蜜桃传媒

Controller To Controller Data Processing Agreement Template for Switzerland

A comprehensive legal agreement governed by Swiss law that establishes the framework for personal data sharing between two independent data controllers. This agreement ensures compliance with the Swiss Federal Act on Data Protection (FADP/nFADP 2022) and addresses potential GDPR considerations where applicable. It defines the responsibilities of each party in processing personal data, establishes data protection standards, outlines security measures, and provides mechanisms for handling data subject rights, breach notifications, and dispute resolution. The agreement is particularly important for organizations that regularly share personal data while maintaining independent control over their respective data processing activities.

Typically:
i
This cost is based on prices provided by
6 legal services in your market.
With 蜜桃传媒AI:

拢0

i
Generate and export your first
document completely free.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Get template free

Your data doesn't train 蜜桃传媒's AI

You keep IP ownership聽of your docs

4.6 / 5
4.6 / 5
4.8 / 5
Alternatively...

What is a Controller To Controller Data Processing Agreement?

A Controller To Controller Data Processing Agreement is essential when two organizations, each acting as independent data controllers, need to share personal data in Switzerland. This agreement is specifically designed to comply with the Swiss Federal Act on Data Protection (FADP/nFADP 2022) and becomes necessary when both parties independently determine the purposes and means of processing personal data they share with each other. The document outlines mutual obligations, security requirements, data subject rights handling, and breach notification procedures. It's particularly relevant for cross-organizational data sharing, joint ventures, or collaborative projects where both parties maintain separate control over data processing activities. The agreement should address Swiss legal requirements while considering potential international data protection standards, especially when dealing with cross-border data transfers or EU-based partners.

What sections should be included in a Controller To Controller Data Processing Agreement?

1. Parties: Identification of the contracting parties (both controllers) including full legal names, registration details, and addresses

2. Background: Context of the agreement, relationship between the parties, and purpose of the data sharing arrangement

3. Definitions: Definitions of key terms used in the agreement, including technical terms and references to applicable laws

4. Scope and Purpose of Data Processing: Detailed description of the data processing activities, categories of data, and purposes of processing

5. Roles and Responsibilities: Clear delineation of each controller's obligations and responsibilities regarding data processing

6. Lawful Basis for Processing: Specification of the legal grounds for data processing under Swiss law

7. Data Protection Principles: Commitment to comply with fundamental data protection principles under FADP

8. Data Subject Rights: Procedures for handling data subject requests and ensuring rights can be exercised

9. Data Security: Security measures required to protect personal data during processing and transfer

10. Data Breach Notification: Procedures for notifying about and handling personal data breaches

11. Confidentiality: Obligations regarding confidentiality of processed data

12. Term and Termination: Duration of the agreement and conditions for termination

13. Governing Law and Jurisdiction: Specification of Swiss law as governing law and jurisdiction for disputes

What sections are optional to include in a Controller To Controller Data Processing Agreement?

1. Cross-border Data Transfers: Required when personal data will be transferred outside Switzerland, including safeguards and mechanisms for international transfers

2. Audit Rights: Include when parties require mutual audit rights to ensure compliance

3. Sub-processing: Include when either controller may engage sub-processors for data processing activities

4. Insurance: Include when specific insurance coverage requirements are needed for data processing activities

5. Joint Processing Activities: Required when controllers jointly determine processing purposes and means

6. Industry-Specific Requirements: Include when processing involves regulated industries (e.g., healthcare, financial services)

7. Data Protection Impact Assessments: Include when high-risk processing activities require DPIAs

8. Liability and Indemnification: Detailed provisions on liability allocation and indemnification obligations

What schedules should be included in a Controller To Controller Data Processing Agreement?

1. Schedule 1 - Categories of Data: Detailed list of personal data categories being processed

2. Schedule 2 - Processing Activities: Detailed description of specific processing activities and purposes

3. Schedule 3 - Technical and Organizational Measures: Specific security measures implemented by both parties

4. Schedule 4 - Contact Points: List of key contacts for operational, legal, and data protection matters

5. Schedule 5 - Data Retention Periods: Specific retention periods for different categories of data

6. Appendix A - Data Transfer Mechanisms: Details of mechanisms used for any cross-border data transfers

7. Appendix B - Sub-processors: List of approved sub-processors if applicable

8. Appendix C - Security Breach Response Plan: Detailed procedures for handling data breaches

Authors

Alex Denne

Advisor @ 蜜桃传媒AI | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents

Jurisdiction

Switzerland

Cost

Free to use

Find the document you need

International Data Transfer Addendum

Swiss law-governed addendum for regulating international personal data transfers, ensuring compliance with FADP requirements and data protection standards.

Download

Intra Group Agreement Data Protection

Swiss law-governed agreement regulating data protection and transfers between group companies under FADP/DSG.

Download

Joint Controller Agreement

A Swiss law-governed agreement establishing responsibilities and obligations between joint controllers for personal data processing under FADP and considering GDPR requirements.

Download

Data Processing Addendum DPA

A Swiss law-governed agreement defining terms and responsibilities for personal data processing between controller and processor, ensuring compliance with FADP/revFADP and relevant GDPR requirements.

Download

Controller To Controller Data Processing Agreement

Swiss law-governed agreement establishing data sharing framework between two independent data controllers, ensuring FADP compliance and defining mutual data protection responsibilities.

Download

DPA Agreement

Swiss law-governed Data Processing Agreement defining controller-processor relationships and compliance requirements under FADP/DSG.

Download

Sub Processing Agreement

A Swiss law-governed agreement establishing terms for sub-processor data handling, ensuring compliance with Swiss FADP and related data protection requirements.

Download
See more related templates

骋别苍颈别鈥檚 Security Promise

蜜桃传媒 is the safest place to draft. Here鈥檚 how we prioritise your privacy and security.

Your data is private:

We do not train on your data; 骋别苍颈别鈥檚 AI improves independently

All data stored on 蜜桃传媒 is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it