Privacy Notice for Employees
Last Updated: July 26, 2024
INTRODUCTION
This Privacy Notice is provided by Celltrion Healthcare Australia Pty Ltd (hereinafter "Celltrion" or "we") and its subsidiaries/branches to explain who we are, how we collect, share and use Personal Data about you, the employee, as well as how you can exercise your privacy rights. If you have any questions or concerns about our use of your Personal Data, or would like to exercise any of your rights — including, but not limited to, objecting to the processing of your Personal Data in the ways that we describe here — then please contact us using the details provided at the end of this Privacy Notice. Celltrion does its best to protect your privacy rights.
WHO WE ARE
Celltrion is a global pharmaceutical company whose ultimate parent company is headquartered in Incheon, Republic of Korea (South). For more information about us, please visit our website at
https://www.celltrion.com/en-us
PERSONAL DATA
"Personal Data" is any data that identifies you as an individual or relates to an identifiable individual. There are also "special categories" of more sensitive Personal Data which require a higher level of protection.
Personal Data that we may collect and use includes:
• Your name, address, contact details such as email addresses and telephone numbers, date of birth, and gender;
• The terms and conditions of your employment;
• Details of your qualifications, skills, experience, education, and employment history (including duty services like military service), including start and end dates, previous employers and organizations;
• Information about your remuneration, including entitlement to benefits such as pensions or insurance coverage;
• Details regarding your bank account and social security number;
• Information about your marital status, next of kin, dependents and emergency contacts;
• Information about your nationality and entitlement to work in the employed country;
• Details regarding your schedule (work days and working hours) and attendance at work;
• Details regarding periods of leave taken by you, including holidays, sickness absences, family matters, and other absences, as well as the reason for the absence;
• Details regarding any disciplinary or grievance procedures in which you have been involved, including any warnings issued to you and/or the related correspondence; or
• Assessments of your performance, including appraisals, performance reviews, performance improvement plans and related correspondence.
We may also collect, store and use "personally identifiable information" (such as your driver license number, passport number, and social security number) and the following "special categories" of sensitive personal information including:
• Information about medical or health conditions, including whether or not you have a disability for which the organization needs to make reasonable adjustments;
• monitoring information in order to maintain fair and equal opportunity, including information about your ethnic origin, sexual orientation, health, and religion or belief; or
• Biometric data, including fingerprints, hand geometry, and samples.
Your Personal Data may be collected through application forms or CVs, your passport or other personal identity, documents completed by you at the start of or during employment, any correspondence with you, or through interviews, meetings or other assessments.
In addition, we may collect personal data about you from third parties, such as references supplied by former employers and information from employment background check providers.
Providing us with, or giving us permission to collect, any Personal Data relating to individuals other than yourself requires you to have valid authority to do so pursuant to relevant legislation
In general, we will use the personal information we collect from you only for the purposes described in this Privacy Notice; for any other purpose not mentioned, we will explain to you at the time your personal information is collected. However, we may also use your personal information for other purposes not incompatible with the purposes we have disclosed to you if and where this is permitted by applicable data protection laws.
HOW WE USE PERSONAL DATA
We use Personal Data in order to:
• Manage the employment relationship;
• Perform contractual obligations under your employment contract; or
• Comply with legal/regulatory obligations.
We also use Personal Data as necessary for our legitimate interests and do not override your data protection or fundamental rights and freedoms at any time before, during and after the end of the employment relationship.
Our contractual obligations include:
• Payment in accordance with the employment contract; or
• Administration and operation (such as benefit, tax, pension, and insurance).
Our legal/regulatory obligations include, but are not limited to:
• Checking an employee's entitlement to work in the employed country; or
• Complying with labor laws and other applicable laws related with employment.
Our legitimate interests include:
• Running recruitment and promotion processes;
• Maintaining accurate and up-to-date employment records, contact details (including details regarding who to contact in the event of an emergency), and records of employee contractual and statutory rights;
• Operating and keeping a record of disciplinary and grievance processes in order to ensure acceptable conduct within the workplace;
• Operating and keeping a record of employee performance and related processes in order to plan for career development, and for succession planning and workforce management purposes;
• Operating and keeping a record of absence and absence management procedures in order to allow effective workforce management and ensure that employees are receiving the appropriate pay or other benefits to which they are entitled;
• Obtaining occupational health advice, to ensure that it complies with duties in relation to individuals with disabilities, meeting its obligations under applicable laws, and making sure that employees are receiving the appropriate pay or other benefits to which they are entitled;
• Operating and keeping a record of other types of leave (including maternity, paternity, parental and shared parental leave), in order to maintain effective workforce management, to ensure that the organization complies with its duties in relation to leave entitlement, and to make sure that employees are receiving the appropriate pay or other benefits to which they are entitled;
• Managing effective general HR and business administration;
• Providing references on request for current or former employees;
• Responding to and defending against legal claims; or
• Maintaining and promoting equality in the workplace.
Some special categories of Personal Data, such as information about health or medical conditions, are processed in order to carry out obligations related to employment law (such as those in relation to employees with disabilities).
The organization processes other special categories of Personal Data, such as information about ethnic origin, sexual orientation, health or religion or belief; this is done for the purposes of monitoring equal opportunity. Data that the organization uses for such purposes is anonymized. Employees are entirely free to decide whether or not to provide such data and there are no negative consequences of refusing to do so.
Personal Data is stored in the company's HR management and IT systems.
HOW WE DISCLOSE PERSONAL DATA
We disclose your Personal Data only when strictly necessary as follows:
• To selected employees (including your managers and those at the HR/GA/Finance/Account/IT Departments, all of whom have signed a confidentiality agreement) and our subsidiaries/affiliates for the purposes described in this Privacy Notice; or
• Service providers acting on behalf of us and our subsidiaries/affiliates, such as payroll service providers, travel agencies, and IT system and data hosting providers. We may also share your data with third parties in order to obtain pre-employment references from other employers as well as employment background checks from third party providers. These third parties are contractually and legally required to protect the confidentiality and security of your personal data, in compliance with applicable law.
We also use and disclose your Personal Data as we believe to be necessary or appropriate:
• (i) To comply with applicable law and our regulatory monitoring and reporting obligations (which may include laws outside your country of residence), (ii) to respond to requests from public and government authorities (which may include authorities outside your country of residence), (iii) to cooperate with law enforcement, or (iv) for other legal reasons.
LEGAL BASIS FOR PROCESSING PERSONAL INFORMATION (EEA employees only)
If you are a visitor from the European Economic Area, our legal basis for collecting and using the personal information as described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will generally collect personal information from you only when we need the personal information in order to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information.
If we ask you to provide personal information to comply with a legal requirement, we will make this clear at the relevant time and advise you whether or not the provision of your personal information is mandatory (as well as of any possible consequences of not providing your personal information).
Similarly, if we collect and use your personal information in reliance on our legitimate interests (or those of any third party), we will alert you and clarify what those legitimate interests are at the relevant time.
If you have any questions or need further information concerning the legal basis on which we collect and use your personal information, please let us know using the contact details provided under the "CONTACT US" heading below.
INDIVIDUAL RIGHTS
If you would like to request to review, correct, update, suppress, restrict or delete Personal Data that you have provided to us through an HR manager, or if you would like to request to receive an electronic copy of your Personal Data for the purpose of transmitting it to another company, you may contact us as indicated in the "CONTACT US" section. We will respond to your request in compliance with applicable law.
In your request, please tell us what Personal Data you would like to have changed, whether you would like to have it suppressed from our database, or set certain limitation on our use. We may need to verify your identity before implementing your request. We will try our best to respond to your request as soon as reasonably practicable.
When asked to provide Personal Data, you may decline. However, choosing not to provide necessary information may limit our ability to supply you with requested services.
Please note that we may need to retain certain types of Personal Data for record keeping regarding your requests and resolutions responded.
DATA SECURITY
We seek to use reasonable organizational, technical and administrative measures in order to protect your Personal Data. This includes encrypting your personal information in transit and at rest.
DATA RETENTION PERIOD
We will retain your Personal Data for as long as needed or permitted in light of the purpose(s) for which it was obtained and as outlined in this Privacy Notice. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing employment relationship with you; (ii) whether or not there is a legal obligation to which we are subject (such as keeping records of employment and payroll); (iii) whether or not retention is advisable in light of our legal position (such as in regard to the enforcement of the employment contract, applicable statutes of limitations, litigation or regulatory investigations).
When we have no ongoing legitimate purpose to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, if your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until it can be safely deleted.
INTERNATIONAL DATA TRANSFER
Your personal information may be transferred to, and processed in countries other than the one in which you are resident. These countries may have data protection laws that are different from the laws in your country.
Celltrion is headquartered in the Republic of Korea (South). We may transfer your personal information with legitimate purpose to our subsidiaries/affiliates and third-party service providers located around the world.
However, we have taken appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Notice. This includes implementing the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies, which requires all group companies to protect personal information they process from the EEA in accordance with European Union data protection laws.
Appropriate safeguards have also been implemented with our third-party service providers and partners. Further details, along with our Standard Contractual Clauses, can be provided upon request.
UPDATES
We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you in consistence with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws. This Privacy Notice was last updated as of the "Last Updated" date shown above.
CONTACT US
If you have any questions or concerns about our use of your personal information, please contact your HR manager or our data protection officer using the following details:
DPO.CTHC@celltrionhc.com