Legal work in this sector
The work covers SaaS and platform contracts and technology licensing under the OR, and health-data protection under the DSG and the GDPR.
SaaS and cloud platforms
SaaS agreements for regulated industries need to reflect the service being provided. Service levels, data residency, security commitments and exit provisions each have compliance implications that standard terms may not address.
- SaaS and cloud services agreements
- Enterprise licensing and subscription terms
- Platform and marketplace agreements
- Application programming interface (API) and integration contracts
Data and privacy
Data-protection terms need to reflect the actual data flows, processing locations and security controls. Health-related technology may be subject to the GDPR, the Swiss DSG and sector-specific requirements in parallel.
- Data processing agreements
- SCCs and transfer mechanism implementation
- Joint controller arrangements
- Processing inventories and privacy documentation
Health tech and digital therapeutics
Digital health platforms, connected devices and software as a medical device (SaMD) involve both technology contracts and healthcare regulation. Agreements must address both the commercial relationship and the regulatory classification (the MDR and the MepV for devices, the GDPR and the DSG for data, and often sector-specific requirements for clinical integration).
- Health platform and EHR integration agreements
- DTx and SaMD contracts
- Technology licensing and co-development
- Connected device and IoT terms
Defined assignments
These standard assignments each carry a fixed fee, with a 50 percent uplift where priority handling is expressly agreed. Read what a fixed fee covers.
Commercial contract review and markup
A fixed fee covers the review of a counterparty's MSA, SaaS, cloud, supplier or platform agreement with proposed amendments, measured against negotiating positions agreed with the client, with each change explained; a review-only issue memo and non-disclosure agreements are also fixed fees.
- One full markup pass with per-clause rationale
- Up to two negotiation turns included
- A short note explaining what was done and why
Privacy policy
A fixed fee covers a privacy policy under the DSG, or under the DSG and the GDPR, prepared from the information provided at intake: the legal bases, the disclosure of transfers abroad under Art. 19 Abs. 4 DSG, the special categories of data processed, and cookies handled through a separate consent mechanism where consent is required.
- DSG and GDPR coverage as the standard
- One revision round included
- Transfer and cookie disclosures aligned with actual behavior
International data-transfer package
A fixed fee covers the documented transfer assessment for a US-bound or other cross-border data flow to one vendor: mechanism selection (adequacy, the Data Privacy Framework or contractual clauses), the six-step transfer impact assessment where clauses are used, the correct SCC module with the Swiss addendum, supplementary measures, and a risk-rated conclusion.
- Documented six-step assessment, importer-specific
- Risk-rated conclusion with re-assessment triggers
- A reduced fixed fee for each further vendor
Working together
Fees are fixed, capped or phased, or run as a retainer; work beyond the agreed scope is billed by time.
For companies without a full-time legal role, fractional counsel provides part-time legal support on a days-per-month retainer.
To establish which rules apply, the regulatory posture audit reviews the laws relevant to one technology or digital-health product, assesses its compliance position and identifies the work needed to address each gap.
For cybersecurity and product-security questions, the cyber readiness assessment examines the Cyber Resilience Act class the product falls into, the vulnerability-reporting duties that have applied since September 2026, and the supply-chain security terms that a customer subject to NIS2 flows down to its suppliers.
For medical software with an AI component that a notified body has already assessed, the medical-AI readiness assessment reviews the additional AI Act requirements against the existing device documentation.
Technology and digital-health matters are handled through these services:
Explore the topics
Read related articles
- AI-Enabled Medical Devices: The Regulatory Convergence Problem
- Regulatory Sandbox for Digital Health in Switzerland: Opportunities and Limitations
- Cloud Service Contracts: Jurisdictional Complexity
- The EU Data Act in Force: Where US Cloud and IoT Contract Terms Stop Binding
- GDPR, Cookies and the Digital Omnibus: What US SaaS Can Re-Plan, and What It Cannot
- The EU Cyber Resilience Act: A 2026–2027 Compliance Map for US Software and Hardware Vendors
- Swiss Health Data for US SaaS and Digital Therapeutics: Where Neither HIPAA nor the GDPR Predicts the DSG
- Transatlantic Data Transfers in 2026: The DPF After the Supreme Court Challenge
- The EU Digital Omnibus at Two Speeds: An Adopted AI Act Deferral and a Contested GDPR Reset
- Switzerland's AI Regulation Versus the EU AI Act: Why the Federal Council Chose a Sector-Specific Path
Common questions
- When does a company outside Switzerland need a Swiss data-protection representative?
- A private controller domiciled abroad must designate a representative in Switzerland when all four conditions of Art. 14 DSG are met: the processing relates to offering goods or services in Switzerland or to monitoring the behavior of people there; it is large-scale, which the EDÖB reads as processing personal data in more than isolated instances; it is regular; and it carries a high risk to the data subjects. The representative is the contact point for those data subjects and for the EDÖB, and the controller publishes its name and address. GAWEL Legal acts as this representative, for an annual fee tiered by the controller's size.
- Which data-protection regimes apply to a US health platform serving users in Switzerland and the EU?
- The GDPR, the DSG and the sector-specific rules layer on top of one another rather than replacing each other, so the same platform is usually subject to two general regimes and at least one special one. The consequence is contractual: processing agreements have to map the data flows that actually exist, transfer mechanisms have to reflect where processing happens, and the security provisions have to describe the controls that are deployed rather than the ones a template assumes.
- What does a transfer of personal data out of Switzerland require?
- Either a Federal Council finding that the destination state affords adequate protection (for the United States, only for importers certified under the Swiss-US Data Privacy Framework), one of the safeguards Art. 16 DSG allows, in practice the Standard Contractual Clauses with the Swiss addendum, or, exceptionally, one of the exceptions in Art. 17 DSG. Where the clauses are used, the file also needs a documented six-step transfer impact assessment for the specific importer, the supplementary measures that assessment produces, and a risk-rated conclusion carrying the triggers that would require it to be redone.
- Is software as a medical device a technology contract or a regulatory matter?
- Both. Digital health platforms, connected devices and SaMD involve technology contracts and healthcare regulation. Agreements need to address the commercial relationship and regulatory classification: the MDR and the MepV for the device, the GDPR and the DSG for the data, and the clinical-integration requirements of whichever health system the product is deployed into.