As a trusted third party, we manage cryptographic keys and pseudonymisation keys, so that system providers, platforms or research partners do not gain uncontrolled access to the data of their customers or study participants. Typical use cases: medical/HealthTech, HR analytics, clinical trials, M&A escrow.
Working for regulated industries and SMEs
Brief definition
A Trusted Third Party (TTP) is an independent, contractual third party that securely holds cryptographic keys or pseudonymisation mappings and releases them only under clearly defined conditions, typically to separate the data provider from the data processor in order to reduce re-identification risks.
The main tasks of a TTP:
Where a TTP makes the decisive difference today.
Comprehensive escrow for data keys and pseudonymisation tables, on ISO 27001-certified infrastructure.
A TTP is only as trustworthy as its governance. At SIDD:
After a free initial consultation, you will receive a quote. Six phases then follow.
Joint project plan, where applicable involving customers and other stakeholders.
Finalise the project plan and define communication channels.
Choice of KMS solution, taking over existing systems or building on SIDD infrastructure.
Set up systems, with custom development by our privacy engineers where required.
Test phase with you or specialised testing providers.
Productive operation of key generation and safekeeping.
A Trusted Third Party is only as credible as its independence, its confidentiality and its technical diligence, and at SIDD, all three come from a single source.
Where Dr Dominic Staiger acts as a lawyer, the deposited keys and mandate information are subject to professional secrecy under Art. 321 SCC. This is confidentiality protection backed by criminal law that a pure IT service provider cannot offer.
We manage solely keys and pseudonymisation keys and are neither the system provider nor the platform operator in your use case. Release occurs only under the contractually defined conditions, never on the unilateral request of a single party.
Lawyers holding doctorates draft the escrow and release agreement, while our own information-security and software-engineering team under CTO Oliver Stutz operates the key custody. Otherwise, key escrow fails precisely at the gap between contract text and secure implementation.
Every release, access and rotation operation is logged and available via our Priverion Platform as a maintained, auditable record. This allows the escrow to be demonstrated to the supervisory authority, auditors and study participants.
With mandates in CH, EU, UK and US, we position the escrow across multiple jurisdictions, relevant for cross-border clinical trials, HR-analytics group structures or an M&A escrow with parties in different countries.
SIDD has operated as an independent third party since 2017, with a high mandate-renewal rate and an initial response within 24 hours. In an escrow event, such as an escrow trigger or a release request, you reach a named, permanently responsible point of contact.
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your TTP mandate, concretely: LexCommand backs the custody and release agreement and its four-eyes release process with cited sources from the FADP, GDPR, the FINMA outsourcing circular and ISO 27001, and scopes cross-border escrow to the correct legal system without mixing jurisdictions.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Project-specific. Setup typically CHF 15'000 – 60'000, ongoing escrow operation from CHF 9'000/year. The final price depends on complexity, the number of keys/tables and audit requirements.
Switzerland (HQ Baar, ZG). On request additionally EU (Munich) or UK (London). Data residency is agreed contractually.
Only a clearly defined, documented group of individuals under the four-eyes principle. Every access is documented in the audit log.
Yes. We have experience in pseudonymisation escrow between sponsor, CRO and research institution, with a documented re-identification procedure for pharmacovigilance cases.
The custody infrastructure follows ISO 27001 standards with BSI lead-auditor support. Audit reports are available on request.
Yes, Art. 321 SCC. Key contents and audit logs are shared exclusively with the persons you designate.
30-minute initial consultation with Dr. Staiger. If needed, you will subsequently receive a use-case brief with a recommended architecture.