Data Processing Agreement (Auftragsbearbeitung)

An Auftragsbearbeitung is a written contract required by Swiss privacy law (revDSG) between your company and any external vendor—payroll provider, recruitment platform, or HR software—that processes employee personal data on your behalf. It clarifies who is responsible for data security, compliance, and breach notification.

Also available inDeutschFrançaisItaliano

When you use HR software, a payroll bureau, or a recruiting platform, that vendor handles sensitive employee information: names, salaries, health data, social insurance numbers. Swiss privacy law (revDSG) requires you to have a written Auftragsbearbeitung with every such vendor.

This is not a negotiable nice-to-have. It is a legal obligation. Without it, your company and the vendor share liability for data breaches and regulatory fines.

When You Need an Auftragsbearbeitung

You need one whenever a third party processes employee personal data for you. Common cases: payroll processing, recruiting software, benefits administration, background checks, occupational health services, or time-tracking systems.

Even cloud storage (Google Drive, OneDrive) with employee files requires one. If the vendor is in Switzerland, the EU, or overseas, the rule applies. The vendor's location does not exempt you.

  • Payroll bureaus (Lohnabrechnung)
  • Recruiting platforms and ATS systems
  • HR management software
  • Background check providers
  • Occupational health and safety consultants
  • Cloud storage or backup services used for employee records

Your Obligations as the Employer

You must put in writing what data the vendor processes, why, how long it is stored, and who is responsible for security and breach notification. The vendor must confirm they will not use the data for their own purposes and will comply with revDSG.

You must also audit your vendor's security practices—at least a basic check. If they suffer a breach affecting your employees, you must notify the cantonal privacy authority (Datenschutzbehoerde) within 72 hours. The vendor is contractually liable to help you do so.

  • Document the purpose and scope of data processing
  • Require the vendor's written commitment to data security
  • Clarify roles: who handles breach notification, data deletion, and access requests
  • Retain a copy for audit purposes
  • Review and update the agreement when services change
  • Do not assume the vendor's terms of service count as an Auftragsbearbeitung

The Most Common Mistake

Assuming the vendor's standard contract or terms of service is enough. It is not. A standard terms-of-service document typically does not meet revDSG requirements because it lacks clarity on data processing roles, security standards, and breach procedures.

The second mistake: signing an Auftragsbearbeitung once and never updating it. If your use of the software changes—for example, you begin storing health data or expand to a new country—you must update the agreement. A lawyer should review any template before use.

  • Use a written Auftragsbearbeitung, not just email confirmations
  • Do not rely solely on the vendor's standard privacy policy
  • Update the agreement whenever your data processing changes
  • Keep records of all Auftragsbearbeitungen for audit trails
  • If uncertain, ask your vendor: 'Do you have a revDSG-compliant data processing agreement?'
  • Consider legal review if the vendor is unclear or resistant

Frequently asked questions

Do I need an Auftragsbearbeitung for every software I use?
Only if the vendor processes personal data on your behalf. General business software (invoicing, CRM for customers) that does not touch employee records does not need one. But any HR, payroll, or recruiting tool does.
Can I use a template from the vendor?
Yes, but review it carefully. It must cover all revDSG requirements: data scope, purpose, duration, security measures, breach notification, and vendor liability. If it is vague, ask the vendor to clarify or consult a lawyer.
What happens if I do not have an Auftragsbearbeitung?
Your company and the vendor share legal liability for data breaches and regulatory fines. The cantonal privacy authority can impose penalties. You also violate your duty of care to employees. It is not enforced retroactively often, but the risk is real.

General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.

Related