Quintiles (NYSE: Q) helps biopharmaceutical companies and other healthcare companies improve their probability of success by connecting insights from our deep scientific, therapeutic and analytics expertise with superior delivery for better outcomes. From advisory through operations, Quintiles is the world’s largest provider of product development and integrated healthcare services, including commercial and observational solutions. Quintiles has approximately 32,000 employees, conducting operations in approximately 100 countries, Quintiles is a member of the FORTUNE 500 and has been named to FORTUNE’s list of the “World’s Most Admired Companies.”
Quintiles and our subsidiaries and affiliates (collectively referred to as “Quintiles”, “Company”, “we” or “our”) respect the relationships we have with our customers and respect the privacy of employees, patients, healthcare providers, consumers, our business partners and others whose Personal Information (see Definitions) may be processed by Quintiles in the performance of our services, including individuals participating in clinical research studies. Quintiles provides an adequate level of protection with respect to transfer of personal data out of the European and Switzerland to other countries for the performances of our services and business operations. To meet the adequacy requirement with respect to these transfers, Quintiles uses model contractual clauses and other mechanisms approved by the European Union for such transfers. In addition, Quintiles is certified to the Federal Trade Commission’s Safe Harbor program. Further details of this Program can be found on the website at https://safeharbor.export.gov/list.aspx.
* * *
SCOPE: This Policy applies to all Personal Information, either in electronic or paper format, received by Quintiles in the U.S. from the EU or Switzerland, including Personal Information relating to investigators or participants in clinical trials where Quintiles provides services to customers as a Contract Research Organization (“CRO”).
LIMITATIONS ON SCOPE:
Adherence to this Policy may be limited to the extent required to meet a legal, regulatory, governmental, national security or public interest obligation. Also, this Policy may not apply or may be limited when Personal Information is obtained by Quintiles or its subsidiaries:
DEFINITIONS: For purposes of this Policy, the following definitions shall apply:
“Agent” means any third party that uses Personal Information provided to it by Quintiles to perform tasks on behalf of and under the instructions of Quintiles.
“Individual” means any natural person located in the European Union or Switzerland whose Personal Information is shared with Quintiles in the United States.
“Quintiles” means Quintiles Transnational Corp., its affiliates, successors, subsidiaries, divisions and groups in the United States.
“Personal Information” means any information or set of information that identifies or could be used by or on behalf of Quintiles to identify an Individual. Personal Information does not include information that is anonymized such that an Individual cannot be identified.
“Sensitive Personal Information” means Personal Information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or that concerns health or personal sexuality. In addition, Quintiles will treat as Sensitive Personal Information any information received from a third party where that third party treats and identifies the information as sensitive.
“European Union (EU)” means for the purposes of this Policy all countries within the European Economic Area (EEA).
“European Union Data Protection Directive” means Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
* * *
NOTICE: Where Quintiles collects Personal Information directly from Individuals, it will explain the purposes for which it collects and uses Personal Information about the Individuals, the types of non-agent third parties to which Quintiles discloses that information, and the choices and means, if any, Quintiles offers Individuals for limiting the use and disclosure of Personal Information about them. This explanation will be provided as soon as practicable and, in any event, before Quintiles uses the information for a purpose other than that for which it was originally obtained. Where Quintiles receives Personal Information from its subsidiaries, affiliates or other entities, including when acting as a CRO processing Personal Information under the direction of a customer, it will use such information in accordance with the notices provided by such entities and the choices made by the Individuals to whom such Personal Information relates. Quintiles may not need to furnish notice where the processing in question is necessary to respond to a government inquiry; is required / authorized by applicable laws, court orders or government regulations; or is necessary to protect Quintiles’ legal interests and providing notice would interfere with the above requirements.
CHOICE: Quintiles will offer Individuals the opportunity to choose whether their Personal Information is (a) to be disclosed to a non-agent third party, or (b) to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the Individual. Unless required or authorized by law, Quintiles will not process Sensitive Personal Information about Individuals for purposes other than those for which the information was originally obtained or subsequently authorized by the Individual unless the Individual affirmatively and explicitly consents to the processing (“opt-in”). In some cases, even if an Individual opts-out of disclosures of their Personal Information, Quintiles may still disclose such Personal Information if required to do so by law, if disclosure is required to be made to law enforcement authorities, if we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity. Quintiles also may transfer Personal Information in the event we sell or transfer all or a portion of our business or assets. Should such a sale or transfer occur, Quintiles will direct the transferee to use Personal Information in a manner that is consistent with this Policy. Quintiles will provide Individuals with reasonable mechanisms to exercise their choices.
ONWARD TRANSFERS: Transfers to third parties are covered by the provisions in this Policy regarding notice and choice. Quintiles may also share an Individual's Personal Information with Agents, contractors or partners of Quintiles in connection with services that these individuals or entities perform for, or with, Quintiles. Quintiles may, for example, provide an Individual's Personal Information to Agents, contractors or partners for hosting our databases, for data processing services, or to send to that Individual the information that he or she requested. Quintiles will obtain assurances from these third parties that they will safeguard Personal Information consistently with this Policy. Examples of appropriate assurances that may be provided include model contracts from the European Union. Where Quintiles knows that an Agent, contractor, vendor, or partner is using or disclosing Personal Information in a manner contrary to this Policy, Quintiles will take reasonable steps to prevent or stop the use or disclosure.
ACCESS AND CORRECTION: Upon request, and as required by law, Quintiles will provide Individuals with reasonable access to the Personal Information that Quintiles holds about them, subject to permitted exemptions. In addition, upon request, Quintiles will take reasonable steps to provide Individuals with a means to correct, amend, or delete Personal Information that is found to be inaccurate or incomplete. Quintiles when acting as a CRO has no direct relationship with participants in a clinical trial and any such Individuals who seek access, or who seek to correct, amend, or delete their inaccurate Personal Information should direct his or her query to the relevant study sponsor or investigator which has transferred such Personal Information to Quintiles for processing.
SECURITY: Quintiles will employ reasonable technical, administrative and physical safeguards to protect Personal Information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction. When Quintiles is acting as a CRO and processing Personal Information as an Agent under the direction of its customers, Quintiles enters into a contract with such customers specifying the conditions under which Personal Information received from the EU and/or Switzerland are to be processed and kept secure.
DATA INTEGRITY: Quintiles will use Personal Information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the Individual. Quintiles will take reasonable steps to ensure that Personal Information is relevant to its intended use, accurate, complete, current, and otherwise reliable in relation to the purposes for which the information was obtained. Quintiles’ employees have a responsibility to assist Quintiles in maintaining accurate, complete and current Personal Information. When acting as a CRO, Quintiles only processes Personal Information that is relevant to the services it provides, and only for purposes compatible with those for which the Personal Information was collected. As an Agent processing Personal Information as a CRO under the direction of its customers, Quintiles works with such customers so that the customers can provide a way for Individuals to correct their Personal Information.
DISPUTE RESOLUTION: Any questions or concerns regarding the use or disclosure of Personal Information should be directed to Quintiles’ CODP through the contact information given below. Quintiles will investigate and attempt to resolve complaints and disputes regarding use and disclosure of Personal Information in accordance with the principles contained in this Policy. For complaints involving Personal Information other than human resources data that cannot be resolved, such disputes will be referred to the American Arbitration Association for resolution unless the complainant selects an alternate mechanism. For internal complaints by Individuals involving human resources data that cannot be resolved between Quintiles and an employee after following the internal review, complaint, and appeal procedures, Quintiles will participate in the dispute resolution procedures of the applicable national data protection authority and Swiss Federal Data Protection and Information Commissioner to resolve disputes..
CONTACT INFORMATION: Questions, comments or concerns regarding this Policy should be submitted to Quintiles’ Council on Data Protection by e-mail as follows: firstname.lastname@example.org.
RESERVATION OF RIGHTS: Quintiles reserves the right to share an Individual’s Personal Information as required or authorized by law or regulation or in response to duly authorized information requests of government authorities.
* * *
Information about how Quintiles Japan protects privacy is available on Quintiles’ Japan Internet site in Japanese at http://www.quintiles.co.jp/privacy.html.
* * *
Version 9.0; 20 November 2015