Joint Controller Agreement Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Agreement?

This Joint Controller Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Switzerland. It's particularly relevant for collaborative projects, shared services, or joint ventures where multiple entities have decision-making power over data processing activities. The agreement must comply with the Swiss Federal Act on Data Protection (FADP) and considers GDPR requirements due to Switzerland's status as a country with EU adequacy. It should be used whenever organizations share responsibility for data processing decisions, defining clear roles, responsibilities, and liability allocation. The document includes detailed provisions for data security, breach notification, data subject rights, and specific Swiss law compliance requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Agreement

When your organization collaborates with other entities to process personal data, you need a Joint Controller Agreement to establish clear legal responsibilities under Swiss law. This essential document defines how multiple organizations will share decision-making authority over data processing activities while ensuring compliance with the Swiss Federal Act on Data Protection (FADP) and maintaining Switzerland's EU adequacy status.

When do you need this document?

You require a Joint Controller Agreement whenever two or more organizations jointly determine the purposes and means of processing personal data. This applies to collaborative research projects between universities and corporations, joint marketing campaigns where companies share customer databases, shared service arrangements between group companies, or technology partnerships where multiple parties access and process the same personal data. The agreement is also essential when establishing joint ventures that involve customer data sharing, implementing shared IT systems that process employee or customer information, or creating industry consortiums that pool data for analysis. Without this agreement, you risk unclear liability allocation and potential compliance violations under Swiss data protection law.

Key legal considerations

Your Joint Controller Agreement must clearly define each party's specific responsibilities for data processing activities, including who handles data subject requests, breach notifications, and regulatory communications. The agreement should establish transparent arrangements for data subjects, ensuring they understand which controller is responsible for their personal data and how to exercise their rights. You must include detailed provisions for data security measures, incident response procedures, and liability allocation between controllers. The document should address cross-border data transfers, especially given Switzerland's adequacy status with the EU, and specify how controllers will coordinate responses to regulatory inquiries. Additionally, you need clear termination clauses that address data retention, deletion, or return when the joint processing relationship ends.

Legal requirements in Switzerland

Under Swiss FADP, joint controllers must ensure transparency by clearly informing data subjects about their shared responsibilities and providing accessible contact information for exercising rights. Your agreement must comply with Swiss data processing principles, including lawfulness, good faith, proportionality, and purpose limitation. You're required to maintain detailed records of processing activities and implement appropriate technical and organizational measures to protect personal data. The agreement must address the Swiss Federal Data Protection and Information Commissioner's (FDPIC) authority and establish procedures for handling regulatory inquiries. Given Switzerland's EU adequacy decision, your agreement should also consider GDPR Article 26 requirements to maintain seamless data flows with EU entities. You must ensure that data subject rights can be effectively exercised against either controller and establish clear mechanisms for handling complaints and disputes under Swiss law.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it