Data Protection at Fresenius Kabi

Welcome to the Fresenius Kabi AG (“Fresenius Kabi” or “we”) data protection information page. As a global healthcare company that specializes in lifesaving medicines and technologies for infusion, transfusion and clinical nutrition, we need to collect, use and share your personal data to carry out our work. We need to ensure that this data is appropriately handled and protected.

This site explains how we incorporate data protection in our operations and how your data is used in our processes. Furthermore, you will find information on how to execute your rights.


How We Take Care of Your Data

Our Data Protection Organization

Fresenius Kabi operates a central data protection competence center. This center has set up a data protection management framework in alignment with ISO 29100 (privacy framework for the protection of personally identifiable information). The competence center aims to implement a harmonized and consistent way of processing personal data across all Fresenius Kabi entities. It sets the policies, procedures and standards for data protection and provides tools and processes for the employees as well as training and awareness material. Furthermore, this center provides expertise on all data protection topics.

Our local data privacy advisors at the various Fresenius Kabi legal entities support local management with their compliance programs. They do this by executing risk and compliance assessments for the different data processing activities. With these assessments we aim to integrate ‘Privacy by design’ into the design of our processes and IT systems.

The monitoring of our data protection compliance efforts is overseen by our data protection officer.

Our Data Protection Policy

The Fresenius Kabi Group has adopted Binding Corporate Rules on the protection of personal data. These rules have been approved by the European Data Protection Authorities and describe the principles for protecting personal data and determine how we apply them when collecting and using personal data.

The Fresenius Binding Corporate Rules, associated security policies and procedures aim to create a global adequate and uniform level of data protection across our group. They set the rules for the internal data transfers between Fresenius Kabi companies and our internal service providers worldwide.

Our Security Measures 

At Fresenius Kabi we know information security is important to our customers, patients, and business partners. We are committed to maintaining information security through responsible management, appropriate use, and protection of our and your data in accordance with legal and regulatory requirements and our agreements. Please find more about the Information Security at Fresenius Kabi.


Transparency on Our Data Processing Activities

We collect and use your personal data in various ways and for various purposes. We collaborate with other organizations to achieve our purposes. In the sections below you can find when and how we do that. If you have any further questions, requests, inquiries or complaints relating your personal data you can contact us.

Situations in Which We Collect Your Data


With Whom We Share Your Data

In all the situations as mentioned above, we collaborate with other organizations to achieve our purposes. Therefore, we may send your personal data in parts or as a whole to other organizations.

Apart from the specific recipients as mentioned above for the specific situations, such recipients are:

  • Other Fresenius Kabi Group companies
  • Other Fresenius Group Companies
  • Service providers which process personal data on our behalf (e.g., for hosting or maintenance services) and have to follow our instructions on such processing; 
  • Authorities, courts and/or parties, or their delegated bodies, in a litigation in case we are required to do so to meet any applicable laws, regulations, legal processes or enforceable governmental requests
  • Professional advisors or auditors, such as tax advisors, financial auditors, lawyers, insurers, banks and other external professional advisors in the countries in which we operate
  • Other entities in the event of a change in ownership, a merger with, acquisition by, or sale of assets.

International data transfers

We may send your personal data in parts or as a whole to the above recipients in other countries. For some of these countries the European Commission or respective legislator or authority in your country has determined an adequate level of data protection to be in place that matches the level of data protection in your country. 

The European Commission has done this for the following countries / international organizations in which Fresenius entities are located: Argentina, Canada, Japan, South-Korea, United Kingdom, New Zealand, Switzerland or Uruguay.

For countries where the respective legislator or authority has not decided that an adequate level of data protection exists that matches the level of data protection in your country, we have provided safeguards in order to secure your personal data to a degree that is equivalent to the level of data protection in the European Union or your home country as a minimum.

These safeguards are:

  • For the exchange of data within our company: our Binding Corporate Rules for Controllers
  • For the exchange of data with our service providers and other international organizations: Standard Contractual Clauses that have been issued by the European Commission, and/or as issued by other authorities or legislators as applicable.

You can obtain a copy of these Standard Contractual Clauses and our Binding Corporate Rules, online, or upon request.

Changes to Our Personal Data Processing Activities

As our collection and use of your data may change over time, we may update the information on this site from time to time to correctly reflect our data processing practices. We encourage you to review it from time to time. Previous versions are available as link under the sections of the different situations in which we collect your data.

Contact, Requests, Inquiries and Complaints Relating to Your Data

For all the situations where we collect and use your data the following information is applicable.

Controller contact

The controller or designated responsible entity representing the Fresenius Kabi group, for processing of your personal data is:

Fresenius Kabi AG
Else-Kröner-Straße 1
61352 Bad Homburg
Germany
General Contact Form

Requests and inquiries

By using this data protection contact form you can request information and execute your rights. Where applicable based on data protection legislation, you have the right to request:

  • confirmation whether or not we process your personal data
  • access to or a copy of your personal data: You an ask to access/receive information about e.g. the purpose of processing, the categories of personal data concerned, the recipients, storage periods, any existence of automated decision-making.
  • rectification of your personal data if they are incomplete or incorrect
  • deletion of your personal data, unless it must be maintained e.g. due to legal retention requirements
  • to restrict of processing of your personal data if either the accuracy of the personal data is contested, or the processing is unlawful (no longer required for the pursued purposes).
  • data portability of your data to another organization in a commonly used and machine-readable format, if the following conditions are met: 
    • Personal data have been provided by the individual
    • The processing is based on the individual’s consent or on a contract with the individual
    • The processing is carried out by automated means.
  • Object to processing on grounds specific to your situation or to direct marketing and profiling.
  • revocation or withdrawal of your previously given consent at any time. You can withdraw your consent to all processing or for individual purposes of your choice. The withdrawal of consent will not affect the lawfulness of processing based on your consent before the withdrawal.
    • to be not subject to automated decision making (incl. profiling) which could lead to legal or similar significant effects to your, unless:
    • It is necessary for entering into or performance of a contract between the you and Fresenius Kabi    It is based on your explicit consent.

If you submit a request, our data protection organization may contact you for additional information to confirm your identity and to clarify your request. We provide information free of charge unless requests are manifestly unfounded or excessive. In those circumstances we may charge a fee.

We aspire to answer your request within four weeks. We reserve the right to extend the period within the scope of the admissibility by law and will inform you if this is the case. Please do not inquire about your processing status.

If you want to submit a request to another Fresenius Kabi entity than listed in this form, please navigate to the website of the country the respective entity is located. Web addresses can be found here.

For more information on how we handle your personal data, please read the information under If you submit a data subject request.


Complaints

You have the right to lodge a complaint about the way we manage your personal data with our data protection officer, via our compliance hotline or with the data protection authority. You can contact those as follows:

Data Protection Officer:

Fresenius Kabi AG
Data Protection Officer
Else-Kröner-Straße 1
61352 Bad Homburg
Germany
E-mail: dataprotectionofficer@fresenius-kabi.com

Data Protection Authority:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Presse- und Öffentlichkeitsarbeit
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany