Sub Processing Agreement Template for Switzerland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Sub Processing Agreement?

A Sub Processing Agreement is essential when a primary data processor needs to engage another entity (sub-processor) to process personal data on its behalf. This document is particularly crucial in the Swiss legal context, where data protection requirements are stringent and align closely with European standards. The agreement must comply with the Swiss Federal Data Protection Act (FADP/DSG) and may also need to address GDPR requirements if European data is involved. It typically includes detailed provisions on data security measures, breach reporting obligations, audit rights, and liability arrangements. The Sub Processing Agreement is commonly used in outsourcing arrangements, cloud services implementations, or any scenario where data processing activities are delegated to third parties. It serves as a critical tool for ensuring unbroken accountability and compliance in data processing chains.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Switzerland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Sub Processing Agreement

A Sub Processing Agreement is a critical legal document that governs the relationship between a primary data processor and a sub-processor when personal data processing activities are delegated to third parties. Under Swiss law, this agreement ensures compliance with the Swiss Federal Data Protection Act (FADP) and maintains the integrity of data protection obligations throughout the processing chain.

When do you need this document?

You need a Sub Processing Agreement whenever your organization, acting as a data processor, requires the services of another entity to process personal data on your behalf. This commonly occurs in cloud computing arrangements where you engage hosting providers, when outsourcing customer service operations that involve personal data access, or when using specialized software-as-a-service platforms that process personal information. The agreement is also essential when implementing multi-vendor IT solutions where different suppliers handle various aspects of data processing, or when engaging consultants who require access to personal data to perform their services.

Key legal considerations

The agreement must clearly define the scope of processing activities, specify the categories of personal data involved, and outline the purposes for which data may be processed. Critical clauses include data security measures that meet or exceed your own standards, breach notification procedures with specific timeframes, and audit rights allowing you to verify compliance. The agreement should address data transfer restrictions, particularly for cross-border transfers, and include provisions for data deletion or return upon contract termination. Liability allocation clauses are essential to ensure appropriate risk distribution between parties, while indemnification provisions protect against potential data protection violations. The sub-processor must also commit to engaging only authorized personnel and implementing appropriate technical and organizational measures.

Legal requirements in Switzerland

Under the Swiss Federal Data Protection Act (FADP), sub-processing arrangements must maintain the same level of data protection as the original processing agreement. The sub-processor must provide sufficient guarantees regarding technical and organizational security measures, and any cross-border data transfers must comply with Swiss adequacy requirements or implement appropriate safeguards. If your organization also processes EU personal data, GDPR Article 28 requirements apply, mandating written agreements with specific content requirements and ensuring sub-processors provide sufficient guarantees for GDPR compliance. Swiss law requires that sub-processors be held to the same data protection standards as the primary processor, with clear accountability mechanisms throughout the processing chain. The agreement must also address the Swiss Federal Data Protection Ordinance requirements for data processor relationships and include provisions for regulatory cooperation and assistance with data subject rights.

GOVERNING LAW

Applicable law

This Sub Processing Agreement is drafted to comply with Switzerland law. Key legislation includes:

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it