This Consumer Health Data Privacy Notice supplements the Novo Nordisk US Privacy Notice and applies to personal data defined as “consumer health data” by the Washington State My Health My Data Act (MHMDA) and Nevada Consumer Health Data Privacy Law. It provides information about how Novo Nordisk and its Affiliates (“Novo Nordisk” or “we”) may collect, use, disclose or otherwise process your health information, how we protect it, and your rights and choices with respect to your health information.

This Notice applies to all Novo Nordisk operations in the US as well as websites, mobile applications and digital services (“Services”) that link to or post it.

Health information for purposes of this Notice has the definition given in Washington or Nevada law, including information that identifies or is reasonably capable of being associated or linked, directly or indirectly, with a particular consumer and that identifies the consumer’s past, present, or future physical or mental health status. This Notice applies only to residents of Washington and Nevada and individuals whose information is processed in Washington or Nevada.

This Notice does not apply to the personal information that we collect and process about Novo Nordisk workforce members in the US, including job applicants; active and inactive Novo Nordisk US employees; former employees; retirees; dependents; beneficiaries; employees of Novo Nordisk third-party vendors and partners, such as contractors on assignment at Novo Nordisk in the US; and other individuals about whom Novo Nordisk collects personal information for HR related purposes. It does not apply to health information that is used to engage in public or peer-reviewed scientific, historical, or statistical research that adheres to all other applicable ethics and privacy laws.

We Collect the following categories of Consumer Health Data from Consumers:

  • Individual health conditions, treatment, diseases, or diagnosis;
  • Social, psychological, behavioral, and medical interventions;
  • Health-related surgeries or procedures;
  • Use or purchase of prescribed medication;
  • Bodily functions, vital signs, symptoms, or measurements related to health;
  • Diagnoses or diagnostic testing, treatment, or medication;
  • Reproductive or sexual health information;
  • Biometric data;
  • Genetic data;
  • Precise location information that could reasonably indicate a Consumer's attempt to acquire or receive health services or supplies;
  • Data that identifies a Consumer seeking health care services;
  • Health-related data that have been derived or inferred from the above. 

We use the above-mentioned categories of Consumer Health Data for the following purposes:

  • Performing the services or providing the goods reasonably expected by an average Consumer who requests those goods or services;
  • Ensuring security and integrity to the extent the use of the Consumer's Personal Information is reasonably necessary and proportionate for these purposes;
  • Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted Personal Information;
  • Resisting malicious, deceptive, fraudulent, or illegal actions directed at the business and prosecuting those response for those actions;
  • Ensuring the physical safety of natural persons;
  • Short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a Consumer's current interaction with us; provided that we will not disclose the Consumer's Personal Information to a Third Party and or build a profile about the Consumer or otherwise alter the Consumer's experience outside the current interaction with the business;
  • Performing services on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on our behalf;
  • Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured by, manufactured for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by us; and
  • Collecting or processing Sensitive Personal Information where such collection or processing is not for the purpose of inferring characteristics about a consumer.

We Collect Consumer Health Data directly from Consumers and from the following sources:

As described further in the Personal Information we collect section of our State-Specific Supplemental Privacy Notice, we may Collect Consumer Health Data about patients and caregivers directly from patients and caregivers, as well as from healthcare providers, and health insurance providers. We may also collect Consumer Health Data about patients and caregivers from publicly available sources and from commercial sources, including third parties that aggregate and sell data. Further, we collect Consumer Health Data from website viewers directly from these Consumers, including via cookies and similar technologies on our websites and apps.

We Share all of the categories of Consumer Health Data listed in Section 1. 

We Share Consumer Health Data with the following Third Parties:

  • At Your Direction. Disclosure to third parties at your direction and with your consent. In the case of marketing materials or events in or at which you have consented to appear, this includes disclosure of your Consumer Health Data to the public.
  • Marketing Vendors. Third Parties to provide marketing services to serve Consumers with online advertising that is more relevant to them based on their network activity data, IP addresses, other online identifiers, and similar information and inferences derived therefrom.
  • Healthcare & Insurance Providers. To your healthcare provider, pharmacy, and health insurance provider or administrator.
  • Business Transfers or Assignments. To other entities as reasonably necessary to facilitate a merger, sale, joint venture or collaboration, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
  • Legal and Regulatory. We may disclose your Consumer Health Data to government authorities, including regulatory agencies and courts, as reasonably necessary for our business operational purposes, to assert and defend legal claims, and otherwise as permitted or required by law.
  • Enhancing Website Experience. We may utilize your Consumer Health Data to draw inferences to tailor your website experience and identify products you may be interested in.
  • Affiliates. As noted below, we enable access to data across our subsidiaries, affiliates, and related companies, for example, where we share common data systems or where access helps us to provide our services and operate our business. 

We Share Consumer Health Data with the following Affiliates:

  • Novo Nordisk Inc.
  • Novo Nordisk A/S
  • Novo Nordisk Health Care AG
  • Novo Nordisk US Research & Development

Subject to certain legal limitations and exceptions, you may be able to exercise specific rights, including rights to access, delete, or withdraw consent relating to such data.

We will not discriminate against you for exercising any of your rights under this Consumer Health Privacy Notice.

To exercise your rights with respect to your Consumer Health Data, depending on your state of residence, you may contact us at any time through any of the following methods:

If your request to exercise a right is denied, you may appeal that decision by contacting our privacy support team via our web form. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint.

We reserve the right to amend this Consumer Health Data Privacy Notice at our discretion and at any time. When we make changes, we will post the updated Consumer Health Data Privacy Notice on the website and update the effective date. Your continued use of our website following the posting of changes constitutes your acceptance of such changes.

The effective date of the rights for this Consumer Health Data Privacy Notice is March 31, 2024. Changes to will not affect our use of previously provided Consumer Health Data.

If you have any questions about this Consumer Health Data Privacy Notice, the ways in which we use your Consumer Health Data described herein, and your choices and rights regarding such use, please contact us by:

Sending an email request to: NNIPrivacy@novonordisk.com

Sending a letter via U.S. Mail to:

Novo Nordisk Inc.
800 Scudders Mill Road
Plainsboro, NJ 08536
ATTN: North America Privacy Office

Supplement to Consumer Health Data Privacy Notice for Nevada Consumers

This Supplement applies to Nevada Consumers for purposes of providing additional disclosures required by Nevada’s Consumer Health Data privacy law. Terms used herein that are defined terms under Nevada’s Consumer Health Data privacy law shall have the meanings afforded to them therein.

Purposes & Manner of Processing. We Collect, Use, Process, and Share Consumer Health Data for the purposes and in the manners described in Section 1 of our  Consumer Health Data Privacy Notice, which also provides additional disclosures relevant to Nevada Consumers.

Review & Revision of Consumer Health Data. If you would like to review and/or revise your Consumer Health Data, you may submit a request to us via any of the methods listed in our Consumer Health Data Privacy Notice. We will respond to your requests to exercise your rights in accordance with applicable law, but in any case, no later than 45 days after receiving your request. We may extend this period up to 45 days only where doing so is permitted under applicable law. 

Changes to this Supplement. We will notify you before making any changes to our privacy practices with respect to your Consumer Health Data by posting an updated notice on this page, with an updated effective date. 

Third Party Collection of Consumer Health Data. Please note that some Third Parties may collect Consumer Health Data about you over time and across different websites or online services you may visit. 

Effective Date: March 31, 2024