Joint Controller Data Processing Agreement Template for Switzerland
Generate a bespoke document
What is a Joint Controller Data Processing Agreement?
This Joint Controller Data Processing Agreement is essential when two or more entities jointly determine the purposes and means of processing personal data in Switzerland. It is particularly relevant following the implementation of the revised Swiss Federal Data Protection Act (FADP) in 2023, which introduced stricter requirements for data processing arrangements. The document should be used when organizations share decision-making authority over data processing activities, need to clearly define their respective responsibilities, and must ensure compliance with Swiss data protection requirements. It includes crucial provisions on data security, breach notification, liability allocation, and data subject rights management, while also considering potential GDPR implications for cross-border activities.
About the Joint Controller Data Processing Agreement
When your organization collaborates with other entities to process personal data, you need a Joint Controller Data Processing Agreement to comply with Swiss data protection laws. This legal document establishes clear responsibilities between parties who jointly determine how and why personal data is processed, ensuring compliance with the Swiss Federal Data Protection Act (FADP) and related regulations.
When do you need this document?
You need this agreement when your organization shares decision-making authority over personal data processing with another entity. Common scenarios include joint marketing campaigns where multiple companies collect and use customer data, research collaborations between universities and corporations that involve participant data, healthcare partnerships where patient information is shared between providers, and technology platforms where multiple organizations access the same user database. The agreement becomes essential when both parties have a say in determining the purposes of data processing and the means used to achieve those purposes, rather than one party simply processing data on behalf of another.
Key legal considerations
The agreement must clearly allocate responsibilities between joint controllers to avoid regulatory violations and liability disputes. Key provisions include defining each party's role in obtaining valid consent from data subjects, establishing procedures for handling data subject requests such as access, correction, and deletion rights, and creating protocols for data breach notification to both authorities and affected individuals. The document should specify which party serves as the primary contact point for data subjects and regulatory authorities, detail data security measures each controller must implement, and establish liability allocation mechanisms for potential damages or regulatory fines. Cross-border data transfer provisions are crucial if either party processes data outside Switzerland, requiring appropriate safeguards under both Swiss law and potentially the EU GDPR.
Legal requirements in Switzerland
Under the Swiss Federal Data Protection Act (FADP), joint controllers must have a written agreement that transparently allocates their respective responsibilities, particularly regarding data subject rights fulfillment. The agreement must comply with the principle of data minimization, ensuring processing is limited to what is necessary for the stated purposes. Swiss law requires that data subjects can exercise their rights against each controller independently, so your agreement must establish clear procedures for handling such requests. The document must address data retention periods, deletion procedures, and cross-border transfer mechanisms if applicable. Additionally, if your joint processing activities involve EU residents' data, you may need to comply with GDPR requirements, including appointing data protection officers where required and implementing privacy by design principles. The agreement should also consider Swiss Code of Obligations provisions regarding contract formation, performance, and liability between the parties.
GOVERNING LAW
Applicable law
This Joint Controller Data Processing Agreement is drafted to comply with Switzerland law. Key legislation includes:
Swiss Federal Data Protection Ordinance (FDPO): The implementing ordinance that provides detailed requirements and specifications for implementing the FADP.
EU General Data Protection Regulation (GDPR): While not directly applicable, Swiss companies often need to comply with GDPR if they process EU residents' data or offer goods/services to EU residents.
Swiss Code of Obligations (CO): Relevant for contractual aspects of the agreement, including formation, execution, and liability provisions between joint controllers.
Swiss Federal Act on Electronic Signatures (ZertES): Relevant if the agreement will be signed electronically, providing framework for valid electronic signatures in Switzerland.
Federal Act on the Implementation of International Sanctions (Embargo Act): May be relevant for international data transfers and business relationships, especially if one joint controller is located in a jurisdiction subject to international sanctions.
Swiss Criminal Code: Contains provisions on data theft, unauthorized data access, and breach of privacy obligations that joint controllers must be aware of.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it