Swiss nLPD compliance for your self-hosted apps

You stay the controller under the revised Federal Act on Data Protection. Pilae acts as your processor, signs the agreement, and delivers the security, records and breach reporting your obligations depend on.

Talk to our teamRequest the security pack

Law
Revised FADP (nLPD), in force since 1 September 2023
Pilae role
Processor under art. 9, on your written instructions
Hosting
Your premises, or any of 12 Pilae Cloud regions, six of them in Switzerland and the EU
Contact
privacy@pilae.com

What Pilae covers under the revised FADP

The nLPD puts the obligations on you as controller. Several of them can only be met with your processor. These are the parts Pilae delivers.

A processor agreement under art. 9

We process personal data only on your instructions and only for your purposes. The agreement is signed at onboarding, before any data moves.

Data security under art. 8

Apps answer only on a private mesh, behind one hardened gate on port 443. Access is by named account, and every administrative action is logged.

Records of processing under art. 12

We keep the processor record for your services and give you the facts your own record needs: categories of data, locations, recipients and retention.

Breach reporting under art. 24

A breach affecting your data is reported to you without delay, with what happened, what data it touched and what we have done, so you can notify the FDPIC.

Cross-border disclosure under art. 16 and 17

You choose where your data lives: your premises, Switzerland, or the EU. Any transfer outside those follows the Federal Council list or standard contractual clauses.

Data subject requests

Your data sits in apps you control. We help you find, export, correct or delete a person's data when they exercise a right under the Act.

Processor obligations under art. 9 of the nLPD

The revised Federal Act on Data Protection makes your organisation answerable for the personal data it processes. When your apps run with Pilae, part of that processing happens on our machines or under our hands. The Act calls us your processor, and art. 9 says you may only hand work to a processor who guarantees data security and follows your instructions.

That guarantee is written into a signed agreement. Our data processing agreement names the data, the purposes, the location and every sub-processor. It is signed at onboarding, before your first app is migrated.

Data security under art. 8 of the nLPD

Art. 8 asks for security appropriate to the risk. Our answer is concrete. Each app answers only on a private network, with one hardened gate on port 443. Every change is planned, approved and recorded by the Pilae Agent. Your contract specifies encrypted backups and scheduled restore tests. The details are on the security page and in the measures annex of your DPA.

Data location and cross-border transfers

You decide where your data lives: on your own servers, or on dedicated machines in Pilae Cloud in Zurich or an EU region, with six worldwide regions for teams that need them. The location is written into your contract. We do not move data across a border without your written agreement, and any transfer outside Switzerland and the EU follows art. 16 and art. 17. See data residency for the regions.

How we set up your nLPD file at onboarding

  1. Map the processing

    We list the apps, the categories of personal data each one holds, and who uses it.

  2. Choose the location

    You pick your premises, Pilae Cloud in Switzerland, or the EU. The choice is written into your contract.

  3. Sign the processor agreement

    Our standard DPA, with the sub-processor list attached, signed before any data is migrated.

  4. Hand over the records

    You receive the processing facts for your art. 12 record and the security measures for your file.

What your contract includes

Processor agreement
Our standard DPA under art. 9 of the revised FADP, signed at onboarding.
Data location
Named in the contract. We do not move it without your written agreement.
Breach notice
Reported to you without delay after we confirm a breach, with the facts the FDPIC asks for.
Sub-processors
Disclosed to you in the DPA. Changes are notified to you in advance, with a right to object.
Audit
The audit log and our security measures are available to you and your auditors on request.
End of contract
Your data is returned in open formats, then deleted from our systems and backups.

The apps behind it

Questions

Is Pilae nLPD certified?

No. The revised FADP provides for voluntary certification under art. 13, and Pilae SA does not hold one. Pilae meets its processor obligations through a signed processor agreement, security measures built to ISO 27001 controls, and the reporting described on this page.

Who is the controller and who is the processor?

Your organisation is the controller: you decide why and how personal data is processed. Pilae is the processor: we operate the apps and machines that hold it, on your written instructions.

Does my data leave Switzerland?

Only if you choose it. You can run everything on your premises or on dedicated machines in Zurich. If you choose EU regions, the EU is on the Federal Council list of countries with adequate protection.

How fast do you report a data breach?

Without delay once we confirm a breach affecting your data. You receive the nature of the breach, the data concerned, the likely consequences and the measures taken, which is what you need to notify the FDPIC as soon as possible under art. 24.

Do you also cover the GDPR?

Yes. Our DPA covers the processor obligations of the revised FADP and of the GDPR, so an organisation that falls under both signs one agreement.

Related

Bring your data protection questions to an engineer.

Thirty minutes with your data protection officer and ours: we walk through where your data will live and what the DPA says.