This privacy notice tells you what to expect when Medtronic collects information about you (“personal data”) in connection with the activities described below, including when you order Medtronic products and services, when you visit this website and Medtronic locations, when you contact Medtronic, or when you participate in Medtronic events, surveys or clinical studies.  

Unless set out otherwise below, the Medtronic company responsible for processing your personal data is Medtronic International Trading Sárl, Route du Molliau 31, CH - 1131 Tolochenaz, Switzerland or the Medtronic company that you interact with (together, "Medtronic“, “we" or "us”). 

In this privacy notice, we’ll tell you what personal data we collect about you, how we use that information, with whom we share it, what rights you have regarding your information, and how to contact us to exercise these rights. 

This privacy notice does not apply when you have been notified that an alternative notice applies (for example on other Medtronic websites) or where Medtronic processes your personal data on behalf of your medical institution or healthcare professional in connection with your medical treatment. Your medical institution and/or healthcare professional is solely responsible for the processing of your personal data for the provision of your medical treatment and care. 

This notice also does not apply to data processing activities specifically relating to current or former Medtronic employees or applicants – the relevant notice may be requested by contacting AskHR@Medtronic.com.

Personal data we collect and how we use it

This section explains, for each situation, what personal data we may collect, how we use that information and what is our lawful basis to do so. 

You may wish to create a Medtronic online account to take advantages of our services.

What personal data we collect

If you create a Medtronic online user account, the types of personal data we collect or process about you include: 

  • Identification information, such as your name, user ID number, date of birth or age, profile picture; 
  • Location data, such as your country/region and language preference;
  • Login credentials, such as your username/email address and password; 

In addition, if you create a Medtronic online account in your capacity as a healthcare professional, we’ll also process your professional details, such as your profession, your job title and your medical specialty, the name of the institution you work for and your professional email address.

How we use your data   

We will use your data in order to create and manage your account, including to authenticate you and ensure account security. We’ll do so with your consent or based on a contractual relationship we have with you or to take steps at your request, before entering a contract.

We may further use your account information, together with the information collected through Medtronic’s products or services, to communicate with you and provide you with the products and services you requested, unless you have been notified that an alternative notice applies to such use.

Back to top

You can request or order certain Medtronic products and services directly from us (e.g. in our e-shop).

What personal data we collect

If you order our products and services, the types of personal data we collect or process about you include:

  • Your contact information, such as your name, email address or account data. In certain cases, you may choose to also provide us with your phone number (optional) if you want delivery service providers or our support team to be able to contact you via phone about your order; 
  • Your  shipping details, such as your shipping address and instructions;
  • Information about the product and service ordered; and
  • Where applicable, payment information, such as your billing address, account number, payment card details (including card number, expiration date and security code). Depending on the payment method, your information may be shared with a trusted payment service provider. That service provider may process your data for its own purposes (e.g., to monitor, prevent and detect fraud). Please read the privacy policy of the payment service provider to learn more on how they’ll use your data.

How we use your data  

We will use your data as needed to fulfill our contractual obligations to provide you with the products and services you requested and to deliver the products ordered. Your payment details will also be used to protect against, identify and prevent fraud and, where applicable, to handle payment-related complaints or investigations, based on our legitimate interests to do so. With your consent, we may also keep your payment card details to facilitate future orders.

Back to top

When you visit our websites or apps, we may collect certain information by automated means, including cookies and similar technologies, such as Flash cookies, local storage, web beacons and pixels, JavaScript, software development kits (SDKs) and device identifiers. 

What personal data we collect

The information collected in this manner may include your device IP address, domain name, identifiers associated with your devices, device and operating system type and characteristics, web browser characteristics, language preferences, your interactions with our site or app (such as the pages you visit, links you click and features you use, dates and times of access to our site/app, the pages that led or referred you to our site), and other information about your use of our site or app. 

How we use your data 

Cookies and similar technologies (“Cookies”) are used by Medtronic for several reasons. Cookies are sometimes necessary for our sites or apps to operate correctly and secure log-ins to work properly. Cookies allow us to count the visitors to our sites/apps and learn how they use our sites/apps and their features, enabling us to continually improve the visitor’s experience. Cookies may also allow us to provide you with enhanced functionality such as video content, and show you targeted ads on other sites or social media channels. Depending on your location, some Cookies may require your consent. Click here to know more about our use of Cookies and how to manage your Cookie settings and preferences.

Back to top

You may visit our locations in order to interact with our personnel, to provide services or perform certain tasks. 

What personal data we collect

If you visit Medtronic locations, the types of personal data we collect or process about you include:

  • Your contact information and visit details, such as your name, signature and arrival/departure time and date, to enable you to access our premises and provide you with a badge as applicable;
  • Video recordings of you if we operate closed-circuit television (CCTV) systems in the location you visit.

How we use your data

We will use this information for security and safety reasons. We will do so as necessary for the purposes of Medtronic’s legitimate interests in ensuring the security of Medtronic personnel, property and assets and complying with our internal security policies. 

Back to top

You may make an inquiry, require assistance or support by contacting our customer service or support team by phone, email or by using our “Contact Us” form, our chatbots or other customer support tools.

What personal data we collect 

If you contact our customer and support services to make an inquiry or request support, the types of personal data we collect or process about you include:

  • Identification and contact information, such as your name, title, email address, telephone number, address (as relevant);
  • Location data, such as country/region, 
  • Information about you that you submit in your request;
  • Any other information about you necessary for dealing with your request, including data relating to your device or health if you’re a patient;
  • Audio recordings and notes if we record the conversation we have with you;

How we use your data

We will use your data to respond to you, provide you with required support, and follow up on your request, including, where applicable, ensuring compliance with our regulatory obligations and establishing, exercising or defending ourselves from legal claims. We may also keep a record of the communications we have with you for evidentiary purposes and to train our personnel and improve the quality of our services. If you call us, you will be notified at the beginning of the call whether our conversation will be recorded.  

We will use your data for the above reasons based on the following bases:

  • Our need to perform the contract we may have with you (if you are an existing customer), or to take pre-contractual steps at your request;
  • Our legitimate interests, in particular in training our personnel, improving our services to you and defending our legal rights; or
  • Our need to comply with our legal obligations. 

If we need to use sensitive information about you (e.g., health data) as part of your request, we will seek your explicit consent or we will do so as necessary to ensure high standards of quality and safety of our products.

Please note that, in some circumstances, we may use your data to provide technical support on behalf of and in the name of your medical institution or healthcare professional. This is the case if the Medtronic product or service you use was provided to your medical institution or healthcare professional, as part of the services Medtronic provides to them. If that product or service requires technical support, we’ll use your data as directed by your medical institution and/or healthcare professional, as part of your medical treatment. Please contact your medical institution or healthcare professional to learn more on their use of your data for the provision of medical treatment or care. 

Back to top

 

If you’re a patient, your medical institution and/or healthcare professional (your “Medical Institution”) may use Medtronic products and services as part of your medical treatment. In such instance, we may obtain information about you, including health data, as determined by your Medical Institution. We will use this information on behalf of your Medical Institution in order to provide the services requested by your Medical Institution. Please contact your Medical Institution or physician to learn more on the use of your data for the provision of your medical treatment and care. Medtronic is not responsible for this use. In such instance, your data is subject to your Medical Institution’s own data policies and privacy notices.  

When we obtain your data this way, we’ll use it only based on the instructions of your Medical Institution, unless we are required to do so to comply with our regulatory obligations, or your Medical Institution has authorized us to further use your data, as described below.

Health vigilance/Post-Market Surveillance/Recalls/Complaints

As a manufacturer of medical devices, we are subject to regulatory obligations when we place (or make available or put into service) our products on the market. Compliance with those obligations require us to process personal data.

What personal data we collect

The types of personal data we collect or process as a manufacturer of medical devices include:

  • Data allowing the indirect identification of the patient or person exposed to an adverse health event, such as age, year or date of birth, sex, weight, height, or identification number;
  • Data relating to the identification of the product concerned, such as the type of product used, serial number, implant date; 
  • Health data; 
  • Any other information necessary for the assessment of an undesirable health event, such as professional life, consumption of tobacco, alcohol, drugs, life habit and behavior; and
  • Contact details of the person who made a complaint or notified us of an adverse health event, or of any health professional likely to provide details. 

How we use your data 

We will use your data to conduct health-vigilance related activities, manage adverse health events and handle product complaints. We’ll do so to ensure compliance with our legal obligations and with high standards of quality and safety of healthcare and medical devices.

The Medtronic entity responsible for processing your data for the above purposes is the manufacturer of your Medtronic product or the Medtronic affiliate responsible for placing it on the market as mentioned on the product, package label or instructions for use.

If you use Medtronic BioPharma products, please read the Medtronic BioPharma Privacy Notice to learn more about how Medtronic BioPharma processes personal data in the context of pharmacovigilance-related activities, medical information enquiries and product complaints handling related to Medtronic BioPharma products. 

Secondary Use of Data

With the authorization of your Medical Institution, the data obtained as part of the services provided to your Medical Institution may be further used for Medtronic’s legitimate business purposes, including to improve and develop Medtronic products and services, to conduct benchmarking, business analytics or market research, to train and educate Medtronic personnel or healthcare professionals, or to support regulatory filings and the reimbursement of Medtronic products and services, based on Medtronic’s legitimate interests to do so. 

For such purposes, your data will be used in a de-identified, aggregated or otherwise anonymized manner.

Back to top

 

We perform clinical activities, including clinical studies, clinical investigations, clinical surveys and other studies or research activities. In this context, we process personal data of participants to these activities, as well as personal data of healthcare personnel involved in such activities.

What personal data we collect

The types of personal data we collect or process this way will vary depending on the research activity but this will generally include:

  • Information indirectly identifying participants in those research activities (such as age, or date of birth, place of birth, gender, country and department of residence, serial number or alphanumeric code excluding first and last name);
  • Where applicable, administrative data identifying participants that may be obtained by our service provider (such as first and last name, contact details, bank details) for very limited purposes, including to reimburse travel costs and/or to pay compensation; 
  • Data concerning participants’ health, including vital status, and any other sensitive data, as relevant to the subject of the research activity (such as participants’ ethnic origin or data concerning their sexual life);
  • Dates relating to the conduct of the research activity (such as the date of inclusion);
  • Details of participants’ personal and professional life, such as family situation, current profession, business trips, consumption of tobacco, alcohol, drugs, lifestyle habits and behaviors, and any other relevant information;
  • social security affiliation scheme/insurance;
  • participation in other research activities;
  • reimbursement of costs incurred by the participant and annual amount of compensation received, where applicable.

For such activities, we typically have no access to directly identifiable information about patients as that information is kept confidential by the relevant healthcare professional.

If you’re a healthcare professional involved in our (clinical) research activities, the types of personal data we collect or process about you include:

  • Identification data, such as name, gender, professional contact details, bank details;
  • Training and qualifications;
  • Other relevant details of professional life (e.g. professional curriculum);
  • If applicable, identification number in the directory of health professionals;
  • Amount of compensation and remuneration received;
  • Collaboration in research activities;
  • History of access, and connection to the medical data of participants in the research activities, where relevant.

How we use your data

We process your data in order to carry out research activities in the public interest, including to generate evidence to submit to health regulatory authorities in order to comply with our medical device manufacturer’s obligations, to assess the safety, performance and quality of our medical devices, and to develop and improve the safety and performance of these medical devices aiming at enhancing and improving healthcare. 

We will do so based on our legitimate interests in conducting research activities, and for scientific research or to ensure high standards of quality and safety of our products, or with your consent as required by applicable law.

The Medtronic entity responsible for the processing of your personal data is the sponsor or Medtronic entity that determines the purposes of the clinical study or research project, as indicated in the clinical study or research documentation or in other relevant documentation provided by the healthcare professional in connection with the clinical or research activities you participate in.

Back to top

You may wish to participate in one of our physical or virtual events (such as workshops, meetings, webinars or live broadcast events), or we may ask you to share your story, provide testimonial or take part in an interview about your treatment with a Medtronic product.  In this case, we’ll need to process some personal data about you, as described below.

If you’re a healthcare professional receiving or benefitting from Medtronic consultancy, training, events and education services, or if you provide such services to us, please read the Medtronic Privacy Notice for education services to learn more on the use of your data in relation to those services. 

What personal data we collect

If you participate in one of our events, testimonials or interviews, the types of personal data we collect or process about you include: 

  • Identification/contact information , such as your name (or a fictionious name to protect your privacy), email address, nationality, country;   
  • Personal details, such as dietary requirements, where applicable; 
  • Professional information, such as your job type, title; 
  • Product/service of interest to you, where applicable; 
  • Health data, such as the medical condition treated by the Medtronic product (if you’re providing information as a patient);
  • Images, video and/or audio recordings of you, if our event/interview is filmed or recorded. 

How we use your data

We will use your data to organize and facilitate the event/interview, and conduct Medtronic’s educational, promotional and advertising activities. We will do so with your (explicit) consent, where required by applicable law (e.g., if the event is recorded and/or we collect sensitive information such as your health data), or as otherwise necessary for the purposes of Medtronic’s legitimate interests in promoting and supporting Medtronic activities.   

The Medtronic entity responsible for processing your data for the above purposes is the Medtronic affiliate organizing the event/interview (in practice, the Medtronic business entity of the country where the event takes place).

Surveys

From time to time, we may invite you to participate in a Medtronic survey to gather your feedback to help us determine customer satisfaction levels, identify areas of potential improvement or to carry out market research. 

What personal data we collect 

To the extent possible, we will gather your feedback in an anonymous manner. In some cases however, the survey may gather identifiable respondent information.  In such instance, the types of the personal data we collect or process about you include:

  • Identification/contact information, such as your name, email address, phone number;
  • Professional details (if you are a business customer), such as your employer’s details, specialty, professional experience, professional qualifications;
  • Opinions, views or information you choose to provide us as part of your survey responses.  If you’re a patient, this may include your age and information about your health, such as your medical condition, type of Medtronic product/services you are treated with, details of the medical procedure you underwent as a patient;
  • Where applicable, information collected by automated means (including cookies), such as your IP address, and survey metadata (e.g., the language you take the survey in, duration of your survey response, last date the survey was started).

How we use your data

We will use your personal data to conduct the survey, including to send it to you, allow you to submit your survey responses, prevent survey fraud, analyze the survey results, and improve or develop our products and services accordingly, based on our legitimate interests to do so or with your consent, where required by applicable law. 

The Medtronic entity responsible for the processing of your personal data for the above purposes is the Medtronic entity that sends you the survey, or the entity indicated in the survey questionnaire or notice provided to you at the time of data collection. 

Back to top

You may send us a private or direct message via social media, or you may communicate about us or Medtronic products on social media (e.g., if you participate in our online communities, share a comment about a Medtronic product or if you tag Medtronic in your post).

What personal data we collect

If you interact on social media with or about us, the types of personal data we collect or process about you include:

  • Social media information, such as your social media username, profile picture, country;
  • Any information about you that is contained in your comments, posts or other content about Medtronic that you share on social media services.

How we use your data

We will use your data to review or respond to your message or comments, and where applicable, to provide you with the required support and take any necessary follow-up actions.  If you communicate about us or our products, we will also use your data to gain a general understanding of what people are saying about us and our products. We’ll do so based on our legitimate interests, in particular in improving our products and services.

(back to top)

We may share relevant information and updates about our products and services, either via direct communication with you, or by using online advertisements.

Direct Marketing Communications 

When we communicate with you directly to promote our product and service offerings (e.g. by email or phone), we will use your personal data to do so. 

What personal data we collect  

The types of personal data we collect or process about you to send you such communications include:

  • Information you have shared directly with us (e.g. when you complete a form to sign-up for such communications), such as your name,  email address and/or phone number, age and status as a patient or caregiver, or – if you are a business customer, your professional details; 
  •  Information that we have obtained through our interactions with you, such as expressions of interest you have made to our sales representatives;
  • Publicly available information about you (e.g. from the public website of the medical institution where you work); 
  • Metadata collected from cookies or similar techniques, including to understand how you have interacted with our website and whether you have opened or clicked on the content in the emails that we have sent you. For more information on how we use cookies, and your choices in that regard, please click here.   

How we use your data

We use such information to tailor our communications to your specific interests and preferred method of communication, to avoid sending you communications that are not of interest or for which you have not consented, and to follow up with you on the subjects that appear to be most relevant and useful for you. To this end, we may organize the data we collect into interest-based groups.  

We will ask you to "opt-in" or consent to the use of your personal data for the purposes of such communications, where required by law. You can decide at any time to stop such communications by using the opt-out procedure provided in the relevant message (e.g., clicking the unsubscribe link in our promotional emails), or alternatively by contacting us as specified in the  How to Contact Us section below.  If permitted by applicable law, we may rely on our  legitimate interests to carry out some of the activities mentioned above. 

Please note that if you choose to no longer receive promotional messages from us, we may still continue to send you relevant information for other lawful purposes, such as to administer any account or contract you may have with us, send you communications of an operational nature (e.g., planned outage or updates), respond to your requests and as required by law (e.g. in case of a product recall). 

The Medtronic entity responsible for processing your data for the above purposes is the Medtronic affiliate contacting you (in practice, the Medtronic business entity of the country or region where you are located).

Online Advertising 

From time to time you may come across Medtronic ads online, including on social media platforms. Such ads are often presented to you based on your perceived interests, as gathered from your activities on social media or browsing the internet.  

What personal data we collect and how we use it 

Online advertising may be based on your search terms (in the case of ads on search engines) or user information on online platforms (such as the email address associated with your social media account, the country or professional interests selected on a social media platform). 

In some instances, we will use your email address to show ads for our products and services on social media platforms. To do so, we will provide your email address, in a hashed or other secure manner, to the social media platform. The social media platform will then match your email address with the personal data (such as email addresses) you provided to them, and use that information to show you, or other platform users, a particular Medtronic ad. For more information on how social media platforms use your data, please refer to their privacy notices.  

We may also place on our websites or apps advertising cookies or similar technologies that are made available by social media platforms or other third parties. If you visit our websites or apps and accept those advertising cookies and similar technologies, where required by law, then the information they collect (such as device identifiers and information on the pages visited) may also be used to display relevant ads for our products and our services on the social media platform or third party’s site, and create interest based profiles for advertising purposes. Often Medtronic itself will not actually receive identifiable data about you when such ads are displayed, but we may be able to further tailor our advertising to you depending on what ads you have already seen, and we can receive aggregated statistics on how many ads have been viewed and clicked on, etc. 

We will rely on your consent for the use of your data for online advertising purposes (e.g. when you accept advertising cookies), or otherwise on our legitimate interest to do so where legally permissible. You should be able to configure your cookie settings on websites that use tracking cookies for advertising purposes. For more information on how Medtronic uses cookies, and how to configure your preferences on Medtronic websites, please see our Cookie Policy.    

The Medtronic entity responsible for processing your information for the above purposes is the entity placing the advertisement (i.e. the Medtronic business entity in your country or region). For advertising on social media and other platforms, the platform provider itself will also have responsibility for how the advertising on its platform works. Please refer to the policies, privacy controls, and notices on the platform itself for more information on how advertising may be displayed to you, and your choices in this regard. 

Back to top

If you or the entity that employs you have a business relationship with Medtronic – as a current or prospective supplier, business customer or partner, distributor or agent, we will process personal data to manage this relationship and ensure compliance with applicable laws. 

For more information, please read the Medtronic B2B Privacy Notice.

Back to top

In some circumstances, we are obliged to process personal data to comply with legal requirements and our policies, to perform auditing and other internal functions, or for litigation and dispute resolution purposes. 

What personal data we collect

When this is the case, the types of personal data we collect or process about you include your identification and contact information, and any other information as is necessary and relevant to the particular case, e.g., in the event of an (internal) audit, information contained in documents and materials audited, or in the event of litigation, information gathered in the evidence necessary for the litigation. 

How we use your data

We will use your information - in an anonymized, de-identified or redacted form, where appropriate -  in order to: 

  • comply with applicable legal requirements, regulations, court orders or other legal processes;
  • comply with our policies; 
  • establish, exercise or defend our legal rights;
  • conduct (internal) audits, investigations or due diligence checks for the above reasons. 

We will do so as necessary to comply with legal obligations to which we are subject in your country or region, or as needed to fulfil our legitimate interests, in particular in conducting business in compliance with all applicable laws and the highest ethical standards,  protecting our rights or property; and asserting or defending legal claims, or with your consent where required by law.  

Back to top

Data sharing

Only duly authorized Medtronic personnel will have access to your personal data as needed to perform their job duties. In addition, we may share your personal data with third parties for the purposes described in this privacy notice.

We may share your personal data with:

  • Medtronic affiliated companies: given the corporate structure of Medtronic, your personal data may be shared with other affiliates within the Medtronic group.
  • Service providers: we may share personal data with relevant third-party service providers, who act on our behalf to fulfil the activities noted in this privacy notice, including IT providers, providers of communication tools and customer relationship management systems, survey tool providers or platforms, event organization management tools providers, outsourced operations such as Accounts Payable providers, email automation tool providers, cloud hosting service providers, and contract management platform providers.  
  • Business partners and other specialists: Medtronic may also share personal data with external organizations with which it has partnered (such as research partners and as part of co-branding initiatives), and with external specialists or professional advisors within a particular field (such as lawyers, consultants, tax advisors, auditors, specialist delivery providers, banks, payment service providers, and benchmarking agencies).
  • Parties to a corporate transaction:  We also reserve the right to share your personal data in the event we sell or transfer all or a portion of our business or assets (including in the event of a merger, acquisition, joint venture, reorganization, divestiture, dissolution, or liquidation). 
  • Public authorities and others for legal reasons:  In addition, we may disclose your personal data with other parties, including public and judicial authorities, (1) if we believe we are required to do so by law or legal process (such as a court order or subpoena); (2) in response to requests by government agencies, such as law enforcement or regulatory authorities; (3) to establish, exercise or defend our legal rights; (4) when we believe disclosure is necessary or appropriate to prevent physical or other harm or financial loss; or (5) in connection with an investigation of suspected or actual illegal activity. 
  • Others, per your request: With your consent, we will share your personal data with any other parties you choose, such as your caregivers.  

International transfers

The above recipients may be located in countries other than the country in which the information originally was collected. Those countries may not have the same data protection laws as the one in which you initially provided the information. When we transfer your personal data to recipients in other countries (including the United States), we will implement appropriate safeguards to ensure an adequate level of data protection as provided for by applicable law. This can include selecting service providers and business partners located in a country recognized as providing an adequate level of data protection, and implementing safeguards based on standard data protection clauses (such as the European Commission’s Standard Contractual Clauses), where applicable. Subject to applicable laws, you may request a copy of these safeguards by contacting us as specified in the How to Contact Us section below. 

Data retention

We will keep your personal data for so long as necessary to fulfill the purposes for which we are allowed to use them, as set out in this privacy notice. Your data may be kept longer in order to take into account applicable statute of limitation periods, or as otherwise required by law. For more information on the retention of your personal data, please contact us as indicated in the How to Contact Us section below.

Your privacy rights

You may have certain rights in relation to the personal data we process about you, depending on the reason for which we process your data or the lawful basis we rely on to do so. To the extent provided by applicable law, you can:

  • request access to the personal data we hold about you. Your request should contain a detailed, accurate description of the personal data you want access to;
  • ask us to correct information about yourself you think is inaccurate or incomplete. 
  • object, based on your particular situation, to any use or processing of your personal data based on our legitimate interests;
  • withdraw the consent you previously provided to us for using your data. If you do so, this will not affect the lawfulness of data that we have processed before you withdrew consent;
  • ask us to receive, in a structured, commonly used and machine-readable format, the personal data you have provided to us and to have this information transmitted to another company, where it is technically feasible. This right may apply only in certain circumstances, where you have provided your personal data to us based on your consent or a contract to which you are party;
  • ask us to restrict or limit our use of your personal data. 
  • ask us to delete your personal data. Note that we may not be able to delete all your personal data as this right only applies in certain circumstances, e.g., when your data is no longer necessary in light of the purposes explained in this privacy notice and there is no legal or regulatory obligation which obliges us to keep it. 

If you wish to exercise your rights, please contact us as specified in the How to Contact Us section below. In certain cases, we may ask you to confirm your identity before we can process your request.

Depending on your location, you may have the right to file a complaint with a data protection authority, in particular in the country of your habitual residence, if you are not satisfied with our response.

How to contact us

If you would like to exercise your privacy rights or if you have any questions about this privacy notice, please contact us at rs.privacyeurope@medtronic.com

Medtronic’s Data Protection Officer may be contacted at rs.europeanDPO@medtronic.com.  

Updates to this privacy notice

This privacy notice may be updated periodically to reflect changes in our personal data practices. We will indicate at the top of the privacy notice when it was most recently updated.

Back to top