Regulatory compliance: what a contract must provide for regarding personal data

Article 28 GDPR, Article 9 nFADP, international transfers: the mandatory clauses of a data processing contract.


A contract involving an IT sub-processor, a hosting provider, a SaaS tool: as soon as there's personal data processing, precise clauses become mandatory — not optional.

Quick check: Analyze your contract on subblink — GDPR and nFADP clauses expected, international transfers, sub-processing.


1. Mandatory clauses of a data sub-processing contract

The problem

A contract with an IT provider that processes personal data on the client's behalf must strictly govern this relationship — the absence of a formalized sub-processing contract is itself a compliance gap.

Legal reminder (GDPR)

Article 28 of the GDPR requires a written contract specifying the subject matter, duration, nature and purpose of processing, the categories of data and data subjects, security obligations (Art. 32), prior authorization for any further sub-processing, and the fate of data at contract end.

Legal reminder (nFADP, Switzerland)

Article 9 of the new Federal Act on Data Protection requires that processing by a sub-processor be based on a contract or the law, with an equivalent security guarantee, and that any further sub-processing be subject to prior authorization.

What subblink detects

The regulatoryCompliance field checks for the presence of clauses expected under Article 28 GDPR or Article 9 nFADP, with a "compliant / gaps identified / not applicable" status depending on the identified jurisdiction.

Useful resource

The CNIL (French data protection authority) offers a reusable data sub-processing clause template: see the library of official contract references.


2. Data transfers outside the European Union

The problem

A sub-processor hosted outside the EU (particularly the US) requires specific governance of the data transfer, under penalty of non-compliance even if the local contract is otherwise correctly drafted.

Legal reminder

The European Commission's standard contractual clauses (Implementing Decision 2021/914) govern this type of transfer, in the absence of an adequacy decision for the destination country.

What subblink detects

A mention of hosting or processing outside the EU in the contract text is flagged as a point requiring verification of the applicable transfer mechanism.


3. What regulatory compliance doesn't cover

Honest limitation

The compliance check covers personal data protection (GDPR/nFADP). It doesn't cover sector-specific obligations: anti-money-laundering (AML/KYC) for financial professions, FINMA compliance for regulated Swiss institutions, or any other business-specific regulation. These checks fall under dedicated expertise.


4. Cascading sub-processing

The problem

A sub-processor that itself uses another sub-processor (cloud hosting, emailing service) must inform the data controller and obtain their authorization — a chain that's easy to lose track of.

What subblink detects

The presence of a clause governing further sub-processing is checked as one of the clauses expected under Article 28 GDPR.


Regulatory compliance checklist: contracts involving personal data

Analyze your contract on subblink.


FAQ: regulatory compliance of contracts

Does subblink check a company's full GDPR compliance?

No. It checks for the presence of expected clauses in the text of a given contract. A full GDPR compliance audit (records of processing activities, impact assessment, governance) is a broader exercise, distinct from analyzing a contract.

What happens if the contract doesn't mention personal data processing?

The regulatoryCompliance field then indicates a "not applicable" status — never a fabricated gap on a topic the contract doesn't address.

Does subblink cover sector-specific obligations (FINMA, AML/KYC)?

No, these checks aren't covered. See the article dedicated to legal and advisory professionals for details on what is and isn't checked.

Are the European Commission's standard contractual clauses available somewhere?

Yes, they're part of subblink's library of official contract references, with the source and country clearly indicated.


Conclusion

A contract's regulatory compliance rests on precise clauses required by law — not on a general impression of seriousness.

Article 28 GDPR, Article 9 nFADP, international transfer mechanism: three points to check systematically whenever a contract involves personal data.

Analyze your contract now →