Medical Information, Pharmacovigilance 
and Product Complaints 
Privacy Notice

Last Updated: 11 March 2026

1. Introduction

 

Protecting your personal data while ensuring your safety is extremely important for Galderma SA or any of its subsidiary or affiliated companies worldwide (“Galderma”). This Privacy Notice outlines how Galderma collects, uses, shares, stores, and otherwise processes the information that relates to an identified or identifiable natural person (“personal data”) in relation to medical information inquiries, pharmacovigilance activities and product complaints in compliance with applicable data protection laws and regulations.

 

2. Scope of the Privacy Notice

 

This Privacy Notice applies to the processing of personal data of:

  • any individual (e.g., patients or their representatives, professional caregivers, healthcare professionals etc.) requesting medical information, or reporting safety information (suspected side effects or adverse events), or raising product complaints to a Galderma entity (“submitter”), and

  • any individual whom such medical or safety information concerns (“subject”).

In this Privacy Notice, “you” refers to the individuals described above.

Information on processing activities by Galderma regarding personal data in the context of Galderma websites can be found in the Global Privacy Notice.

With respect to the processing of personal data in healthcare professionals (HCPs), please see the HCP Privacy Notice.

 

3. Responsible Entity - Controller

 

The data controller is the Galderma entity with which the individual requesting or reporting the medical or safety information report interacts, namely Galderma Australia Pty Ltd (“Controller” or “we”, “us”, “our”). 

If you have any questions or concerns about this Privacy Notice or our processing of your personal data, please contact us via the email address included in the ‘Contact Information’ section.

 

4. Data We Collect

 

Depending on how you interact with Galderma (online, offline, over the phone, etc.), We may collect various types of personal data about you, as described below:

For the submitters:

  • Personal identification data: Name, relationship with the subject.

  • Contact details: Email address, phone number, postal address.

  • Professional details: Occupation/affiliation.

  • Interaction data: Communications, Statements.

For the subjects:

  • Personal identification and demographic data: Name/initials, gender, date of birth/age, weight and height.

  • Sensitive data: Medical and treatment history and status, genetic or biometric data.

  • Feedback data: suspected side effects or adverse events, medical information queries, product quality complaints, details of the product of interest, including the dosage and duration you have been taking or were prescribed, the reason you have been using the product and any subsequent change to your regimen.

In some cases, the submitter and the subject may be the same individual (for example, a patient directly reporting a suspected side effect or adverse event).

Please note that we only request personal data that is requested or permitted under the applicable laws and is necessary to serve the lawful purposes. If you choose not to provide certain personal data, we might not be able to handle appropriately your medical information inquiries, pharmacovigilance reports and product complaints.

 

5. Sources Of Your Personal Data 

 

We collect personal data either directly from the individual to whom the personal data relates, or from the individual’s representatives, professional caregivers, healthcare professionals. 

 

6. Our Purposes and Legal Bases

 

Below, you may find a detailed overview of all the purposes for and all the legal bases under which we will process your personal data in line with the respectful activity. Please note that not all of the uses below will be relevant to every individual.

 

Activity

What we use your personal data for (Purpose)

Legal Basis for regular personal data

Legal Basis for sensitive personal data

Medical InformationReview, document, and respond to medical inquiries Legitimate interest in handling the request and providing medical guidance

N/A

We will only process anonymized sensitive information

Pharmacovigilance

Review, clarify and investigate suspected side effects or adverse events reports 

Legitimate interest in ensuring accurate reporting

Public health interest in detecting, assessing, and preventing adverse events

Follow up on suspected side effects or adverse events reports

Legitimate interest in handling the request and providing medical guidance

Public health interest in detecting, assessing, and preventing adverse events

Report adverse events 

Legal obligation in in regulatory reporting

Public health interest in detecting, assessing, and preventing adverse events

Product Complaints

Review, document, and respond to product quality complaints

Legitimate interest to support customers

N/A

We will only process anonymized sensitive information

Medical Information Pharmacovigilance Product Complaints

Document and analyze the quality and safety of our products 

Legitimate interest to monitor trends, ensure consistency and improve products and support

N/A

We will only process anonymized sensitive information

 

In case we want to use your personal data for purposes unrelated to those described in the table above, we will appropriately notify you and, where required, obtain your consent or offer you a choice as to whether or not we may use your personal data in this manner.

When publishing information about adverse events (such as case studies and summaries), we will remove identifiers from any publication to keep your identity private.

 

7. Data Sharing

 

We may share your personal data with service providers that process personal data on our behalf and subject to our instructions as so-called data processors, for the purpose of providing their professional services to us:

  • IT service providers (hosting services, email services, document processing software, website analytics, website operation, website development)

  • Tag management, cookie consent and analytics technology providers (e.g., providers enabling pixels, tags, web beacons or other tracking technologies)

  • Cybersecurity, fraud prevention and data protection service providers responsible for system monitoring, security and backup

  • Customer support and patient or consumer engagement service providers supporting educational materials or product-related information services

  • Event management and advertising, media and social media partners who support targeted advertising, campaign measurement and audience insights

  • Marketing support providers (e.g., handling and dispatch of newsletters)

  • Market research agencies or consultants conducting surveys, interviews and studies

  • Privacy and compliance management service providers (for example, OneTrust LLC)

  • Logistics and delivery providers assisting with shipment of materials, samples or event-related items.

Furthermore, we may share your data with the following third parties:

  • Other entities of the Galderma group. 

  • Other third parties (data controllers):

    • Regulatory authorities (including healthcare authorities, tax authorities and law enforcement agencies) for the purpose of compliance with legal obligations (e.g., under healthcare transparency laws, tax law, drug/medical device safety laws) 

    • Other pharmaceutical companies who are our co-marketing, co-distribution, or other license partners of Galderma if they relate to the product/activity of interest

    • Healthcare professionals and clinical research organizations for the purpose of collaboration

    • Consultants (including lawyers and auditors) for the purpose of compliance with legal obligations and/or safeguarding rights

    • Courts for the purpose of safeguarding our rights

    • Potential buyers or acquirers of all or part of our asset(s) and/or activity(ies) for the purpose of corporate transactions

    • Social media platforms (e.g., Facebook/Instagram, LinkedIn Corporation, TikTok) for the purposes of managing, delivering, and measuring advertising campaigns including audience targeting and retargeting, creation of similar audiences, and analysis of campaign performance

Where any such organization is located outside of your country of residence, the resulting international transfers of Personal Data are carried out in accordance with Section 8 of this Privacy Notice.

 

8. International Data Transfers

 

The storage as well as the processing of your personal data as described above may require that your personal data is ultimately transferred/transmitted to, and/or stored at, a destination outside of your country of residence. When we share your personal data with an entity located outside of your country of residence (e.g. other Galderma entities, third parties), including to countries which have different data protection standards to those which apply in your country of residence, we will put in place, in line with applicable legal requirements, appropriate safeguards to ensure that your personal data is appropriately protected.

 

9. Data Retention

 

We will hold your personal data for as long as it is necessary to fulfil the purposes that we collected it for, taking into consideration the nature of the personal data, the purposes for which we are processing your personal data and the potential risk of harm from unauthorized use or disclosure of your personal data. Therefore, personal data may be kept for as long we reasonably determine it is required for, according to our retention policy and applicable laws.

 

In any case:

  • Personal data in relation to medical information inquiries is kept for at least 10 years after receipt and closure of the inquiry

  • Personal data in relation to pharmacovigilance reports is kept for at least 10 years following termination of Galderma’s marketing authorization for the product related to the report

  • Personal data in relation to product complaints is kept for at least 10 years following termination of Galderma’s marketing authorization for the product related to the report

 

Retention periods may be extended where required by applicable pharmacovigilance or quality regulations. We may also retain personal data further and as necessary for the establishment, exercise or defense of legal claims.

Data that is no longer needed will be securely deleted or anonymized.

 

10 .Rights of Individuals

 

Depending on your jurisdiction, you may have the following rights, in accordance with the applicable data protection laws:

  • Access and to be informed: To request a copy and/or to be informed of the personal data we hold about you.

  • Rectification: To request correction of inaccurate or incomplete personal data.

  • Withdraw consent: To withdraw consent at any time, where consent was provided for processing.

Please note that the exercise of these rights may be subject to limitations and/or restrictions set out in applicable laws; they may also be subject to variations or additional rights may be available to you in your country of residence or place of work.

If you wish to exercise one of these privacy rights, you may submit a relevant request using our Data Subject Request Webform; alternatively, you may also send an email at privacyofficer.au@galderma.com, or write at the local offices at the address included in the ‘Contact Information’ section.

If we do not satisfy your request or if you consider that the processing of your personal data infringes data protection law otherwise, depending on your jurisdiction, you may also have the right to lodge a complaint with a data protection authority in your country of residence, or your place of work or of the alleged infringement.

 

11. Data Security

 

We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it from unauthorized access, accidental loss, or misuse, alteration or unlawful processing. Please note, however, that these protections do not apply to information you choose to share in public areas such as third-party social networks.

 

12. Changes to the Privacy Notice

We might change the way we process your personal data. Therefore, Galderma reserves the right to modify this Privacy Notice at any time. Please check back frequently to see any updates or changes in our Privacy Notice.

13. Contact Information

 

If you have any questions or concerns about this Privacy Notice or your personal data, please contact us at privacy.office@galderma.com.

 

For Australia:
Galderma Australia Pty Ltd,
Level 18, 1 Denison Street,
North Sydney NSW 2060 Australia
privacyofficer.au@galderma.com