When a Swiss company engages a service provider that processes personal data on its behalf, Swiss FADP requires a written agreement covering the processing. This is the FADP equivalent of a GDPR Article 28 Data Processing Agreement. Swiss enterprise customers are increasingly requiring these agreements, and non-Swiss SaaS vendors serving Swiss customers need to be ready to execute them.
This article covers what FADP requires in a data processing agreement and what the key clauses are.
The FADP Requirement for Processing Agreements
FADP Article 9 requires that when a controller (the company responsible for data) engages a processor (a service provider that handles data on the controller's behalf), the processor must:
- Process data only as instructed by the controller
- Maintain the same level of data protection as the controller is required to maintain
- Take the necessary technical and organisational security measures
There is no explicit Article 28-equivalent in FADP that prescribes every element of the DPA in as much detail as GDPR. However, the FDPIC's guidance and market practice have developed a standard structure for FADP-compliant processing agreements.
FADP DPA: Required Elements
1. Identification of the Parties
- Controller: name, registered address, contact
- Processor: name, registered address, contact
- Date and duration of the agreement
2. Description of the Processing
- Purpose of the processing: what the processor does with the data
- Categories of personal data: what data the processor handles
- Categories of data subjects: who the data is about
- Duration of processing: how long the processor holds the data
3. Instructions Clause
The processor must process personal data only on the documented instructions of the controller. A key obligation under FADP. The agreement must state this explicitly and create a mechanism for the controller to issue updated instructions.
4. Confidentiality
Persons authorised to process the personal data must be committed to confidentiality or be subject to an appropriate statutory obligation of confidentiality.
5. Security Measures
The processor must implement appropriate technical and organisational measures to protect personal data. The agreement should either specify these measures or reference an exhibit/annex that describes them.
Under FADP, the security measures must be appropriate to the sensitivity of the data and the risks involved. For standard commercial data, this typically includes: encryption in transit and at rest, access controls, audit logging, and regular security testing.
6. Sub-Processors
The processor must not engage sub-processors without the prior authorisation of the controller. The agreement should specify:
- Whether specific or general authorisation is given
- If general: the notification and objection mechanism
- That sub-processors are bound to the same obligations
Include or reference a current sub-processor list.
7. Data Subject Rights
The processor must assist the controller in responding to data subject rights requests — including access, correction, deletion, and objection. The agreement should specify how this assistance is provided (data export functionality, deletion capabilities, timelines).
8. Cross-Border Transfers
If the processor transfers data outside Switzerland to countries without adequate protection, the agreement must:
- Identify the countries of transfer
- Specify the transfer mechanism (Swiss SCCs or Swiss DPF certification)
- Confirm that sub-processors in those countries are bound to equivalent protections
9. Data Breach Notification
The processor must notify the controller of a breach without undue delay. Define:
- What constitutes a reportable breach
- The notification timeframe (aligning with FADP's "as soon as possible" standard)
- What information the notification must include
10. Return or Deletion of Data
On termination of the agreement, the processor must return or delete all personal data as directed by the controller. Specify the format for return and the timeline for deletion.
11. Audit Rights
The controller has the right to audit the processor's compliance with the agreement. The agreement should specify:
- How audits are conducted (on-site, questionnaire, third-party certification review)
- Notice requirements
- Frequency
- Cost allocation
Differences Between FADP DPA and GDPR Article 28 DPA
If you already have a GDPR-compliant DPA, it covers most FADP requirements. The key additions for Swiss compliance:
- Reference to FADP (not just GDPR) as the applicable regulation
- Swiss supervisory authority (FDPIC) contact details where relevant
- Swiss transfer mechanisms (Swiss SCCs or Swiss DPF) in addition to EU mechanisms
- Acknowledgment of Swiss personal liability provisions (relevant if the processor is instructing data handling that affects individual responsibility)
A practical approach for SaaS companies serving both EU and Swiss customers: maintain a primary GDPR-compliant DPA with a Swiss FADP addendum that addresses the specific Swiss differences. This avoids maintaining two entirely separate agreements.
Template Clause: Core Processing Instructions
Processing Instructions
The Processor shall process the Personal Data only on documented
instructions from the Controller, including with regard to transfers
of Personal Data to a third country or an international organisation,
unless required to do so by Swiss law applicable to the Processor.
In such a case, the Processor shall inform the Controller of that
legal requirement before the processing, unless that law prohibits
such information on important grounds of public interest.
The Processor shall immediately inform the Controller if, in its
opinion, an instruction infringes applicable data protection law.