The legal view – Key points when implementing a cloud ERP

Implementing a cloud-based ERP (Enterprise Resource Planning) system is one of the most strategically important decisions a company can make. Especially in Switzerland, where data security and legal requirements are of paramount importance, companies face specific challenges. To ensure the project’s success, three key legal questions must be addressed.
1. How are the legal requirements met?
A crucial aspect of implementing a cloud ERP system in Switzerland is ensuring compliance with legal requirements. Data protection, in particular, plays a central role here. With the revised Data Protection Act (revDSG), which came into force in 2023, companies must meet strict requirements to protect personal data.
- Data localization: Where is the data stored? Swiss companies often prefer cloud providers with data centers in Switzerland or at least within the EU to minimize legal and regulatory risks.
- Contractual safeguards: It is essential to make clear agreements with the provider, e.g. through Data Processing Agreements (DPAs) that guarantee compliance with the GDPR.
- Audits and certifications: A cloud ERP provider should meet standards such as ISO 27001, SOC 2, or similar security certifications. These provide assurance that data is managed and processed securely.
Ignoring these points can result in expensive fines of up to CHF 250,000 and a loss of customer trust.
2. What liability issues need to be clarified?
Responsibility for data security and compliance with legal regulations often lies not only with the cloud provider, but also with the company itself. Therefore, a clear liability agreement is essential.
- Contract drafting: What liability does the provider assume in the event of a data breach or data incident? Clear clauses should be defined here.
- Contractual partners: Companies should check whether the provider can also be sued abroad or whether there is jurisdiction in Switzerland.
- Recourse options: If an error occurs at the supplier, companies must ensure that they can assert claims for damages.
3. How is access to data secured in the long term?
Another legal aspect concerns ensuring the availability of and control over one’s own data. Companies can otherwise run into difficulties, especially when switching providers or if the cloud provider discontinues services.
- Data return: The contract should stipulate that companies have access to their data at any time and can receive it back in a usable format.
- Notice periods: It is important that deadlines are set for an orderly data transfer.
- Exit strategies: Companies should have a plan from the outset for how they will handle their data in the event of a change of provider or termination of the contract.
Conclusion
Implementing a cloud ERP system in Switzerland presents numerous legal challenges. Companies should place particular emphasis on compliance with legal requirements, clear liability regulations, and long-term data availability. By addressing these points from the outset, companies not only ensure legal compliance but also the sustainable use of the system.