document?

You require this addendum whenever your Swiss organization transfers personal data internationally. This includes engaging cloud service providers based outside Switzerland, outsourcing customer service operations to foreign companies, or sharing employee data with overseas subsidiaries. The document becomes particularly critical when transferring data to countries without adequacy decisions from Swiss authorities, such as the United States, India, or most Asian and Latin American jurisdictions. Even transfers within multinational corporations require this protection when crossing Swiss borders.

Key legal considerations

Your addendum must address several critical legal elements to ensure enforceability and compliance. Data processing purposes must be clearly defined and limited to what you originally collected the data for under Swiss law. You need explicit provisions covering data subject rights, including access, rectification, erasure, and data portability rights that Swiss individuals retain even after international transfer. Security measures must meet Swiss standards, including encryption requirements, access controls, and regular security assessments. The document should establish clear breach notification procedures, requiring the data importer to notify you within 72 hours of any security incidents. Additionally, you must include audit rights, allowing you or third-party auditors to verify the data importer's compliance with the agreed safeguards.

Legal requirements in Switzerland

Under the Swiss Federal Data Protection Act (FADP) that took effect in September 2023, international data transfers require adequate protection levels or appropriate safeguards. Your addendum must demonstrate these safeguards through contractual clauses that mirror Swiss data protection standards. The Swiss Federal Data Protection and Information Commissioner (FDPIC) requires that you conduct transfer impact assessments for high-risk destinations, documenting why the transfer is necessary and how you will maintain data protection. You must also ensure the data importer can comply with Swiss law requirements, including responding to data subject requests and cooperating with Swiss authorities. The addendum should reference both the Swiss FADP and the Federal Data Protection Ordinance (FDPO), establishing jurisdiction clauses that allow Swiss courts to hear disputes and Swiss law to govern the agreement.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it