General Data Processing Agreement (DPA)
Preamble
Partner & Partner (the «Processor») provides its customers (the «Controller») with services under a separate contractual relationship that involve processing personal data on the Controller’s behalf.
This DPA enables the Processor and Controller (together, the «Parties») to meet their obligations under applicable data-protection law, in particular Art. 9 FADP and Art. 28 GDPR, where the Processor processes personal data on behalf of the Controller.
1. Processing Details and Duration
1.1. Subject Matter
This DPA governs the Processor’s processing of personal data on behalf of the Controller as a data processor.
1.2. Duration
This DPA begins on its effective date and remains valid while the Processor processes personal data on the Controller’s behalf.
1.3. Nature of Processing
The Processor processes personal data only on the Controller’s behalf and documented instructions.
1.4. Purpose of Processing
Processing takes place solely to perform the separate contractual relationship between the Controller and Processor and/or to comply with legal obligations.
2. Technical and Organisational Measures (TOMs)
- The Processor implements appropriate technical and organisational measures to ensure adequate personal-data security and compliance with applicable data-protection rules.
- In particular, the Processor implements appropriate measures ensuring the confidentiality, integrity, availability and resilience of systems and services used to process personal data.
- Personal data is generally processed in Switzerland and the European Economic Area (EEA). It may also be exported or transferred to other countries for processing where their law ensures adequate protection according to a decision of the Swiss Federal Council and, where the GDPR applies, the European Commission. Transfers to countries without adequate law may occur where protection is otherwise ensured, especially through standard data-protection clauses or other suitable safeguards. Exceptionally, data may be exported without adequate or suitable protection where special legal requirements are met, such as the data subject’s explicit consent or a direct connection with concluding or performing a contract.
3. Subprocessing
The Processor informs the Controller in good time of any intended engagement of a new third party. The Controller may object within 30 days and accepts any resulting disadvantages. Otherwise, the engagement is deemed approved after 30 days. The Processor ensures that third parties are bound by the same data-protection obligations under this DPA.
4. Notification Duties
The Processor notifies the Controller immediately of personal-data breaches affecting data processed on its behalf, including substantiated suspicions. Notification is documented according to current information and made no later than 36 hours after the Processor becomes aware of the event. It describes the nature of the breach and, where possible, the categories and approximate numbers of affected persons, data categories and records.
5. Liability
The Processor is liable to the Controller only for direct loss caused by breach of this DPA’s data-protection obligations. Further liability is excluded unless mandatory by law. In particular, the Processor is not liable for independently provided third-party services, consequential loss caused by defects or other indirect loss.
The Controller is fully liable to the Processor for direct and indirect loss arising because data provided for processing violates legal requirements or is not lawfully available to the Controller. The Controller shall fully indemnify the Processor against all expenses, claims and loss, including legal and procedural costs.
6. Termination
Either Party may terminate this DPA immediately if the other materially breaches it and fails to remedy the breach within a reasonable period after written notice.
Upon termination, regardless of reason, the Processor must delete all personal data processed under this DPA unless statutory retention duties apply.
The Processor must also ensure immediate destruction of the personal data by its appointed third parties.
7. Governing Law and Jurisdiction
This agreement is governed exclusively by Swiss law. Exclusive jurisdiction lies at the Agency’s registered office. Mandatory law and jurisdictions remain reserved.