The California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations (collectively, the “CCPA”), gives California residents certain rights and requires businesses to make certain disclosures regarding their Collection, use, and disclosure of Personal Information. This California HCP Privacy Notice (the “Notice”) provides such notice to healthcare professionals who are residents of California and who interact with Novo Nordisk (“we,” “us,” “our”) in a commercial context (collectively, “HCPs”).
Please note that this Notice only addresses Novo Nordisk’s Collection, use, and disclosure of Personal Information Collected in a commercial context and only applies to residents of California. This Notice does not apply to individuals who are residents of other U.S. states or other countries, who are not healthcare professionals, and/or who do not interact with Novo Nordisk in a commercial context. Further, this Notice does not apply to non-HCP business contacts who interact with Novo Nordisk. For further details about our general privacy practices, please see our Privacy Policy. For details about our privacy practices pertaining to Personal Information we Collect from or about non-HCP business contacts who are residents of California, please see here.
All companies need to collect and share Personal Information for everyday business purposes, marketing, and maintenance of the safety, security, and integrity of their websites and other assets, among other reasons. This Notice describes our practices regarding the Collection, use, and disclosure of HCP Personal Information and provides instructions for submitting data subject requests. This Notice is broader in scope than the Novo Nordisk Privacy Policy because it provides details about the Personal Information we Collect from and about HCPs through online and offline interactions.
As an HCP, you have the right to know what categories of Personal Information Novo Nordisk Collects, uses, discloses, Sells, and Shares about you. This Policy provides that information and other disclosures required by California law.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal Information includes “Sensitive Personal Information,” as defined below, except where otherwise noted.
“Sensitive Personal Information” means Personal Information that reveals a consumer’s social security, driver’s license, state identification card, or passport number; account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious beliefs, or union membership; contents of email or text messages; and genetic data. Sensitive Personal Information also includes processing of biometric information for the purpose of uniquely identifying a consumer and Personal Information Collected and analyzed concerning a consumer’s health, sex life, or sexual orientation.
Other CCPA Definitions: As used in this Notice, the terms “Collect,” “Processing,” “Service Provider,” “Third Party,” “Sale,” “Share,” “Consumer,” and other terms defined in the CCPA and their conjugates, have the meanings afforded to them in the CCPA, whether or not such terms are capitalized herein, unless contrary to the meaning thereof.
We, and our Service Providers, Collect the following categories of Personal Information about HCPs. We also have Collected and Processed the following categories of Personal Information about HCPs in the preceding 12 months:
1. Identifiers, such a real name, alias, postal address, unique personal identifier, online identifier, internet protocol (IP) address, or other similar identifiers;
2. Contact and financial information, including phone number, address, email address, bank account number, credit or debit card number;
3. Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, marital status, and religion;
4. Commercial information, such as including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies;
5. Biometric information, including an individual’s physiological, biological, or behavioral characteristics (including DNA) to the extent it can be used to establish individual identity;
6. Internet or other electronic network activity information, such as browsing history, search history, and information regarding an individual’s interaction with an internet website, application, or advertisement;
7. Geolocation data, such as device location;
8. Audio, electronic, visual, thermal, olfactory, or similar information, such as a call or video recording or profile photograph;
9. Professional or employment-related information, such as work history and prior employer, medical license number, information about health and/or medical specialties;
10. Education information, such as academic information and records;
11. Inferences drawn from any of the information listed above to create a profile about an individual reflecting the individual’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. (e.g., predications about an individual’s preferences or tendencies);
12. Individuals’ written signatures; and
13. Sensitive personal information, including:
a. Personal Information that reveals:
i. Social security, driver’s license, state identification card, or passport number;
ii. Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials for allowing access to an account;
iii. Precise geolocation data;
iv. Racial or ethnic origin, religious or philosophical beliefs, or union membership;
b. Biometric data processed for the purpose of uniquely identifying a consumer.
Retention of Personal Information. We retain each of the categories of HCP Personal Information listed in Section C for the period reasonably necessary to provide goods and services to you and for the period reasonably necessary to support our business operational purposes listed in Section G.
We have disclosed the following categories of HCP Personal Information to Service Providers and Third Parties for a business purpose in the past twelve months:
1. Identifiers, such a real name, alias, postal address, unique personal identifier, online identifier, internet protocol (IP) address, or other similar identifiers;
2. Contact and financial information, including phone number, address, email address, bank account number, credit or debit card number;
3. Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, marital status, and religion;
4. Commercial information, such as including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies;
5. Biometric information, including an individual’s physiological, biological, or behavioral characteristics (including DNA) to the extent it can be used to establish individual identity;
6. Internet or other electronic network activity information, such as browsing history, search history, and information regarding an individual’s interaction with an internet website, application, or advertisement;
7. Geolocation data, such as device location;
8. Audio, electronic, visual, thermal, olfactory, or similar information, such as a call or video recording or profile photograph;
9. Professional or employment-related information, such as work history and prior employer, medical license number, information about health and/or medical specialties;
10. Education information, such as academic information and records;
11. Inferences drawn from any of the information listed above to create a profile about an individual reflecting the individual’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. (e.g., predications about an individual’s preferences or tendencies);
12. Individuals’ written signatures; and
13. Sensitive personal information, including:
a. Personal Information that reveals:
i. Social security, driver’s license, state identification card, or passport number;
ii. Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials for allowing access to an account;
iii. Precise geolocation data;
iv. Racial or ethnic origin, religious or philosophical beliefs, or union membership;
b. Biometric data processed for the purpose of uniquely identifying a consumer.
Sale & Sharing of Personal Information: We Sell and Share HCP Personal Information. Of the categories of HCP Personal Information listed in Section C, we sell and share the below categories of HCP Personal Information. Further, in the past twelve months, we have Sold or Shared the below categories of HCP Personal Information.
We Sell and Share such information with marketing vendors to provide HCPs with online advertising that is more relevant.
We Sell and Share Personal Information for the purposes listed in Section G. We do not Sell or Share, and have not Sold or Shared in the past twelve (12) months, categories of Personal Information that are not listed in this Section E.
We Collect Personal Information directly from HCPs, as well as from joint marketing partners; public databases; providers of demographic data; publications; professional organizations; educational institutions; social media platforms; and Service Providers and Third Parties when they disclose information to us.
We, and our Service Providers, Collect, process, and disclose the HCP Personal Information (excluding Sensitive Personal Information) described in this Notice to:
We, and our Service Providers, Collect, Process, and disclose the Sensitive Personal Information described in this Notice only for the below purposes that are authorized by the CCPA and its implementing regulations:
Affiliates & Service Providers. For each category of HCP Personal Information listed in Section D, we disclose such information to our affiliates and Service Providers for the purposes described in this Notice (see "Purposes for Processing Personal Information,” above). Our Service Providers provide us with services for our websites, as well as other products and services, such as web hosting, data analysis, payment processing, order fulfillment, customer service, infrastructure provision, technology services, email delivery services, credit card processing, legal services, and other similar services. We grant our Service Providers access to Personal Information only to the extent needed for them to perform their functions, and we require them to protect the confidentiality and security of such information.
Third Parties. For each category of HCP Personal Information listed in Section D, we disclose such Personal Information, and have disclosed such Personal Information in the past twelve months, to the following categories of Third Parties:
Exercising Data Subject Rights. You may exercise your data subject rights by contacting our Privacy Office at NNIPrivacy@novonordisk.com, by calling (888) 870-3901, or by clicking here. You may also authorize an agent to make data subject requests on your behalf via the above methods. When you submit a data subject request, please indicate the type of request you are making, so that we may properly process and respond to your request in accordance with applicable law.
Verification of Data Subject Requests. We value the security and confidentiality of your Personal Information. Depending on the type of data subject request you submit, we may ask you to provide information that will enable us to verify your identity before complying with the request. We verify requests carefully and in accordance with applicable law. In particular, if you authorize an agent to make a request on your behalf, we may require the agent to provide proof of signed permission from you to submit the request, or we may require you to verify your own identity to us or confirm with us that you provided the agent with permission to submit the request. In some instances, we may decline to honor your request if an exception applies under applicable law. We will respond to your request consistent with applicable law.
Non-Discrimination. We will not discriminate against you for exercising your data subject rights. For example, we will not deny goods or services to you, or charge you different prices or rates, or provide a different level of quality for products or services as a result of you exercising your data subject rights.
As an HCP, you have the following rights under the CCPA with respect to your Personal Information, subject to certain exceptions:
Right to Receive Information on Privacy Practices: You have the right to receive the following information at or before the point of Collection:
We have provided such information in this Notice, and you may request further information about our privacy practices by contacting us as at the contact information provided above.
Right to Deletion: You may request that we delete any Personal Information about you we that we Collected from you.
Right to Edit: You may request that we edit any inaccurate Personal Information we maintain about you.
Right to Know: You may request that we provide you with the following information about how we have handled your Personal Information:
Right to Receive Information About Onward Disclosures: You may request that we disclose to you:
Right to Non-Discrimination: You have the right not to be discriminated against for exercising your data subject rights. We will not discriminate against you for exercising your data subject rights.
Right to Opt-Out of the Sale and Sharing of Personal Information. You have the right, at any time, to direct us not to sell or share your Personal Information. To exercise this right, please click on the “Do Not Sell or Share My Personal Information” button in this policy or on any Novo Nordisk webpage where the button is present. Novo Nordisk does not have actual knowledge that it sells or shares the Personal Information of minors under 16 years of age without affirmative authorization.
Opt-Out Preference Signals. We recognize opt-opt preference signals that we are required to recognize for compliance with applicable law. We treat such opt-out preference signals as a valid request to opt-out of sale and sharing for the browser or device through which the signal is sent and any consumer profile we have associated with that browser or device, including pseudonymous profiles. If we know the identity of the consumer from the opt-out preference signal, we will also treat such opt-out preference signal as a valid request to opt out of sale and sharing for the consumer. California HCPs may use opt-out preference signals by downloading or otherwise activating them for use on supported browsers and setting them to send opt-out preference signals to websites they visit.
California Residents Under Age 18. If you are a resident of California under the age of 18 and a registered user of our website, you may ask us to remove content or data that you have posted to the website by writing to NNIPrivacy@novonordisk.com. Please note that your request does not ensure complete or comprehensive removal of the content or data, as, for example, some of your content or data may have been reposted by another user.
Disclosure About Direct Marketing for California Residents. California Civil Code § 1798.83 permits California residents to annually request certain information regarding our disclosure of Personal Information to other entities for their direct marketing purposes in the preceding calendar year. To make such a request, please send an email to NNIPrivacy@novonordisk.com with the subject “Shine the Light Request.”
Financial Incentives for California HCPs. Under California law, we do not provide financial incentives to California HCPs who allow us to Collect, retain, sell, or share their Personal Information. We will describe such programs to you if and when we offer them to you.
Changes to this Notice. We reserve the right to amend this Notice at our discretion and at any time. When we make material changes to this Notice, we will notify you by posting an updated Notice on our website and listing the effective date of such updates.
Call (888) 870-3901 or email us at NNIPrivacy@novonordisk.com to contact us with questions regarding this Notice. If you are unable to review or access this Notice due to a disability, you may contact us to request access to this Notice in an alternative format.