Data protection notice

 

  1. Introduction

This data protection statement concerns the processing of information connected to user access and activity on the clinical data publication website.

The clinical data publication website was developed by the European Medicines Agency to implement EMA Policy 0070, and is maintained by the communications department.

The statement explains the reason for the processing, the way of collecting, handling and ensuring protection of all personal data provided, how that information is used and what rights you may exercise in relation to your data (the right to access, rectify, block etc.) and how.

In accordance with EMA Policy 0070, in order to access the clinical data published you must understand and accept the terms of use.

European Union institutions and bodies are committed to protecting and respecting your privacy. As EMA collects and further processes personal data, Regulation (EC) N°45/2001,of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data, is applicable.

 

  1. Why do we process your data?

Your personal data is collected and processed for two reasons:

  • to authenticate you as an authorised user and therefore grant you access to the clinical data published through your personal account
  • to record your user access and activity on the clinical data publication website.

 

  1. Which data do we collect and process ?

The personal data collected and further processed to ensure the secure authentication of users on the clinical data publication website are:

  • Log in to access the clinical data published
  • Terms of use acceptance on first time log in for access
  • Terms of use confirmation to view and /or download each clinical data package or package together with a log of the documents selected for view or download
  • Terms of use acceptance on upgrade from general information purposes to academic/non-commercial research purposes
  • Saved searches for the duration that the specific search is saved
  • Profile edit/update of details stored: EMA account
  • Profile upgrade: clinical data publication access from general information purposes to academic/non-commercial research purposes

 

  1. How long do we keep your data?

Personal data is retained for the duration that an individual holds an EMA account and /or access to the clinical data publication website.

 

  • General information purposes access holder who actively closes or does not use his/her EMA account (s) and /or clinical data publication website access,
  • the EMA account(s) is deemed inactive after 6 months; access to the clinical data publication website will be closed and
  • the access holder’s personal details/activity will be deleted after a further 6 months.
  • Academic/Non-commercial research purposes access holder who actively closes or does not use his/her EMA account and/or clinical data publication website access
  • the EMA account is deemed inactive after 6 months, access to the clinical data publication website will be closed and
  • personal details are deleted after a further 5 years.

 

  1. How do we protect your data?

All data in electronic format (e-mails, documents, uploaded batches of data etc.) are stored either on the servers of the European Medicines Agency or of its contractors which are subject to adequate security measures.

 

  1. Who has access to your data and to whom is it disclosed?

Access to your data is provided to authorised staff in the European Medicines Agency, according to the “need to know” principle only. Such staff abide by statutory, and when required, additional confidentiality agreements.

In accordance with the Terms of Use, EMA can be required to disclose your personal information by law, such as to comply with a judicial proceeding, court order, or legal process.

 

  1. What are your rights and how can you exercise them?

According to Regulation (EC) n°45/2001, you are entitled to access your personal data and rectify and/or block it in case the data is inaccurate or incomplete.You can exercise your rights by contacting the data controller, or in case of conflict the Data Protection Officer and if necessary the European Data Protection Supervisor using the contact information given at point 8 below.

 

  1. Contact information

If you have comments or questions, any concerns or a complaint regarding the collection and use of your personal data, please feel free to contact the Data Controller as follows:

Controller:          Noel Wathion

 Unit:                   Deputy Executive Director

 Mail:                   datacontrollerpolicy70@ema.europa.eu

Recourse

You can also address your complaints to:

The Data Protection Officer (DPO) of EMA: dataprotection@ema.europa.eu

The European Data Protection Supervisor (EDPS): edps@edps.europa.eu

 

  1. Where to find more detailed information?

For further information on the rights of data subjects and data protection see the EMA privacy statement.