Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Controller To Controller Data Processing Agreement
"I need a Controller to Controller Data Processing Agreement under Swiss law for a financial services company sharing customer data with a marketing analytics provider, with specific provisions for cross-border transfers to the EU and enhanced security measures for sensitive financial data."
1. Parties: Identification of the contracting parties (both controllers) including full legal names, registration details, and addresses
2. Background: Context of the agreement, relationship between the parties, and purpose of the data sharing arrangement
3. Definitions: Definitions of key terms used in the agreement, including technical terms and references to applicable laws
4. Scope and Purpose of Data Processing: Detailed description of the data processing activities, categories of data, and purposes of processing
5. Roles and Responsibilities: Clear delineation of each controller's obligations and responsibilities regarding data processing
6. Lawful Basis for Processing: Specification of the legal grounds for data processing under Swiss law
7. Data Protection Principles: Commitment to comply with fundamental data protection principles under FADP
8. Data Subject Rights: Procedures for handling data subject requests and ensuring rights can be exercised
9. Data Security: Security measures required to protect personal data during processing and transfer
10. Data Breach Notification: Procedures for notifying about and handling personal data breaches
11. Confidentiality: Obligations regarding confidentiality of processed data
12. Term and Termination: Duration of the agreement and conditions for termination
13. Governing Law and Jurisdiction: Specification of Swiss law as governing law and jurisdiction for disputes
1. Cross-border Data Transfers: Required when personal data will be transferred outside Switzerland, including safeguards and mechanisms for international transfers
2. Audit Rights: Include when parties require mutual audit rights to ensure compliance
3. Sub-processing: Include when either controller may engage sub-processors for data processing activities
4. Insurance: Include when specific insurance coverage requirements are needed for data processing activities
5. Joint Processing Activities: Required when controllers jointly determine processing purposes and means
6. Industry-Specific Requirements: Include when processing involves regulated industries (e.g., healthcare, financial services)
7. Data Protection Impact Assessments: Include when high-risk processing activities require DPIAs
8. Liability and Indemnification: Detailed provisions on liability allocation and indemnification obligations
1. Schedule 1 - Categories of Data: Detailed list of personal data categories being processed
2. Schedule 2 - Processing Activities: Detailed description of specific processing activities and purposes
3. Schedule 3 - Technical and Organizational Measures: Specific security measures implemented by both parties
4. Schedule 4 - Contact Points: List of key contacts for operational, legal, and data protection matters
5. Schedule 5 - Data Retention Periods: Specific retention periods for different categories of data
6. Appendix A - Data Transfer Mechanisms: Details of mechanisms used for any cross-border data transfers
7. Appendix B - Sub-processors: List of approved sub-processors if applicable
8. Appendix C - Security Breach Response Plan: Detailed procedures for handling data breaches
Authors
Applicable Data Protection Laws
Business Day
Confidential Information
Controller
Data Breach
Data Protection Authority
Data Protection Impact Assessment
Data Protection Laws
Data Protection Officer
Data Subject
Data Subject Rights
FADP
GDPR
Information Security Incident
Joint Processing Activities
Personal Data
Personal Data Breach
Processing
Processor
Professional Secrecy
Receiving Controller
Regulatory Authority
Sensitive Personal Data
Services
Sub-processor
Swiss Data Protection Laws
Technical and Organizational Measures
Term
Third Party
Transfer Mechanism
Transferring Controller
Transborder Data Flow
Permitted Purpose
Authorized Personnel
Data Protection Principles
Security Measures
Adequate Country
Shared Personal Data
Processing Records
Scope
Roles and Responsibilities
Data Protection Compliance
Data Processing
Data Security
Confidentiality
Data Subject Rights
Cross-border Transfers
Breach Notification
Audit Rights
Sub-processing
Liability
Indemnification
Term and Termination
Force Majeure
Assignment
Notices
Severability
Entire Agreement
Amendments
Waiver
Third Party Rights
Dispute Resolution
Governing Law
Data Retention
Technical Measures
Organizational Measures
Regulatory Compliance
Joint Controllers
Insurance
Record Keeping
Professional Secrecy
Financial Services
Healthcare
Technology
E-commerce
Professional Services
Manufacturing
Insurance
Telecommunications
Education
Research and Development
Retail
Transportation and Logistics
Marketing and Advertising
Consulting
Legal
Compliance
Information Security
Data Protection
Risk Management
Information Technology
Operations
Privacy
Regulatory Affairs
Data Governance
Business Development
Corporate Affairs
Chief Privacy Officer
Data Protection Officer
Legal Counsel
Compliance Manager
Information Security Manager
Risk Manager
Chief Information Security Officer
Privacy Manager
Chief Legal Officer
Data Governance Manager
Regulatory Compliance Officer
Chief Technology Officer
Chief Information Officer
Operations Director
Business Development Manager
Find the exact document you need
International Data Transfer Addendum
Swiss law-governed addendum for regulating international personal data transfers, ensuring compliance with FADP requirements and data protection standards.
Intra Group Agreement Data Protection
Swiss law-governed agreement regulating data protection and transfers between group companies under FADP/DSG.
Joint Controller Agreement
A Swiss law-governed agreement establishing responsibilities and obligations between joint controllers for personal data processing under FADP and considering GDPR requirements.
Standard Data Processing Agreement
Swiss law-governed Data Processing Agreement establishing controller-processor obligations under FADP/DSG and aligned with GDPR requirements.
Data Addendum
Swiss law-governed data protection addendum establishing data processing obligations and compliance with FADP/DPA requirements.
Data Processing Addendum DPA
A Swiss law-governed agreement defining terms and responsibilities for personal data processing between controller and processor, ensuring compliance with FADP/revFADP and relevant GDPR requirements.
International Data Protection Agreement
Swiss law-governed agreement regulating international data protection and cross-border data transfers, ensuring compliance with Swiss FADP and relevant international standards.
Data Sharing Agreement Controller To Processor
Swiss law-governed Data Sharing Agreement between Controller and Processor, ensuring FADP/LPD compliance and establishing data processing safeguards.
Processor To Processor DPA
A Swiss law-governed agreement between two data processors establishing terms and conditions for delegated data processing activities.
Controller To Controller Data Processing Agreement
Swiss law-governed agreement establishing data sharing framework between two independent data controllers, ensuring FADP compliance and defining mutual data protection responsibilities.
Intercompany Data Processing Agreement
Swiss law-governed agreement regulating intra-group personal data processing activities, ensuring compliance with Swiss FADP and relevant GDPR requirements.
Controller To Controller DPA
Swiss law-governed agreement between two data controllers establishing framework for lawful personal data sharing and processing.
DPA Agreement
Swiss law-governed Data Processing Agreement defining controller-processor relationships and compliance requirements under FADP/DSG.
Order Processing Agreement
A Swiss law-governed agreement between a data controller and processor that establishes obligations and responsibilities for personal data processing under FADP/DSG.
Data Privacy Addendum
Swiss law-governed Data Privacy Addendum ensuring compliance with Swiss FADP/revFADP and alignment with GDPR requirements for personal data processing.
Sub Processing Agreement
A Swiss law-governed agreement establishing terms for sub-processor data handling, ensuring compliance with Swiss FADP and related data protection requirements.
International Data Transfer Agreement
Swiss-law governed International Data Transfer Agreement for compliant cross-border personal data transfers under the revFDPA.
Data Protection Addendum
A Swiss law-governed Data Protection Addendum establishing data processing requirements and responsibilities between parties under Swiss FADP/DSG.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.