Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Article 14 Swiss Representative Services

This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of Article 14 Swiss Representative services to be delivered by GDPRLocal (through the Appointed Representative). Terms used in this Schedule have the same meaning as in the Master Services Agreement.

In the event of any conflict between this Schedule and the Master Services Agreement, this Schedule prevails.

1. Scope of Services

1.1 Designation. With effect from the Service Start Date, the Customer appoints the Appointed Representative to act as its representative in Switzerland pursuant to Article 14 of the Swiss Federal Act on Data Protection (“FADP”). This Schedule constitutes the written mandate required under Article 14 FADP. The Appointed Representative accepts this appointment and agrees to perform the Representative services described in this Schedule in compliance with Article 14 FADP. The mandate does not confer authority to make substantive decisions on behalf of the Customer regarding processing activities, to bind the Customer to any compliance undertaking, or to act as legal representative in litigation or enforcement proceedings.

1.2 Article 14 Swiss Representative duties. In accordance with Article 14 FADP, GDPRLocal shall (through the Appointed Representative):

act as a contact point for the Federal Data Protection and Information Commissioner (FDPIC) and any other competent Supervisory Authority on all issues related to the processing activities covered by the relevant mandate;

act as a contact point for data subjects in Switzerland on issues relating to such processing activities;

receive and transmit communications addressed to the Appointed Representative and forward such communications to the Customer without undue delay;

keep a register of the Customer’s processing activities (containing the information required by Article 12 FADP) and make it available to the FDPIC on request, in accordance with the Appointed Representative’s obligations under Article 15 FADP;

cooperate with the FDPIC in the performance of the Appointed Representative’s direct obligations under Article 15 FADP;

support the Customer in responding to Supervisory Authority inquiries and investigations or enforcement actions and coordinate responses but not assume decision-making authority;

provide general guidance on Swiss regulatory expectations (including FDPIC guidance) related to the representative function and notify the Customer of relevant regulatory developments affecting Article 14 obligations.

The Appointed Representative shall, in the performance of its tasks, have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of the processing.

2. Service Levels and Deliverables

2.1 Service Delivery. GDPRLocal shall act on instructions from the Customer Contact identified in the Customer’s account profile, or any other person expressly authorised by the Customer in writing.

2.2 Advice and reporting. Where GDPRLocal receives a communication from the FDPIC, any other competent Supervisory Authority, or a Data Subject requiring a response within a defined deadline, GDPRLocal shall notify the Customer Contact immediately and specify the response deadline. If the Customer fails to provide instructions in time, GDPRLocal may either (a) respond with a holding acknowledgement, or (b) notify the FDPIC or Data Subject that the matter is being forwarded to the Customer. The Customer acknowledges that GDPRLocal cannot be held responsible for missed deadlines caused by the Customer’s failure to provide timely instructions.

3. Customer Obligations

In addition to the obligations set out in MSA §6, the Customer shall:

3.1 provide GDPRLocal with such information, documents and cooperation as are reasonably necessary for the performance of the Services, including: accurate details of the Customer’s legal entity or entities covered by the appointment; details of the processing activities within the scope of the relevant appointment; and a copy of the Records of Processing Activities;

3.2 respond promptly to all communications forwarded by GDPRLocal and provide timely instructions, information and decisions necessary for the handling of such communications;

3.3 promptly notify GDPRLocal of: (a) any suspected or actual data breach; (b) any change to the Customer’s processing activities that materially affects the scope or nature of the representative appointment; (c) any direct communication received by the Customer from the FDPIC or any other competent Supervisory Authority; (d) any litigation or regulatory proceeding initiated against the Customer relating to its processing of personal data of data subjects in Switzerland; and (e) any data subject request relating to rights under the FADP;

3.4 publish the Swiss Representative contact details and communicate them to the FDPIC as required by the FADP, using the contact details for the Appointed Representative set out in the Appendix to this Schedule, and ensure that those contact details are accurately reflected in all of the Customer’s privacy notices, website privacy policies, and communications to data subjects as required by Article 19 FADP;

3.5 retain sole responsibility for the accuracy, completeness, and currency of the ROPA. The Appointed Representative’s obligation to maintain a register under Article 15 FADP is contingent upon the Customer providing an accurate ROPA;

3.6 not take any action that would (a) expose GDPRLocal or the Appointed Representative to enforcement proceedings or regulatory sanctions other than as an unavoidable consequence of the Appointed Representative’s role; (b) require GDPRLocal or the Appointed Representative to make any inaccurate representation to a Supervisory Authority; or (c) cause GDPRLocal or the Appointed Representative to act in violation of the FADP or other applicable law.

4. Services Outside the Scope

4.1 Unless expressly agreed at activation, the Services shall not include substantive FADP compliance advice or services (which are covered under separate Service Schedules if applicable) or the provision of legal advice or legal representation. Where legal advice is required, the Customer should seek independent legal counsel.

4.2 GDPRLocal and the Appointed Representative shall not assume management responsibility or operational decision-making authority.

4.3 The Appointed Representative’s role in relation to data subject rights requests is advisory and supervisory; operational handling of DSARs remains the Customer’s sole responsibility.

4.4 Any services outside the statutory Article 14 representative role may be requested as billable additional services and Tasks in accordance with the Master Services Agreement.

5. Liability and Indemnity (Service-specific supplement to MSA §10 / §11)

5.1 Acknowledgement of Liability Framework. The parties acknowledge:

Under the FADP and consistent with FDPIC guidance, the Appointed Representative is not substitutively liable for the Customer’s FADP breaches. Direct liability is limited to its own statutory obligations under Article 14 FADP.

The Appointed Representative’s exposure to enforcement proceedings arises from its position as the Customer’s local contact point in Switzerland and is a structural feature of the Article 14 role, not a reflection of culpability. The contractual allocation of risk reflects this.

5.2 Limitation of Liability (service-specific).

5.2.1 Subject to clause 5.5, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Customer in respect of the Article 14 Swiss Representative Service in the twelve (12) month period immediately preceding the event giving rise to the claim.

5.2.2 Neither party shall be liable for indirect, consequential, special, or punitive loss.

5.2.3 GDPRLocal and the Appointed Representative shall have no liability for: FADP fines or sanctions imposed on the Customer; loss arising from the Customer’s failure to comply with the FADP or provide accurate/timely ROPA or instructions; consequence of failure to update privacy notices with correct contact details; loss attributable to the Customer’s failure to notify of a relevant event per clause 3; loss arising from GDPRLocal’s good-faith forwarding of communications where the Customer failed to respond adequately.

5.3 Customer Indemnity. The Customer shall indemnify, defend, and hold harmless GDPRLocal, the Appointed Representative, and their respective affiliates, officers, employees, and agents (each an “Indemnified Person”) against losses (including reasonable legal costs on a full indemnity basis) arising from: enforcement proceedings; Data Subject claims relating to the Customer’s processing; Customer’s failure to meet clause 3 obligations; failure to provide an accurate ROPA; and costs of responding to Enforcement Proceedings or Supervisory Authority inquiries on the Customer’s behalf.

5.4 Defence procedure. On notification of any potentially indemnifiable claim: GDPRLocal notifies the Customer promptly; the Customer assumes conduct of defence at its cost (Indemnified Person may participate at Customer’s cost; no settlement adverse to the Indemnified Person without consent); the Indemnified Person cooperates reasonably; failing assumption within 15 Business Days, GDPRLocal may take over conduct at the Customer’s cost.

5.5 Exclusions from Limitation. The liability cap in clause 5.2 does not apply to: the Customer’s indemnity obligations under clause 5.3; liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; any other liability that cannot be limited by applicable law.

5.6 Professional Indemnity Insurance. GDPRLocal shall maintain throughout the term professional indemnity insurance in an amount no less than £1,000,000 per claim and in the aggregate per policy year. Evidence available on reasonable written request.

6. Term and Termination (Service-specific)

6.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (“Initial Term”), unless terminated earlier in accordance with this clause 6 or MSA §12. It auto-renews for successive twelve-month Renewal Terms unless notice of non-renewal is given at least ninety (90) days prior to the end of the then-current term.

6.2 Termination for Convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule on not less than ninety (90) days’ prior written notice, exercisable only after expiry of the Initial Term. The 90-day notice reflects GDPRLocal’s legitimate interest in continuity and the Customer’s need to identify a replacement Article 14 Swiss representative to avoid violating the FADP.

6.3 Additional Termination Right. GDPRLocal may additionally terminate with immediate effect if (a) the Customer provides materially inaccurate ROPA information such that performance would involve misrepresentation to Supervisory Authorities; or (b) the Customer’s instructions would require unlawful action or expose GDPRLocal or the Appointed Representative to disproportionate liability.

6.4 Right of Resignation in Enforcement Situations. Market standard practice for Article 14 representatives establishes a specific right of resignation where the Customer stops cooperating during Enforcement Proceedings. GDPRLocal may resign with immediate effect if:

Enforcement Proceedings are commenced against the Appointed Representative and the Customer (i) fails to assume defence within 15 Business Days; (ii) fails to provide adequate instructions within deadlines; or (iii) fails to cooperate;

the Customer ceases to respond to GDPRLocal’s communications for 15+ Business Days during a live FDPIC inquiry or Enforcement Proceeding;

the Customer is conducting processing constituting a serious ongoing FADP violation that it refuses to remedy following written notice.

Immediate resignation in such circumstances shall not constitute a breach. The Customer accepts sole responsibility for any regulatory consequence of a coverage gap.

6.5 Consequences of Termination. Within 5 Business Days: GDPRLocal ceases holding out as the Customer’s representative and notifies the FDPIC where required by Swiss law; the Customer updates all privacy notices to remove the Appointed Representative’s details. Within 15 Business Days: GDPRLocal delivers a copy of the ROPA + communications log. Any pending Enforcement Proceedings handled per transitional arrangements (or, failing those within 10 Business Days, GDPRLocal may notify the FDPIC of termination and direct it to the Customer). Customer pays outstanding fees and costs. Clauses 5 and 6.5 survive termination.

6.6 Regulatory Notice. The Customer accepts sole responsibility for appointing a replacement Article 14 representative before or immediately upon termination to avoid violating the FADP. GDPRLocal will cooperate as a courtesy with any replacement at its then-current standard rates.

__________________________________________________

Appendix to Schedule 3 — Statement of Work (Article 14 Swiss Representative Services)

This Statement of Work (“SOW”) is appended to and forms part of this Schedule, which in turn forms part of the Master Services Agreement between the Customer and GDPRLocal Ltd. Capitalised terms have the same meaning as in the Schedule or the Agreement.

The SOW is generated and recorded by GDPRLocal at the point of Service activation (whether via the GDPRLocal platform or by written confirmation) and captures the bespoke scope, fees, and operational parameters of this engagement. Customer identity is auto-populated from the Customer’s account profile and is not re-captured here.

1. Customer Details

Company Name[Company Name]
Contact Name[Contact Name]
Contact Email[Contact Email]
Contact Number[Contact Number]

2. Effective Date and Term

Effective Date: the date and time of Service activation (the “Service Start Date”).

Initial Term: twelve (12) months from the Service Start Date [Service Activation Date], in accordance with Schedule §6.1, unless variation is negotiated.

Auto-renewal and notice as per Schedule §6.1.

3. Service Scope

Territory of representation: Switzerland (Article 14 FADP).

Processing activities in scope: as set out in the Customer’s Records of Processing Activities (ROPA) provided to GDPRLocal under §3.5 of the Schedule.

ROPA reference: ROPA appended at activation, or to be provided by the Customer within 15 days of activation.

Scope exclusions (if any): any processing activities expressly outside the Rep’s scope, otherwise “none”.

4. Service Fees

Subscription fee: as set out in the Rate Card current at activation.

Billing cadence: [monthly/annual], per the Customer’s selection at activation (MSA §5.2).

Negotiated variation (if any, it will be provided in separate written documentation).

Currency: GBP. All fees exclusive of VAT and any applicable taxes.

5. Designated Personnel

Appointed Representative entityALTRION Sagl 
Registered addressVia Luigi Lavizzari 8, Mendrisio – Switzerland 
Emailcontact@gdprlocal.com
Tel+44 1772 217 800

GDPRLocal delivers the Swiss Representative Service through its Swiss partner ALTRION Sagl. ALTRION Sagl performs the Appointed Representative role at the Mendrisio address under GDPRLocal’s contract with the Customer. Internal allocation of individuals performing the Representative role from time to time is at the discretion of GDPRLocal and ALTRION Sagl; GDPRLocal will notify the Customer of any permanent change to the designated contact within thirty (30) business days.

6. Privacy Notice Wording

The Customer shall publish, in its privacy notices, website privacy policies, and any other communications required by Article 19 FADP, the following wording (or equivalent that conveys the same information):

“Our Swiss Representative under Article 14 FADP is ALTRION Sagll, Via Luigi Lavizzari 8, Mendrisio – Switzerland, Switzerland. Web: https://gdprlocal.com. Swiss data subjects and the Federal Data Protection and Information Commissioner (FDPIC) may contact our Swiss Representative at contact@gdprlocal.com or +44 1772 217 800.”

The Customer shall update such notices promptly upon written notice from GDPRLocal of any change to those contact details.

7. Swiss Representative Services and Deliverables

ServiceServices includedTimeline
Appointment & RepresentationFormal designation as Swiss Representative under Article 14 FADP; authorised representation mandate; inclusion in privacy noticeOne-off (onboarding)
Regulatory Point of ContactReceipt and forwarding of FDPIC and other Supervisory Authority communications; coordination support for responsesForwarding within 1–3 business days
Data Subject Contact FunctionReceipt and forwarding of data subject requests (DSARs) from Swiss data subjects; logging where applicableForwarding within 1–3 business days
Records of Processing Activities (ROPA)Maintain access to Article 12 records for regulatory inspection; secure storage / access; provision to authorities on requestOngoing / on request
Regulatory Cooperation SupportCommunication coordination during inquiries or investigations; tracking of regulatory exchangesAs required
Communication Handling & EscalationTimely escalation of regulatory or high-risk communications; priority flagging of urgent mattersAs required
Compliance InterfaceHigh-level guidance related to Article 14 obligations; notifications of regulatory developments; practical guidance (non-legal advice)As needed

8. Review of Services

This SOW may be reviewed and updated by written agreement between the parties where required to reflect material changes to the Customer’s processing activities, service requirements, or compliance priorities. Any such update will be recorded as a revised SOW associated with the Customer’s account.

9. Acceptance

This SOW is deemed accepted by the Customer at the moment of Service activation (whether via in-portal activation or written confirmation accepted by GDPRLocal). No physical signature is required.