Swiss FADP service

Swiss Cross-Border Data Transfer Support

Create a reliable view of how personal data connected with Switzerland is accessed, hosted, supported, and transferred internationally.

A practical service built around your evidence

Cross-border transfer reviews need to connect contracts to actual systems and operating arrangements. We help identify the relevant parties, countries, purposes, data, access patterns, onward transfers, and safeguards.

The scope can cover a single vendor, a product environment, or a broader transfer inventory. Outputs are designed for practical use in procurement, security, contracting, privacy notices, and internal records.

Preparing for the first discussion

Prepare a transfer map that includes remote access as well as the location where information is stored. For each relevant supplier, identify the contracting entity, countries of access, subprocessors, information categories, purpose, and applicable contractual arrangements. Ask the system owner to check the actual configuration against the supplier's written description. If the two differ, preserve the difference as a review question rather than treating a contract as proof of the technical setup. The first useful deliverable is a clear list of transfer relationships and unresolved safeguards that the organisation can validate and maintain when vendors or access locations change.

Service outputs

What you receive

The exact scope is confirmed before work begins. These are the core outputs normally used to turn the review into accountable action.

1

Swiss transfer map

Parties, locations, purposes, data, access, hosting, support, and onward transfers.

2

Documentation review

Review of relevant contractual and internal transfer materials within the agreed scope.

3

Safeguards record

A clear view of the contractual, technical, and organisational measures relied upon.

4

Remediation roadmap

Prioritised actions for vendors, contracts, controls, notices, and processing records.

How we work with your team

01

Confirm the scope

We agree the business question, processing, stakeholders, locations, deadlines, and evidence needed for a useful review.

02

Gather reliable evidence

We collect the relevant records, system and vendor information, existing documents, and input from accountable teams.

03

Complete the review

We test the current position, make assumptions explicit, resolve inconsistencies, and identify practical improvements.

04

Deliver and maintain

You receive decision-ready outputs, prioritised actions, accountable owners, and clear triggers for future review.

How we help

See how this service fits your organisation

Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.

01 · Fit

Is Swiss cross-border data transfer support right for your organisation?

Use this service when you need to map and assess transfers or remote access involving Swiss personal data. We can focus on a vendor, group service, cloud architecture, support model, or customer question where contracts and operational access need to be reconciled.

Swiss cross-border transfer work is needed when personal data is hosted, accessed, supported, or onward-transferred across borders and the contract does not reflect the real route. The review connects Swiss processing, countries, suppliers, group companies, data categories, access, safeguards, and business purpose so the team can make a reasoned decision rather than rely on a generic international transfer clause.

02 · Decision

What you will be able to decide

The organisation should know what data moves, between which parties and locations, for which purpose, under which documents, and with which safeguards. The assessment helps decide whether to approve, change, document, or further investigate a transfer pattern.

You should know which routes are in scope, which documents or mechanisms support them, what supplementary safeguards are realistic, what residual risk remains, and who owns the choice. We distinguish Swiss storage, remote access, support, and onward transfer because a single vendor name can hide several different flows.

03 · Trigger

When to bring us in

New hosting, support, analytics, group access, a vendor or subprocessor, acquisition, customer diligence, or a change in destination can make an old transfer description inaccurate. A Swiss review can also be useful when a global assessment does not explain the local processing facts.

04 · Evidence

What we need from your team

Use architecture, vendor locations, support access, data categories, purposes, recipients, onward transfer, contracts, security controls, encryption, access management, retention, notices, and existing records. The assessment should compare what the service can do with what the contract says.

Bring contracts, vendor and subprocessor lists, hosting and support locations, data-flow diagrams, access roles, encryption and key management, retention, deletion, incident terms, data categories, purposes, and the Swiss-facing processing context. We use technical and procurement evidence together and identify claims that need verification by the system or supplier owner.

05 · People

Who should join the work

Privacy and legal coordinate with security, engineering, procurement, vendor management, and the business owner. Customer teams may add contractual obligations. The owner approving the transfer should understand the safeguards and the trigger for reviewing them again.

06 · Method

How we will work together

The work maps the flow, checks the relevant documents and safeguards, records the risk and decision, and assigns actions. It can start with a single supplier and then turn the evidence questions into a reusable onboarding and renewal workflow.

The output can support a supplier decision, contract action, architecture change, safeguard test, or management risk acceptance. Each action should have an owner and closing evidence. If the designed route cannot be supported, the business can decide whether to limit data, change the service, add controls, or stop the transfer until a better option exists.

07 · Output

What you will receive

Outputs may include a Swiss transfer map, assessment, contract and vendor actions, security dependencies, notice changes, owner assignments, and refresh triggers. Each should be tied to the systems and commercial processes that can implement the change.

08 · Friction

What can make this harder

A contract-first review can miss remote administration, support tools, backups, logs, or onward transfers. A spreadsheet can also become misleading when no one updates it after an architecture or vendor change. The service joins legal, procurement, and technical facts.

09 · Maintenance

How you keep it current

Review transfers at onboarding, renewal, subprocessors change, architecture change, customer diligence, and incident review. Keep evidence links and owner information current. Reassess when destination, access, data category, purpose, or safeguard changes.

Reopen the Swiss transfer review after a new subprocessor, hosting change, support model, contract renewal, access expansion, encryption change, or new purpose. Keep the assessment beside the vendor and architecture records. A stable contract does not prove a stable route when cloud services and group operations evolve frequently.

10 · Boundaries

What stays with your organisation

Transfer support does not operate safeguards, make a vendor secure, or remove all legal risk. The organisation remains responsible for accurate facts, contractual decisions, and implementation. Additional legal or technical specialists may be required.

11 · Scope

What to prepare before you start

Bring the priority flow or vendor, parties, locations, access pattern, data categories, contracts, security material, customer deadline, and owner. A defined one-flow scope can produce a useful result faster than an undefined global inventory.

  • Swiss purpose, data, country, and access facts
  • Storage, support, remote access, and onward routes
  • Vendor, subprocessor, contract, and safeguard evidence
  • Procurement, security, architecture, and risk owners
  • Supplier or system change trigger

12 · Buyer brief

What your first working brief should contain

A Swiss transfer brief should describe the local processing, purpose, data categories, countries, storage, remote access, support, onward route, vendor, subprocessor, contract, retention, deletion, safeguards, encryption, and business necessity. Include the architecture and procurement owners who can verify the route. A contract or vendor name is only a starting point; the assessment needs to show how Swiss data can actually be accessed and protected.

Connect the result to the vendor and architecture record. Track contract work, safeguards, access limits, tests, risk acceptance, and the person responsible for closing each action. Review after a hosting move, new subprocessor, support change, contract renewal, new purpose, or access expansion. If the route is not supportable as designed, make the practical alternatives visible. A Swiss transfer decision remains current only when its source facts and review trigger are maintained.

13 · First test

What we will test first

The first Swiss transfer period tests local processing, purpose, data, countries, storage, remote access, support, onward route, vendor, subprocessor, contract, retention, deletion, safeguards, encryption, and necessity. Procurement and architecture owners should verify the real route. Track contract changes, controls, access limits, tests, risk acceptance, and closing evidence beside the vendor record. Reopen after a hosting, subprocessor, support, access, purpose, or contract change. A Swiss transfer assessment should show the current source facts and the owner who can decide what happens when the route is no longer supported.

14 · Working record

How the result stays usable

A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.

15 · Progress

How you can judge progress

Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.

16 · Proportion

What a proportionate scope looks like

A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.

17 · Handoff

What remains with your organisation

Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.

In practice

See what you can expect

Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.

Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock
Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock; evidence view for this page
Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock; decision view for this page
Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock; workflow view for this page
Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock; safeguard view for this page
Editorial still life showing Swiss cross-border transfers with alpine contours, a paper globe, secure route lines, and a lock; review view for this page

Frequently asked questions

Can you work with our procurement team?

Yes. Transfer questions can be integrated into vendor intake, due diligence, contracting, approval, and periodic review.

Can the review cover onward transfers?

Yes. Subprocessors, support providers, and other onward access should be included where relevant to the scoped service.

What evidence is useful?

Data-flow descriptions, vendor lists, agreements, hosting and support locations, security measures, subprocessors, notices, and existing assessments are common starting points.

Discuss the scope before you commit

Tell us what changed, what evidence you already have, and which decision or deadline the work needs to support.

Contact our team

Service information is general and does not replace advice based on the facts of a specific matter. Final scope, responsibilities, and deliverables are confirmed in the service documentation.

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services