Getinge Privacy Policies and Directives
The below documents are some of Getinge’s internal policies and directives related to processing of personal data. In these documents we give guidance on what personal data is, the fundamental principles of GDPR, what legal bases there are etc. We provide information to our employees related to certain topics such as personal data breaches and data retention.
Getinge Data Privacy Global Policy
This policy provides transparent and clear information on how Getinge guarantees its employees and partners the protection of their personal data and privacy rights.
Personal Data Retention Directive
(not made public)
Getinge is committed to processing personal data in accordance with applicable data protection laws, including complying with applicable personal data retention requirements.
Getinge has established a Personal Data Retention Policy to provide high-level guidance on the storage and retention of personal data. This guideline provides Getinge companies with advice on how to comply with data protection laws when setting retention periods for personal data and considerations to be taken into account when retaining personal data.
Getinge Companies should consider whether they are subject to additional laws and regulations in the countries in which they operate, such as laws governing tax and financial information, employee health and other benefits, which may require data, whether or not it qualifies as personal data, to be retained for a specific period of time.
Personal Data Breach Directive
(not made public)
Getinge is committed to processing personal data in accordance with applicable data protection laws, including adhering to applicable personal data breach requirements.
Getinge has implemented a Personal Data Breach Directive and a Personal Data Breach Instruction to provide the necessary guidance to:
- Assess the seriousness of personal data breaches
- To ensure the safety of persons and property.
- To provide the necessary guidance to assess the seriousness of personal data breaches and,
- To notify the affected person(s) and the competent supervisory authority in accordance with legal obligations.