Compliance with Data Privacy Laws The Company and its Subsidiaries are, and at all prior times were, in compliance with all applicable state and federal data privacy and security laws and regulations, including without limitation HIPAA, and the Company and its Subsidiaries have taken commercially reasonable actions to prepare to comply with, and since May 25, 2018, have been and currently are in compliance with, the GDPR (EU 2016/679) (collectively, the “Privacy Laws”) except in each case, where such would not, either individually or in the aggregate, reasonably be expected to result in a Material Adverse Effect. To ensure compliance with the Privacy Laws, the Company and its Subsidiaries have in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling, and analysis of Personal Data (the “Policies”). The Company and its Subsidiaries have at all times made all disclosures to users or customers required by applicable laws and regulatory rules or requirements, and none of such disclosures made or contained in any Policy have, to the knowledge of the Company, been inaccurate or in violation of any applicable laws and regulatory rules or requirements in any material respect. The Company further certifies that neither it nor any Subsidiary: (i) has received notice of any actual or potential liability under or relating to, or actual or potential violation of, any of the Privacy Laws, and has no knowledge of any event or condition that would reasonably be expected to result in any such notice; (ii) is currently conducting or paying for, in whole or in part, any investigation, remediation, or other corrective action pursuant to any Privacy Law; or (iii) is a party to any order, decree, or agreement that imposes any obligation or liability under any Privacy Law.
Privacy and Data Protection The Company and its subsidiaries have operated their business in a manner compliant in all material respects with all United States federal, state, local and non-United States privacy, data security and data protection laws and regulations applicable to the Company’s collection, use, transfer, protection, disposal, disclosure, handling, storage and analysis of personal data. The Company and its subsidiaries have been and are in compliance in all material respects with internal policies and procedures designed to ensure the integrity and security of the data collected, handled or stored in connection with its business; the Company and its subsidiaries have been and are in compliance in all material respects with internal policies and procedures designed to ensure compliance with the Health Care Laws that govern privacy and data security and take, and have taken reasonably appropriate steps designed to assure compliance in all material respects with such policies and procedures. The Company and its subsidiaries have taken reasonable steps to maintain the confidentiality of its personally identifiable information, protected health information, consumer information and other confidential information of the Company, its subsidiaries and any third parties in its possession (“Sensitive Company Data”). The tangible or digital information technology systems (including computers, screens, servers, workstations, routers, hubs, switches, networks, data communications lines, technical data and hardware), software and telecommunications systems used or held for use by the Company and its subsidiaries (the “Company IT Assets”) are adequate and operational for, in accordance with their documentation and functional specifications, the business of the Company and its subsidiaries as now operated and as currently proposed to be conducted as described in the Registration Statement, the General Disclosure Package and the Prospectus. The Company and its subsidiaries have used reasonable efforts to establish, and have established, commercially reasonable disaster recovery and security plans, procedures and facilities for the business consistent with industry standards and practices in all material respects, including, without limitation, for the Company IT Assets and data held or used by or for the Company and its subsidiaries. The Company and its subsidiaries have not suffered or incurred any security breaches, compromises or incidents with respect to any Company IT Asset or Sensitive Company Data, except where such breaches, compromises or incidents would not, individually or in the aggregate, be material to the Company or any of its subsidiaries; and there has been no unauthorized or illegal use of or access to any Company IT Asset or Sensitive Company Data by any unauthorized third party. The Company and its subsidiaries have not been required to notify any individual of any information security breach, compromise or incident involving Sensitive Company Data.
Compliance with Privacy Laws NCPS represents and warrants that its collection, access, use, storage, disposal and disclosure of Personal Data does and will comply with all applicable federal and state privacy and data protection laws, as well as all other applicable regulations. Without limiting the foregoing, NCPS shall implement administrative, physical and technical safeguards to protect Personal Data that are no less rigorous than accepted industry, and shall ensure that all such safeguards, including the manner in which Personal Data is collected, accessed, used, stored, processed, disposed of and disclosed, comply with applicable data protection and privacy laws, as well as the terms and conditions of this Escrow Agreement. NCPS shall use and disclose Personal Data solely and exclusively for the purposes for which the Personal Data, or access to it, is provided pursuant to the terms and conditions of this Escrow Agreement, and not use, sell, rent, transfer, distribute, or otherwise disclose or make available Personal Data for NCPS’s own purposes or for the benefit of any party other than Issuer. For purposes of this section, “Personal Data” shall mean information provided to NCPS by or at the direction of the Issuer, or to which access was provided to NCPS by or at the direction of the Issuer, in the course of NCPS’s performance under this Escrow Agreement that: (i) identifies or can be used to identify an individual (also known as a “data subject”) (including, without limitation, names, signatures, addresses, telephone numbers, e-mail addresses and other unique identifiers); or (ii) can be used to authenticate an individual (including, without limitation, employee identification numbers, government-issued identification numbers, passwords or PINs, financial account numbers, credit report information, biometric or health data, answers to security questions and other personal identifiers), including the identifying information on individuals described in Section 12.
Third-Party Information; Privacy or Data Protection Laws Each Party acknowledges that it and members of its Group may presently have and, following the Effective Time, may gain access to or possession of confidential or proprietary information of, or personal information relating to, Third Parties (i) that was received under confidentiality or non-disclosure agreements entered into between such Third Parties, on the one hand, and the other Party or members of such Party’s Group, on the other hand, prior to the Effective Time; or (ii) that, as between the two Parties, was originally collected by the other Party or members of such Party’s Group and that may be subject to and protected by privacy, data protection or other applicable Laws. Each Party agrees that it shall hold, protect and use, and shall cause the members of its Group and its and their respective Representatives to hold, protect and use, in strict confidence the confidential and proprietary information of, or personal information relating to, Third Parties in accordance with privacy, data protection or other applicable Laws and the terms of any agreements that were either entered into before the Effective Time or affirmative commitments or representations that were made before the Effective Time by, between or among the other Party or members of the other Party’s Group, on the one hand, and such Third Parties, on the other hand.
Compliance with Anti-Corruption Laws Neither the Company nor any of its Controlled Entities or their respective affiliates, nor any director, officer or employee thereof nor, to the Company’s knowledge, any agent or representative of the Company or of any of its Controlled Entities or their respective affiliates, has (i) used any corporate funds for any unlawful contribution, gift, entertainment or other unlawful expense relating to political activity; (ii) taken or will take any action in furtherance of an offer, payment, promise to pay, or authorization or approval of the payment, giving or receipt of money, property, gifts or anything else of value, directly or indirectly, to any “government official” (including any officer, director or employee of a government or government-owned or controlled entity or of a public international organization, or any person acting in an official capacity for or on behalf of any of the foregoing, or any political party or party official or candidate for political office) to induce such government official to do or omit to do any act in violation of his lawful duties, influence official action or secure, obtain or retain business or any other improper advantage; (iii) made, offered, agreed, requested or taken an act in furtherance of any unlawful bribe or other unlawful benefit, including, without limitation, any rebate, payoff, influence payment, kickback or other unlawful or improper payment or benefit; or (iv) will use, directly or indirectly, the proceeds of the offering in furtherance of an offer, payment, promise to pay, or authorization of the payment or giving of money, or anything else of value, to any person in violation of any applicable anti-bribery or anti-corruption laws, in each case as amended from time to time, (collectively, the “Anti-Corruption Laws”); and the Company and its Controlled Entities and affiliates have conducted their businesses in compliance with Anti-Corruption Laws and have instituted, maintained and enforced, and will continue to maintain and enforce, policies and procedures reasonably designed to promote and achieve compliance with such laws and with the representations and warranties contained herein; no investigation, action, suit or proceeding by or before any court or governmental agency, authority or body or any arbitrator involving the Company or any of its Controlled Entities with respect to the Anti-Corruption Laws is pending or, to the best knowledge of the Company after due and careful inquiry, threatened.
Compliance with Anti-Corruption Laws and Sanctions Maintain in effect and enforce policies and procedures designed to ensure compliance by the Borrower, its Subsidiaries and their respective directors, officers, employees and agents with Anti-Corruption Laws and applicable Sanctions.
Compliance with International Trade & Anti-Corruption Laws (a) Neither the Group Companies nor, to the Company’s knowledge, any of their Representatives, or any other Persons acting for or on behalf of any of the foregoing, is or has been, since the incorporation of the Company, (i) a Person named on any Sanctions and Export Control Laws-related list of designated Persons maintained by a Governmental Entity; (ii) located, organized or resident in a country or territory which is itself the subject of or target of any Sanctions and Export Control Laws; (iii) an entity owned, directly or indirectly, by one or more Persons described in clause (i) or (ii); or (iv) otherwise engaging in dealings with or for the benefit of any Person described in clauses (i) - (iii) or any country or territory which is or has, since the incorporation of the Company, been the subject of or target of any Sanctions and Export Control Laws (at the time of this Agreement, the Crimea region of Ukraine, Cuba, Iran, North Korea, Venezuela, Sudan and Syria).
Data Protection The Administrator shall implement and maintain a comprehensive written information security program that contains appropriate security measures to safeguard the personal information of the Trust’s shareholders, employees, directors and/or officers that the Administrator receives, stores, maintains, processes or otherwise accesses in connection with the provision of services hereunder. For these purposes, “personal information” shall mean (i) an individual’s name (first initial and last name or first name and last name), address or telephone number plus (a) social security number, (b) driver’s license number, (c) state identification card number, (d) debit or credit card number, (e) financial account number or (f) personal identification number or password that would permit access to a person’s account or (ii) any combination of the foregoing that would allow a person to log onto or access an individual’s account. Notwithstanding the foregoing “personal information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.
Compliance with Safeguarding Customer Information Requirements The Servicer has implemented and will maintain security measures designed to meet the objectives of the Interagency Guidelines Establishing Standards for Safeguarding Customer Information published in final form on February 1, 2001, 66 Fed. Reg. 8616, and the rules promulgated thereunder, as amended from time to time (the “Guidelines”). The Servicer shall promptly provide the Seller information regarding the implementation of such security measures upon the reasonable request of the Seller.
Compliance with Anti-Money Laundering Laws and Anti-Corruption Laws The Collateral Manager, each Person directly or indirectly Controlling the Collateral Manager and each Person directly or indirectly Controlled by the Collateral Manager and, to the Collateral Manager’s knowledge, any Related Party of the foregoing shall: (i) comply with all applicable Anti-Money Laundering Laws and Anti-Corruption Laws in all material respects, and shall maintain policies and procedures reasonably designed to ensure compliance with the Anti-Money Laundering Laws and Anti-Corruption Laws; (ii) conduct the requisite due diligence in connection with the transactions contemplated herein for purposes of complying with the Anti-Money Laundering Laws, including with respect to the legitimacy of any applicable investor and the origin of the assets used by such investor to purchase the property in question, and will maintain sufficient information to identify any applicable investor for purposes of the Anti-Money Laundering Laws; (iii) ensure it does not cause the Borrower to use any of the credit in violation of any Anti-Corruption Laws or Anti-Money Laundering Laws; and (iv) ensure it does not cause the Borrower to fund any repayment of the Obligations in violation of any Anti-Corruption Laws or Anti-Money Laundering Laws.