Information Technology 2026

SWITZERLAND Law and Practice Contributed by: Dirk Spacek, Wenger Plattner

• Regulatory or legal obligations – compliance with court orders, law enforcement requests or regula - tory requirements may sometimes justify temporary suspension. Suspension rights are usually defined in the relevant contract, but default law provisions of the CO would also provide for such rights in certain instances. Sus - pension rights should be proportionate and notified to the customer. They often include curing periods to mitigate the disputes. 2.3 Audit Rights Customer Audit Rights Customers often request audit rights to ensure com - pliance with licence terms, service levels, and data protection obligations. Common requests include verification that the supplier is not overcharging and that usage matches the agreed licence scope, Service Level Agreement (SLA) adherence and that the sup - plier’s technical and organisational measures comply with the FADP. Supplier Audit Rights Suppliers seek audit rights primarily to ensure proper use of software or services by the customer. Common triggers include licence compliance (verifying that the customer is not exceeding user numbers or copy - ing software beyond the agreed scope), security and infrastructure or other contractual obligations. In Switzerland, audit rights are typically contractu - ally negotiated, should be proportionate, limited in frequency, and conducted with notice to avoid dis - putes. In a regulatory context, audits by supervisory authorities may sometimes be imposed by mandatory law especially in the case of specific events. Further - more, in the course of a dispute (pending or pre-liti - gative measures), an audit could also be ordered and enforced by a judge. 2.4 Escrow Provisions In Switzerland, software escrow arrangements are increasingly included in contracts, particularly for critical business applications, SaaS, or on-premise enterprise systems. An escrow agent ensures that the customer can access the source code or essen - tial components, if the supplier fails to maintain, sup -

port, or continue operations, mitigating business continuity and dependency risks. Escrow provisions are contractually agreed, not expressly mandated by Swiss law. Commonly stated trigger events include supplier insolvency, breach of support obligations, or prolonged unavailability of updates. Contracts usu - ally specify which source code, documentation, and materials are deposited, and under what conditions the customer can access them. Independent third- party escrow agents with technical knowledge are often used to safeguard the materials and to ensure enforceability. While not legally required, escrow is considered best practice for high-value or mission-critical software or when the licensor is in a financially unstable position. 2.5 Commitments Regarding Ongoing Availability of Saas Solutions In Swiss cloud-based SaaS (Software as a Service) contracts, providers typically give service availabil - ity commitments to ensure reliability and continuity. These are generally expressed as SLAs and may include uptime guarantees (commonly 99–99.9%, excluding scheduled maintenance), maintenance and downtime notification, incident response and resolu - tion mechanisms, data backup and recovery and rem - edies for non-compliance (eg, service credits or partial fee reductions). Swiss law does not impose specific availability stand - ards; rather, a general standard of diligence and care (Article 398, CO). However, contractually agreed SLAs become a contractually binding framework within the contract. SLA terms are negotiated based on criticality of the service and customer risk tolerance.

3. Artificial Intelligence 3.1 AI Legislation and Regulation 3.1.1 General Legislative Regime for AI

Switzerland does not yet have a specific, comprehen - sive AI law. The use and development of AI are primar - ily governed by existing sectoral legislation. • Data protection – the FADP applies to personal data processed by AI systems.

79

CHAMBERS.COM

Powered by