DE
Illustrative image: Government agencies and public organizations

Government Agencies & Public Organizations

Government agencies and public organizations must balance their statutory mandates, the public interest, and increasing digitalization. Legal issues often arise at the intersection of public mandates, data protection, technology, governance, and implementation under private law.

We support public organizations, particularly with digitization and technology projects, data processing, cloud and AI applications, contract structures, and internal policies. In doing so, we help integrate legal requirements early on into projects, decision-making processes, and organizational structures.

Data Protection and Public Data Processing
Digitalization, the Cloud, and AI
Governance and Internal Policies
Contracts with Private Service Providers
Public Procurement and Project Implementation
Classification

Why Public Organizations Have Special Requirements

Acting in Accordance with the Law

Public agencies cannot base their activities solely on economic or operational criteria. Jurisdictions, legal frameworks, and public responsibilities determine which decisions may be made and how services may be organized. When undertaking new projects, the question therefore arises early on as to whether competencies, procedures, and responsibilities have been sufficiently clarified.

Several levels of regulation are interlinked

Depending on whether an organization operates at the federal, cantonal, or municipal level, different laws and regulations may apply. This applies in particular to data protection, the principle of public access to information, procurement law, and organizational law. State-affiliated enterprises or private organizations performing public functions may also take hybrid forms, in which case the specific function and legal basis are decisive.

Digitization Is Transforming Administrative Processes

Cloud solutions, digital platforms, automated workflows, and AI systems can simplify administrative processes, but they also raise new questions regarding data protection, information security, traceability, procurement, and accountability. Legal requirements should therefore be integrated into the project and system architecture as early as possible.

Transparency and Accountability

Public organizations are often required to document and justify their decisions to a greater extent than private companies. Rules regarding transparency, record-keeping, and access to information can be just as relevant as internal control and governance requirements. Clear and traceable documentation is therefore essential not only from an organizational standpoint but also from a legal one.

Legal Issues

Key Legal Issues for Government Agencies and Public Organizations

Data Protection and Public Data Processing

For public organizations, the applicable data protection law depends in particular on whether they operate at the federal, cantonal, or municipal level and on the capacity in which personal data is processed. In addition to the general data protection principles, legal bases, purpose limitation, disclosure obligations, and specific documentation requirements can play an important role.

We provide support in assessing the legal classification of data processing activities, in new digital projects, and in designing appropriate data protection and governance structures.

‍

Digitalization, the Cloud, and Outsourcing

Cloud, SaaS, and other digital solutions are increasingly becoming part of the operational infrastructure in the public sector as well. This raises questions regarding data locations, access rights, subcontractors, information security, oversight mechanisms, dependencies, and exit strategies.

The legal assessment should not be conducted in isolation, but should be coordinated with IT, information security, data protection, project organization, and, if applicable, procurement.

‍

Artificial Intelligence in Public Administration

AI systems can assist public organizations with analysis, communication, internal processes, and decision support. At the same time, legal and organizational questions arise regarding data protection, transparency, traceability, human accountability, and permissible areas of application.

Clear responsibilities, approval processes, and rules of use help ensure that AI is integrated into existing administrative and governance structures in a controlled manner.

‍

Governance and Internal Policies

Internal policies, organizational charters, data protection guidelines, procurement processes, and AI rules establish the organizational framework for legally compliant operations.

It is crucial that such documents not be created in isolation, but rather reflect actual tasks, responsibilities, and decision-making processes. Particularly in digitalization projects, it is important to clarify early on how the business units, IT, data protection, information security, procurement, and management will collaborate.

‍

Contracts with Private Service Providers

Public organizations regularly collaborate with private providers on IT, cloud, consulting, and digital transformation projects. Even after a proper procurement process, the terms of the contract remain crucial.

The scope of services, responsibilities, liability, data protection, information security, audit rights, subcontractors, rights to deliverables, and exit provisions should be tailored to the public mission and the specific risk.

‍

Public Procurement and Project Implementation

When contracting with external providers, it is important to determine early on whether any procurement law requirements apply and, if so, which ones. Depending on the contracting authority, the contract, and the legal basis, federal law as well as cantonal or intercantonal regulations may be relevant.

Procurement law requirements should be coordinated with contract drafting, data protection, technology, and project governance. This allows legal requirements to be integrated into request for proposal documents, statements of work, and subsequent contract structures from the outset.

‍

From the Task to Legally Sound Implementation

‍

Clarify the Assignment and Responsibilities

First, it is necessary to determine which public function is being fulfilled, the legal basis for the project, and who within the organization is responsible for decisions, approvals, and implementation.

‍

Define the Implementation and Contract Model

Next, it is determined how the service is to be implemented from an organizational and contractual standpoint. In doing so, it may also be necessary to assess whether a public procurement process is required and what requirements must already be taken into account in the request for proposals.

‍

Putting Data and Technology into Perspective

In digital projects, data flows, system access, cloud usage, information security, and, where applicable, AI functions are addressed from a legal perspective and integrated into the project requirements.

‍

Establishing Governance and Documentation

Responsibilities, control processes, guidelines, and documentation requirements should be structured in such a way that the solution remains legally and organizationally sound not only at the start of the project but also during ongoing operations.

‍

Issues of Concern to the Public Sector

‍

AI in Administrative Processes

The use of generative and analytical AI is also on the rise in public organizations. The focus is on safe use, transparent results, human accountability, and clear internal responsibilities and guidelines.

‍

The Cloud and Digital Sovereignty

As services are migrated to the cloud, data control, vendor dependencies, the ability to exit, and robust vendor governance are becoming increasingly important.

‍

Digital Resilience and Third Parties

Public organizations are increasingly dependent on external technology and service providers for digital services. Contracts, information security, oversight rights, subcontractors, and termination options should therefore be considered together.

‍

Data Use and Transparency

Digital administration generates larger data sets and opens up new possibilities for their use. At the same time, designated use, data protection, access to information, and transparent governance remain key framework conditions.

‍

Issues of Concern to the Public Sector

‍

AI in Administrative Processes

The use of generative and analytical AI is also on the rise in public organizations. The focus is on safe use, transparent results, human accountability, and clear internal guidelines.

‍

The Cloud and Digital Sovereignty

As services are migrated to the cloud, the importance of data control, dependencies, the ability to exit, and robust vendor governance continues to grow.

‍

Procurement and Contract Implementation

In projects involving external vendors, procurement law requirements may be relevant in addition to contractual, data protection, and technological issues. These should be identified early on and aligned with the project structure, scope of work, contract terms, and governance.

Our focus is on the legal intersections with technology, data protection, contracts, and project organization.

‍

Data Use and Transparency

Digital administration generates larger data sets and opens up new opportunities for analysis. At the same time, purpose limitation, access to information, data protection, and transparent governance remain key framework conditions.

Combining Public and Private Law

Many projects operate at the intersection of public service and private-sector implementation. We consider both aspects together.

Understanding Digitalization

Technical processes, cloud models, platforms, and AI are analyzed in terms of how they actually function and classified from a legal perspective.

Pragmatic Implementation

Legal requirements must be able to be incorporated into procurement, project organization, contracts, and internal processes.

Thinking About Governance

We do not view responsibilities and decision-making processes as separate from the project itself, but rather as part of the legal solution.

Clear Documentation

Complex requirements are translated into clear contracts, guidelines, decision-making frameworks, and recommendations for action.

Coordinate Interfaces

Data protection, procurement, IT, information security, and the business unit must work together. We help structure legal interfaces early on.

FAQ

Frequently Asked Questions from Government Agencies and Public Organizations