data transfer policy

OVERVIEW

The European Union (EU) Data Protection Directive 2016/680 of the European Council of 27 April 2016 (the "Directive") applies to all Member States of the EU. Special precautions need to be taken when personal data is transferred to countries outside of the European Economic Area ("EEA"), i.e. in case of transfers to countries such as the United States, which do not provide EU-standard data protection.

This Policy for Data Transfers Outside the European Economic Area (this "Policy") sets forth the privacy principles that Capsugel Holdings US, Inc. ("Capsugel US"), its affiliates, subsidiaries and relevant third­ party service providers, in each case, in the United States follow with respect to personal information received from European entities affiliated with Capsugel Holdings US, Inc. (each a "Capsugel EU Entity") within the scope defined herein.


ABOUT THE MODEL CONTRACT CLAUSES

The EU Commission has published model contract clauses for data transfers (the "Model Contract Clauses") and determined that organizations which use the Model Contract Clauses offer sufficient safeguards for cross-border data transfer as required by the Directive. Accordingly, each Capsugel EU Entity shall enter into a set of Model Contract Clauses with the respective Capsugel US entity receiving Personal Information from the EU. Two sets of standard contractual clauses have been adopted for transfers between Data Controllers,and one set exists for transfers between a Data Controller and a Data Processor. Which set of Model Contract Clauses to use depends upon whether the company receiving the data is a Data Controller or a Data Processor. Further, whether a company is a Data Controller depends upon whether that company determines how the data is processed.


SCOPE

This Policy governs Personal Information (as defined below) received from the Capsugel EU Entities about i) employees (potential, current or former), contractors and contingent workers; ii) business entities and individuals referenced in contractual documentation and retained in Capsugel's centralized electronic repository of executed agreements; and iii) individuals processed within certain information technology applications or platforms that support our business functions and which are hosted, supported or maintained by Capsugel US. Personal information that is transferred from the Capsugel EU Entities to the Capsugel US is used to carry out and support respective Capsugel EU Entity's and/or Capsugel US' human resources,contract management,information technology provisioning and related activities.


DEFINITIONS

"Capsugel" means Capsugel US and the Capsugel EU Entities.

"Capsugel US" means Capsugel Holdings US,Inc. and its subsidiaries in the United States.

"Capsugel EU Entity'' Capsugel Belgium NV and its owned or controlled affiliates located in the European Union.

"Controller'' means the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by national or European Community  laws or regulations, the controller or the specific criteria for his nomination may be designated by national or European Community law.

"Personal Information" means any information that identifies or could be used to identify an individual. Personal Information does not include information that is anonymized so as not to permit identification of the relevant individual. Notwithstanding the above, to the extent such information is deemed personal information or personal data in an EU member state,Capsugel US will treat such information as Personal Information under this Policy.

"Processing" means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available,alignment or combination,blocking,erasure or destruction.

"Processor'' means the natural or legal person, public authority, agency or other body which processes personal data only on behalf of the Controller and as instructed by the Controller.

"Sensitive Personal Information" means personal information about an individual's race, ethnic origin, political opinions,religious or philosophical beliefs,trade union membership, sexual orientation, physical or mental health condition, and data relating to offenses, and/or criminal convictions. In addition, Capsugel shall treat as Sensitive Personal Information any information received from a third party where that third party determines that information to be sensitive and Capsugel agrees with this determination in writing.


PRIVACY PRINCIPLES

Model Contract Clauses' Principles: Capsugel will comply with the principles set out in the applicable set of Model Contract Clauses (Controller to Controller, or Controller to Processor clauses).

NOTICE: The respective transferring Capsugel EU Entity will,as required by law,inform individuals about the purposes for which it collects and uses Personal Information,how to contact such Capsugel entity,the types of third  parties (including other  Capsugel entities)  with  which it shares that  information. If a Capsugel EU Entity transfers data to Capsugel US,it will also inform the individual about this transfer,the purposes of the transfer and how the receiving entity can be contacted. This information will be provided as soon as practicable and, in any event, before Capsugel  US uses the information  for a purpose other than that for which it was originally obtained.

Capsugel may not need to furnish notice where providing notice is not required by law, in cases where, subject to applicable EU data protection laws, the Processing in question is necessary to respond to a government inquiry;is required by applicable laws, court orders or government regulations; in the case of a merger or acquisition,or is necessary to protect Capsugel's legal interests (each to the extent allowed under applicable EU data protection laws).

DATA INTEGRITY: Capsugel seeks to ensure that any Personal Information held about individuals is accurate,complete,current and otherwise reliable in relation to the purposes for which the information was obtained. Capsugel seeks to collect PersonalInformation that is adequate,relevant and not excessive for the purposes for which it is to be processed. Capsugel employees have a responsibility to assist Capsugel in maintaining accurate, complete and current Personal Information.

TRANSFERS TO AGENTS OR THIRD PARTIES: Capsugel US will only transfer Personal Information about individuals to an agent who has entered into Model Contract Clauses with Capsugel or otherwise complies with the Model Contract Clauses' onward transfer principles.

In the event that Capsugel transfers Personal Information to third parties for their independent purposes, it will do so only in compliance with the onward transfer principles set out in the respective set of the Model Contract Clauses.

ACCESS AND CORRECTION: Upon request,and as required by law,Capsugel will provide individuals with access to Personal Information about them, subject to permitted exemptions. Capsugel will also take reasonable steps to allow individuals to review Personal Information about them for the purposes of correcting such information.

SECURITY: Capsugel will take adequate precautions to protect Personal Information in its possession from loss,misuse,unauthorized access, disclosure, alteration and destruction.

ENFORCEMENT: Capsugel has established internal mechanisms to verify ongoing adherence to this Policy, Capsugel commits to resolve complaints about a person's privacy and/or collection or use of personal information. European Union citizens with inquiries or complaints regarding this privacy policy should first contact Capsugel at

Chief Information Officer
Capsugel
412 Mt. Kemble Ave Suite 200C Morristown, NJ 07960
Privacy.Officer@Capsugel.com

CHANGES TO THIS POLICY: This Policy may be amended from time to time, in accordance with the requirements of European data protection laws.


RESPONSIBILITY 

Capsugel expects and requires all applicable colleagues to comply with this Policy and all applicable procedures. Failure to comply may result in a number of serious consequences, including probation, suspension without pay, reduction in salary,termination of employment, and restitution.

If you are aware of or suspect questionable conduct or potential violations by another colleague, agent, intermediary,  customer, or consultant, you should immediately report these concerns to the Legal Department. A Capsugel colleague may raise a concern anonymously through the internet or telephone with Capsugel's Compliance Helpline (compliance.capsugel.com). Capsugel colleagues may also contact the Capsugel Chief Compliance Officer at compliance@capsugel.com. Capsugel reserves the right to modify or discontinue this Policy at its discretion at any time without prior notice.