Processing of personal data by the Parties Clause Samples

POPULAR SAMPLE Copied 1 times
Processing of personal data by the Parties. The processing of personal data by the Parties shall meet the requirements of Regulation (EU) 2018/1725 and be processed solely for the following purposes: Contact with employees and subcontractors in order to collaborate under the Agreement. Both Parties agree each act as Data Controllers with regards to the Processing of Personal Data they each undertake. Each Party represents and warrants that it has provided an appropriate data privacy notice and obtained appropriate consent (if legally required) from the data subjects whose In-Scope Personal Data is being shared with the other Party and that such notice and consent is in accordance with Applicable Laws regarding data protection and allows for the desired use of such In-Scope Personal Data. Should a Party learn that it has provided In-Scope Personal Data that may not be shared pursuant to a consent or notice, such Party is responsible for promptly notifying the other Party so that the affected In-Scope Personal Data can be deleted as required. The Parties agree that the responsibility for complying with any communication addressed to one or both Parties under this Agreement made by a Data Subject exercising one or several of his/her data protection rights under Applicable Laws regarding Data Protection (“Data Subjects Requests”) falls to the Party receiving the Data Subject Request in respect of the personal data held and under the responsibility of that Party as data controller. The Parties agree to cooperate and provide reasonable assistance as is necessary to each other to enable them to (1) comply with Applicable Laws regarding Data Protection, (2) comply with Subject Requests and (3) respond to any other queries or complaints from data subjects. In the event a Party suffers a personal data breach, such Party shall ensure it complies with Applicable Laws regarding Data Protection and, if applicable, complies with any obligations to notify Data Protection Supervisory Authority, data subjects or other regulatory bodies as required by Applicable Law regarding the Personal Data Breach. To the extent the Commission or Participating Member State suffers a personal data breach that (1) has an impact on the services provided under this Agreement or (2) relates to In- Scope Personal Data AstraZeneca shared with the Commission or Participating Member State, the Commission or Participating Member State shall promptly notify AstraZeneca about such personal data breach.
Processing of personal data by the Parties materiály obsahující důvěrné informace, s výjimkou informací, které musí podle platných právních předpisů zůstat na pracovišti klinického hodnocení. Zdravotnické zařízení si však může ponechat jednu archivní kopii důvěrných informací výhradně za účelem stanovení rozsahu závazků vyplývajících z této smlouvy, přičemž na tuto kopii se bude nadále vztahovat bod 11.
Processing of personal data by the Parties a. Both prior to and during the course of the Study, the Principal Investigator and other employees/contractors, representatives and/or agents of the Institution may be called upon to provide personal data to Sponsor. This personal data may include names, contact information, work experience and professional qualifications, publications, resumes, educational background and information relating to payments made pursuant to this Agreement. For other employees/contractors, representatives and/or agents of the Institution, this data may include names and contact information. Such data may be processed and stored electronically by Sponsor and/or transferred to third parties (situated throughout the world) for the following purposes: (1) the conduct of clinical trials or Observational Studies; (2) verification by government or regulatory authorities, the Sponsor, , and their agents and affiliates; (3) compliance with legal and regulatory requirements; (4) publication on ▇▇▇.▇▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇ and other websites and/or databases that serve a comparable purpose; (5) storage in databases to facilitate the selection of investigators for future Observational Studies/clinical trials; and (6) anti-corruption compliance.
Processing of personal data by the Parties. 3.1 The Processing of Personal Data in relation to the Agreement and under this DPA is carried out by the Parties in the respective roles foreseen in the table “Parties and execution”. 3.2 In this regard, such Processing shall be carried out in accordance with: (i) Applicable Data Protection Laws and (ii) the respective provisions and agreements foreseen in relation to the applicable scenario(s) specified below: No Restricted International Transfer Controller or Processor entity established inside or outside the Protected Area Processor or Controller entity established inside the Protected Area The Controller-to-Processor DPA shall apply. This includes Processing which takes place within the same country, as well as International Transfers within and/or towards the Protected Area. Restricted International Transfer (C2P) Controller entity established inside or outside the Protected Area Processor entity established outside the Protected Area This is a Restricted International Transfer and the EU international SCCs (module 2) shall apply. Restricted International Transfer (P2C) Processor entity established inside or outside the Protected Area Controller entity established outside the Protected Area This is a Restricted International Transfer and the EU international SCCs (module 4) shall apply. The Controller- to-Processor DPA shall also apply to the extent that module 4 of the EU international SCCs does not cover the requirements for a controller to processor data processing agreements under the GDPR. No Restricted International Transfer Controller entity established inside or outside the Protected Area Controller entity established inside the Protected Area The obligations foreseen below for “All C2C scenarios” shall apply. Unless explicitly foreseen in the table “Parties and execution”, the Parties shall be deemed as independent and separate Controllers and not Joint-Controllers. Restricted International Transfer Controller entity established inside or outside the Protected Area Controller entity established outside the Protected Area This is a Restricted International Transfer and the EU international SCCs (module 1) shall apply. Unless explicitly foreseen in the table “Parties and execution”, the Parties shall be deemed as independent and separate Controllers and not Joint-Controllers.