Joint Controller Data Processing Agreement Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Data Processing Agreement?

This Joint Controller Data Processing Agreement is essential when two or more entities jointly determine the purposes and means of processing personal data in Switzerland. It is particularly relevant following the implementation of the revised Swiss Federal Data Protection Act (FADP) in 2023, which introduced stricter requirements for data processing arrangements. The document should be used when organizations share decision-making authority over data processing activities, need to clearly define their respective responsibilities, and must ensure compliance with Swiss data protection requirements. It includes crucial provisions on data security, breach notification, liability allocation, and data subject rights management, while also considering potential GDPR implications for cross-border activities.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Data Processing Agreement

When your organization collaborates with other entities to process personal data, you need a Joint Controller Data Processing Agreement to comply with Swiss data protection laws. This legal document establishes clear responsibilities between parties who jointly determine how and why personal data is processed, ensuring compliance with the Swiss Federal Data Protection Act (FADP) and related regulations.

When do you need this document?

You need this agreement when your organization shares decision-making authority over personal data processing with another entity. Common scenarios include joint marketing campaigns where multiple companies collect and use customer data, research collaborations between universities and corporations that involve participant data, healthcare partnerships where patient information is shared between providers, and technology platforms where multiple organizations access the same user database. The agreement becomes essential when both parties have a say in determining the purposes of data processing and the means used to achieve those purposes, rather than one party simply processing data on behalf of another.

Key legal considerations

The agreement must clearly allocate responsibilities between joint controllers to avoid regulatory violations and liability disputes. Key provisions include defining each party's role in obtaining valid consent from data subjects, establishing procedures for handling data subject requests such as access, correction, and deletion rights, and creating protocols for data breach notification to both authorities and affected individuals. The document should specify which party serves as the primary contact point for data subjects and regulatory authorities, detail data security measures each controller must implement, and establish liability allocation mechanisms for potential damages or regulatory fines. Cross-border data transfer provisions are crucial if either party processes data outside Switzerland, requiring appropriate safeguards under both Swiss law and potentially the EU GDPR.

Legal requirements in Switzerland

Under the Swiss Federal Data Protection Act (FADP), joint controllers must have a written agreement that transparently allocates their respective responsibilities, particularly regarding data subject rights fulfillment. The agreement must comply with the principle of data minimization, ensuring processing is limited to what is necessary for the stated purposes. Swiss law requires that data subjects can exercise their rights against each controller independently, so your agreement must establish clear procedures for handling such requests. The document must address data retention periods, deletion procedures, and cross-border transfer mechanisms if applicable. Additionally, if your joint processing activities involve EU residents' data, you may need to comply with GDPR requirements, including appointing data protection officers where required and implementing privacy by design principles. The agreement should also consider Swiss Code of Obligations provisions regarding contract formation, performance, and liability between the parties.

GOVERNING LAW

Applicable law

This Joint Controller Data Processing Agreement is drafted to comply with Switzerland law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it