Effective: January 15, 2024
Novartis processes information of its business partners, which constitutes “personal data” and considers the protection of personal data and privacy a very important matter.
Novartis is responsible for the processing of personal data as it decides why and how it is processed, thereby acting as the “controller”. It may exercise this responsibility alone or jointly with other company(-ies) in the Novartis group, acting as “co-controller(s)”. In this Privacy Notice, “Novartis”, “we” or “us” refers to the Novartis India entity processing your personal data, as listed at https://www.novartis.com/in-en/about/india-site-locations.
This Privacy Notice is addressed to:
We invite you to carefully read this Privacy Notice, which sets out in which context we are processing your personal data and explains your rights and our obligations when doing so.
Should you have any further question in relation to the processing of your personal data, we invite you to contact us at [email protected].
This information may either be directly provided by you, by our business partners (i.e. the legal entity for whom you work), by third parties (e.g. external vendors, chemists, pharmacists or medical agencies) or be obtained through trusted publicly available sources (such as PubMed, Clinical Trials.gov, congress websites or university websites). We may collect various types of personal data about you, including:
If you intend to provide us with personal data about other individuals (e.g. your colleagues), you must provide a copy of this Privacy Notice to the relevant individuals, directly or through their employer.
2.1 Legal basis for the processing
We will not process personal data that Novartis may have about you if we do not have a proper justification foreseen in the law for that purpose. Therefore, we will only process your personal data if:
Please note that, when processing your personal data on this last basis, we always seek to maintain a balance between our legitimate interests and your privacy.
Examples of such ‘legitimate interests’ are data processing activities performed:
2.2 Purposes of the processing
We always process your personal data for a specific purpose and only process the personal data that is relevant to achieve that purpose. In particular, we process your personal data for the following purposes:
any other purposes imposed by law and authorities.
We will not sell, share, or otherwise transfer your personal data to third parties other than those indicated in this Privacy Notice.
In the course of our activities and for the same purposes as those listed in this Privacy Notice, your personal data can be accessed by, or transferred to the following categories of recipients, on a need to know basis to achieve such purposes:
The above third parties are contractually obliged to protect the confidentiality and security of your personal data, in compliance with applicable law.
Your personal data can also be accessed by or transferred to any national and/or international regulatory, enforcement, public body or court, where we are required to do so by applicable law or regulation or at their request.
The personal data we collect from you may also be processed, accessed or stored in a country outside the country where Novartis is located , which may not offer the same level of protection of personal data.
If we transfer your personal data to external companies in other jurisdictions, we will make sure to protect your personal data by
Unless otherwise specified, only transferring your personal data on the basis of standard contractual clauses approved by the European Commission.
You may request additional information in relation to international transfers of personal data and obtain a copy of the adequate safeguard put in place by exercising your rights as set out in Section 6 below.
For intra-group transfers of personal data to, the Novartis Group has adopted Binding Corporate Rules, a system of principles, rules and tools, provided by European law, in an effort to ensure effective levels of data protection relating to transfers of personal data outside the EEA and Switzerland.
Read more about the Novartis Binding Corporate Rules by clicking here https://www.novartis.com/privacy/novartis-binding-corporate-rules-bcr.
We have implemented appropriate technical and organisational measures to provide a necessary level of security and confidentiality to your personal data.
These measures take into account:
The purpose thereof is to protect it against accidental or unlawful destruction or alteration, accidental loss, unauthorized disclosure or access and against other unlawful forms of processing.
Moreover, when handling your personal data, we:
For the latter, we may request you to confirm the personal data we hold about you. You are also invited to spontaneously inform us whenever there is a change in your personal circumstances so we can ensure your personal data is kept up-to-date.
We will only retain your personal data for as long as necessary to fulfil the purpose for which it was collected or to comply with legal or regulatory requirements.
You may exercise the following rights under the conditions and within the limits set forth in the law:
the right to object to a channel of communication used for direct marketing purposes; and
Any future changes or additions to the processing of your personal data as described in this Privacy Notice will be notified to you in advance through an individual notice through our usual communication channels (e.g. by email or via our internet websites).