DE
Data Processing Agreements Under the DSG and GDPR

Data Processing Agreements Under the DSG and GDPR

We advise companies, data controllers, and data processors on the legal structuring, review, and implementation of data processing agreements (DPAs). Our focus is on addressing gaps in the regulation of external personal data processing. We establish clear contractual frameworks, assess risks, and help translate business objectives into practical and robust provisions.

DPA Compliant with the DSG and GDPR
Clear Allocation of Risks and Responsibilities
Pragmatic Solutions for Negotiation and Implementation
Challenges

Common Challenges in Data Processing Agreements (DPA)

Unclear Responsibilities

In data processing agreements (DPAs), it is often unclear which party is responsible for which tasks and risks. We analyze roles, contributions, and dependencies, and ensure that responsibilities are transparent and aligned with the actual business model.

Liability and Risk Allocation

Liability clauses often determine the financial implications of a contract only when a dispute arises. We review the scope of liability, exclusions, limits, and indemnification provisions, and compare them with the specific risks and insurance coverage.

Performance and Consideration

Vague service descriptions lead to differing expectations. We help define services, compensation, deadlines, obligations to cooperate, and quality requirements in a way that facilitates operational implementation and subsequent enforcement.

Amendment and Termination

Business models and projects evolve. That is why data processing agreements (DPAs) must also address amendments, termination, transfer, and exit. We review whether the mechanisms for making changes and the consequences of termination are practical and whether critical dependencies are adequately addressed.

Overview of Services

Our Services Related to Data Processing Agreements (DPA)

We assist companies in drafting, reviewing, and negotiating data processing agreements in accordance with Swiss data protection law and the GDPR. In doing so, we consider not only the text of the agreement but also the actual data flows, roles, and technical processes. The goal is to establish clear and practical guidelines for the collaboration between data controllers and data processors.

‍

Role Definition and Scope of Application

First, we clarify which data protection roles the parties involved actually assume and which data processing activities should be covered by the DPA. In doing so, we take into account, in particular, the purpose, categories of data, data subjects, and the actual authority to issue instructions and make decisions.

  • Data Controller and Data Processor
  • Subject Matter and Purpose of Data Processing
  • Data Categories and Data Subjects

‍

DPA under the DSG and GDPR

We draft, review, and revise data processing agreements and align the contractual provisions with applicable data protection requirements. In doing so, we ensure that obligations, the right to issue instructions, duties to provide assistance, and responsibilities are clearly defined and can be implemented in practice.

  • Preparation and Review of DPAs
  • DSG and GDPR Requirements
  • Duties to Provide Guidance and Support

‍

Technical and Organizational Measures

Technical and organizational measures should not merely be mentioned as a formality, but should be described in such a way that their level of protection can be assessed in a transparent manner. We verify whether the agreed-upon technical and organizational measures are appropriate for the type of data processing and the specific risk.

  • TOM Audit
  • Information Security
  • Risk-Based Protective Measures

‍

Subcontractors and International Data Transfers

The use of additional service providers and international data flows may give rise to additional contractual requirements. We review authorization and notification mechanisms, subcontractor chains, and the incorporation of necessary transfer provisions.

  • Subcontractor
  • Approval and Information Processes
  • International Data Transfers

‍

Liability, Audit, and Control Rights

DPA agreements often contain far-reaching provisions regarding audits, information sharing, and liability. We assess whether these provisions are appropriate given the actual risk and the nature of the business relationship, and we assist in drafting a balanced contract.

  • Audit and Oversight Rights
  • Disclosure Requirements
  • Liability and Risk Allocation

‍

Negotiation and Practical Implementation

We facilitate coordination with customers, suppliers, data protection officers, IT, procurement, and other internal departments. In doing so, we prioritize the issues that are critical to actual data protection and business risks.

  • Contract Negotiations
  • Coordination with internal departments
  • Integration into Existing Processes

Data Protection Law and Contract Practice: A Holistic Approach

A data processing agreement must not only comply with data protection requirements but also be tailored to the actual collaboration between the parties. We therefore combine data protection analysis with a pragmatic contractual implementation.

A Look at the DSG and GDPR

Depending on the business model and international operations, both Swiss data protection law and the GDPR may apply simultaneously. We tailor DPAs to ensure that the applicable requirements are consistently reflected and that unnecessary duplication is avoided.

Explaining Technical Processes in an Easy-to-Understand Way

DPA often involve complex IT, cloud, or platform services. We map out data flows, systems, and technical processes and translate them into clear contractual provisions regarding roles, authority to issue instructions, security measures, and responsibilities.

Real-world processes instead of boilerplate language

A DPA should not consist solely of standard clauses. We verify whether the allocation of roles, subcontractors, technical and organizational measures, as well as audit and information rights, are actually appropriate for the service provider in question and the specific data processing activities.

Pragmatic Negotiations

DPA negotiations can become deadlocked, particularly regarding liability, audit rights, subcontractors, or security requirements. We prioritize these issues based on the actual data protection and business risks and seek solutions that are legally sound and operationally feasible.

Direct Support

You will work directly with the attorneys in charge and receive clear recommendations on which contractual provisions are essential, where adjustments are needed, and which risks, if any, can be accepted.

FAQ

Frequently Asked Questions About Order Processing Agreements