The requirements a municipality should place on its IT provider
Published · updated
You can’t infer the law that governs a municipality from a supplier’s domicile or from a compliance badge. And starting with the GDPR can hide the cantonal law that governs the municipality’s own processing.
Cantonal law is the starting point
For a public body, data protection is a matter of cantonal law. In Vaud that’s the LPrD, supervised by the cantonal authority. The revised federal FADP governs private processing: it applies to the provider’s own activities, not ordinarily to the municipality when the municipality carries out its public task. The presence of personal data does not by itself bring the GDPR into play either, though its Article 3 conditions may. So a supplier who answers only “we are GDPR compliant” hasn’t answered the municipal question.
Awarding the engagement: the thresholds
A municipality doesn’t purchase freely: it applies the intercantonal agreement on public procurement (AIMP 2019) and its cantonal implementing law. For services, the Vaud thresholds are, excluding VAT: direct award below CHF 150,000; invitation procedure from CHF 150,000 to below CHF 250,000; and an open or selective procedure from CHF 250,000.
Splitting a procurement artificially to stay below a threshold is prohibited. The duration, the options, the renewals, the lots and the related services have to be counted the way the applicable rules require. For example, a firm three-year engagement at CHF 60,000 per year is worth CHF 180,000, and that would ordinarily require an invitation procedure. Annual support isn’t automatically a separate direct award.
The contract is not a formality
When I review a municipal contract, I read the exit clause before anything else. A contract that doesn’t say how it ends commits the municipality well past its term.
Art. 18 LPrD governs processing by a service provider, while the municipality stays responsible for the processing it entrusts. The contract records the instructions and the safeguards; it can’t make a purpose, a collection or a transfer lawful when the legal basis is missing. The current Vaud authority checklist, dated 6 August 2025 provides the working frame. The essentials the contract has to contain:
- processing on the municipality’s instructions only, immediate notice of relevant incidents, and controls over disclosure to any third party
- approved processing and access locations, including subprocessors, with the safeguards required for the relevant data and risk
- audit rights or sufficient assurance evidence, and timely support for data subject rights
- at the end of the contract: data returned in a readable format, copies destroyed, an organised transition to a successor
- Swiss law and a Swiss forum
The exit clause is the one everyone neglects at signing and regrets at leaving: without it, changing provider means negotiating to get your own data back.
Official secrecy follows the data
Where the entrusted data falls under official secrecy, the contract has to impose role-appropriate confidentiality on the authorised staff and strictly limit the access. Calling every provider employee an “auxiliary” doesn’t establish the criminal-law status by itself: the mandate, the instructions, the need for access and the cantonal law all count. Get legal confirmation for data covered by a statutory secrecy duty.
Sensitive data and the CLOUD Act: the position is in writing
The Vaud checklist calls for particular care when a partner subject to the US CLOUD Act can access sensitive data. It indicates that, where no sufficient legal basis exists, encryption with the key kept in Switzerland by the municipality or by an independent third party may be decisive. Joining the Swiss–US Data Privacy Framework doesn’t, on its own, remove the risk of government access. Ask where the data sits, but also who can access it, from where, under which law and with which keys.
The documents the council signs are public
Under Vaud’s freedom-of-information law, a contract a municipality holds may be an official document open to inspection in principle. The statutory exceptions still apply, including privacy and certain business secrets. The contract should nevertheless stand up to public scrutiny, and any redaction you request should have a precise legal basis.
Six questions before signing
- Does the total amount, over the full duration, stay under the threshold invoked?
- Are the processing and access locations approved, subprocessors included?
- Is access to information covered by statutory secrecy necessary, named, restricted and legally validated?
- Who in the supplier chain answers to foreign law, and who controls the keys?
- In what format, and within what period, does the data come back at the end?
- Which provisions are accessible, and what exception would justify a redaction?
The legal texts cited
- Canton of Vaud: procurement thresholds
- Vaud authority: IT-processing contract checklist, 6 August 2025
- Federal report on the CLOUD Act
This article describes the Vaud framework and isn’t legal advice. Every canton has its own rules, and the procurement value or the lawfulness of a processing depends on the facts. Refer the case to the municipal association’s legal service or to a specialist lawyer.
Texts consulted on 14 August 2026.