Privacy and Data Security. (a) The Company and its Subsidiaries are, and at all times in the past three years have been, in compliance in all material respects with all (i) applicable Information Privacy and Security Laws; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”). (b) Neither the Company nor any of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws. (c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification. (d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents. (e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations. (f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 2 contracts
Sources: Merger Agreement (Coherus BioSciences, Inc.), Merger Agreement (Surface Oncology, Inc.)
Privacy and Data Security. (a) The Company Each of the Acquired Companies is currently complying and its Subsidiaries arehas, and at all times in the past three years have beensince January 1, in compliance 2017 complied in all material respects with all (i) applicable Information Privacy and Information Security Laws; (ii) published policies or notices , including Laws relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing privacy of Personal Information (collectivelyregarding clinical trial participants, patients, patient family members, caregivers or advocates, physicians and other health care professionals, clinical trial investigators, researchers and pharmacists that interact with any of the Acquired Companies in connection with the operation of the Acquired Companies’ business. To the Knowledge of the Company, no investigations, claims or complaints are pending or have been threatened against the Acquired Companies by any Person regarding a violation of Privacy and Information Security Laws, and/or other information security policies. None of the Acquired Companies is a “Privacy Requirements”)covered entity” or “business associate” for purposes of HIPAA. The Acquired Companies have provided all requisite notices, obtained all required consents, and satisfied all other material requirements for their processing of Personal Information for the conduct of business as currently conducted and in connection with the consummation of the Contemplated Transactions.
(b) Neither The Acquired Companies have adopted reasonable and appropriate, organizational, physical, administrative and technical measures consistent with industry practices to protect Personal Information and protect against Security Incidents (as defined below). Without limitation to the Company nor any generality of its Subsidiaries has received any subpoenasthe foregoing, demandssuch measures are appropriate to protect the Personal Information collected, or other written notices from any Governmental Entity or other entity investigating, inquiring intostored, or otherwise relating to any actual processed by or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Acquired Companies, the confidential or proprietary information of or related to their businesses, and the Company IT Systems from unauthorized access, acquisition, interruption, alteration, modification, use or other processing, or any other compromise of its Subsidiariestheir confidentiality, including, without limitation, contract research organizations and clinical investigators, integrity or availability (any such incident a “Security Incident”). Except as expressly disclosed pursuant to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control Section 3.17 of the Company and each of its Subsidiaries can be transferred as part Disclosure Schedule, since January 1, 2017, none of the Mergers and Acquired Companies (nor, to the other transactions contemplated by this AgreementKnowledge of the Company, any Third Parties acting on their behalf) have experienced any actual or alleged Security Incident, and can be used after none of the Closing Acquired Companies (nor, to the Knowledge of the Company, any Third Parties acting on their behalf) have notified, or been required to notify, any person of any Security Incident or other event involving Personal Information that is in a manner substantially the same as currently used by custody, possession or control of any of the Acquired Companies. In addition, to the Knowledge of the Company, no individuals or Third Parties (including any threat actors described in Section 3.17 of the Company Disclosure Schedule) have ongoing unauthorized access to Company IT Systems, and its applicable Subsidiariesto the Knowledge of the Company, none of the Acquired Companies or Company IT Systems have any information security vulnerabilities that would reasonably be expected to materially adversely impact the operation of relevant Company IT Systems or cause a Security Incident.
Appears in 2 contracts
Sources: Merger Agreement (BioNTech SE), Merger Agreement (Neon Therapeutics, Inc.)
Privacy and Data Security. (a) The Company operation of Parent’s and its Subsidiaries are, and at all times in the past three years have been, Subsidiaries’ business is in compliance in all material respects with all applicable Data Protection Regulations. Neither the execution, delivery or performance of this Agreement, nor the consummation of the Contemplated Transactions will result in any material violation of applicable Data Protection Regulations. Since January 1, 2023, there have been (i) no Security Incidents materially impacting Personal Data (including any clinical trial data or other data obtained from or about clinical trial subjects, research participants, investigators, or investigator personnel) or any confidential data or Trade Secrets used in the business of Parent or its Subsidiaries as currently conducted (collectively, “Parent Sensitive Data”) (and Parent and its Subsidiaries have not provided or been required under applicable Information Privacy and Security Laws; Data Protection Regulations to provide notification of any breach of privacy or data security), (ii) published policies no material violations of any security policy of Parent or notices relating its Subsidiaries regarding any such Parent Sensitive Data and (iii) no material unintended or improper disclosure of any Parent Sensitive Data in the possession, custody or control of Parent or its Subsidiaries or a contractor or agent acting on behalf of Parent or its Subsidiaries. Since January 1, 2023, none of Parent or its Subsidiaries has received any written notice (x) from a vendor or data processor that processes Parent Sensitive Data on behalf of Parent or any of its Subsidiaries with respect to a Security Incident materially impacting Parent Sensitive Data or (y) from any other Person, including from any supervisory authority or Governmental Entity of any complaint, investigation, inquiry or enforcement action regarding its Parent Sensitive Data processing.
(b) Each of Parent and its Subsidiaries has materially complied, and continues to materially comply, with applicable Data Protection Regulations, including with (i) requirements to process Personal Data lawfully, (ii) contractual requirements applicable to the Companyengagement of data processors processing Personal Data on behalf of Parent and its Subsidiaries, (iii) requirements to provide adequate security measures to protect Parent Sensitive Data, (iv) conduct of appropriate data privacy impact assessments to the extent required by applicable Data Protection Regulations, (v) provisions related to lawful cross-border data transfers of Personal Data and (vi) applicable requirements for the collection, use, storage and security of clinical trial data under ICH Guidelines for Good Clinical Practice and applicable regulations.
(c) Each of Parent and its Subsidiaries has implemented commercially reasonable physical, technical and organizational measures designed to protect Parent Sensitive Data against loss, destruction and damage, unauthorized access, use, modification, disclosure or other misuse.
(d) To Parent’s Knowledge, (i) Parent and its Subsidiaries have implemented commercially reasonable safeguards for transfers of Personal Data outside of a country of origin in compliance in all material respects with applicable Data Protection Regulations, and (ii) none of Parent or its Subsidiaries has suspended or terminated a transfer of Personal Data due to violation of applicable Data Protection Regulations or received any written notice from a supervisory authority regarding any concerns about a transfer of Personal Data, except, in each case, as would not have a Parent Material Adverse Effect.
(e) With respect to any clinical trial or other clinical research study conducted by or on behalf of Parent or any of its Subsidiaries, to Parent’s Knowledge, Parent and its Subsidiaries have obtained all required informed consents from clinical trial subjects and research participants and all required approvals from institutional review boards or independent ethics committees, in each case in compliance in all material respects with Data Protection Regulations, 21 C.F.R. Parts 50 and 56 and ICH Guidelines for Good Clinical Practice.
(f) Parent and its Subsidiaries have deployed and used AI in material compliance with all applicable Laws and Data Protection Regulations, as well as in all material respects with Contract terms applicable to Parent and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, processing of Training Data. Parent and its Subsidiaries do not use any data that is subject to an obligation of confidentiality by Parent or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any its Subsidiaries under all applicable Laws and Contracts to which the Company and/or Parent or any of its Subsidiaries are bound; is subject or a party, in any prompts or input to any AI tools by Parent or its Subsidiaries, except in cases where such AI tools do not use such data, prompts or inputs to train the machine learning or algorithm of such tools or to improve the services related to such AI tools other than solely for use by the Parent or its Subsidiaries as permitted by all applicable Laws and (iv) industry standards and/or codes-of-conduct Contracts to which the Company and/or Parent or any of its Subsidiaries are legally bound is subject or a party. Parent has implemented and maintains commercially reasonable policies relating to the Companygovernance or implementation of AI, including its policies relating to (A) management oversight and approval of employees’ and contractors’ use and implementation of AI, and (B) use and implementation of AI in a manner that is designed to avoid violation, infringement or misappropriation of any third Person’s Intellectual Property Rights and violation of applicable Laws. Parent and its Subsidiaries have not used or employed any AI tools in a manner that would materially limit Parent’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring intoownership of, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Companyimpair Parent’s or any of its Subsidiaries’ possession and/or control from unauthorized ability to use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, usecommercialize, or disclosure; otherwise exploit, the Intellectual Property Rights in or other adverse events pertaining to any output generated by the use of AI tools by or incidents related to Personal Information for Parent and its Subsidiaries. Parent does not use AI for any activity that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, is banned or any others prohibited under any applicable Privacy Requirements. The Company has not received written notice of Law, including activities designated as “high risk” or otherwise subject to heightened requirements or restrictions under any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidentsapplicable Law.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 2 contracts
Sources: Merger Agreement (Standard Biotools Inc.), Merger Agreement (Standard Biotools Inc.)
Privacy and Data Security. (a) The Company and its Subsidiaries are, and at all times in the past three years have been, in compliance in all material respects with all (i) applicable Information Privacy and Security Laws; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security operation of the Company’s and its Subsidiaries’ softwarebusiness is in compliance in all material respects with applicable Data Protection Regulations. Neither the execution, systemsdelivery or performance of this Agreement, and websites nor the consummation of the Contemplated Transactions will result in any material violation of applicable Data Protection Regulations. Since January 1, 2023, there have been (i) no Security Incidents materially impacting Personal Data (including any clinical trial data or other data obtained from or about clinical trial subjects, research participants, investigators, or investigator personnel) or any confidential data or Trade Secrets used in the business of the Company or its Subsidiaries as currently conducted (collectively, “IT AssetsCompany Sensitive Data”) that are involved in (and the Processing Company and its Subsidiaries have not provided or been required under applicable Data Protection Regulations to provide notification of Personal Informationany breach of privacy or data security), and (ii) Personal Information no material violations of any security policy of the Company or its Subsidiaries regarding any such Company Sensitive Data and (iii) no material unintended or improper disclosure of any Company Sensitive Data in the Company’s possession, custody or control of the Company or its Subsidiaries or a contractor or agent acting on behalf of the Company or its Subsidiaries. Since January 1, 2023, none of the Company or its Subsidiaries has received any written notice (x) from a vendor or data processor that processes Company Sensitive Data on behalf of the Company or any of its Subsidiaries with respect to a Security Incident materially impacting Company Sensitive Data or (y) from any other Person, including from any supervisory authority or Governmental Entity of any complaint, investigation, inquiry or enforcement action regarding its Company Sensitive Data processing.
(b) Each of the Company and its Subsidiaries has materially complied, and continues to materially comply, with applicable Data Protection Regulations, including with (i) requirements to process Personal Data lawfully, (ii) contractual requirements applicable to the engagement of data processors processing Personal Data on behalf of the Company and its Subsidiaries’ possession and/or control from unauthorized , (iii) requirements to provide adequate security measures to protect Company Sensitive Data, (iv) conduct of appropriate data privacy impact assessments to the extent required by applicable Data Protection Regulations, (v) provisions related to lawful cross-border data transfers of Personal Data and (vi) applicable requirements for the collection, use, storage and security of clinical trial data under ICH Guidelines for Good Clinical Practice and applicable regulations.
(c) Each of the Company and its Subsidiaries has implemented commercially reasonable physical, technical and organizational measures designed to protect Company Sensitive Data against loss, destruction and damage, unauthorized access, disclosureuse, deletionmodification, and/or modificationdisclosure or other misuse.
(d) To the Company’s knowledgeKnowledge, neither (i) the Company nor any and its Subsidiaries have implemented commercially reasonable safeguards for transfers of Personal Data outside of a country of origin in compliance in all material respects with applicable Data Protection Regulations, and (ii) none of the Company or its Subsidiaries has experienced suspended or terminated a transfer of Personal Data due to violation of applicable Data Protection Regulations or received any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice from a supervisory authority regarding any concerns about a transfer of any complaintsPersonal Data, Actionsexcept, finesin each case, or other penalties facing the as would not have a Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidentsMaterial Adverse Effect.
(e) To the extent required With respect to any clinical trial or other clinical research study conducted by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information or on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither Company’s Knowledge, the Company nor and its Subsidiaries have obtained all required informed consents from clinical trial subjects and research participants and all required approvals from institutional review boards or independent ethics committees, in each case in compliance in all material respects with applicable Data Protection Regulations, 21 C.F.R. Parts 50 and 56 and ICH Guidelines for Good Clinical Practice.
(f) The Company and its Subsidiaries have deployed and used AI in material compliance with all applicable Laws and Data Protection Regulations, as well as in all material respects with Contract terms applicable to the Company and its Subsidiaries’ processing of Training Data. The Company and its Subsidiaries do not use any data that is subject to an obligation of confidentiality by the Company or its Subsidiaries under all applicable Laws and Contracts to which the Company or any of its Subsidiaries is aware subject or a party, in any prompts or inputs to any AI tools by Company or its Subsidiaries, except in cases where such AI tools do not use such data, prompts or inputs to train the machine learning or algorithm of such tools or to improve the services related to such AI tools other than solely for use by the Company or its Subsidiaries as permitted by all applicable Laws and Contracts to which the Company or any of its Subsidiaries is subject or a party. The Company has implemented and maintains commercially reasonable policies relating to governance or implementation of AI, including its policies relating to (A) management oversight and approval of employees’ and contractors’ use and implementation of AI, and (B) use and implementation of AI in a manner that is designed to avoid violation, infringement or misappropriation of any violations third Person’s Intellectual Property Rights and violation of such contractual obligations.
(f) To applicable Laws. The Company and its Subsidiaries have not used or employed any AI tools in a manner that would materially limit the Company’s knowledgeor any of its Subsidiaries’ ownership of, or otherwise materially impair the Company’s or any of its Subsidiaries’ ability to use, commercialize, or otherwise exploit, the Personal Information Intellectual Property Rights in or pertaining to any output generated by the possession, custody, and/or control use of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated AI tools by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by or for the Company and its Subsidiaries. The Company does not use AI for any activity that is banned or prohibited under any applicable SubsidiariesLaw, including activities designated as “high risk” or otherwise subject to heightened requirements or restrictions under any applicable Law.
Appears in 2 contracts
Sources: Merger Agreement (Standard Biotools Inc.), Merger Agreement (Standard Biotools Inc.)
Privacy and Data Security. (a) The Company and its Subsidiaries arecomply, and at all times in the past three years have beenhave, in compliance since January 1, 2020, complied, in all material respects with all all: (i) applicable Information Privacy and Security Laws; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ published policies, statements, and binding contractual obligations relating to the receipt, collection, compilation, use, storage, processing, sharing, safeguarding, security, disposal, destruction, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; and (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) all applicable industry standards and/or codes-of-conduct to which including, without limitation, the Company and/or any Payment Card Industry Data Security Standard and all other applicable requirements of its Subsidiaries are legally bound relating to the Company’s or any payment card brands (all of its Subsidiaries’ Processing of Personal Information (the foregoing, collectively, the “Privacy Requirements”). The Company and its Subsidiaries display a privacy policy on each website and mobile application owned, controlled, or operated by the Company and its Subsidiaries, and each such privacy policy incorporates all material disclosures to data subjects as required by the Privacy Requirements. None of the disclosures made or contained in any such privacy policy has been materially inaccurate, misleading or deceptive, or in violation of the Privacy Requirements (including containing any material omission).
(b) Neither The Company and its Subsidiaries have obtained, or have contractually obligated its customers to obtain, all consents required from data subjects under Privacy Requirements, and the Company nor any of and its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Lawshold auditable records evidencing such consent.
(c) The Company and its Subsidiaries maintain records of their processing activities in accordance with Privacy Requirements.
(d) The Company and its Subsidiaries have each taken implemented commercially reasonable stepsorganizational, physical, administrative, and technical measures and policies consistent with the Privacy Requirements (including HIPAA) to protect: (i) the integrity, security, and operations of all Computer Systems under the Company’s control that process Personal Information; and (ii) all Personal Information owned, controlled, or stored by or on behalf of the Company and its Subsidiaries from and against data security incidents or other misuse. The Company and its Subsidiaries have implemented reasonable procedures, materially compliant consistent with the requirements of all applicable Privacy Requirements, designed to detect data security incidents and to protect Personal Information against loss and against unauthorized access, use, modification, disclosure, or other misuse.
(e) The Company and its Subsidiaries have: (i) the operationregularly conducted and regularly conduct vulnerability testing, confidentiality, integrityrisk assessments, and security of the Company’s and its Subsidiaries’ software, systemsexternal audits of, and websites track security incidents related to, the Computer Systems (collectively, “IT AssetsInformation Security Reviews”) that are involved in the Processing of Personal Information, and ); (ii) Personal timely remediated material or critical findings or vulnerabilities identified in such Information Security Reviews, including by installing software security patches and other fixes; and (iii) timely made available true and accurate copies of all Information Security Reviews conducted in the Company’s previous year.
(f) Except as would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect, the Computer Systems are adequate for, and operate and perform in all material respects in accordance with their documentation and functional specifications and otherwise as required in connection with the operation of the business of the Company and its Subsidiaries as previously conducted and as currently conducted. Since January 1, 2020, the Computer Systems have not materially malfunctioned or failed in a manner that resulted in significant or chronic disruptions to the operation of the business of the Company or any of its Subsidiaries’ possession and/or control from . Except as would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect, and to the Knowledge of the Company, the Computer Systems do not contain any computer code designed to disrupt, disable or harm in any manner the operation of any software or hardware. Except as would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect, and to the Knowledge of the Company, none of the Computer Systems contain any unauthorized usefeature (including any worm, accessbomb, disclosurebackdoor, deletionclock, and/or modificationtimer or other disabling device, code, design or routine) that causes the software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time, or upon command by any Person. The Company and its Subsidiaries have implemented reasonable backup, security and disaster recovery technology consistent with industry practices.
(dg) To In connection with each third-party servicing, outsourcing, processing, or otherwise using Personal Information collected, held, or processed by or on behalf of the Company and its Subsidiaries, the Company and its Subsidiaries have, in accordance with Privacy Requirements, entered into binding written data processing agreements with any such third party that comply in all material respects with applicable Privacy Requirements with respect to Personal Information. The Company and its Subsidiaries have disclosed all such data processing agreements to which the Company is a party.
(h) There have been no data security incidents, data breaches, ransomware incidents, or unauthorized access or other misuse related to any Computer Systems or Personal Information in the custody or control of the Company or its Subsidiaries or, to the Knowledge of the Company, any service provider acting on behalf of the Company or its Subsidiaries, that would require notification of individuals or any Governmental Authority, or otherwise have a Company Material Adverse Effect on the Company’s knowledgebusiness. The Company and its Subsidiaries have a data breach response plan, which is regularly tested.
(i) The consummation of any of the transactions contemplated hereby or thereby will not materially violate any Privacy Requirements as they currently exist or as they existed at any time during which any of the Personal Information was collected or obtained. The Company and its Subsidiaries are not subject to any Privacy Requirements that, following the Closing, would prohibit the Company or Parent from receiving or using Personal Information in the manner in which the Company receives and uses such Personal Information prior to the Closing.
(j) There have not been any Legal Proceedings against the Company or its Subsidiaries related to any data security incidents, ransomware incidents, or any violations of any Privacy Requirement, and, to the Knowledge of the Company, there are no facts or circumstances which could serve as the basis for any such Legal Proceedings. To the Knowledge of the Company, neither the Company nor any of its Subsidiaries has experienced have been party to or the subject of any failures; crashes; security incidents; data breaches; unauthorized accessLegal Proceedings or alleged violations of Privacy Requirements from any Person, use, and there is no such ongoing Legal Proceeding.
(k) The Company and its Subsidiaries have not transferred or disclosure; or other adverse events or incidents related directed any third party to transfer on their behalf Personal Information that would require notification outside of individuals, law enforcement, any Governmental Entity, customers, vendors, the European Economic Area or any others under any the United Kingdom except in material compliance with applicable Privacy Requirements. The .
(l) To the Knowledge of the Company, the Company has and its Subsidiaries have not received written notice distributed marketing communications to any data subject, including in the European Union and the United Kingdom, except in accordance with the Privacy Requirements.
(m) To the Knowledge of any complaintsthe Company, Actions, fines, or other penalties facing the Company or any of its Subsidiaries is in connection material compliance with all federal and state privacy and data security laws governing health information, including, without limitation, HIPAA. The Company or any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated has entered into business associate agreements (as defined under HIPAA) with all of their applicable vendors and data processors authorized to process Personal Information on behalf third parties acting as business associate subcontractors, as defined in 45 C.F.R. § 160.103, of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigatorsas applicable. To the Knowledge of the Company, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither extent the Company nor or any of its Subsidiaries is aware acting as a business associate or subcontractor (as those terms are defined under HIPAA), the Company or any of its Subsidiaries is not and has never been in material violation or breach of a business associate agreement. The Company or any violations of its Subsidiaries has never received any written communication from any Governmental Authority that alleges that it is not in compliance with HIPAA. All of the respective workforce (as such contractual obligationsterm is defined in 45 C.F.R. § 160.103) of the Company or any of its Subsidiaries have received regular training on privacy and data security matters in compliance with Privacy Requirements.
(fn) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control The Company has provided to Parent accurate and complete copies of any written complaint(s) delivered to the Company and each alleging a violation of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiariesany Privacy Requirements.
Appears in 1 contract
Sources: Merger Agreement (Kaleyra, Inc.)
Privacy and Data Security. (a) The Each of the Company and its Subsidiaries arehave, and at all times in the past three years have beensince January 1, 2017 (i) been in compliance in all material respects with all (i) applicable Information Privacy Laws and Security Laws; (ii) with their own respective published privacy policies or notices and internal privacy policies relating to privacy, data protection and data security, including with respect to the Company’s and its Subsidiaries’ collection, use, storage, disclosuretransmission, processing, handling, protection, or transfer (including cross-border transfer (“Processing”) transfers), disclosure and use of Personal InformationData; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized usetaken commercially reasonable measures to protect against loss, accessdamage, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; and unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, finesmodification, or other penalties facing misuse of Personal Data collected, transmitted or stored by the Company or its Subsidiaries. Since January 1, 2017, no Person (including any Governmental Authority) has commenced any Legal Proceeding against the Company or its Subsidiaries with respect to the Company’s alleged loss, damage, or unauthorized access, use, modification, or other misuse of any Personal Data collected, transmitted or stored by the Company or any of its Subsidiaries in connection with (or any of their respective employees or contractors), and to the knowledge of the Company, there is no reasonable basis for any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidentsLegal Proceeding.
(eb) To None of the extent required Company or its Subsidiaries has experienced any material unauthorized access to, use or misuse of, or other breach of security with respect to (A) any Software or other Company Systems or any Personal Data or other Data or information stored or Processed thereon or thereby; (B) the Confidential Information in the Company’s or its Subsidiaries’ possession, custody or control; (C) the Company Data, in each case, collected, held or otherwise managed by applicable Information Privacy and Security Lawsthe Company or any of its Subsidiaries; or (D) the Company Data, in each case, collected, transmitted or stored on behalf of the Company or any of its Subsidiaries.
(c) Since January 1, 2017, the Company and each its Subsidiaries have taken reasonable measures for responding, and have complied in all material respects with any obligations relating, to data subject requests for access, rectification, deletion, portability or objections to Processing of Personal Data or other rights under Privacy Laws. To the extent the Company or any of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process entered into Contracts with any third parties who are Processing Personal Information Data on behalf of the Company or any of its Subsidiaries, includingsuch Contracts obligate any such third parties to comply with all Privacy Laws. To the knowledge of the Company, without limitationsuch third parties are in compliance with such Contracts and all Privacy Laws, contract research organizations and clinical investigatorsexcept as would not, to individually or in the aggregate, be bound by contractual terms relating material to the protection Company and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligationsSubsidiaries, taken as a whole.
(fd) To The execution, delivery and performance of this Agreement and the consummation of the transactions contemplated hereby complies (and the disclosure to and use by the Surviving Corporation, the Surviving Entity, and Parent and its Affiliates of such information after the Effective Time will comply) with the Company’s knowledgeand its Subsidiaries’ applicable privacy policies and in all material respects with all applicable Laws relating to privacy and data security. Since January 1, the Personal Information in the possession2017, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreementhave made all material disclosures to, and can be used after obtained any necessary consents from, users, customers, employees, contractors and other applicable Persons required by applicable Laws related to privacy and data security and have filed any required registrations with the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiariesdata protection authority.
Appears in 1 contract
Sources: Agreement and Plan of Merger and Reorganization (SoFi Technologies, Inc.)
Privacy and Data Security. (a) The Company Each of the Company’s and its Subsidiaries areSubsidiaries’, and at all times in to the past three years have beenknowledge of the Company each Facility Entity’s, in compliance in all material respects receipt, collection, use, disclosure, processing, storage, disposal and security of Personal Information has, since December 31, 2013, materially complied, and materially complies, with all (i) any Contracts to which the Company or any Subsidiary or Facility Entity is a party, (ii) applicable Information Privacy and Security Laws; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; extent applicable, PCI DSS, and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating all required consents and authorizations from individuals that apply to the Company’s or any of its Subsidiaries’ Processing or Facility Entities’ receipt, access, use and disclosure of such individual’s Personal Information (collectivelyInformation. Except as has not had and would not reasonably be expected to have a Company Material Adverse Effect, “Privacy Requirements”).
(b) Neither the Company nor any and each of its Subsidiaries has received any subpoenashas, demands, or other written notices from any Governmental and each Facility Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation the knowledge of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy has, all necessary authority, consents and Security Laws.
(c) The Company authorizations to receive, access, use and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) disclose the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ or Facility Entities’ possession and/or or under its control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To in connection with the Company’s knowledge, neither the Company nor any operation of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any Subsidiary or Facility Entity. Except as set forth in Section 4.21(a) of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security LawsCompany Disclosure Schedule, the Company and each of its Subsidiaries has, and each Facility Entity to the knowledge of the Company has, since December 31, 2013, (y) posted its Notice of Privacy Practices as that term is defined under HIPAA (“HIPAA Notice of Privacy Practices”) and (z) except as has not had and would not be reasonably expected to have obligated all a Company Material Adverse Effect, complied with its HIPAA Notice of their Privacy Practices and any other privacy policies it has provided to individuals or made publicly available on its website(s).
(b) Except as has not had and would not reasonably be expected to have a Company Material Adverse Effect, since December 31, 2013, each of the Company and each of its Subsidiaries has, and each Facility Entity to the knowledge of the Company has, entered into a Contract that addresses the provisions for “business associate contracts” if and as required by 45 C.F.R. § 164.504(e) or § 164.314(a), as amended (“Business Associate Contracts”), with the applicable vendors third party in each instance where (i) the Company or its Subsidiaries or Facility Entities (as the case may be) acts as a Business Associate to that third party or (ii) the Company or its Subsidiaries or Facility Entities (as the case may be) provides protected health information (as defined in 45 C.F.R. § 160.103) to that third party, or that third party otherwise acts as a Business Associate to Company or any of its Subsidiaries or Facility Entities, in each case as required by, and in material conformity with, HIPAA and the applicable Business Associate Contracts to which the Company or its Subsidiaries or Facility Entities is a party.
(c) Except as has not had and would not reasonably be expected to have a Company Material Adverse Effect or otherwise disclosed in Section 4.21(c) of the Company Disclosure Schedule, there has been no (i) data processors authorized security breach of any IT Assets of the Company, its Subsidiaries or, to process the knowledge of the Company, a Facility Entity that store, process, protect, transmit or maintain Personal Information, (ii) any unauthorized access, control, use, modification or destruction of such IT Asset or (iii) unauthorized access, use, acquisition or disclosure of any Personal Information, in the case of each of clauses (i) through (iii) with respect to Personal Information that is owned, used, stored, or controlled by or on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating or to the protection and Processing knowledge of Personal Information; and neither the Company nor any of its Subsidiaries Facility Entities, in a manner not authorized by the Company or a Subsidiary or Facility Entity, as applicable, including any unauthorized access, use, or disclosure of Personal Information that would constitute a breach for which notification to individuals or Governmental Entities is aware of required under any violations of such contractual obligationsapplicable Information Privacy and Security Laws.
(fd) To Except as has not had and would not reasonably be expected to have a Company Material Adverse Effect or otherwise disclosed in Section 4.21(d) of the Company’s knowledgeCompany Disclosure Schedule, the Personal Information in the possession, custody, and/or control each of the Company and each of its Subsidiaries can be transferred as part has, and each Facility Entity to the knowledge of the Mergers Company has responded to and mitigated each known Security Incident (as defined in 45 C.F.R. § 164.304) related to any IT Assets or Personal Information transmitted, processed, maintained, stored or otherwise available on or through any IT Assets.
(e) Neither the Company nor any of its Subsidiaries, nor any Facility Entity to the knowledge of the Company, (i) is, to the knowledge of the Company, under investigation by any Governmental Entity for a violation of any applicable Information Privacy and Security Laws; (ii) has received since December 31, 2013 any written notices or audit requests from a Governmental Entity relating to any such violations that remain open or pending or, with respect to those that are closed, are material, other transactions contemplated by this Agreementthan those set forth in Section 4.21(e) of the Company Disclosure Schedule; or (iii) is subject to any Order, and can be used after nor, to the Closing in a manner substantially knowledge of the same as currently used Company, is any such Order pending or threatened, relating to the Company’s or any of its Subsidiaries’ or Facility Entities’ processing of Personal Information processed by the Company or its Subsidiaries or Facility Entities.
(f) Except as would not reasonably be expected to have a Company Material Adverse Effect, the consummation of the transactions contemplated hereby is not prohibited by the Company’s, each of its Subsidiaries’, and to the knowledge of the Company, each of its Facility Entities’, applicable SubsidiariesHIPAA Notice of Privacy Practices, as defined above.
(g) The Company has performed a security risk assessment that meets the standards set forth at 45 C.F.R. § 164.308(a)(1)(ii)(A), including an assessment as described at 45 C.F.R. § 164.306(d)(3), taking into account factors set forth in 45 C.F.R. § 164.306(a)–(c) and updated periodically as required by 45 C.F.R. § 164.316(b)(2)(iii) (collectively, the “Security Risk Assessment”). Unless set forth in Section 4.21(g) of the Company Disclosure Schedule, the Company has addressed the security safeguards sufficient to reduce any reasonably anticipated and material threats and deficiencies identified in its current Security Risk Assessment to a reasonable and appropriate level to comply with 45 C.F.R. § 164.306(a).
Appears in 1 contract
Sources: Agreement and Plan of Reorganization (Surgical Care Affiliates, Inc.)
Privacy and Data Security. (a) The Company operation of Parent’s and its Subsidiaries are, and at all times in the past three years have been, Subsidiaries’ business are in compliance in all material respects with all Data Protection Regulations, except to the extent that such noncompliance has not and would not have a Parent Material Adverse Effect. Since January 1, 2021, there have been (i) no Security Incidents impacting Personal Data or any confidential information or Trade Secrets used in the business of Parent or its Subsidiaries (collectively, “Parent Sensitive Data”), (ii) no violations of any security policy of Parent or its Subsidiaries regarding any such Parent Sensitive Data and (iii) no unintended or improper disclosure of any Parent Sensitive Data in the possession, custody or control of Parent or its Subsidiaries or a contractor or agent acting on behalf of Parent or its Subsidiaries, in each case of (i) through (iii), except as would not have a Parent Material Adverse Effect. Between January 1, 2021 and the date hereof, none of Parent or its Subsidiaries has received any written notice from a vendor or data processor that processes Parent Sensitive Data on behalf of Parent or any of its Subsidiaries with respect to a Security Incident materially impacting Parent Sensitive Data.
(b) Each of Parent and its Subsidiaries has complied, and continues to comply, with applicable Information Privacy Data Protection Regulations, including with (i) binding principles relating to processing Personal Data, (ii) requirements to process Personal Data lawfully, (iii) contractual requirements applicable to the engagement of data processors processing Personal Data on behalf of Parent and Security Lawsits Subsidiaries, (iv) requirements to provide adequate security measures to protect Personal Data, (v) regulatory notification obligations to the extent required by applicable Data Protection Regulations, (vi) conduct of appropriate data privacy impact assessments to the extent required by applicable Data Protection Regulations and (vii) provisions related to lawful cross-border data transfers of Personal Data, except, in each case, as would not have a Parent Material Adverse Effect.
(c) Each of Parent and its Subsidiaries has implemented, and regularly assessed its implementation of, commercially reasonable physical, technical and organizational measures necessary to ensure that Personal Data is protected against loss, destruction and damage, unauthorized access, use, modification, disclosure or other misuse, except as would not have a Parent Material Adverse Effect.
(i) None of Parent or its Subsidiaries transfers Personal Data outside of a country of origin of the Personal Data unless Parent or such Subsidiary, as applicable, has ensured, if required by applicable Data Protection Regulations, that the recipient has adequate safeguards to protect such Personal Data in compliance with applicable Data Protection Regulations and has complied with all applicable transfer provisions of Data Protection Regulations, including consent of individuals where necessary; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) where any transfers of Personal InformationData outside the European Economic Area or the United Kingdom formerly relied upon the EU-US or Swiss-US Privacy Shield framework, Parent or such Subsidiary, as applicable, has ensured that the Personal Data transfers are lawful through an alternative mechanism or derogation in accordance with the GDPR; (iii) terms where required by applicable Data Protection Regulations, Parent or such Subsidiary, as applicable, has conducted a risk assessment regarding the transfer of any Contracts Personal Data pursuant to which the Company and/or any of its Subsidiaries standard contractual clauses or binding corporate rules or other requirements and has concluded that such transfers are boundadequately protected; and (iv) none of Parent or its Subsidiaries has suspended or terminated a transfer of Personal Data or notified a supervisory authority due to any concerns regarding a transfer of Personal Data pursuant to standard contractual clauses or binding corporate rules and, to the Company’s Knowledge, nor are there circumstances which reasonably justify such a notification, except in each case of clauses (i), (ii), (iii) and (iv), as would not have a Company Material Adverse Effect.
(e) (i) Each of Parent and its Subsidiaries has implemented and maintained commercially reasonable measures and policies to protect the integrity, continuous operation and security of the IT Systems of Parent and its Subsidiaries and the data stored thereon, including from Harmful Code; (ii) the IT Systems used in the business of Parent and its Subsidiaries operate and perform in all respects as required to permit Parent and its Subsidiaries to conduct their business as currently conducted; and (iii) Parent and its Subsidiaries have implemented commercially reasonable backup and disaster recovery technology and procedures consistent with standard practices applicable to entities similarly situated as Parent and its Subsidiaries for the industry standards and/or codes-in which Parent and its Subsidiaries operate in each applicable jurisdiction in which they conduct business and have acted in material compliance therewith, except, in each case of clauses (i), (ii) and (iii), as would not have a Parent Material Adverse Effect. Since January 1, 2021, the IT Systems of Parent and its Subsidiaries have not malfunctioned or failed, or been subject to any Security Incident that has caused or, to Parent’s Knowledge, would reasonably be expected to cause (A) material disruption of or interruption in the conduct of the business of Parent and its Subsidiaries as presently conducted; (B) material loss, destruction, damage or harm of Parent and its Subsidiaries or any of the businesses of Parent and its Subsidiaries; or (C) material liability of any kind to Parent and its Subsidiaries or their business as currently conducted, except in each case of clauses (A), (B) and (C), as would not have a Parent Material Adverse Effect.
(f) Between January 1, 2021 and the date hereof, none of Parent or its Subsidiaries has been notified in writing of-conduct , and, to which Parent’s Knowledge, there has not been, (i) an actual or threatened Security Incident materially compromising, or threatening to materially compromise, the Company and/or processing of Personal Data (whether by Parent or any of its Subsidiaries are legally bound or, to Parent’s Knowledge, any data processor engaged to process Personal Data on behalf of Parent or its Subsidiaries) or (ii) any action or any circumstance requiring Parent or any of its Subsidiaries to notify a Governmental Entity or any individual to comply with applicable notification requirements of Data Protection Regulations as a direct result of a Security Incident or a violation of any Data Protection Regulations.
(g) Between January 1, 2021 and the date hereof, none of Parent or its Subsidiaries has received a written notice or allegation of any actual or alleged or, to Parent’s Knowledge, threatened Security Incident compromising or revealing a material weakness in the security of Personal Data or IT Systems of Parent and its Subsidiaries, or any other material breach of the Data Protection Regulations relating to Personal Data while in its possession or under its control.
(h) Between January 1, 2021 and the Companydate hereof, none of Parent or its Subsidiaries has received a written claim, complaint, allegation or other notice of a dispute or violation (whether directly or indirectly) from or on behalf of an individual regarding Parent’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)Data processing activities.
(bi) Neither Between January 1, 2021 and the Company nor any date hereof, none of Parent or its Subsidiaries has received any subpoenas, demands, or other a written notices notice from any supervisory authority or Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledgeinvestigation, neither the Company nor any of inquiry, request for information or for co-operation regarding its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security LawsPersonal Data processing activities.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 1 contract
Sources: Merger Agreement (SomaLogic, Inc.)
Privacy and Data Security. (a) The Seller has disclosed to Buyer a true and complete list of all of the types of Personal Data or highly-sensitive information that the Company and its Subsidiaries are, and at all times in the past three years have been, in compliance in all material respects with all collect or transmit through (i) applicable Information Privacy their products or service offerings, and Security Laws; (ii) published policies any website or notices relating to other platforms they maintain, operate or use in the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) conduct of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)their business.
(b) Neither the The Company nor any and each of its Subsidiaries subsidiaries is and has received any subpoenasat all times been in material compliance with all Privacy Laws, demandsPCI Requirements, or other written notices from any Governmental Entity or other entity investigatingapplicable payment card brand, inquiring intocard association, or otherwise relating payment processor, and bank rules and requirements, Privacy Agreements, and federal, state, local and foreign laws, rules and regulations pertaining to any actual or potential violation of any Information Privacy sales and Security Laws. To marketing practices, including, without limitation, the Company’s knowledgeCAN-SPAM Act, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy Telephone Consumer Protection Act, and Security Lawsthe Telemarketing Sales Rule.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information implemented Privacy and Data Security Policies that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirementsare no less rigorous than industry best practices. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated is in material compliance with, and has always complied with, any statutory and fiduciary obligations to safeguard the privacy of Personal Data that the Company or such Subsidiary collects, uses, transmits or processes through its products or service offerings, including its websites or platforms that it maintains, operates or uses in the ordinary conduct of its business. The Company and each of its Subsidiaries satisfies any statutory and fiduciary obligations it has to provide notice to its website visitors or obtain consent for its or a third party’s use of monitoring features such as cookies or tags. The Company has made available a true, correct, and complete copy of each Privacy and Data Security Policy in effect for the Company and each Subsidiary at any time since the inception of the Company or such Subsidiary. The Company and each Subsidiary has at all times been in material compliance with all of their its Privacy and Data Security Policies. Neither the execution, delivery or performance of this Agreement, nor the consummation of any of the transactions contemplated hereby will violate any Privacy Agreement, Privacy and Data Security Policy or any Privacy Law applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations . The Company has delivered to Buyer accurate and clinical investigators, to be bound by contractual terms relating to complete copies of all of the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligationsPrivacy Agreements.
(fd) To There is no pending, nor has there ever been any, complaint, audit, proceeding, investigation, or claim against the Company’s knowledgeCompany or any Subsidiary initiated by any person or entity, the Personal Information in the possessionany Governmental Authority, custody, and/or control foreign or domestic or any regulatory or self-regulatory entity alleging that any Data Activity of the Company or any Subsidiary (i) violates any applicable Privacy Laws, (ii) violates any Privacy Agreements, (iii) violates any Privacy and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this AgreementData Security Policy, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiariesor (iv) constitutes an unfair, deceptive, or misleading trade practice.
Appears in 1 contract
Sources: Stock Purchase Agreement (Future FinTech Group Inc.)
Privacy and Data Security. (a) The Company’s and each Company and its Subsidiaries areSubsidiary’s Processing of Personal Information has, since January 1, 2017, complied, and at all times in the past three years have beencomplies, in compliance (i) in all material respects with (A) any Contracts, public representations or terms of use to which the Company or any Company Subsidiary is a party and (B) all consents and authorizations that apply to the Company’s or any Company Subsidiary’s receipt, access, use and disclosure of Personal Information and (ii) with applicable Information Privacy and Security Laws and PCI DSS, except as would not have a Company Material Adverse Effect. Except as would not have a Company Material Adverse Effect, where applicable (i) the Company and each Company Subsidiary has all necessary lawful bases, authority, consents and authorizations to Process the Personal Information in the Company’s or each Company Subsidiary’s possession or under its control in the manner in which it is Processed by the Company and the Company Subsidiaries; (ii) the Company, and each Company Subsidiary, has entered into all agreements it is required to enter into by Information Privacy and Security Laws ; and (iii) the Company and each Company Subsidiary has posted, in accordance with Information Privacy and Security Laws, privacy policies governing its use of Personal Information on the websites made available by the Company and each Company Subsidiary, those privacy policies accurately describe the Processing of Personal Information collected from users of such website, and the Company and each Company Subsidiary has complied since January 1, 2017 with such privacy policies. Since January 1, 2017, the Company and each Company Subsidiary has implemented and complies, in all material respects, with reasonable internal policies governing the Processing of Personal Information.
(b) The Company and each Company Subsidiary has, since January 1, 2017, implemented and maintains an information security program that, except as would not be material to the Company and the Company Subsidiaries, taken as a whole: (i) complies with applicable Information Privacy and Security Laws; (ii) published policies or notices relating identifies internal and external risks to the Company’s and security of any proprietary or confidential information in its Subsidiaries’ collectionpossession, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of including Personal Information; (iii) terms of monitors and protects Personal Information and all IT Assets against any Contracts unauthorized use, access, interruption, modification or corruption; (iv) implements, monitors, and maintains appropriate, adequate and effective administrative, organizational, technical, and physical safeguards to which control the risks described above in (ii) and (iii); (v) is described in a written data security plan; (vi) assesses the Company’s and each Company and/or any of its Subsidiaries are boundSubsidiary’s data security practices, programs and risks; and (ivvii) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any maintains incident response and notification procedures in compliance with applicable Information Privacy and Security Laws. To the Company’s knowledgeThe Company and each Company Subsidiary takes, neither and has since January 1, 2017 taken, reasonable steps to ensure that any Personal Information Processed by authorized third parties acting on behalf of the Company nor or any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Company Subsidiary provides similar safeguards consistent with applicable Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable stepsSince January 1, materially compliant with applicable Privacy Requirements2017, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries there has experienced any failures; crashes; security incidents; data breaches; been no unauthorized access, use, acquisition or disclosure; or other adverse events or incidents related to disclosure as would constitute a “breach” (as defined under HIPAA) of the Personal Information of more than 500 individuals (per incident) that would require notification of individualsis owned, law enforcementused, any Governmental Entitystored, customers, vendors, received or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, controlled by or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any Company Subsidiary. Except as set forth in Section 3.20(c) of its Subsidiariesthe Company Disclosure Letter, includingthe Company and each Company Subsidiary has identified, without limitationdocumented, contract research organizations investigated, contained and clinical investigatorsremediated each material breach of the security of any IT Asset or Personal Information of which the Company has knowledge.
(d) Since January 1, 2017, there have been no material Judgments or Proceedings pending or, to be bound the knowledge of the Company, threatened against the Company or any Company Subsidiary or its “workforce” (as defined under HIPAA) by contractual terms relating to any person or by or before any Governmental Entity for: (i) a violation of any applicable Information Privacy and Security Laws; (ii) any alleged “breach” (as defined in 45 C.F.R. § 164.402); or (iii) the protection and Company’s or any Company Subsidiary’s Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(fe) To Since January 1, 2017, none of the Company Material Contracts has required the Company or Company Subsidiaries to physically separate data of one customer from that of another customer. The (i) Processing of Personal Information in connection with the Transactions and (ii) execution, delivery and performance of this Agreement and the other agreements and instruments contemplated hereby, and the consummation of the Transactions, comply with the Company’s knowledgeand each Company Subsidiary’s applicable privacy notices and policies and, the Personal in all material respects, with applicable Information in the possession, custody, and/or control of the Privacy and Security Laws. The Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially Company Subsidiary shall continue to have at least the same rights to use, process and disclose Personal Information immediately after Closing as currently used by the applicable Company and its applicable Subsidiariesor Company Subsidiary had immediately before the Closing.
Appears in 1 contract
Privacy and Data Security. (a) The Company operation of the Company’s and its Subsidiaries are, and at all times in the past three years have been, Subsidiaries’ business are in compliance in all material respects with all Data Protection Regulations, except to the extent that such noncompliance has not and would not have a Company Material Adverse Effect. Since January 1, 2021, there have been (i) no Security Incidents impacting Personal Data or any confidential information or Trade Secrets used in the business of the Company or its Subsidiaries (collectively, “Company Sensitive Data”), (ii) no violations of any security policy of the Company or its Subsidiaries regarding any such Company Sensitive Data and (iii) no unintended or improper disclosure of any Company Sensitive Data in the possession, custody or control of the Company or its Subsidiaries or a contractor or agent acting on behalf of the Company or its Subsidiaries, in each case of (i) through (iii), except as would not have a Company Material Adverse Effect. Between January 1, 2021 and the date hereof, none of the Company or its Subsidiaries has received any written notice from a vendor or data processor that processes Company Sensitive Data on behalf of the Company or any of its Subsidiaries with respect to a Security Incident materially impacting Company Sensitive Data.
(b) Each of the Company and its Subsidiaries has complied, and continues to comply, with applicable Information Privacy Data Protection Regulations, including with (i) binding principles relating to processing Personal Data, (ii) requirements to process Personal Data lawfully, (iii) contractual requirements applicable to the engagement of data processors processing Personal Data on behalf of the Company and Security Lawsits Subsidiaries, (iv) requirements to provide adequate security measures to protect Personal Data, (v) regulatory notification obligations to the extent required by applicable Data Protection Regulations, (vi) conduct of appropriate data privacy impact assessments to the extent required by applicable Data Protection Regulations, and (vii) provisions related to lawful cross-border data transfers of Personal Data, except, in each case, as would not have a Company Material Adverse Effect.
(c) Each of the Company and its Subsidiaries has implemented, and regularly assessed its implementation of, commercially reasonable physical, technical and organizational measures necessary to ensure that Personal Data is protected against loss, destruction and damage, unauthorized access, use, modification, disclosure or other misuse, except as would not have a Company Material Adverse Effect.
(i) None of the Company or its Subsidiaries transfers Personal Data outside of a country of origin of the Personal Data unless the Company or such Subsidiary, as applicable, has ensured, if required by applicable Data Protection Regulations, that the recipient has adequate safeguards to protect such Personal Data in compliance with applicable Data Protection Regulations and has complied with all applicable transfer provisions of Data Protection Regulations, including consent of individuals where necessary; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) where any transfers of Personal InformationData outside the European Economic Area or the United Kingdom formerly relied upon the EU-US or Swiss-US Privacy Shield framework, the Company or such Subsidiary, as applicable, has ensured that the Personal Data transfers are lawful through an alternative mechanism or derogation in accordance with the GDPR; (iii) terms of any Contracts to which where required by applicable Data Protection Regulations, the Company and/or any or such Subsidiary, as applicable, has conducted a risk assessment regarding the transfer of its Subsidiaries Personal Data pursuant to standard contractual clauses or binding corporate rules or other requirements and has concluded that such transfers are boundadequately protected; and (iv) none of the Company or its Subsidiaries has suspended or terminated a transfer of Personal Data or notified a supervisory authority due to any concerns regarding a transfer of Personal Data pursuant to standard contractual clauses or binding corporate rules and, to the Company’s Knowledge, nor are there circumstances which reasonably justify such a notification, except in each case of clauses (i), (ii), (iii) and (iv), as would not have a Company Material Adverse Effect.
(i) Each of the Company and its Subsidiaries has implemented and maintained commercially reasonable measures and policies to protect the integrity, continuous operation and security of the IT Systems of the Company and its Subsidiaries and the data stored thereon, including from Harmful Code; (ii) the IT Systems used in the business of the Company and its Subsidiaries operate and perform in all respects as required to permit the Company and its Subsidiaries to conduct their business as currently conducted; and (iii) the Company and its Subsidiaries have implemented commercially reasonable backup and disaster recovery technology and procedures consistent with standard practices applicable to entities similarly situated as the Company and its Subsidiaries for the industry standards and/or codes-of-conduct to in which the Company and/or and its Subsidiaries operate in each applicable jurisdiction in which they conduct business and have acted in material compliance therewith, except, in each case of clauses (i), (ii) and (iii), as would not have a Company Material Adverse Effect. Since January 1, 2021, the IT Systems of the Company and its Subsidiaries have not malfunctioned or failed, or been subject to any Security Incident that has caused or, to the Company’s Knowledge, would reasonably be expected to cause (A) material disruption of or interruption in the conduct of the business of the Company and its Subsidiaries as presently conducted; (B) material loss, destruction, damage or harm of the Company and its Subsidiaries or any of the businesses of the Company and its Subsidiaries; or (C) material liability of any kind to the Company and its Subsidiaries or their business as currently conducted, except in each case of clauses (A), (B) and (C), as would not have a Company Material Adverse Effect.
(f) Between January 1, 2021 and the date hereof, none of the Company or its Subsidiaries has been notified in writing of, and, to the Company’s Knowledge, there has not been, (i) an actual or threatened Security Incident materially compromising, or threatening to materially compromise, the processing of Personal Data (whether by the Company or any of its Subsidiaries are legally bound or, to the Company’s Knowledge, any data processor engaged to process Personal Data on behalf of the Company or its Subsidiaries) or (ii) any action or any circumstance requiring the Company or any of its Subsidiaries to notify a Governmental Entity or any individual to comply with applicable notification requirements of Data Protection Regulations as a direct result of a Security Incident or a violation of any Data Protection Regulations.
(g) Between January 1, 2021 and the date hereof, none of the Company or its Subsidiaries has received a written notice or allegation of any actual or alleged or, to the Company’s Knowledge, threatened Security Incident compromising or revealing a material weakness in the security of Personal Data or IT Systems of the Company and its Subsidiaries, or any other material breach of the Data Protection Regulations relating to Personal Data while in its possession or under its control.
(h) Between January 1, 2021 and the date hereof, none of the Company or its Subsidiaries has received a written claim, complaint, allegation or other notice of a dispute or violation (whether directly or indirectly) from or on behalf of an individual regarding the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)Data processing activities.
(bi) Neither Between January 1, 2021 and the date hereof, none of the Company nor any of or its Subsidiaries has received any subpoenas, demands, or other a written notices notice from any supervisory authority or Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledgeinvestigation, neither the Company nor any of inquiry, request for information or for co-operation regarding its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security LawsPersonal Data processing activities.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 1 contract
Sources: Merger Agreement (SomaLogic, Inc.)
Privacy and Data Security. (a) The With respect to Personally Identifiable Information directly collected by any Acquired Company, no such Personally Identifiable Information has been collected, stored, used, processed, disclosed, or transferred (including across national borders) by any Acquired Company and its Subsidiaries arein violation of any applicable Laws. Since January 1, and at all times in 2015, excluding the past three years have beenUSEU Privacy Shield Registration, in compliance each Acquired Company has complied in all material respects with all (i) applicable Information Privacy and Security Laws; (ii) externally published policies or notices privacy policy statements relating to the Company’s and its Subsidiaries’ collection, storage, use, storageprocessing, disclosure, or transfer (including transfer across national borders), of any Personally Identifiable Information used by any Acquired Company. Since September 30, 2016, each Acquired Company has complied in all material respects with the USEU Privacy Shield Registration. Each Acquired Company has appropriate contracts to obligate its customers to comply with applicable Laws with respect to the collection, storage, use, processing, handlingdisclosure, protection, or cross-border and transfer (“Processing”including transfer across national borders) of Personal Information; (iii) terms such information, including Personally Identifiable Information and/or the provision of such Personally Identifiable Information to any Contracts Acquired Company for purposes of providing Customer Offerings to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)such customer.
(b) Neither Buyer has been provided with copies of all current externally published privacy policies that apply to the Company nor any collection, storage, use, processing, disclosure, and transfer (including transfer across national borders) of its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security LawsPersonally Identifiable Information.
(c) The Company and its Subsidiaries have each taken commercially reasonable stepsExcept as set forth on Schedule 2.17(c), materially compliant with applicable Privacy Requirementssince January 1, designed to protect (i) the operation2015, confidentialitythere has been no material incident of unauthorized access to, integrityacquisition of, and security or other misuse of the such Personally Identifiable Information within any Acquired Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modificationcontrol.
(d) To Since January 1, 2015, no person, company, advocacy organization, government entity, or other third party has made any complaint directly to any Acquired Company or claim, or commenced any action, investigation, or inquiry relating to any Acquired Company’s information privacy, data security, or data protection practices, or to the Company’s knowledgeknowledge threatened any such complaint, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized accessclaim, useaction, investigation, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidentsinquiry.
(e) To Since January 1, 2015, all Acquired Companies have been in material compliance with all aspects of the extent required Payment Card Industry Data Security Standards applicable to the Acquired Companies (“PCI-DSS”) published by applicable Information Privacy the PCI Security Standards Council, as they have been amended and Security Lawsupdated from time to time. The Acquired Companies have been in material compliance with PCI DSS v3.2 from the time such standard was published in April 2016. Since January 1, the Company and each of its Subsidiaries 2015, all Acquired Companies have obligated been in compliance with all of their applicable vendors respective merchant agreements with all credit and data processors authorized to debit card companies that process Personal Information on behalf of transactions for the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligationsAcquired Companies.
(f) To Schedule 2.17(f) sets forth a complete list of the Company’s knowledgedata security and/or data privacy certifications, attestations, laws, regulations, alignments and/or frames works to which any Acquired Company has committed, whether by public statement, self-certification, government filing and/or contract (e.g., ISO 27001, PCI-DSS, PCI PA-DSS, SOC 1, SOC 2, SOC 3, EU-US Privacy Shield, EU Model Clauses, Gramm L▇▇▇▇ B▇▇▇▇▇ (GLB), the Personal Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), United States National Institute of Standards and Technology publications (NIST), and International Traffic in Arms Act).
(g) This Section 2.17 and Section 2.09 contain the possession, custody, and/or control sole and exclusive representations and warranties of Seller with respect to the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated matters covered by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable SubsidiariesSection 2.17.
Appears in 1 contract
Sources: Share Purchase Agreement (Liberated Syndication Inc.)
Privacy and Data Security. (a) The a. In connection with the Company’s and any Company Subsidiary’s collection, use, disclosure, storage and other processing of Personal Data, the Company and its Subsidiaries are, any Company Subsidiary have (i) in all material respects and at all times in during the past three (3) years have beencomplied with all applicable Data Protection Legislation in all relevant jurisdictions and with all contractual obligations to which the Company or any Company Subsidiary are bound, in compliance as applicable, and (ii) implemented privacy and security policies, practices and procedures for the collection, processing, use, transfer, disclosure, access and protection of Personal Data that comply with all applicable Data Protection Legislation in all material respects with respects.
b. With respect to all (i) applicable Information Privacy Personal Data and Security Laws; (ii) published policies other data collected, stored, used or notices relating maintained by or for the Company or any Company Subsidiary, each of the Company and each Company Subsidiary has used commercially reasonable efforts to protect the Personal Data and other data against loss and against unauthorized access, use, modification, disclosure or other misuse, and, to the Knowledge of the Company’s , there has been no material unauthorized access to, or unauthorized manipulation, erasure, processing, use or disclosure of, any data (including Personal Data) owned, used, stored, received, or controlled by the Company, any Company Subsidiary (or, to the Knowledge of the Company, any service provider in the course of providing services for or on behalf of the business of the Company or any Company Subsidiary). A copy of the most recent internally or externally prepared reports or audits that describe or evaluate the information security procedures of the Company and its Subsidiaries’ the Company Subsidiaries have been made available to Parent. The Company and the Company Subsidiaries implement and maintain, consistent with industry standard practices, commercially reasonable disaster recovery plans and procedures designed to protect the integrity and availability of all data and all Business IT Systems. To the Knowledge of the Company, no circumstance has arisen in the last three (3) years in which Data Protection Legislation would require the Company or any Company Subsidiary to notify a person or Governmental Entity of a data security breach or similar security incident. None of the Company or any Company Subsidiary has been or is currently under audit or investigation by any Governmental Entity, including regarding protection, storage, collection, use, storage, disclosure, processingprocessing and transfer of Personal Data.
c. In the past three (3) years, handling, protection, or cross-border transfer (“Processing”except as set forth in Section 3.18(c) of Personal Information; (iii) terms of any Contracts to which the Company and/or any Disclosure Schedule, none of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries Subsidiary has received any subpoenas, demands, or other written notices notice from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation Person of any Information Privacy lawsuits, investigations, legal claims or material complaints regarding its collection, storage, transfer, maintenance and Security Laws. use of any Personal Data or for a breach of applicable Data Protection Legislation.
d. To the Knowledge of the Company’s knowledge, neither the Company nor any of its Subsidiaries is under investigation by Company Subsidiary has disclosed, made accessible or transferred any Governmental Entity or other entity Personal Data, even for transit purposes, to any actual or potential violation of any Information Privacy and Security Laws.
(c) The Company and its Subsidiaries have each taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) third party outside the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing country where the Company or any of Company Subsidiary is established or where its Subsidiaries in connection with any Personal Data is collected from, if such failures; crashes; security incidents; data breaches; unauthorized accessdisclosure, useaccessibility or transfer is prohibited by applicable Data Protection Legislation. If such disclosure, accessibility, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Lawstransfer is not prohibited, the Company and each of its the Company Subsidiaries have obligated all of their implemented reasonable measures and guarantees designed to ensure the disclosure, accessibility, or transfer in compliance with applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligationsData Protection Legislation.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 1 contract
Sources: Merger Agreement (ZAGG Inc)
Privacy and Data Security. Except as would not, individually or in the aggregate, have or reasonably be expected to have a Company Material Adverse Effect:
(a) The Company and its the Company Subsidiaries arehave since January 1, and at all times in the past three years have been, in compliance in all material respects 2022 complied with all applicable (i) applicable Information Privacy and Data Security Laws; , (ii) published policies or notices relating written public policies, notices, and/or statements related to the Company’s Personal Information and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating contractual commitments related to the Company’s or any of its Subsidiaries’ Processing processing of Personal Information (collectively, “Company Privacy Requirements”). Company and the Company Subsidiaries have all lawful bases, authorizations, rights, consents, permissions, data processing agreements and data transfer agreements and have provided all notices as required under Privacy and Data Security Laws to Process the Company Data in Company’s or any of the Company Subsidiaries’ possession or under its or their respective control. Since January 1, 2022, Company and the Company Subsidiaries have performed security risk assessments to the extent required by the Company Privacy Requirements and addressed and fully remediated all material threats and deficiencies identified in those security risk assessments.
(b) Neither Company and the Company nor any Subsidiaries have established an information security program that both includes reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, availability, and integrity of all Company Data and Company IT Systems and is appropriately implemented and maintained, and there have been no material violations of such information security program. Company has assessed its Subsidiaries has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any Information Privacy and Security Laws. To the Company’s knowledge, neither the Company nor any of its Subsidiaries’ information security program, which has proven compliant with Company Privacy Requirements in all material respects. All Personal Information and Company Data will continue to be available for Processing by Company and the Company Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy following the Closing Date on substantially the same terms and Security Lawsconditions as existed immediately before the Closing Date.
(c) The Company and its each Company Subsidiary have at all times since January 1, 2022 used their commercially reasonable efforts to implement and maintain, commercially reasonable measures to protect Personal Information against any Security Incident. Since January 1, 2022, neither Company nor any Company Subsidiary has experienced a Security Incident, and neither Company nor any Company Subsidiary is currently investigating a potential Security Incident. In relation to any Security Incident and/or Company Privacy Requirement, none of Company or the Company Subsidiaries, have been notified or been required to notify any Person under Privacy and Data Security Laws. Since January 1, 2022, none of Company or any of the Company Subsidiaries have each taken commercially reasonable stepsreceived any written notice, materially compliant claim, or complaint, or been the subject of any investigation or enforcement action by, any Person with applicable Privacy Requirements, designed respect to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, . The Company and (ii) Company Subsidiaries also require third parties processing Personal Information in the Company’s on behalf of Company or any Company Subsidiary or otherwise receiving from, or sharing with, Company or a Company Subsidiary to comply in all material respects with applicable Privacy and Data Security Laws and for these third parties to timely notify the Company or the Company Subsidiaries of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modificationany Security Incident that affects the Company IT Systems.
(d) To The Company IT Systems are configured in accordance with, and perform, and have at all times since January 1, 2022, performed, in compliance with industry standards. The Company IT Systems have been maintained in accordance with standards set by the manufacturers or otherwise in accordance with standards prudent in the industry, to ensure proper operation, monitoring and use. The Company IT Systems (i) are in good repair and operating condition to effectively perform all information technology operations necessary to conduct Company’s knowledgeand the Company Subsidiaries’ business, neither (ii) do not contain any viruses or other computer code intentionally designed to disrupt, disable, or harm in any manner the operation of, or to provide unauthorized access to, any Company IT System, and (iii) do not contain unauthorized code. There has not been since January 1, 2022 any error, failure, breakdown, security breach or continued substandard performance of any Company IT Systems that has caused a material disruption or interruption in or to the operation of Company’s business. Company and the Company Subsidiaries have implemented and tested reasonable backup, security and disaster recovery technology, plans, procedures and facilities consistent with industry practice. Neither Company nor any of its the Company Subsidiaries has experienced is in breach in any failures; crashes; security incidents; data breaches; unauthorized access, usematerial respect of any contract relating to any Company IT System, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations event that, with the passage of such contractual obligationstime or the giving of notice, or both, would constitute a breach in any material respect of any contract relating to any Company IT System.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 1 contract
Sources: Agreement and Plan of Merger (NorthStar Healthcare Income, Inc.)
Privacy and Data Security. (a) Except as set forth in section 4.13 of the Disclosure Schedule, in the collection, use, storage and Processing (including transfer to a third party or to any jurisdiction, to the extent applicable) by the Company or any of its Subsidiaries of any Personal Data, the Company or such Subsidiarity, its Personal Data Processors and, to the Company’s Knowledge, its Personal Data Suppliers have complied in all material respects with applicable Information Privacy Laws, the Privacy Policies of the Company or any of its Subsidiaries and, to the extent obligated by contract to do so, the Privacy Policies of Personal Data Suppliers. The Company and its Subsidiaries arehave taken commercially reasonable measures to prevent unauthorized use, access or alteration of Personal Data in their possession or control, which measures are in material compliance with applicable Information Privacy Laws and at all times in Privacy Policies. Without limiting the past three years have beenforegoing, in compliance in all material respects with all (i) applicable Information Privacy the Company and Security Laws; (ii) published policies or notices relating its Subsidiaries and, to the Company’s Knowledge, its Personal Data Suppliers have provided, and its Subsidiaries’ collectionin such manner as required under applicable Information Privacy Laws, adequate notices to and acquired all necessary consents from Data Subjects for the use, storageand Processing (including transfer to a third party of any jurisdiction, disclosure, processing, handling, protection, or cross-border transfer (“Processing”to the extent applicable) of all Personal Information; (iii) terms of any Contracts to which Data Processed by the Company and/or or any of its Subsidiaries are bound; and otherwise have all requisite legal authority to Process, use and hold (ivincluding transfer to a third party of any jurisdiction, to the extent applicable) industry standards and/or codes-of-conduct to which Personal Data in the Company and/or manner it is now Processed by the Company, any of its Subsidiaries are legally bound relating or any Personal Data Processor on behalf of the Company or any of its Subsidiaries and (ii) with respect to all Personal Data in the databases owned or licensed by the Company or its Subsidiary, the Company, its Subsidiaries and, to the Company’s Knowledge, its Personal Data Suppliers have provided, where and in such manner as required under applicable Information Privacy Laws, adequate disclosures and notices, requisite consents from Data Subjects and have sufficient legal ground under applicable law to Process such Personal Data in the manner it is now Processed by the Company or its Subsidiary or any Personal Data Processor on behalf of its Subsidiaries’ Processing the Company, including transfer to a third party of Personal Information (collectivelyany jurisdiction, “Privacy Requirements”to the extent applicable).
(b) Neither To the extent that the Company nor or any of its Subsidiaries has received Processes any subpoenasfinancial account numbers (such as credit cards, demandsbank accounts, PayPal accounts, debit cards), passwords, CCV data, or other written notices from related data (“Cardholder Data”), the Company and/or each of its Subsidiaries as applicable has implemented information security procedures, processes and systems that have at all times met or exceeded all applicable Laws related to the Processing of Cardholder Data, including those established by applicable Governmental Authorities, and the Payment Card Industry Standards Council (including the Payment Card Industry Data Security Standard).
(c) Each of the Company and its Subsidiaries has at all times made available, where and in such manner as required under applicable Information Privacy Laws, a Privacy Policy which materially complies with applicable Information Privacy Laws to Persons (including any Governmental Entity or other entity investigating, inquiring into, or otherwise relating Data Subjects) prior to any actual or potential violation and during the collection of any Information Personal Data online. Such Privacy Policy, and Security Lawsany other representations, marketing materials and advertisements that address privacy issues and the treatment of Personal Data, accurately and completely describe, in a timely manner in accordance with applicable Law, the Company’s or its Subsidiaries’, as applicable, information collection and use practices, including reasonable safeguards in place designed to protect the privacy, security, and integrity of all Personal Data, and no such notices or disclosures have been misleading or deceptive or, to the Knowledge of the Company, inaccurate. To the Knowledge of the Company’s knowledge, neither the Company nor any of its Subsidiaries is has collected or received any Personal Data online from children under investigation by the age of 16 without verifiable parental consent or directed any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Lawsits websites to children under the age of 16 through which such Personal Data could be obtained.
(cd) Other than as set forth on Section 4.13(d) of the Disclosure Schedule, none of the Company or its Subsidiaries sells, rents or otherwise makes available to any Person any Personal Data, except in a manner that complies in all material respects with the applicable Privacy Policies and in compliance with Information Privacy Laws. The execution, delivery and performance of this Agreement and the transactions contemplated herein, including any transfer of Personal Data resulting from the execution, delivery and performance of this Agreement, complies, and will comply with, all Information Privacy Laws, the Privacy Policy of the Company and its Subsidiaries, and, to the extent obligated by contract to do so, the Privacy Policies of Personal Data Suppliers. Following the Closing Date, the Company and its Subsidiaries will continue to be permitted to collect, store, use and disclose Personal Data held by the Company or its Subsidiaries on terms identical to those in effect as of the date of this Agreement and to the same extent they would have been able to had the transactions contemplated by this Agreement not occurred.
(e) None of the Company and its Subsidiaries has received any written notice that it is or has been in material breach of any contractual obligation to limit its use of, secure or otherwise safeguard Personal Data, including any allegation that there has been a material breach of any Business Associate Agreement (i.e., a “business associate contract” as described under HIPAA at 45 C.F.R. § 164.504(e)) to which the Company or any of its Subsidiaries is a party, the EU General Data Protection Regulation, any data protection agreement (including standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC of the European Parliament and of the Council or any equivalent of successor thereof) to which the Company or any of its Subsidiaries is a party or of any violation by the Company or any of its Subsidiaries of their commitments under the EU-US Privacy Shield (as applicable), and, to the Company’s Knowledge, no such breach or violation has occurred within the applicable statute of limitation for a claim arising out of such a breach or violation. The Company and its Subsidiaries have each taken in place and follows commercially reasonable steps, materially compliant with applicable Privacy Requirements, procedures designed to protect (i) ensure that all written contracts with Confidential Data Processors require that such Confidential Data Processor Process Data in compliance with the operationInformation Privacy Laws, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modificationPrivacy Policy and the Company’s or its Subsidiaries’ obligations under any contract that governs the Processing of any Confidential Data.
(df) To Except as set forth on Section 4.13(f) of the Company’s knowledgeDisclosure Schedule, (i) neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized accessaccess to, usedisclosure, or disclosure; deletion or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcementmisuse of, any Governmental EntityPersonal Data in its possession or control (a “Security Incident”) or made or been required to make any disclosure, customers, vendors, notification or take any others other action under any applicable Information Privacy RequirementsLaws in connection with any Security Incident, (ii) no Confidential Data Processor has experienced any Security Incident or made or been required to make any disclosure, notification or take any other action under any applicable Information Privacy Laws in connection with any Security Incident with respect to any Personal Data Processed by it for the Company or for any of its Subsidiaries, (iii) to the Company’s Knowledge, no Personal Data Supplier has experienced any Security Incident or made or has been required to make any disclosure, notification or take any other action under any applicable Information Privacy Laws in connection with any Security Incident with respect to any Personal Data provided by it to the Company or to any of its Subsidiaries. The Company and each of its Subsidiaries has not received written notice of any complaintsmade all notifications to Data Subjects, Actions, fines, customers or other penalties facing individuals required to be made by the Company or any of its Subsidiaries in connection with (as applicable) under any such failures; crashes; security incidents; data breaches; applicable Information Privacy Laws arising out of or relating to any event of unauthorized access, use, access to or disclosure; disclosure or other adverse events or incidentsacquisition of any Personal Data by any person of which the Company has Knowledge.
(eg) To No action, audit, assessment, suit, legal proceeding, investigation, administrative enforcement proceeding or arbitration proceeding before any court, administrative body or Governmental Authority has been filed or commenced against the extent required by applicable Company, any of its Subsidiaries or, to the Company’s Knowledge, threatened against the Company or its Subsidiaries, alleging any failure to comply with any Information Privacy and Security Laws, and the Company and each of its Subsidiaries has not incurred any material liabilities under any Information Privacy Laws. To the Company’s Knowledge, no Action has been filed, commenced or threatened against any Personal Data Supplier or Confidential Data Processor with respect to any Personal Data supplied to or Confidential Data Processed for the Company and each of its Subsidiaries.
(h) The Company, its Subsidiaries and its third-party service provider(s), if applicable, have obligated all implemented appropriate technical and organizational security measures to protect the confidentiality, integrity and security of their applicable vendors the IT Assets (and data processors authorized to process Personal Information on behalf of information stored or contained therein or transmitted thereby) against unauthorized use, access, disclosure, loss, destruction, interruption, modification or corruption.
(i) In the Processing by the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledgePersonal Data, the Personal Information in the possession, custody, and/or control each of the Company and each its Subsidiaries, its Confidential Data Processors and, to the Company’s Knowledge, its Personal Data Suppliers has materially complied with all applicable Information Privacy Laws and applicable codes of practice in relation to marketing, advertising and profiling activities, as well as the placing of cookies on the Company’s or its Subsidiaries can be transferred Subsidiaries’ websites, including providing any notices an disclosures and obtaining any consents as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its necessary under applicable SubsidiariesLaws.
Appears in 1 contract
Privacy and Data Security. (a) The Company and each of its Subsidiaries areand, to the Knowledge of the Company with respect to the Processing of Company Data, their Data Processors, comply and have complied with all Privacy Requirements, in each case except as would not reasonably be expected to be, individually or in the aggregate, material to the Company and its Subsidiaries, taken as a whole. To the extent required by Privacy Requirements or Company Privacy Policies, Personal Data is securely deleted or destroyed by Company and each of its Subsidiaries. Neither the execution, delivery or performance of this Agreement nor any of the other agreements contemplated by this Agreement, nor the consummation of any of the transactions contemplated by this Agreement or any such other agreements violate any Privacy Requirements or Company Privacy Policies. Where the Company or its Subsidiaries use a Data Processor to Process Personal Data, the Data Processor has provided guarantees, warranties or covenants in relation to Processing of Personal Data, confidentiality, and at all times security measures, and has agreed to comply with those obligations in a manner sufficient for the past three years have been, in Company’s and each of its Subsidiaries’ compliance in all material respects with all Privacy Requirements. Since December 31, 2018, the Company and its Subsidiaries have not: (i) applicable Information Privacy and experienced any Security LawsIncident; or (ii) published policies been subject to or notices relating to the Company’s and its Subsidiaries’ collectionreceived any notice (including any enforcement notice) of any audit, useinvestigation, storage, disclosure, processing, handling, protectioncomplaint, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of other legal action by any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to Governmental Entity or other Person concerning the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectivelycollection, “Privacy Requirements”).
(b) Neither the Company nor any of its Subsidiaries has received any subpoenasuse, demandsprocessing, storage, transfer, or other written notices from any Governmental Entity protection of personal information or other entity investigatingactual, inquiring intoalleged, or otherwise relating to any actual or potential suspected violation of any Information Privacy Requirement, and Security Laws. To to the Knowledge of the Company’s knowledge, neither there are no facts or circumstances that could reasonably be expected to give rise to any such legal action, in each case except as could not reasonably be expected to be, individually or in the Company nor any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Laws.
(c) The aggregate, material to the Company and its Subsidiaries have each Subsidiaries, taken commercially reasonable steps, materially compliant with applicable Privacy Requirements, designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirementsas a whole. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all are not in material breach of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms Contracts relating to the protection Company IT Systems or to Company Data and Processing of do not transfer Personal Information; Data internationally except where such transfers comply with Privacy Requirements and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Privacy Policies. The Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreementmaintain, and can be used after have maintained for the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiarieslast five (5) years, cyber liability insurance with reasonable coverage limits.
Appears in 1 contract
Sources: Merger Agreement (SharpSpring, Inc.)
Privacy and Data Security. (a) The Company Each Seller and its Subsidiaries are, and at all times each subsidiary of Seller is in the past three years have been, in material compliance in all material respects with all (i) applicable Information Privacy and Security Laws; (ii) published policies or notices relating Data Protection Requirements related to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)Data in connection with the conduct of the Business. Each Seller and each of their Subsidiaries has maintained all Personal Data in its possession or control in the country of collection.
(b) Neither No Seller or its subsidiary has in the Company nor any of its Subsidiaries has past three (3) years (and, with respect to the Telephone Consumer Protection Act and other similar Laws, in the past four (4) years) received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise seeking information relating to any actual or potential violation of any Information Privacy and Security Laws. To Data Protection Requirement in connection with the Company’s knowledgeProcessing of Personal Data related to the conduct of the Business, neither and, to the Company nor any Knowledge of the Sellers, no Seller or its Subsidiaries subsidiary is under investigation by any Governmental Entity or other entity for any actual or potential violation of any Information Privacy and Security Lawsapplicable Data Protection Requirement with respect to the Business. No notice, complaint, claim, enforcement action, or litigation of any kind has been served on, or, to the Knowledge of the Sellers, initiated against any Seller or its subsidiaries for any material violation of any applicable Data Protection Requirement.
(c) The Company Each Seller and its Subsidiaries have each taken subsidiary of Seller currently maintains and, for the last three (3) years has maintained, commercially reasonable steps, materially compliant with applicable Privacy Requirements, security measures designed to protect (i) the operation, confidentiality, integrity, and security of the Company’s Business Data in their possession and its Subsidiaries’ softwarecontrol and the Business Products from unauthorized access, systemsacquisition, destruction, or other misuse. Such measures comply in all material respects with applicable Data Protection Requirements and websites (“IT Assets”) that are involved include notification procedures in compliance in all material respects with applicable Data Protection Requirements in the Processing case of Personal Informationany Security Incident, and (ii) Personal Information in each case, with respect to the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modificationBusiness.
(d) To In the Company’s knowledgepast three (3) years, to the Knowledge of the Sellers, (i) neither the Company Sellers nor any of its Subsidiaries has their subsidiaries have experienced any failures; crashes; material security breaches or similar incidents; data breaches; , or any unauthorized access, useuse or disclosure of Personal Data Processed by the Sellers or any of their subsidiaries in the conduct of the Business (each, or disclosure; or other adverse events or incidents related to Personal Information a “Security Incident”) that would require notification of the Sellers or their subsidiaries to notify individuals, law enforcement, or any Governmental EntityEntity or to take any remedial action, customersin each case, vendors, or any others under any applicable Privacy Data Protection Requirements. The Company ; and (ii) neither the Sellers, their Affiliates, nor any Person acting on their behalf has not received written notice paid, or caused to be paid, any perpetrator of any actual or threatened Security Incident, including a ransomware attack or a denial-of-service attack in relation to the Business (including systems used in relation to or in connection with Business Data). None of the Sellers or their subsidiaries, in each case, in the conduct of the Business, is the subject of any pending complaints, Actionsactions, fines, fines or other penalties facing the Company or any of its Subsidiaries in connection with any resulting from such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidentsSecurity Incident.
(e) To Neither the extent required by applicable Information Privacy execution, delivery, or performance of this Agreement or the other operative documents nor the consummation of the transactions contemplated in this Agreement or the other operative documents, or the transfer of any or all Personal Data to Purchaser and Security Laws, the Company and each Purchaser’s use of its Subsidiaries have obligated any or all of their applicable vendors and data processors authorized to process such Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information Data in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred same manner as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as Sellers currently used by the Company and its applicable Subsidiariesuse such Personal Data will violate any Data Protection Requirements.
Appears in 1 contract
Sources: Asset Purchase Agreement (Progress Software Corp /Ma)
Privacy and Data Security. (a) The There has not been any material data security breach of any IT Assets or material unauthorized access, use, loss or disclosure of any Personal Information owned, used, maintained, received, or controlled by or on behalf of the Company and its Subsidiaries areor any Company Subsidiary including any unauthorized access, and at all times in the past three years have been, in compliance in all material respects with all (i) use or disclosure of Personal Information that would constitute a breach for which notification to individuals or Governmental Authorities is required under any applicable Information Privacy and Security Laws; (ii) published policies Laws or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or or any Company Subsidiary is a party. The execution, delivery and performance of its Subsidiaries are bound; this Agreement and (iv) industry standards and/or codes-of-conduct to the consummation of the transactions contemplated hereby do not violate in any material respect any applicable Privacy Policy as it currently exists or as it existed at any time during which any Personal Information was collected or obtained by the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Requirements”)Company Subsidiary.
(b) Neither the The Company’s and each Company nor any Subsidiary’s collection, maintenance, transmission, transfer, use, disclosure, storage, disposal and security of its Subsidiaries Personal Information has received any subpoenas, demands, or other written notices from any Governmental Entity or other entity investigating, inquiring into, or otherwise relating to any actual or potential violation of any complied and complies with (i) Information Privacy and Security Laws. To the Company’s knowledge, neither (ii) Contracts to which the Company nor or any of its Subsidiaries Company Subsidiary is under investigation by any Governmental Entity a party that govern that Personal Information, (iii) PCI DSS (if applicable) and (iv) applicable privacy policies or disclosures posted to websites or other entity for media maintained or published by the Company or any actual Company Subsidiary that govern Personal Information processed by the Company or potential violation of any the Company Subsidiary (the “Privacy Policies”). The Company and each Company Subsidiary have a lawful basis and all required authorizations, rights, consents, data processing agreements and data transfer agreements that are required under Information Privacy and Security LawsLaws to receive, access, use and disclose the Personal Information in such entity’s possession or under its control in connection with the operation of the business of such entity. No suit, claim, action, proceeding, arbitration, mediation or, to the Knowledge of the Company, investigation is pending or, to the Knowledge of the Company, threatened in writing against the Company or any Company Subsidiary relating to the processing or security of Personal Information.
(c) The Company and its Subsidiaries have each taken commercially Company Subsidiary has implemented, and is in compliance with, a reasonable steps, materially compliant with applicable Privacy Requirements, designed cybersecurity program to protect (i) the operation, confidentiality, integrity, IT Assets and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modification.
(d) To the Company’s knowledge, neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing processed by the Company or any of its Subsidiaries in connection a Company Subsidiary that complies with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by industry standards and all applicable Information Privacy and Security Laws, the . The Company and each of its Subsidiaries Company Subsidiary have obligated all of their applicable vendors performed reasonable security risk assessments required under Information Privacy and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
Security Laws (f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreementif any), and can be used after the Closing has addressed, in a manner substantially the same as currently used by the Company commercially reasonable fashion and its applicable Subsidiariesin accordance with industry standards, all material threats and deficiencies identified in those security risk assessments.
Appears in 1 contract
Sources: Stock Purchase Agreement (Wanda Sports Group Co LTD)
Privacy and Data Security. (a) The Company Each Seller and its Subsidiaries are(with respect to the Salient JVs, to the Knowledge of the Sellers) materially comply with, and at since January 1, 2019 have materially complied with, all times in the past three years have been, in compliance in all material respects with all (i) applicable Information Privacy and Security Laws; (ii) published policies or notices relating to the Company’s and its Subsidiaries’ collection, use, storage, disclosure, processing, handling, protection, or cross-border transfer (“Processing”) of Personal Information; (iii) terms of any Contracts to which the Company and/or any of its Subsidiaries are bound; and (iv) industry standards and/or codes-of-conduct to which the Company and/or any of its Subsidiaries are legally bound relating to the Company’s or any of its Subsidiaries’ Processing of Personal Information (collectively, “Privacy Data Protection Requirements”).
(b) Neither the Company nor There is no Proceeding pending, and since January 1, 2019, there has not been any Proceeding, against any Seller or any of its Subsidiaries has received (with respect to the Salient JVs, to the Knowledge of the Sellers) by any subpoenas, demands, private party or other written notices from any Governmental Entity or other entity Authority investigating, inquiring into, or otherwise relating to any actual or potential violation of any Data Protection Requirements with respect to the collection, use, retention, disclosure, transfer, storage or disposal of Personal Information Privacy or Business Data and Security Laws. To no notice, complaint, claim, enforcement action, inquiry, audit, or litigation has been served on, or, to the Company’s knowledgeKnowledge of the Sellers, neither the Company nor initiated against any Seller or any of its Subsidiaries is under investigation by any Governmental Entity or other entity for any actual or potential alleging violation of any Data Protection Requirements relating to the Sellers’ or any of their Subsidiaries’ use of Personal Information Privacy and Security Lawsand/or Business Data.
(c) The Company Each Seller and its Subsidiaries have each (with respect to the Salient JVs, to the Knowledge of the Sellers) have, at all times since January 1, 2019, taken commercially reasonable steps, materially steps compliant with applicable Privacy Requirements, Data Protection Requirements that are designed to protect (i) protect the operation, confidentiality, integrity, availability, and security of the Company’s Sellers’ and its their Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing collection and/or processing of Personal Information, and Information and/or Business Data (ii) identify internal and organizational risks to the confidentiality, integrity, security, availability of Personal Information and/or Business Data, taking into account the sensitivity of the data or systems and (iii) maintain notification procedures in compliance with applicable Data Protection Requirements in the Company’s or case of any breach of its Subsidiaries’ possession security compromising Personal Information and/or control from unauthorized use, access, disclosure, deletion, and/or modificationBusiness Data.
(d) To Since January 1, 2019, there have been no material failures, crashes, security incidents, or Data Security Breaches of any of the Company’s knowledgeinformation systems used to store or process Personal Information and/or Business Data, neither the Company nor or otherwise related to Personal Information and/or Business Data that would require (i) notification of individuals, law enforcement or any Governmental Authority or (ii) remedial action under Data Protection Requirements. There are no pending complaints, actions, fines, or other penalties facing any Seller or any of its Subsidiaries has experienced (with respect to the Salient JVs, to the Knowledge of the Sellers) in connection with any such failures; , crashes; , security incidents; data breaches; , unauthorized access, use, or disclosure; or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcement, any Governmental Entity, customers, vendors, or any others under any applicable Privacy Requirements. The Company has not received written notice of any complaints, Actions, fines, or other penalties facing the Company or any of its Subsidiaries in connection with any such failures; crashes; security incidents; data breaches; unauthorized access, use, or disclosure; or other adverse events or incidents.
(e) To the extent required by applicable Information Privacy and Security Laws, the Company and each of its Subsidiaries have obligated all of their applicable vendors and data processors authorized to process Personal Information on behalf of the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledge, the Personal Information in the possession, custody, and/or control of the Company and each of its Subsidiaries can be transferred as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its applicable Subsidiaries.
Appears in 1 contract
Privacy and Data Security. (a) Except as set forth in section 4.13 of the Disclosure Schedule, in the collection, use, storage and Processing (including transfer to a third party or to any jurisdiction, to the extent applicable) by the Company or any of its Subsidiaries of any Personal Data, the Company or such Subsidiarity, its Personal Data Processors and, to the Company’s Knowledge, its Personal Data Suppliers have complied in all material respects with applicable Information Privacy Laws, the Privacy Policies of the Company or any of its Subsidiaries and, to the extent obligated by contract to do so, the Privacy Policies of Personal Data Suppliers. The Company and its Subsidiaries arehave taken commercially reasonable measures to prevent unauthorized use, access or alteration of Personal Data in their possession or control, which measures are in material compliance with applicable Information Privacy Laws and at all times in Privacy Policies. Without limiting the past three years have beenforegoing, in compliance in all material respects with all (i) applicable Information Privacy the Company and Security Laws; (ii) published policies or notices relating its Subsidiaries and, to the Company’s Knowledge, its Personal Data Suppliers have provided, and its Subsidiaries’ collectionin such manner as required under applicable Information Privacy Laws, adequate notices to and acquired all necessary consents from Data Subjects for the use, storageand Processing (including transfer to a third party of any jurisdiction, disclosure, processing, handling, protection, or cross-border transfer (“Processing”to the extent applicable) of all Personal Information; (iii) terms of any Contracts to which Data Processed by the Company and/or or any of its Subsidiaries are bound; and otherwise have all requisite legal authority to Process, use and hold (ivincluding transfer to a third party of any jurisdiction, to the extent applicable) industry standards and/or codes-of-conduct to which Personal Data in the Company and/or manner it is now Processed by the Company, any of its Subsidiaries are legally bound relating or any Personal Data Processor on behalf of the Company or any of its Subsidiaries and (ii) with respect to all Personal Data in the databases owned or licensed by the Company or its Subsidiary, the Company, its Subsidiaries and, to the Company’s Knowledge, its Personal Data Suppliers have provided, where and in such manner as required under applicable Information Privacy Laws, adequate disclosures and notices, requisite consents from Data Subjects and have sufficient legal ground under applicable law to Process such Personal Data in the manner it is now Processed by the Company or its Subsidiary or any Personal Data Processor on behalf of its Subsidiaries’ Processing the Company, including transfer to a third party of Personal Information (collectivelyany jurisdiction, “Privacy Requirements”to the extent applicable).
(b) Neither To the extent that the Company nor or any of its Subsidiaries has received Processes any subpoenasfinancial account numbers (such as credit cards, demandsbank accounts, PayPal accounts, debit cards), passwords, CCV data, or other written notices from related data (“Cardholder Data”), the Company and/or each of its Subsidiaries as applicable has implemented information security procedures, processes and systems that have at all times met or exceeded all applicable Laws related to the Processing of Cardholder Data, including those established by applicable Governmental Authorities, and the Payment Card Industry Standards Council (including the Payment Card Industry Data Security Standard).
(c) Each of the Company and its Subsidiaries has at all times made available, where and in such manner as required under applicable Information Privacy Laws, a Privacy Policy which materially complies with applicable Information Privacy Laws to Persons (including any Governmental Entity or other entity investigating, inquiring into, or otherwise relating Data Subjects) prior to any actual or potential violation and during the collection of any Information Personal Data online. Such Privacy Policy, and Security Lawsany other representations, marketing materials and advertisements that address privacy issues and the treatment of Personal Data, accurately and completely describe, in a timely manner in accordance with applicable Law, the Company’s or its Subsidiaries’, as applicable, information collection and use practices, including reasonable safeguards in place designed to protect the privacy, security, and integrity of all Personal Data, and no such notices or disclosures have been misleading or deceptive or, to the Knowledge of the Company, inaccurate. To the Knowledge of the Company’s knowledge, neither the Company nor any of its Subsidiaries is has collected or received any Personal Data online from children under investigation by the age of 16 without verifiable parental consent or directed any Governmental Entity of its websites to children under the age of 16 through which such Personal Data could be obtained. 50
(d) Other than as set forth on Section 4.13(d) of the Disclosure Schedule, none of the Company or other entity for its Subsidiaries sells, rents or otherwise makes available to any actual or potential violation of Person any Personal Data, except in a manner that complies in all material respects with the applicable Privacy Policies and in compliance with Information Privacy Laws. The execution, delivery and Security performance of this Agreement and the transactions contemplated herein, including any transfer of Personal Data resulting from the execution, delivery and performance of this Agreement, complies, and will comply with, all Information Privacy Laws, the Privacy Policy of the Company and its Subsidiaries, and, to the extent obligated by contract to do so, the Privacy Policies of Personal Data Suppliers. Following the Closing Date, the Company and its Subsidiaries will continue to be permitted to collect, store, use and disclose Personal Data held by the Company or its Subsidiaries on terms identical to those in effect as of the date of this Agreement and to the same extent they would have been able to had the transactions contemplated by this Agreement not occurred.
(ce) None of the Company and its Subsidiaries has received any written notice that it is or has been in material breach of any contractual obligation to limit its use of, secure or otherwise safeguard Personal Data, including any allegation that there has been a material breach of any Business Associate Agreement (i.e., a “business associate contract” as described under HIPAA at 45 C.F.R. § 164.504(e)) to which the Company or any of its Subsidiaries is a party, the EU General Data Protection Regulation, any data protection agreement (including standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC of the European Parliament and of the Council or any equivalent of successor thereof) to which the Company or any of its Subsidiaries is a party or of any violation by the Company or any of its Subsidiaries of their commitments under the EU-US Privacy Shield (as applicable), and, to the Company’s Knowledge, no such breach or violation has occurred within the applicable statute of limitation for a claim arising out of such a breach or violation. The Company and its Subsidiaries have each taken in place and follows commercially reasonable steps, materially compliant with applicable Privacy Requirements, procedures designed to protect (i) ensure that all written contracts with Confidential Data Processors require that such Confidential Data Processor Process Data in compliance with the operationInformation Privacy Laws, confidentiality, integrity, and security of the Company’s and its Subsidiaries’ software, systems, and websites (“IT Assets”) that are involved in the Processing of Personal Information, and (ii) Personal Information in the Company’s or any of its Subsidiaries’ possession and/or control from unauthorized use, access, disclosure, deletion, and/or modificationPrivacy Policy and the Company’s or its Subsidiaries’ obligations under any contract that governs the Processing of any Confidential Data.
(df) To Except as set forth on Section 4.13(f) of the Company’s knowledgeDisclosure Schedule, (i) neither the Company nor any of its Subsidiaries has experienced any failures; crashes; security incidents; data breaches; unauthorized accessaccess to, usedisclosure, or disclosure; deletion or other adverse events or incidents related to Personal Information that would require notification of individuals, law enforcementmisuse of, any Governmental EntityPersonal Data in its possession or control (a “Security Incident”) or made or been required to make any disclosure, customers, vendors, notification or take any others other action under any applicable Information Privacy RequirementsLaws in connection with any Security Incident, (ii) no Confidential Data Processor has experienced any Security Incident or made or been required to make any disclosure, notification or take any other action under any applicable Information Privacy Laws in connection with any Security Incident with respect to any Personal Data Processed by it for the Company or for any of its Subsidiaries, (iii) to the Company’s Knowledge, no Personal Data Supplier has experienced any Security Incident or made or has been required to make any disclosure, notification or take any other action under any applicable Information Privacy Laws in connection with any Security Incident with respect to any Personal Data provided by it to the Company or to any of its Subsidiaries. The Company and each of its Subsidiaries has not received written notice of any complaintsmade all notifications to Data Subjects, Actions, fines, customers or other penalties facing individuals required to be made by the Company or any of its Subsidiaries in connection with (as applicable) under any such failures; crashes; security incidents; data breaches; applicable Information Privacy Laws arising out of or relating to any event of unauthorized access, use, access to or disclosure; disclosure or other adverse events or incidentsacquisition of any Personal Data by any person of which the Company has Knowledge.
(eg) To No action, audit, assessment, suit, legal proceeding, investigation, administrative enforcement proceeding or arbitration proceeding before any court, administrative body or Governmental Authority has been filed or commenced against the extent required by applicable Company, any of its Subsidiaries or, to the Company’s Knowledge, threatened against the Company or its Subsidiaries, alleging any failure to comply with any Information Privacy and Security Laws, and the Company and each of its Subsidiaries has not incurred any material liabilities under any Information Privacy Laws. To the Company’s Knowledge, no Action has been filed, commenced or threatened against any Personal Data Supplier or Confidential Data Processor with respect to any Personal Data supplied to or Confidential Data Processed for the Company and each of its Subsidiaries.
(h) The Company, its Subsidiaries and its third-party service provider(s), if applicable, have obligated all implemented appropriate technical and organizational security measures to protect the confidentiality, integrity and security of their applicable vendors the IT Assets (and data processors authorized to process Personal Information on behalf of information stored or contained therein or transmitted thereby) against unauthorized use, access, disclosure, loss, destruction, interruption, modification or corruption.
(i) In the Processing by the Company or any of its Subsidiaries, including, without limitation, contract research organizations and clinical investigators, to be bound by contractual terms relating to the protection and Processing of Personal Information; and neither the Company nor any of its Subsidiaries is aware of any violations of such contractual obligations.
(f) To the Company’s knowledgePersonal Data, the Personal Information in the possession, custody, and/or control each of the Company and each its Subsidiaries, its Confidential Data Processors and, to the Company’s Knowledge, its Personal Data Suppliers has materially complied with all applicable Information Privacy Laws and applicable codes of practice in relation to marketing, advertising and profiling activities, as well as the placing of cookies on the Company’s or its Subsidiaries can be transferred Subsidiaries’ websites, including providing any notices an disclosures and obtaining any consents as part of the Mergers and the other transactions contemplated by this Agreement, and can be used after the Closing in a manner substantially the same as currently used by the Company and its necessary under applicable SubsidiariesLaws.
Appears in 1 contract
Sources: Share Purchase Agreement