Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Controller To Controller DPA
"I need a Controller to Controller DPA under Swiss law for a fintech company sharing customer data with a credit scoring provider, with specific focus on cross-border transfers to the UK and enhanced security measures for financial data."
1. Parties: Identification of the data controllers entering into the agreement
2. Background: Context of the data sharing relationship and purpose of the agreement
3. Definitions: Key terms used in the agreement, including Swiss law-specific terminology
4. Purpose and Scope: Detailed description of the data sharing purposes and processing activities covered
5. Roles and Responsibilities: Clear delineation of each controller's obligations and responsibilities
6. Legal Basis for Processing: Specification of the legal grounds for data processing under Swiss law
7. Data Protection Principles: Commitment to comply with fundamental data protection principles
8. Data Subject Rights: Procedures for handling data subject requests and ensuring rights are respected
9. Security Measures: Required technical and organizational security measures
10. Data Breach Notification: Procedures and timeframes for breach notification
11. Cross-border Transfers: Rules and safeguards for international data transfers
12. Confidentiality: Confidentiality obligations regarding shared personal data
13. Liability and Indemnification: Allocation of risks and responsibilities between controllers
14. Term and Termination: Duration of the agreement and termination provisions
15. Governing Law and Jurisdiction: Confirmation of Swiss law application and jurisdiction
1. Audit Rights: Optional provisions for mutual auditing rights, recommended for high-risk processing
2. Sub-processing: Include if either controller may engage sub-processors
3. Insurance Requirements: Specific insurance obligations, recommended for high-value data processing
4. Data Protection Impact Assessments: Procedures for DPIAs, recommended for high-risk processing
5. Joint Controller Provisions: Include if any processing activities involve joint controllership
6. Industry-Specific Requirements: Additional provisions for regulated industries (e.g., healthcare, financial services)
7. Data Retention and Deletion: Specific retention periods and deletion procedures, if not covered in main agreement
1. Schedule 1 - Categories of Data: Detailed list of personal data categories being processed
2. Schedule 2 - Processing Activities: Detailed description of processing activities performed by each controller
3. Schedule 3 - Technical and Organizational Measures: Specific security measures implemented by both parties
4. Schedule 4 - Transfer Mechanisms: Details of cross-border transfer mechanisms and safeguards
5. Schedule 5 - Contact Points: Key contacts for operational, security, and privacy matters
6. Appendix A - Data Subject Rights Procedure: Detailed procedures for handling data subject requests
7. Appendix B - Breach Notification Procedure: Detailed procedures for handling and reporting data breaches
Authors
Applicable Data Protection Laws
Business Day
Confidential Information
Controller
Cross-border Transfer
Data Protection Impact Assessment
Data Subject
Data Subject Rights
EEA
FADP
GDPR
Information Commissioner
Personal Data
Personal Data Breach
Processing
Recipient
Restricted Transfer
Sensitive Personal Data
Services
Swiss Data Protection Laws
Technical and Organizational Measures
Term
Third Country
Third Party
Transfer Mechanism
Transferring Controller
Receiving Controller
Affiliate
Authorized Personnel
Business Purpose
Consent
Data Protection Officer
Data Transfer Agreement
Effective Date
Force Majeure Event
Group
Implementation Date
Joint Controllers
Material Change
Permitted Purpose
Privacy Notice
Processing Records
Representative
Security Incident
Standard Contractual Clauses
Sub-processor
Supervisory Authority
Working Day
Interpretation
Scope
Data Protection
Compliance
Security
Confidentiality
Liability
Indemnification
Term and Termination
Force Majeure
Assignment
Data Transfer
Breach Notification
Audit Rights
Governing Law
Dispute Resolution
Notices
Amendments
Severability
Entire Agreement
Data Subject Rights
Technical Requirements
Regulatory Compliance
Risk Allocation
Insurance
Warranties
Cooperation
Sub-processing
Reporting
Record Keeping
Financial Services
Healthcare
Insurance
Technology
E-commerce
Telecommunications
Professional Services
Manufacturing
Education
Research
Pharmaceutical
Real Estate
Retail
Logistics
Consulting
Legal
Compliance
Privacy
Information Security
Risk Management
Information Technology
Data Protection
Information Governance
Operations
Procurement
Corporate Affairs
Data Protection Officer
Privacy Officer
Legal Counsel
Compliance Manager
Information Security Officer
Risk Manager
Chief Privacy Officer
Chief Legal Officer
Chief Compliance Officer
Chief Information Security Officer
Data Protection Manager
Privacy Manager
Contract Manager
Information Governance Manager
Legal Operations Manager
Find the exact document you need
International Data Transfer Addendum
Swiss law-governed addendum for regulating international personal data transfers, ensuring compliance with FADP requirements and data protection standards.
Intra Group Agreement Data Protection
Swiss law-governed agreement regulating data protection and transfers between group companies under FADP/DSG.
Joint Controller Agreement
A Swiss law-governed agreement establishing responsibilities and obligations between joint controllers for personal data processing under FADP and considering GDPR requirements.
Standard Data Processing Agreement
Swiss law-governed Data Processing Agreement establishing controller-processor obligations under FADP/DSG and aligned with GDPR requirements.
Data Addendum
Swiss law-governed data protection addendum establishing data processing obligations and compliance with FADP/DPA requirements.
Data Processing Addendum DPA
A Swiss law-governed agreement defining terms and responsibilities for personal data processing between controller and processor, ensuring compliance with FADP/revFADP and relevant GDPR requirements.
International Data Protection Agreement
Swiss law-governed agreement regulating international data protection and cross-border data transfers, ensuring compliance with Swiss FADP and relevant international standards.
Data Sharing Agreement Controller To Processor
Swiss law-governed Data Sharing Agreement between Controller and Processor, ensuring FADP/LPD compliance and establishing data processing safeguards.
Processor To Processor DPA
A Swiss law-governed agreement between two data processors establishing terms and conditions for delegated data processing activities.
Controller To Controller Data Processing Agreement
Swiss law-governed agreement establishing data sharing framework between two independent data controllers, ensuring FADP compliance and defining mutual data protection responsibilities.
Intercompany Data Processing Agreement
Swiss law-governed agreement regulating intra-group personal data processing activities, ensuring compliance with Swiss FADP and relevant GDPR requirements.
Controller To Controller DPA
Swiss law-governed agreement between two data controllers establishing framework for lawful personal data sharing and processing.
DPA Agreement
Swiss law-governed Data Processing Agreement defining controller-processor relationships and compliance requirements under FADP/DSG.
Order Processing Agreement
A Swiss law-governed agreement between a data controller and processor that establishes obligations and responsibilities for personal data processing under FADP/DSG.
Data Privacy Addendum
Swiss law-governed Data Privacy Addendum ensuring compliance with Swiss FADP/revFADP and alignment with GDPR requirements for personal data processing.
Sub Processing Agreement
A Swiss law-governed agreement establishing terms for sub-processor data handling, ensuring compliance with Swiss FADP and related data protection requirements.
International Data Transfer Agreement
Swiss-law governed International Data Transfer Agreement for compliant cross-border personal data transfers under the revFDPA.
Data Protection Addendum
A Swiss law-governed Data Protection Addendum establishing data processing requirements and responsibilities between parties under Swiss FADP/DSG.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.