Privacy and Data Security. (a) In the prior three (3) years, the Company and its Subsidiaries have been in compliance with Privacy Laws, and in all material respects with (i) Contracts (or portions thereof) between the Company or its Subsidiaries and other Persons relating to Personal Data and (ii) applicable written policies, public statements and other public representations relating to the Processing of Personal Data, inclusive of all disclosures required by applicable Privacy Laws (“Privacy and Data Security Policies,” and together with Privacy Laws and such Contracts, “Privacy Commitments”). The execution, delivery and performance by the Company of this Agreement to which the Company is or will be a party, and the consummation of the transactions contemplated hereby or thereby, are not reasonably expected to, directly or indirectly, result in a violation of any Privacy Commitments that would be materially adverse to the Company and its Subsidiaries, taken as a whole.
(b) In the prior three (3) years, the Privacy and Data Security Policies have at all times been maintained and made available to individuals in accordance with reasonable industry practices and as required by Privacy Laws, are accurate and complete and are not misleading or deceptive (including by omission). The practices of the Company or its Subsidiaries with respect to the Processing of Personal Data conform in all material respects to the Privacy and Data Security Policies that govern such Personal Data.
(c) There is (and in the prior three years there has been) no material Legal Proceeding pending or, to the Company’s knowledge, threatened against or involving the Company or its Subsidiaries initiated by any Person (including (i) the Federal Trade Commission, any state attorney general or similar state official, (ii) any other Governmental authority, foreign or domestic or (iii) any regulatory or self-regulatory entity) alleging that any Processing of Personal Data by or on behalf of the Company or its Subsidiaries is or was in violation of any Privacy Commitments. To the Company’s Knowledge, there are no facts, circumstances or conditions that would reasonably be expected to form the basis for any proceeding for any potential violation of any Privacy Commitments.
(d) In the prior three (3) years, (i) there has been no unauthorized access to, or unauthorized use, disclosure, or Processing of Personal Data in the possession or control of the Company or its Subsidiaries or any of its contractors with regard to a...
Privacy and Data Security. (a) Each Group Company that maintains a web site has posted on its web site a privacy policy regarding the collection, use and disclosure of Personal Information that it collects, is in its possession, or in its custody or control. Each Group Company has complied in all material respects with all Information Privacy and Security Laws and material agreements to which it is a party that contain, involve or deal with receipt, collection, compilation, use, storage, processing, sharing, safeguarding, security (technical, physical and administrative), disposal, destruction, disclosure, or transfer (including cross-border) Personal Information. No Group Company has been notified in writing of any Action or any other claim related to data security or privacy or alleging a violation of any of its privacy policies, or any Information Privacy and Security Law, nor, to the Knowledge of the Company, has any such claim been threatened in writing. Each Group Company has taken commercially reasonable administrative, physical and technical measures designed to protect and maintain the confidentiality, security, integrity and accessibility (as applicable) of: (a) Systems and all data contained therein (including Company Data and Data Sets and other data subject to confidentiality obligations), (b) all Personal Information and other Sensitive Data collected by or on behalf of the Group Companies in connection with their business, including in each case, in accordance with all Information Privacy and Security Laws and Group Company’s published policies. Each Group Company has taken commercially reasonable steps to ensure that all material third party service providers, outsourcers, contractors, or other persons who access, process, store or otherwise handle Personal Information for or on behalf of a Group Company have agreed in writing to materially comply with applicable Information Privacy and Security Laws and taken reasonable steps to protect and secure Personal Information from loss, theft, misuse or unauthorized access, use, modification or disclosure.
(b) There are no unsatisfied written requests that any Group Company has received from individuals seeking to exercise their data protection rights under Information Privacy and Security Laws. Except as set forth on Schedule 3.13.9(b), there is not and has not been any (i) Action or (ii) written allegation that a Group Company has received by any private party, any data protection authority, or any other Governmental Auth...
Privacy and Data Security. (a) The parties will keep confidential any information regarding the Trust, the Company, Nationwide, the Variable Accounts and Contract Owners received in connection with providing services and meeting their respective obligations hereunder, except: (a) as necessary to provide the services or otherwise meet their respective obligations under this Agreement; (b) as necessary to comply with applicable law; and (c) information regarding the Trust or Variable Accounts which is otherwise publicly available. The parties will maintain internal safekeeping procedures to safeguard and protect the confidentiality of the data transmitted to another party or its designees or agents in accordance with Section 248.11 of Regulation S-P (17 CFR 248.1–248.30) (“Reg S-P”), and any other applicable federal or state privacy laws and regulations, including without limitation 201 CFR 17.00 et seq. and applicable security breach notification regulations (collectively “Privacy Laws”). Each party shall use such data solely to effect the services contemplated herein, and none of the parties will directly, or indirectly through an affiliate, disclose any non-public personal information protected under Privacy Laws (“Non-public Personal Information”) received from another party to any person that is not an affiliate, designee, service provider, or agent of the receiving party and provided that any such information disclosed to an affiliate, designee, service provider, or agent will be under the same or substantially similar contractual limitations on use and non-disclosure and will comply with all legal requirements. The Company and the Trust will not use information, including Non-public Personal Information, directly or indirectly provided to it by Nationwide or its designees or agents pursuant to this Agreement for the purpose of marketing to Contract Owners or any other similar purpose, except as may be agreed by the parties hereto. Except for confidential information consisting of Non-public Personal Information, which will be governed in all respects in accordance with the immediately preceding sentence, confidential information does not include information which (i) was publicly known and/or was in the possession of the party receiving confidential information (“Receiving Party”) from other sources prior to the Receiving Party’s receipt of confidential information from the party disclosing confidential information (“Disclosing Party”), or (ii) is or becomes publicly available ...
Privacy and Data Security. The Company and each of its Subsidiaries have complied with all applicable Laws, contractual obligations, and internal or publicly posted policies, procedures, notices, and statements concerning the collection, acquisition, use, processing, storage, transfer, distribution, dissemination, disclosure, protection and security (“Data Activities”) of personally identifiable information of individual natural persons (including any information that alone or in combination with any other information held by the Company and its Subsidiaries, can be used to specifically identify an individual person and any “individually identifiable health information,” “personal data” or “personal information” or similar terms defined under applicable Law (“Personal Data”) (such applicable Laws, contractual obligations, and internal or publicly posted policies, procedures notices and statements, collectively the “Data Protection Requirements”) in the conduct of the Company’s and its Subsidiaries’ businesses, in each case except as would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect. The Company and each of its Subsidiaries have all necessary authority, rights, consents and authorizations to engage in the Data Activities of Personal Data maintained by or for the Company and its Subsidiaries to the extent required in connection with the operation of the Company’s and its Subsidiaries’ business as currently conducted. Since January 1, 2019, the Company and its Subsidiaries have not: (i) experienced any actual, alleged, or suspected data breach or other security incident involving Personal Data in their possession or control; or (ii) been subject to or received any notice of any audit, investigation, complaint, or other Legal Action by any Governmental Entity or other Person concerning the Company’s or any of its Subsidiaries’ Data Activities in relation to Personal Data or actual, alleged, or suspected violation of any Data Protection Requirement concerning privacy, data security, or data breach notification, and to the Company’s Knowledge, there are no facts or circumstances that could reasonably be expected to give rise to any such Legal Action, in each case except as would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect. Parent and its Subsidiaries (i) have executed current and valid “Business Associate Agreements” (as described by HIPAA and the corresponding regulatio...
Privacy and Data Security. (a) The Target Company is, and at all times has been, in material compliance with (A) all federal, state, local and foreign Laws pertaining to (i) data security, cyber security, and e-commerce; (ii) the collection, storage, use, access, disclosure, processing, security, and transfer of Personal Data (referred to collectively in this Agreement as “Data Activities”) ((i) and (ii) together, and together with the Data Protection Laws, “Privacy Laws”); and (B) all Contracts (or portions thereof) to which the Target Company is a party that are applicable to Data Activities (collectively, “Privacy Agreements”). The Target Company is, and at all times has been, in compliance with the PCI Security Standards Council’s Payment Card Industry Data Security Standard and all other applicable rules and requirements by the PCI Security Standards Council, by any member thereof, or by any entity that functions as a card brand, card association, payment processor, acquiring bank, merchant bank or issuing bank, including, without limitation, the Payment Application Data Security Standards and all audit and filing requirements (collectively, “PCI Requirements”).
(b) The Target Company has implemented written policies relating to Data Activities, including, without limitation, a publicly posted website privacy policy, mobile app privacy policy, and a comprehensive information security program that includes appropriate written information security policies (“Privacy and Data Security Policies”). At all times, the Target Company has been and is in compliance with all such Privacy and Data Security Policies. Neither the execution, delivery, or performance of this Agreement, nor the consummation of any of the transactions contemplated under this Agreement will violate any of the Privacy Agreements, Privacy and Data Security Policies or any applicable, Privacy Laws.
(c) The Target Company has collected, used, and disclosed all Personal Data in accordance with applicable Privacy Laws, Privacy and Data Security Policies in effect at the time of the collection of such Personal Data, and Privacy Agreements. Neither applicable Privacy Laws, Privacy and Data Security Policies, nor Privacy Agreements restrict the transfer of any Personal Data to the Acquirer. Assuming Acquirer is not otherwise prohibited by Law or contractually obligated otherwise, Acquirer may use such Personal Data in at least the same manner as the Target Company.
(d) To the Knowledge of the Owners, there is no pending, ...
Privacy and Data Security. The Loan Parties and their Subsidiaries shall, at all times, remain in compliance in all material respects with all applicable United States and international privacy and data security laws and regulations including GDPR (to the extent applicable).
Privacy and Data Security. During the course of the Agreement, CampMinder may receive or have access to Personal Data of Licensee. CampMinder agrees and covenants that it will use and disclose Personal Data solely and exclusively for the purposes for which the Personal Data, or access to it, is provided pursuant to the terms and conditions of this Agreement. Further, each Party shall comply with all Data Protection Laws applicable to the parties’ respective collection, use, disclosure and other processing of Personal Data hereunder. Without limiting the generality of the foregoing, Licensee represents and warrants that it has, and will obtain, all right, title, and interest in and to any Licensee Data provided hereunder which may be necessary for CampMinder to process such Personal Data for the purposes set forth herein, including in connection with the analysis and monitoring of Licensee’s and its Authorized Users’ use of the Software Products, and in connection with the legitimate non-commercial business and information security operations of Licensee. In the event the Parties must enter into any agreement or additional provisions to maintain compliance with all applicable Data Protection Laws, the Parties shall negotiate in good faith to agree to such additional terms, including any processing terms required under the GDPR. Licensee represents that it is not subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), will not provide any information that is subject to HIPAA to CampMinder, and will promptly advise CampMinder if Licensee becomes or provides any information subject to HIPAA. CampMinder will maintain reasonable and appropriate administrative, physical and technical safeguards for protection of the security, confidentiality and integrity of Licensee Data, including Personal Data. In the event that any Personal Data is disclosed by CampMinder (or its employees, subcontractors or agents) to an unauthorized third party (a “Data Breach”), then CampMinder shall give notice to Licensee, with full particulars if known, and shall commence an investigation of any such incident. Licensee shall be solely responsible for providing any notices or providing any remedies required by applicable Data Protection Law.
Privacy and Data Security. Any data, including all Personal Information related to the current, former or prospective shareholders, officers or trustees of each Trust, that MUIS receives, generates, collects or otherwise processes on behalf of a Trust pursuant to the services performed under the terms of this Agreement (collectively, “Trust Data”) will be used by MUIS solely in connection with performing or enforcing any obligations with respect to the Agreement. For purposes of this Agreement, “
Privacy and Data Security. (a) Each Group Company complies, and at all times have complied, except as has not been and would not reasonably be expected to be material to the Company or its Subsidiaries, taken as a whole, with all applicable Privacy Laws, with applicable Privacy Policies, and with applicable contractual obligations of the Company and its Subsidiaries governing privacy, data protection, and data security with respect to the Processing of Personal Data by the Company and its Subsidiaries. There are no material unsatisfied requests from individuals to the Company or any of its Subsidiaries seeking to exercise rights under any Privacy Law. Neither the execution of this Agreement nor the consummation of the Transactions constitutes a material breach or violation of any applicable Privacy Law, any applicable Privacy Policy, or any applicable contractual obligations of the Company and its Subsidiaries governing privacy, data protection, and data security with respect to the Processing of Personal Data by the Company and its Subsidiaries. There is no, and has not been any, (i) Action of any nature pending or threatened against the Company or any of its Subsidiaries relating to privacy, data protection, or data security with respect to the Processing of Personal Data by the Company and its Subsidiaries; or (ii) written notice of any actual or asserted noncompliance with any Law to which the Company or any of its Subsidiaries are subject relating to privacy, data protection, or data security with respect to the Processing of Personal Data by the Company, except for that which would not, individually or in the aggregate, reasonably be expected to have a Company Material Adverse Effect.
(b) The Company and its Subsidiaries have at all times (i) implemented and maintained reasonable measures in compliance with applicable Privacy Laws, designed to preserve and protect the confidentiality, availability, security, and integrity of all Systems and Personal Data within the possession or control of the Company and its Subsidiaries; (ii) implemented and maintained reasonable disaster recovery and business continuity plans for their business; and (iii) not suffered any security breach resulting in any material unauthorized access to, or acquisition of, any Personal Data within the possession or control of the Company or any of its Subsidiaries.
(c) The IT Assets of the Company and its Subsidiaries, including any portions of which are provided or operated by Third Parties, are adequate an...
Privacy and Data Security. Except as would not reasonably be expected to result in a Material Adverse Effect, (a) the Company and its Subsidiaries have established written privacy policies applicable to the collection, use, disclosure, maintenance and transmission of Personal Data, (b) each of the Company and its Subsidiaries is in compliance in all material respects with their written privacy policies, contracts which impose requirements relating to the collection, processing, storage, disclosure, disposal or other handling of Personal Data, any applicable laws relating to privacy, data protection, anti-spam, personal information and similar consumer protection laws, and any applicable industry standards which impose requirements on the collection, processing, storage, disclosure, disposal or other handling of Personal Data (collectively, the “Privacy Requirements”). Except as would not reasonably be expected to result in a Material Adverse Effect, neither the operation by the Company or any of its Subsidiaries of any its websites nor the content thereof or data processed, collected, stored or disseminated by such entity in connection therewith, violates in any material respect any applicable law regarding privacy, data protection, anti-spam, personal information and similar consumer protection laws. Since January 1, 2021, none of the Company nor any of its Subsidiaries has experienced (i) incidents of unauthorized access or other security breaches, including any loss, misuse, damage, unauthorized access, unauthorized disclosure or unauthorized use of any Personal Data, or (ii) any other event that the Company or any of its Subsidiaries required a data breach notice to any Person or Governmental Entity under Privacy Requirements, except, in each case, as would not reasonably be expected to result in a Material Adverse Effect. Except as, individually or in the aggregate, would not reasonably be expected to result in a Material Adverse Effect, the hardware, software, databases, web sxxxx, xxxxxx applications, servers, workstations, routers, hubs, switches, circuits, networks, communications networks, and other information technology owned, licensed, leased or otherwise used, distributed or held for use by the Company or its Subsidiaries (i) have not, within the three (3) years prior to the date of this Agreement, malfunctioned or failed in a manner that resulted in chronic or otherwise material disruptions to the operation of the business of the Company and its Subsidiaries, and (ii)...