Course : Integrate relevant contractual clauses in a changing regulatory context

RGPD, NIS2, DORA, IA Act, CRA

Practical course - 3d - 21h00 - Ref. CTN
Price : 2460 CHF E.T.

Integrate relevant contractual clauses in a changing regulatory context

RGPD, NIS2, DORA, IA Act, CRA


New course

This training course offers a practical and strategic approach to contractual compliance with regard to personal data and cybersecurity. It helps identify the essential clauses to meet the requirements of the RGPD and new regulations such as NIS2, DORA, CRA or the IA Act.


INTER
IN-HOUSE
CUSTOM

In person or remote class
Available in English on request

Ref. CTN
  3d - 21h00
2460 CHF E.T.




This training course offers a practical and strategic approach to contractual compliance with regard to personal data and cybersecurity. It helps identify the essential clauses to meet the requirements of the RGPD and new regulations such as NIS2, DORA, CRA or the IA Act.


Teaching objectives
At the end of the training, the participant will be able to:
Identify contractual clauses to RGPD compliance and recent regulations NIS2, DORA, CRA, IA Act, etc.
Adapting contracts to suit different roles (controller, subcontractor, etc.)
Integrating data protection and cybersecurity into contracts
Secure relations with partners, service providers and subsidiaries in a complex regulatory environment
Prevent legal, financial and reputational risks

Intended audience
DPOs, CISOs, IT, digital and data project managers, contract managers, in-house lawyers and operational departments involved in contractualization.

Prerequisites
Basic knowledge of contract law and RGPD fundamentals.

Practical details
Teaching methods
Case studies and analysis of real documents, practical exercises and negotiation simulations.

Course schedule

1
Contractual issues of the RGPD

  • Essential reminders of the RGPD (principles, roles, obligations).
  • Risks associated with non-contractual processing.
  • Jurisprudence, CNIL controls, sanctions.

2
Identify roles to qualify parties to the contract

  • Data controller, processor, co-responsibility.
  • Contractual consequences of legal qualification.
Storyboarding workshops
Concrete examples: IT service providers, SaaS publishers, marketing agencies.

3
Nuance according to its contractual role

  • _1_The data controller (RT) :
  • Determines the essential purposes and means of processing.
  • Strictly supervises subcontractors via a contract that complies with Article 28 RGPD.
  • Key obligations: checking compliance, enforcing safety, supervising subcontractors, cooperating with the authorities.
  • _2_The Subcontractor (ST) :
  • Processes data on behalf of a RT.
  • Beware of abusive clauses: unlimited liability, unilateral audits.
  • Negotiate the balance of obligations.
  • _3_The RT facing a big ST :
  • ST imposes its standard clauses on you (GAFAM, cloud, etc.).
  • Identify critical clauses, provide appendices, document arbitrations.
  • _4_Cases of co-responsibility :
  • Clear agreement on sharing obligations.
  • Example: white-label platform.

4
Must-have clauses

  • Processing purposes, duration, nature, categories of data.
  • Subcontractor obligations (Article 28 RGPD).
  • Cooperation, security, audit and notification clauses.
  • Confidentiality, reversibility, data deletion.
Case study
Analysis of an existing contract (SaaS, outsourcing, HR management). Detection of gaps or unsuitable wording. Conforming and operational reformulation.

5
RGPD clauses and drafting: international data transfers

  • Control of transfers outside the EU.
  • Standard contractual clauses (CCT 2021), BCR, derogations.
  • Special cases: international groups, cloud.

6
Articulating RGPD and other contractual requirements

  • Integration into GTC, GCU, customer/supplier contracts.
  • Harmonization with security clauses, SLAs, technical appendices.
  • Specific features of public procurement and calls for tender.
Case study
Réécriture d’une clause type RGPD pour différents contextes (CRM, plateforme web, traitement RH). Équilibre entre conformité et souplesse contractuelle. Dialogue avec les parties : DSI, juristes, achats.

7
Transversality with new regulations

  • Global compliance clause.
  • RGPD, IA Act (high-risk systems).
  • NIS2 (cybersecurity), DORA (operational resilience), CRA (product cybersecurity).
  • Examples of evolving formulations for different types of treatment or service.
  • Safety net clause" and regulatory adaptation clause.

8
RGPD negotiation strategies

  • Anticipate objections (cost, feasibility, liability).
  • Typical arguments according to contractual position.
  • Guarantees, insurance, limitations of liability.
Hands-on work
Objectif : intégrer une clause conforme RGPD dans un contrat déséquilibré. Simulation d’un échange entre client et prestataire. Jeu de rôle : juriste, acheteur, DPO, fournisseur.

9
Building a contractual toolbox

  • Ready-to-use clauses.
  • Model endorsements/appendices Article 28.
  • RGPD contractual audit form.


Publication date : 02/24/2026


Dates and locations

Last places available
Guaranteed date, in person or remotely
Guaranteed session
From 24 to 26 June 2026
FR
Remote class
Registration
From 16 to 18 September 2026
FR
Remote class
Registration
From 25 to 27 November 2026
FR
Remote class
Registration

REMOTE CLASS
2026 : 24 June, 16 Sep., 25 Nov.