PROCESSING OF PERSONAL DATA INFORMATION NOTICE

This information notice sets out details of the personal data relating to data subjects  (You / Your) that Roche Products (Ireland) Limited (Roche / We / Us / Our) collect and how We will process it. Roche Products (Ireland) Limited at 3004 Lake Drive, Citywest Business Park, Naas Road, Dublin 24, Ireland is the Controller of such personal data.

You acknowledge that in relation to engagements and interactions between You and Roche, Roche will collect and process data in electronic systems, databases and manual filing systems. This data is, or may be considered to be “personal data” according to EU Directive 95/46/EC and implementing legislation while applicable, the General Data Protection Regulation (Regulation [EU] 2016/679 [“GDPR”]) and other applicable law

 

Personal data that we process

Depending on Our engagement and interaction with You, processed data may include Your title and job title, first and last names, healthcare professional type, place of qualification and professional qualifications, contact information including name and address of places of work / clinical settings, phone numbers and e-mail addresses, employment status (e.g. full time, part time, contract, retired) and availability, bank account details, details about engagements and interactions between You and Roche and other contractual relationships between You and Roche, health information provided by You and treatments You receive, biographical information (including a CV), employment interview notes and references, professional society memberships, practice and therapeutic areas, specialties, experience and personal and professional interests, prescribing of medicinal products by You, engagements with other pharmaceutical companies, publications by You, clinical trials in which You served or are serving as an investigator, video, audio and other media recordings, and internal Roche documents describing the past and planned professional engagements and interactions with You. Certain other data such as diet or accommodation preferences or restrictions may also be processed as appropriate.

Data will be obtained from the operation of any agreement between You and Roche, from You directly, from Your colleagues, from internal data sources maintained by Roche, from third parties supplying data to Roche and from publicly available sources such as the Internet.

 

Purposes of processing

The personal data referred to above will be processed for the purposes of:

  • facilitating the conduct of business and professional engagements and interactions between You and Roche:
    • for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner; and
    • to comply with Our legal obligations.
  • complying with Our legislative and regulatory (including reporting) obligations (and industry codes and similar) in connection with Our dealings with You, in which case the legal bases for Our processing are that this is necessary:
    • for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner; and
    • to comply with Our legal obligations.
  • internal and external audits and, where necessary, investigations, in which case the legal bases for Our processing are that this is necessary:
    • for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner; and
    • to comply with Our legal obligations.
  • internal training and management of personnel, in which case the legal basis for Our processing is that this is necessary for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner;
  • company operations (including medical, communications, sales and marketing operations) including internal business analysis and competitive intelligence / profiling activities, in which case the legal basis for Our processing is that this is necessary for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner;
  • filming, audio and other media activities in which case the legal basis for Our processing is Your consent; and
  • maintaining appropriate business records, in which case the legal bases for Our processing are that this is necessary:
    • for the purposes of Our legitimate interests in conducting Our business in a responsible and commercially prudent manner;
    • to comply with Our legal obligations.

Only data necessary for legitimate business purposes will be maintained.

Recipients of Data

We may disclose Your personal data to various recipients in connection with the above purposes, including:

  • to third parties who We engage to provide services to Us, such as professional advisers, auditors and outsourced or other service providers including travel, transport and event management companies and other third parties such as hotels, professional medical societies, etc.
  • to other members of the Roche corporate group;
  • to the public in relation to any transfers of value made to You; and
  • to competent regulatory authorities and bodies as requested or required by law.

 

 

Compliance with laws and transfers abroad

Roche (as Controller of Your personal data) as well as all other companies within the Roche Group are fully committed to complying with all applicable data privacy laws, such as the EU Directive 95/46/EC and implementing legislation while applicable, the GDPR, the Swiss Data Privacy Act, and other applicable data privacy laws and principles as amended from time to time.

In connection with the above We may transfer Your personal data outside the European Economic Area, including to a jurisdiction which is not recognised by the European Commission as providing for an equivalent level of protection for personal data as is provided for in the European Union. If and to the extent that We do so, Roche will ensure that appropriate measures are in place to comply with Our obligations under applicable law governing such transfers to protect the privacy and fundamental rights and freedoms of individuals. Further details of the measures that We have taken are available from the Compliance Manager, contactable at (01) 4690700.

Retention

We will retain Your personal data for the duration of Your engagement / interaction with Us and for such a period of time after Our engagement / interaction ends as is necessary to comply with Our obligations under applicable law and, if relevant, to deal with any claim or dispute that might arise in connection with Your engagement / interaction with Us.

Your Rights

You have the following rights, in certain circumstances, in relation to Your personal data:

  • the right to access Your personal data;
  • the right to request the rectification and/or erasure of Your personal data;
  • the right to restrict the use of Your personal data;
  • the right to object to the processing of Your personal data; and
  • the right to receive Your personal data, which You provided to Us, in a structured, commonly used and machine-readable format or to require Us to transmit that data to another Controller.

In order to exercise any of the rights set out above or for further information, please contact the Compliance Manager at (01) 4690700.

Complaints

You have the right to lodge a complaint with the Irish Data Protection Commission (info@dataprotection.ie) or Your local data protection supervisory authority.