1. About this Notice
1.1 This Privacy Notice ('Notice') relates to the processing of any information that, alone or in combination with other information, relates to an identified or identifiable individual ('Personal Information'), namely current and past employee(s), temporary worker(s), intern(s), and applicant(s) for employment and their dependent(s) ('Employees’) of Astellas Pharma Europe Limited ('Astellas', 'we' and 'our').
1.2 This Notice sets out the types of Personal Information that we collect and process about Employees, the purposes for which we process Personal Information and the rights that you have in relation to the Personal Information that we process about you.
1.4 In relation to any Employee located in the EMEA region, the Astellas entity which employs the Employee acts as the data controller for their Personal Information. As a data controller, that Astellas entity is responsible for ensuring that the processing of Personal Information complies with relevant privacy laws across EMEA.
1.5 Please take the time to read this Notice carefully. If you have any questions or comments, please contact your local HR department via [email protected] and/or your data protection officer via [email protected].
2. Personal Information
2.1 We process Personal Information for legitimate interests and contractual purposes, to operate effectively in our role as an employer or when using approved service providers. For more information on these legitimate interests, please see Section 3 below.
2.2 For example, we may collect the following Personal Information about you:
- Name and other Personal Information such as gender, date and place of birth.
- Contact information, such as postal address, telephone number and e-mail address.
- Past employment history, including prior employers, prior compensation and references in order to evaluate potential employees for employment.
- Social security / insurance numbers or similar identifiers for payroll administration.
- Family data and health-related information in order to provide applicable benefits. For instance, we may collect Personal Information about your family and dependants for emergency contact details or to provide health or insurance benefits to them.
- Pay and financial information for payroll, taxes, expense reimbursement and related purposes.
- Information necessary to evaluate the performance of Employees.
- Information relating to company business travel and arrangements.
- Other academic, professional, training and salary related information, such as academic degrees, professional qualifications and security clearance information.
2.3 Where necessary, the Personal Information that we process may contain information relating to a person's race or ethnic origin, political opinions or religious beliefs, physical or mental health or condition, sexual orientation, trade union membership, commission or alleged commission of criminal offences and any related legal actions ('Sensitive Personal Information').
2.4 Although we aim to minimize the amount of Sensitive Personal Information that we process, we may process such Sensitive Personal Information in certain circumstances, when we are required to do so by law (e.g. equal opportunity monitoring) or it is necessary to provide you with a service (such as a health or other benefit) or we are performing a criminal background check. If we are not already permitted by applicable data protection laws to process your Sensitive Personal Information for the purposes it is required, then we will obtain your consent to our use of your Sensitive Personal Information. Where we ask for your consent, you have the right to decline to provide your consent and/or (if provided) to withdraw your consent at any time. In deciding whether to provide your consent, you should note that, for example, Astellas may not be able to proceed with your application, perform your employment contract (or aspects of your employment contract), if you do not provide your consent.
3. The purposes for which we process Personal Information
3.1 We will generally process Personal Information for staffing and human resources purposes and employment-related activities ('HR Purposes'), such as: recruitment; administrative and managerial tasks; time-tracking; compensation; equity-related awards; healthcare and other benefit administration; employee traveling, expense tracking and reimbursement; appointments or removals; disciplinary matters; ensuring compliance with Astellas policies; working time management; determining and reviewing salaries; employee career development (including superannuation, employee evaluations); talent management; compliance with applicable legal and other requirements; management reporting and analysis; enabling internal contacts and communication; providing and monitoring training and learning services; providing IT support to employees, management and maintenance of the functioning and security of the IT systems and network.
3.2 We may also process Personal Information when required or allowed to do so by law or as necessary to enable Astellas to protect its interests, establish legal rights, pursue legal action or litigation (for instance, when necessary to prevent or detect fraud or crime or respond to a regulatory investigation).
3.3 From time to time Astellas may receive requests for references from mortgage providers, estate agents or landlords and accordingly has to process Personal Information in order to respond to such requests.
3.4 From time to time Astellas may receive requests for employment references and accordingly has to process Personal Information in order to respond to such requests. Astellas will offer factual information only. If you require a character reference from a colleague/manager, these must be in a personal capacity only. Such references will not be regarded as official Astellas references and must not be issued on behalf of Astellas or written on company headed paper. Please note that requests must be made in writing to the HR department and will only be answered once your written consent has been obtained. We will not provide employment references by telephone.
4. How we protect your privacy
4.1 We will process Personal Information in accordance with this Notice.
(a) Fairness: We will process Personal Information fairly. This means that we are transparent about how we process Personal Information and that we will process it in accordance with applicable law.
(b) Purpose limitation: We will process Personal Information for specified and lawful purposes, and will not process it in a manner that is incompatible with those purposes.
(c) Proportionality: We will process Personal Information in a way that is proportionate to the purposes which the processing is intended to achieve.
(d) Data accuracy: We take appropriate measures to ensure that the Personal Information that we hold is accurate, complete and, where necessary, kept up to date. However, it is also your responsibility to ensure that your Personal Information is kept as accurate, complete and current as possible by informing Astellas of any changes or errors. You should notify your local HR department of any changes to the Personal Information that we hold about you and your family (e.g. a change of address).
(e) Data security: We implement appropriate physical, technical and organizational security measures to protect Personal Information against unauthorized or unlawful processing or disclosure. For further information on the steps that we take to keep Personal Information secure and your responsibilities in this regard, please refer to the Global Information Technology Security Policy and Global Information Technology Security Standard.
(f) Data processors: We may engage third parties to process Personal Information for and on behalf of Astellas. We require such data processors to process Personal Information and act strictly on our instructions and to take steps to ensure that Personal Information remains protected.
(g) International data transfers: Personal Information may be collected, used, processed, stored or disclosed by Astellas, other Astellas group companies, and our service providers outside your home country. Personal Information is only transferred by us to another country if this is required or permitted under applicable data protection law and the country is deemed by the European Commission to provide "adequate" protection for Personal Information or there is adequate protection in place for the Personal Information such as our Intra-Group Data Transfer Agreement or the EU Standard Contractual Clauses. Please contact [email protected] if you wish to obtain a copy of these documents or understand more about how we transfer data internationally.
(h) Data Retention: We will not keep Personal Information for longer than is necessary for the purposes for which we process it or as required by law, contract, or the Astellas Records and Information Management Policy.
(i) Your rights: You have a right to request access to the Personal Information that Astellas holds about you. Please see our Subject Access Request Policy for more information. You may also ask us to correct any inaccurate Personal Information, delete any Personal Information, restrict how we process Personal Information, object to how we process Personal Information or provide Personal Information in a portable format. Upon receipt of a request, we will assess whether we are required to comply under applicable law. If you wish to exercise one of these rights please contact your local HR department via [email protected] and/or your data protection officer via [email protected]
5.1 Astellas retains the right to monitor all IT systems, physical areas of the business and/or work related activities to protect Astellas and ensure the appropriate use of Astellas resources and information assets in compliance with privacy law and in accordance with the Astellas Acceptable Use Policy.
6. Disclosures of Personal Information
6.1 We will not share, sell or otherwise disclose Personal Information for purposes unrelated to Astellas business functions without the consent of Employees.
6.2 Examples of instances when we might share Personal Information without the consent of the Employee include disclosures:
(a) Compliance with laws: disclosures that Astellas considers necessary or required by laws or regulations, in order to comply with legal process or government requests (including in response to public authorities to meet national security or law enforcement requirements), respond to regulatory investigations, investigate whistleblowing issues and/or to protect the safety of Employees, customers, patients, healthcare professionals, business partners or third parties;
(b) Vendors and other service providers: disclosures to third party vendors and other service providers we use in connection with the services they provide to us, including to support us in areas such as managing résumé/CV information, IT platform management or support services, infrastructure and application services, marketing, data analytics, business travel service providers; payroll processing services, and health care benefits;
(c) Consultants: disclosures to auditors, advisors, legal representatives and similar agents in connection with the advisory services they provide to us for legitimate business purposes and under contractual prohibition of using the Personal Information for any other purpose;
(d) Business transfers: disclosures to a party to which Astellas is contemplating selling a business unit (in which case Personal Information may be included among the transferred assets), but only to the extent necessary for legitimate business purposes and with a contractual prohibition of using the Personal Information for any other purpose; and
(e) Astellas affiliates: disclosures to Astellas affiliates and group companies for purposes consistent with this Notice.
6.3 We take precautions to allow access to Personal Information only to those Employees who have a legitimate business need for access and with a contractual prohibition of using the Personal Information for any other purpose.
7. Questions and complaints
7.1 We will address questions and complaints regarding Personal Information promptly and in accordance with applicable law. If you have a query or complaint please contact your local HR department via [email protected] and/or your data protection officer via [email protected] .
7.2 [If you have a complaint or concern about how we are processing your Personal Information then we will endeavour to address such concern(s). However, if you would like to direct your complaint/concerns to your data protection authority, see as follows for the relevant contact details: Information Commissioner's Office (ICO), 0303 123 1113, [email protected], Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
8. Updates to this Notice
8.1 This Notice was last updated on 1 April 2018.
NON_2020_0118_UK. November 2020