Skip to content
Slide

PRIVACY

Personal Data Processing Agreement

This Personal Data Processing Agreement (the “Agreement”) is entered into between Farmigea, acting through its legal representative pro tempore (the “Controller”), and the Distributor identified in the License and Supply Agreement entered into between Farmigea and the Distributor (the “Processor”). The Controller and the Processor are hereinafter individually referred to as a “Party” and collectively as the “Parties”.

Background

• This Agreement aims to define the obligations of the Parties concerning the protection of personal data, in accordance with Article 28 of Regulation (EU) 2016/679 (hereinafter also referred to as “GDPR”).
• For the purposes of this Agreement, “Applicable Data Protection Law” means the GDPR and any applicable national laws, regulations and binding measures adopted or issued by competent public authorities, including supervisory authorities, concerning the processing of personal data, as amended, supplemented or replaced from time to time. The terms “processing”, “personal data”, “controller”, “processor”, “data subject” and “personal data breach” shall have the meanings given to them under Applicable Data Protection Law.
• For all matters not explicitly governed by this Agreement, reference shall be made to the License and Supply Agreement and the Applicable Data Protection Law.

1. Subject Matter of the Agreement and Remuneration

1.1. The Background and the Annexes form an integral part of this Agreement.

1.2. Pursuant to Article 28 of the GDPR, the Controller appoints the Distributor as its Processor. The Processor accepts the appointment and undertakes to comply with Applicable Data Protection Law and with all the provisions of this Agreement, including its Annexes.

1.3. The Parties acknowledge and agree that the remuneration for the services provided by the Processor in that capacity is included in the remuneration provided for under the License and Supply Agreement and shall be governed by the same terms.

2. Rights and Obligations of the Controller

2.1. The Controller determines the purposes and means of processing personal data collected or processed by the Processor in the execution of the License and Supply Agreement.

2.2. The Controller has the right to verify at any time that the Processor complies with the given instructions and adheres to the Applicable Data Protection Law.

2.3. The Controller is required to inform the Processor of any changes in the purposes and means of processing personal data.

3. Obligations of the Processor

3.1. General Obligations

3.1.1. The Processor shall process personal data on behalf of the Controller in connection with the performance of the License and Supply Agreement and exclusively within the framework of this Agreement, unless otherwise required by Union or Member State law to which the Processor is subject. Personal data shall not be used for any other purpose and, in particular, shall not be processed by the Processor for its own purposes.
The Processor may disclose personal data to third parties providing ancillary or support services where this is necessary for the performance of the License and Supply Agreement, provided that any such disclosure and engagement comply with Section 3.4 of this Agreement. The Processor shall not disclose personal data to any other third party without the Controller’s prior written authorisation.

3.1.2. The processing of personal data shall take place exclusively within the European Economic Area (“EEA”) or in a third country or international organisation in respect of which the requirements set out in Chapter V of the GDPR are satisfied. The Processor shall not transfer personal data, or permit access to personal data, outside the EEA, including through any Sub-processor, without the Controller’s prior written authorisation and without ensuring that the transfer is carried out in compliance with Articles 44 to 49 of the GDPR, including, where applicable, on the basis of an adequacy decision, appropriate safeguards or a valid derogation.

3.1.3. The Processor shall promptly notify the Controller of any request received from a data subject or any third party. The Processor shall not respond to the request unless expressly authorised to do so by the Controller.

3.1.4. The Processor shall assist the Controller in fulfilling the obligations to respond to requests from data subjects for the exercise of their rights, taking into account the nature of the processing.

3.1.5. The Processor shall provide the Controller with all necessary assistance, as requested by the latter, to ensure compliance with the obligations referred to in Articles 32 “Security of Processing”, 33 “Notification of a personal data breach to the supervisory authority”, 34 “Communication of a personal data breach to the data subject”, 35 “Data protection impact assessment”, and 36 “Prior consultation” of the GDPR.

3.1.6. The Processor shall make available to the Controller all necessary information to demonstrate compliance with the obligations and requirements of the Applicable Data Protection Law, and shall cooperate with the Controller in the event of inspections or checks of any kind carried out by the competent authorities or in the event of disputes with the data subject.

3.1.7. Upon termination of the License and Supply Agreement or, in any event, upon termination of this Agreement, the Processor shall return to the Controller all personal data received from the Controller and any personal data generated in connection with processing operations carried out on behalf of the Controller.
The Processor shall then promptly delete all remaining personal data in its possession and any copies existing in its records or systems, unless Union or Member State law to which the Processor is subject requires the retention of such personal data.

3.1.8. If required by the Applicable Data Protection Law or at the explicit request of the Controller, the Processor shall prepare, maintain, and regularly update a record of processing activities carried out on behalf of the Controller, as governed by Article 30 of the GDPR.

3.1.9. The Processor shall designate in writing the persons authorised to process personal data and shall ensure that they have the skills and training necessary for the processing activities to be carried out.

3.2. Processor Obligations – Technical and Organisational Measures

3.2.1. The Processor shall implement the measures required under Article 32 of the GDPR. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
In doing so, the Processor shall give particular consideration to the risks presented by the processing, including risks arising from the accidental or unlawful destruction, loss or alteration of personal data, and from the unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

3.2.2. At the Controller’s request, the Processor shall provide the Controller with information concerning the security measures implemented pursuant to Article 32 of the GDP

3.3. Processor Obligations – Relations with Third Parties

3.3.1. Where data subjects, supervisory authorities or any other third party, including, without limitation, judicial or administrative authorities other than supervisory authorities, submit a request to the Processor, including a request concerning the exercise of rights granted to data subjects under the GDPR, the Processor shall inform the Controller in writing immediately and, in any event, no later than 24 hours after receiving the request.

3.3.2. The Processor shall forward to the Controller a copy of the requests received, together with any additional information or details that may be relevant or useful.

3.3.3. The Processor may respond to such requests only with the Controller’s express written authorisation and in accordance with the directions, instructions and guidelines provided in writing by the Controller. The Processor shall not act independently or as the Controller’s representative or agent unless expressly instructed to do so by the Controller.

3.3.4. The Processor shall not disclose or communicate to any third party, including in response to a request, personal data processed on behalf of the Controller or any other information relating to the processing of personal data without first obtaining the Controller’s written authorisation and instructions.

3.3.5. Where the Processor is required, in order to comply with a legal obligation or in response to a request from a judicial, administrative or law-enforcement authority, to disclose or communicate to a third party personal data processed on behalf of the Controller or information relating to the processing, the Processor shall:
a) immediately notify the Controller in writing of the relevant circumstances, unless prohibited from doing so by applicable law;
b) take all reasonable measures to limit or restrict the scope of the disclosure or communication, including by omitting information that has not been expressly requested; and
c) make every reasonable effort to obtain appropriate confidentiality commitments from the recipients of the disclosure or communication.

3.4. Processor Obligations – Sub-processing Relationships

3.4.1. The Controller grants the Processor general authorisation to engage Sub-processors pursuant to Article 28 of the GDPR solely for the performance of specific personal data processing activities necessary for the performance of the License and Supply Agreement.

3.4.2. The Processor shall provide the Controller, upon request, with a complete and up-to-date list of the Sub-processors engaged to perform necessary, ancillary or support activities.

3.4.3. The Processor shall promptly inform the Controller of any intended addition or replacement of Sub-processors before implementing the relevant change, thereby giving the Controller the opportunity to object. In the event of an objection, the relevant change shall not be implemented and the new Sub-processor shall not be appointed.

3.4.4. Where the Processor engages a Sub-processor, the Processor shall ensure that the contract or other binding legal act with the Sub-processor provides sufficient guarantees that appropriate technical and organisational measures will be implemented so that the processing meets the requirements of the GDPR.
No Sub-processor may commence processing personal data before being formally appointed and bound by contractual obligations. Pursuant to Article 28(4) of the GDPR, the Processor shall impose on each Sub-processor the same data protection obligations as those set out in this Agreement and in any subsequent written instructions issued by the Controller.

3.4.5. The Processor shall remain fully responsible to the Controller for the performance of all obligations assumed under this Agreement. The Processor shall therefore be liable for the proper performance of the activities entrusted to any Sub-processor appointed by it and for any failure, breach or non-compliance attributable to that Sub-processor.

3.5. Personal Data Breach Notification by the Processor

3.5.1. In the event of a personal data breach affecting the Processor’s systems or those of any of its Sub-processors, including any accidental or unlawful destruction, loss or alteration of personal data, or any unauthorised disclosure of, or access to, personal data, the Processor shall notify the Controller in writing by Italian certified electronic mail (PEC) at farmigea@legalmail.it as soon as possible after becoming aware of the breach and, in any event, without undue delay.
The notification shall contain the information required under Article 33(3) of the GDPR, to the extent available to the Processor at the time of notification. Where it is not possible to provide all the information at the same time, the information may be provided in phases without undue further delay.

4. Termination

4.1. In the event of a breach by the Processor of any of the obligations set out in this Agreement, the Controller shall have the right to terminate for breach any agreement then in force between the Parties.

5. Confidentiality

5.1. All personal data received by the Processor from the Controller and/or collected by the Processor in the performance of this Agreement shall be kept confidential and shall not be disclosed to third parties.

5.2. The confidentiality obligation set out in Section 5.1 shall not apply to the extent that disclosure of the relevant information:
a) has been expressly authorised in writing by the Controller;
b) is expressly permitted under this Agreement and is reasonably necessary for its performance; or
c) is required by applicable law or by a competent authority, subject to the requirements set out in Section 3.3.5.

6. Duration of the Agreement

6.1. This Agreement shall enter into force on the date on which it is signed and shall remain valid and effective until the expiry or termination, for any reason, of the License and Supply Agreement or of any subsequent agreement entered into between the same Parties and having the same subject matter.
Where any processing activities remain ongoing upon termination of the License and Supply Agreement, the Processor shall complete such activities and shall remain bound, in relation to them, by all applicable instructions and obligations arising under this Agreement.

7. Liability and Indemnification

7.1. The Processor shall indemnify and hold harmless the Controller from and against any loss, cost, expense, administrative fine, damage, claim, compensation or other liability directly or indirectly arising out of or in connection with:
a) any breach of this Agreement by the Processor or any Sub-processor appointed by it;
b) any breach of Applicable Data Protection Law by the Processor or any Sub-processor appointed by it; or
c) any act or omission of the Processor or any Sub-processor appointed by it in connection with personal data processing activities carried out on behalf of the Controller.

8. Final Provisions

8.1. Any amendment to this Agreement shall be valid only if made in writing and signed by the Parties.

8.2. This Agreement cancels and replaces any previous agreement or understanding between the Parties relating to the processing of personal data carried out by the Processor on behalf of the Controller.

8.3. The Parties declare that all the clauses contained in this Agreement have been carefully and individually reviewed and reflect the mutual intention of the Parties.

8.4. If any clause of this Agreement is declared invalid, such declaration shall not affect the validity of the remaining clauses contained herein. In such a case, and to the extent possible, the invalid clause shall be replaced by another clause whose effect is as close as possible to what the Parties intended at the time of signing this Agreement.

8.5. The failure of the Controller to exercise one or more of the rights arising from this Agreement shall not constitute, nor be construed as, a waiver of such rights. If a Party is legally required to appoint a Data Protection Officer, it must do so and provide the relevant contact details to the other Party.

9. Annexes

Annex 1 – Processing Details

Categories of data subjects whose personal data are processed

Patients, Distributors and Physicians.

Categories of personal data processed

Identification and contact data.
Data relating to adverse reactions.

Nature of the processing

The processing includes all activities aimed at collecting, recording and communicating personal data to the Controller, as well as retaining such data for the periods provided for in the Agreement entered into by the Parties.

Purposes for which personal data are processed on behalf of the data controller

The data are processed for the performance of post-marketing surveillance of the products marketed by the Controller.

Duration of the processing

For the duration of the contractual relationship.

Skip to content