Sub Processing Agreement Template for Switzerland
Generate a bespoke document
What is a Sub Processing Agreement?
A Sub Processing Agreement is essential when a primary data processor needs to engage another entity (sub-processor) to process personal data on its behalf. This document is particularly crucial in the Swiss legal context, where data protection requirements are stringent and align closely with European standards. The agreement must comply with the Swiss Federal Data Protection Act (FADP/DSG) and may also need to address GDPR requirements if European data is involved. It typically includes detailed provisions on data security measures, breach reporting obligations, audit rights, and liability arrangements. The Sub Processing Agreement is commonly used in outsourcing arrangements, cloud services implementations, or any scenario where data processing activities are delegated to third parties. It serves as a critical tool for ensuring unbroken accountability and compliance in data processing chains.
About the Sub Processing Agreement
A Sub Processing Agreement is a critical legal document that governs the relationship between a primary data processor and a sub-processor when personal data processing activities are delegated to third parties. Under Swiss law, this agreement ensures compliance with the Swiss Federal Data Protection Act (FADP) and maintains the integrity of data protection obligations throughout the processing chain.
When do you need this document?
You need a Sub Processing Agreement whenever your organization, acting as a data processor, requires the services of another entity to process personal data on your behalf. This commonly occurs in cloud computing arrangements where you engage hosting providers, when outsourcing customer service operations that involve personal data access, or when using specialized software-as-a-service platforms that process personal information. The agreement is also essential when implementing multi-vendor IT solutions where different suppliers handle various aspects of data processing, or when engaging consultants who require access to personal data to perform their services.
Key legal considerations
The agreement must clearly define the scope of processing activities, specify the categories of personal data involved, and outline the purposes for which data may be processed. Critical clauses include data security measures that meet or exceed your own standards, breach notification procedures with specific timeframes, and audit rights allowing you to verify compliance. The agreement should address data transfer restrictions, particularly for cross-border transfers, and include provisions for data deletion or return upon contract termination. Liability allocation clauses are essential to ensure appropriate risk distribution between parties, while indemnification provisions protect against potential data protection violations. The sub-processor must also commit to engaging only authorized personnel and implementing appropriate technical and organizational measures.
Legal requirements in Switzerland
Under the Swiss Federal Data Protection Act (FADP), sub-processing arrangements must maintain the same level of data protection as the original processing agreement. The sub-processor must provide sufficient guarantees regarding technical and organizational security measures, and any cross-border data transfers must comply with Swiss adequacy requirements or implement appropriate safeguards. If your organization also processes EU personal data, GDPR Article 28 requirements apply, mandating written agreements with specific content requirements and ensuring sub-processors provide sufficient guarantees for GDPR compliance. Swiss law requires that sub-processors be held to the same data protection standards as the primary processor, with clear accountability mechanisms throughout the processing chain. The agreement must also address the Swiss Federal Data Protection Ordinance requirements for data processor relationships and include provisions for regulatory cooperation and assistance with data subject rights.
GOVERNING LAW
Applicable law
This Sub Processing Agreement is drafted to comply with Switzerland law. Key legislation includes:
Swiss Federal Data Protection Ordinance: The implementing ordinance that provides detailed requirements and specifications for implementing the FADP, including specific requirements for data processors and sub-processors.
Swiss Code of Obligations (OR): The primary source of Swiss contract law that governs the fundamental aspects of contractual relationships, including formation, performance, and termination of contracts.
EU General Data Protection Regulation (GDPR): While not Swiss law, it's relevant due to its extraterritorial scope and Switzerland's close alignment with EU standards. Many Swiss businesses need to comply with both GDPR and FADP.
FINMA Circulars (if financial sector): If the sub-processing involves financial services, FINMA regulations regarding outsourcing and data handling must be considered, particularly Circular 2018/3 on Outsourcing.
Swiss Federal Act on International Private Law (IPRG): Relevant for determining applicable law and jurisdiction in cases involving international parties or cross-border data transfers.
Swiss Criminal Code: Contains provisions relevant to data protection violations and business confidentiality, including Article 162 regarding breach of manufacturing or trade secrets.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it