SCRM Supplier Compliance & Risk Management

Home

FADP Art. 8 and 9 · in force since 1 September 2023

You may outsource the processing. Not the responsibility.

Every IT provider, cloud tool and payroll bureau with access to personal data is a processor. And for each one you must be able to show that you assessed them.

The revised Swiss Data Protection Act allows personal data to be passed to processors only where they guarantee data security. The mandate needs a contractual or statutory basis, and any sub-processing requires your prior approval.

In practice this is less a legal problem than a visibility problem. Few companies hold a complete list of their processors, because departments adopt tools without anyone counting. And without the list there is neither assessment nor evidence.

Who is typically missing

  • Cloud services a department subscribed to on its own.
  • Fiduciary, payroll and external accounting.
  • IT providers with remote maintenance access.
  • Marketing and newsletter tools holding customer data.
  • Your providers’ sub-processors – often outside Switzerland.

What is required

Art. 9(1)
Processing may only be delegated on a contractual or statutory basis.
Art. 9(2)
Ensure the processor guarantees data security – before the transfer, not after.
Art. 9(3)
Sub-processing only with your prior approval.
Art. 8
Appropriate technical and organisational measures, at the provider too.
Art. 16 ff.
For disclosures abroad, check whether the destination offers adequate protection, otherwise agree suitable safeguards.

How SCRM covers it

Processor register

Every provider with data category, purpose and processing location in one place.

Contracts with expiry

Processing agreements and security annexes with validity and reminders.

Sub-processors

Approved sub-processing visible – and so are changes to it.

Assessment with a date

The judgement “guarantees data security” is a result with a date, a basis and a person behind it.

Frequently asked

Is a signed processing agreement enough?

It is the basis, not the evidence. You must also satisfy yourself about data security – an assessment you can show later.

How does this relate to the GDPR?

The requirements resemble Art. 28 GDPR but are less formalised. Working to GDPR standards usually satisfies the FADP; the reverse is not always true.

What about US providers?

What matters is whether the destination offers adequate protection from a Swiss perspective, or whether suitable safeguards exist. That assessment belongs on record – it is the first thing asked for in an access request.

As of July 2026. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required