Data Processing Agreement
1 Overview
This agreement specifies the obligations of the parties to the framework agreement with regard to the requirements of the Swiss Data Protection Act (DSG) and the EU General Data Protection Regulation (EU GDPR). It supplements the framework agreement between the service provider and the client in this regard. This may involve one or more contracts between the service provider and the client in which the service provider acts as a service provider to the client.
2 Subject matter and validity
The subject matter and validity are set out in the framework agreement. Offers and invoices are considered contractual documents.
The categories of relevant data processed, the categories of data subjects and the applicable technical and organisational measures are the subject of this appendix.
3 Scope of application and responsibility
3.1 Lawfulness of data processing
The service provider processes the relevant data exclusively for the purpose of fulfilling the contract or for the purposes specified in the framework agreement. The client is responsible for the lawfulness of the data processing itself, including the permissibility of the processing of orders and subcontracts.
3.2 Additional orders
The client has the right to issue additional orders to the service provider in writing at any time with regard to the processing of the relevant data. The service provider shall comply with these orders insofar as they are feasible and objectively reasonable within the scope of the contractually agreed services provided by the service provider. If such orders result in additional costs for the service provider or a change in the scope of services, the contractually agreed contract amendment procedure shall apply.
3.3 Compliance of orders
The service provider shall inform the client immediately if it believes that an order violates the DSG or the EU GDPR. In this case, the service provider may suspend the implementation of the order until it has been confirmed or amended by the client.
The above does not apply to orders from the client in connection with the granting of access authorisations or the disclosure of relevant data to the client itself. The service provider may assume at any time that these orders comply with the law. However, it is entitled to request corresponding written confirmation from the client.
4 Type of data
The service provider classifies systems and data to ensure that information receives an appropriate level of protection. There are three categories of information classification:
- Confidential: Data relating to individuals and affecting their privacy (personal data).
- Internal: Data that does not relate to personal data but is relevant to security and operational continuity.
- Public: Information that is accessible to everyone.
Personal data is classified as confidential data and enjoys the highest level of protection.
4.1 General
The client provides the service provider with personal data for processing in connection with the framework agreement and its order.
4.2 Data subjects
This may include personal data relating in particular to the following data subjects:
- Potential clients, current clients, business partners, suppliers and service providers
- Employees or other auxiliary persons of potential clients, current clients, business partners, suppliers and service providers
- Employees or other auxiliary persons of the client who have been authorised by the client to use the services
- Potential employees, current employees and former employees of the service provider
4.3 Types of personal data
This may include the following types of personal data in particular:
- Business contact details such as email address, telephone number or address
- Other business data such as contract, billing or payment data
- Personal information such as first name, surname, date of birth, gender or nationality
- Private contact details such as email address, telephone number or address
- Details from identity documents
- Information about professional life such as job title or position
- Information about your private life, such as marital status or hobbies
- User information such as login details, customer number, personal identification number or personnel number
- Technical information such as IP address or device information
4.4 Sensitive personal data
These data categories are personal data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data and biometric data for the unique identification of a natural person, health data, or data concerning sex life or sexual orientation.
The service provider ensures that no particularly sensitive personal data is stored.
4.5 Limitations
If the data has been encrypted by the client and is therefore not visible to the service provider, this does not constitute commissioned data processing by the service provider. This means that the agreement on commissioned data processing does not apply to this data.
It is the responsibility of the client to assess whether the technical and organisational measures described below are appropriate for the protection of personal data.
5 Technical and organisational measures
The following chapters describe the measures taken by the service provider with regard to the protection of personal data in the context of commissioned data processing. The service provider maintains an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 standard. The service provider's ISMS is certified, and the certificate is publicly available on the service provider's website (https://www.stepping-stone.ch/de/isoiec-27001/).
The following measures are to be understood as generic and apply to cases in which the service provider itself processes the relevant data. They apply in each case unless otherwise specified in the framework agreement.
If data processing is carried out by third parties commissioned by the service provider, the service provider shall ensure, by means of appropriate contractual agreements, that the third parties comply with comparable measures.
ISO/IEC certification ensures the required level of protection in the following areas.
5.1 Access control
5.1.1 Data centres
The data centres are defined as highly secure premises. Access to the data centres is ensured by authorisation lists, security gates, video surveillance, key cards and personal PIN codes.
The data centres have the necessary physical security measures in place to detect any breach of the building perimeter at an early stage and trigger an appropriate alarm. Early warning alarm systems are in place within the data centres to detect fire, smoke and moisture.
5.1.2 Office premises
The service provider's office premises are defined as public space. Employees receive a personal, numbered key to access the office premises. The issuance of keys to authorised persons is logged.
Personal data is not accessible to visitors. The service provider operates largely paperless. Paper copies containing personal data are stored securely and are only accessible to authorised persons. A clear desk and clear screen policy applies. This ensures that no personal data is left unattended on desks and that employees' laptops are locked when inactive. These rules also apply to work outside the office premises.
The service provider's office premises are equipped with several smoke detectors and a flood alarm.
5.2 Access control
The service provider ensures that no systems are accessible to unauthorised persons.
5.3 Access control
Access rights are created according to the principle of least privilege (POLP).
Access with elevated rights for administration of the service provider's systems always takes place via a dedicated infrastructure with strong authentication. All logins, logouts and failed logins are centrally logged and stored for a defined period of time.
5.4 Transport control
Access to relevant data via the Internet is always via an encrypted connection. The service provider uses the latest protocols and protection mechanisms. This rule may be deviated from at the express request of the client.
Separate communication channels are used for the transmission of access data.
No removable media are used to store sensitive information.
5.5 Storage control
The permanent storage devices in the data centres are protected against loss by physical security measures. These include redundant power supplies and the necessary systems to enable self-sufficient operation for a defined period of time.
In the event of a defect, data carriers are physically rendered unusable by the service provider in order to completely prevent any possible access.
Functioning data carriers are deleted using industry-standard deletion methods in such a way that it is almost impossible to reconstruct the data they contain. If such a procedure is not possible, the data carriers are physically rendered unusable or destroyed.
5.6 Input control
In cases where the service provider is responsible for the input and processing of personal data, the service provider shall take the necessary technical and organisational measures to ensure that this data is recorded and processed correctly.
The service provider collects further personal data from the client for the purpose of providing the service. This data is used, for example, to record fault reports, change requests or for invoicing. The service provider shall take appropriate quality measures to ensure that this data is also recorded and processed correctly.
5.7 Order control
The service provider carefully selects potential subcontractors with access to the data and transfers the relevant responsibilities for data protection to the suppliers.
The service provider has appointed a person responsible for ensuring compliance with data protection requirements. This person can be contacted at ciso@stepping-stone.ch.
New employees of the service provider undergo a security check before starting their employment. The check includes at least the verification of the complete CV, the most recent references and the obtaining of personal reference information. In addition, a confidentiality agreement must be signed and a current extract from the criminal record and a current extract from the debt collection register must be checked.
New employees are familiarised with the relevant rules for their own safety and data security when they start work. This is done through initial training on information security.
Existing employees of the service provider receive refresher training on information security once a year.
When employees leave the company, all access is blocked. On their last day of work, personal work equipment, keys and key cards are collected.
5.8 Availability control
The service provider stores data in accordance with the contractual agreement in data centres with the necessary level of protection (see Chapter 4 Type of data).
To ensure the availability of data, the service provider's storage systems are configured in such a way that one or more components can fail and the data will still be available. This is achieved through redundant, distributed data carriers as well as redundant networks and power supplies.
The service provider backs up the data in accordance with the service description. Backups are always made on storage systems in another data centre with sufficient geographical distance between the two locations. The different geographical locations serve to minimise possible damage from natural events such as lightning, rain or flooding to one location as far as possible.
Depending on the services purchased, the client can additionally order different levels of data backup. This can be found in the service description or requested from the service provider.
The service provider has implemented the necessary processes to identify and evaluate reports of software vulnerabilities and patches and to derive the necessary further steps from them. The standard patch management process ensures that patch announcements for systems are evaluated and installed on the relevant systems after testing. The installation of patches may require the cooperation and approval of the client. This is taken into account in the service provider's standardised processes. If a patch needs to be installed urgently, there is a so-called emergency patch process, depending on the service.
5.9 Separation requirement
The service provider ensures that client data is not mutually visible. Current security procedures are used to ensure the separation of customer data at a logical level.
The service provider has checked the separation at a logical level to ensure that these procedures cannot be circumvented. If the service provider determines that the procedures no longer guarantee this, the service provider will take the necessary countermeasures to restore equivalent protection.
5.10 Review, assessment and evaluation
The service provider regularly monitors internal processes and technical and organisational measures to ensure that processing within its area of responsibility complies with the requirements of applicable data protection law and that the rights of data subjects are protected.
Based on a risk analysis, new services are subjected to a technical review. Any deficiencies identified are rectified by the responsible departments at the service provider. Depending on the severity of the deficiencies, a supplementary review is carried out to verify the effectiveness of the rectification.
The service provider regularly conducts internal and external audits to review and optimise information security. Any deficiencies identified are rectified within the defined time frame and, depending on their severity, reviewed again by the internal audit department.
The service provider conducts an annual risk assessment. The aim of the risk assessment is to identify potential information security risks and their impact and probability of occurrence. An annual risk assessment report describes the measures taken by the service provider to reduce the potential risks and their impact.
6 Obligations of the service provider
6.1 Data processing
The service provider processes the relevant data exclusively in accordance with the provisions of the framework agreement and this appendix. The service provider reserves the right to fulfil legal, regulatory or official obligations.
6.2 Review of technical and organisational measures
The service provider shall continuously review the agreed technical and organisational measures to ensure they are state of the art and, if necessary, propose the implementation of additional measures to the client, which may be agreed upon in a contract addendum.
6.3 List of processing activities
The service provider undertakes to keep a record of processing activities in accordance with Art. 12(1) DSG and Art. 30(2) EU GDPR with regard to the relevant data. The service provider shall grant the client access to those parts of this record that are relevant to the service provider's provision of services to the client at any time upon request.
6.4 Confidentiality
The service provider shall ensure that employees and other auxiliary persons involved in the processing of the client's relevant data are prohibited from processing the relevant data for purposes other than those specified in the contract and in deviation from this agreement.
Furthermore, the service provider shall ensure that the persons authorised to process the relevant data have undertaken to maintain confidentiality. The duty of confidentiality shall continue to apply even after the contract has ended.
6.5 Duty to inform
The service provider shall inform the client promptly if it becomes aware of any breaches of the protection of the relevant data at the service provider or one of its subcontractors.
The service provider shall inform the client in writing (email is sufficient) in an appropriate manner about the nature and extent of the breach and possible remedial measures. In such a case, the parties shall take the necessary measures to ensure the protection of the relevant data and to mitigate any possible adverse consequences for the persons concerned and the parties, and shall consult with each other immediately in this regard.
6.6 Contact
The service provider shall provide the client with the name of the contact person for data protection issues arising within the scope of the contract and, in cases where this is required under Art. 37 EU GDPR, the name of the data protection officer.
6.7 Data deletion
Relevant data shall be surrendered and permanently deleted at the end of the contract in accordance with the contractual provisions. The service provider shall use established procedures in the IT industry for the deletion of relevant data.
7 Obligations of the client
7.1 Duty to provide information
The client must inform the service provider immediately if it discovers any violations of data protection regulations in the service provider's performance of its services.
7.2 Contact
The client shall provide the service provider with the name of the contact person for data protection issues arising within the scope of the contract and, in cases where this is required under Article 37 of the EU GDPR, the name of the data protection officer.
8 Requests from third parties
If a third party contacts the service provider directly with requests for correction, deletion, information or other claims relating to relevant data, the service provider shall refer the third party to the client, provided that it is possible to assign the request to the client based on the information provided by the third party.
The service provider's support to the client in the event of requests from third parties is governed by Chapter 6 "Obligations of the service provider" of this agreement.
9 Verification options, reports and audits
9.1 Compliance with obligations
The parties agree that compliance with the obligations under this agreement is generally evidenced by the service provider being certified according to ISO/IEC 27001:2013.
9.2 Audit rights
Any audit rights defined in the contract and any legally mandatory audit rights of the client or its supervisory authorities remain reserved. In the context of such audits, the principle of proportionality must be expressly observed and the legitimate interests of the service provider (duty of confidentiality) must be taken into account appropriately. Unless otherwise agreed, the client shall bear all costs of such audits (including proven internal costs incurred by the service provider in participating in the audit).
9.3 Breach of obligations
If, after the submission of evidence or reports or in the course of an audit, breaches of this agreement or deficiencies in the implementation of the obligations by the service provider are identified, the service provider must immediately implement appropriate corrective measures.
10 Subcontracting
Unless the framework agreement contains any restrictive provisions on the involvement of third parties, the service provider shall be entitled to engage subcontractors.
The service provider shall maintain a list of subcontracting relationships, which shall be updated whenever changes occur. The service provider shall grant the client access to those parts of this list that are relevant to the service provider's performance of its obligations to the client at any time upon request.
The client may object in writing within a period of 30 days to the involvement of a new subcontractor or the replacement of an existing subcontractor for important data protection reasons. If there is an important data protection reason and if it is not possible for the parties to find a mutually acceptable solution, the client shall be granted a right of termination with regard to the service affected by this.
If the subcontractor fails to comply with its data protection obligations, the service provider shall be liable to the client for the subcontractor's non-compliance.