You are on page 1of 12
DATA SHARING AGREEMENT This Data Sharing Agreement (“Agreement”) is entered into this day of at « by and between: ZUELLIG PHARMA CORPORATION, a corporation organized and existing under the laws of the Republic of the Philippines. with business address at Km 14 West Service Road, South Super Highway cor Edison Ave., Sun Valley. Paranaque City 1700, Philippines, duly represented herein by its President, Danilo J. Cahoy, and hereinafier referred to as “ZPC™: = and - CONSOLIDATED PAPER PRODUCTS INC, a corporation organized iz under the laws of Philippines with business address at 14 Narciso St. jumay, Valenzuela City, duly represented herein by its President. Johnny . Sy, and hereinafier referred to as “Counterparty ZPC and Counterparty shall be individ the “Parties ly referred to as a “Party” and collectively as WITN 1 WHEREAS, the Parties desire to execute this Agreement to supplement the Logistics § Agreement for the purposes set forth in Seetion | below: WHEREAS. ZPC in the course of providing Logistics services, processes, collects, uses a stores, certain personal and sensitive personal information (collectively. the Information”) of individual clients, patients and healthcare professionals that use or eZ Consult app (“Data Subjects"): WHEREAS, Counterparty likewise processes, coll formation of the Data Subjects who also use or register . uses and stores, certain Personal its eZConsult app: WHEREAS. ZPC and Counterparty have agreed to disclose to each other Personal Information pertaining to the Data Subjects in order to enable (a) Counterparty to offer and/or provide [counterparty services] to the Data Subjects, (“Services”).: and (b) ZPC to offer and/or provide to Data Subjects the services and products available in its ¢7/Consult app (*ZPC Services”) (each of the Counterparty Services and the ZPC Services shall be hereafter referred to as “Services”): and WHEREAS, considering the requirements for disclosure and transfer of Personal Information under Republic Act No, 10173 (“Data Privacy Act’), its Implementing Rules and Regulations (IRR”) and other issuances of the National Privacy Commission NPC") related thereto. the Parties have agreed to enter into this Agreement in order to establish adequate safeguards for data privacy and security of the Personal Information of the Data Subjects, and uphold the rights of the Data Subjects. NOW THI EFORE, for in considei ion of the foregoing premises, the Parties hereby agree as follows Purposes The Personal Information to be shared and disclosed by one Party to the other Party shall be used and processed by the latter only in connection with the latter's offering and/or provision of its Services to the Data Subjects. [Specifically, the use and processing of such Personal Information shall only be conducted for the following purposes: (@) offering and providing information on the Services to the Data Subjects: (b) processing orders for the Services made by Data Subjects (“Service Orders”), including arranging for the delivery of the same and communicating with the Data Subjects with respect to the Service Orders: (c) generating aggregate information and statistic: and their Service Orders and preferences: and regarding the Data Subjects ich, ty is strictly prohibited from using, and shall not use and process, the Personal Information of Data Subjects shared and disclosed by the other Party for purposes other than the foregoing. Each Party confirms that only the Parties and the Data Subj online access to the Personal Information of Data Subjects subject of this Agreement. provided that a Data Subject shall have online access only to his/her own Personal Information subject of this Agreement. The Parties confirm that it is important for them to have online access to the said Personal Information to to have seamless authorized and secure sharing of information, which is necessary to facilitate the implementation and delivery of the Services, ensure data integrity and availability and avoid duplication. sues. Fach Party shall have real-time and 24/7 online access to the Personal Information of Data Subjects subject of this Agreement using the app made available by ZPC. except during scheduled or emergency maintenance or down! cts shall be given Each Party undertakes and shall ensure that access to Personal Information of Data Subject under its control or custody shall be done only via a secure encrypted link and it shall deploy middleware for such purpose. Personal Inform: ion Processors The Parties agree that the following personal information proce: appointed by each of them shall have acce purposes of processing the sors to Personal Information of Data Subjects for me in accordance with the relevant Party’s instruction: For ZPC: Name: The General Manager Address: Km 14 West Service Road, South Super Highway corner Avenue, Barangay Sun Valley, Paranaque City Other Contaet Details: +632 $9092: Edison For Counterparty: Name: Richelle R. Llosala Address: 14 Narciso St. East Canumay Valenzuela City Other Contact Details: 0922-89858 11 In case during the term of this Agreement. additional personal. information processors are engaged or appointed by a Party or any of the above personal information processors are replaced or their services terminated. the Party so appointing additional Personal information processors or replacing or terminating a personal. information processor shall promptly advise the other Party of the Description or Categories of Personal Information For the fulfillment of the abovementioned purposes, the following Personal Information of the Data Subjects may be shared and disclosed by a Party to the oth Party (a) Name (Last Name: (b) Gender (©) Email Address: (a) Contact Numbers: (e) Date of Birth: (0) Current Address: (g) Clinical Information: (h) [insert others] Name/Middle Name); Notwithstanding any prov obligation to share, disclose or transle on herein to the contrary, either Party has no any other Personal Information to the other Party Duration and Termination of Agreement ‘This Agreement shall take effect on the date of its execution and shall bind the Parties for as long as the Logistics Service Agreement dated between the Parties is in full force and ef Either Party may terminate this Agreement if the other Party fails to perform, ha made or makes any inaccuracy in, or otherwise materially breaches. any of its obligations, covenants, or representations, and said Party fails to immediately remedy the same within 30 days from receipt of a written notice from the other Party reasonabl detailing the breach, Method of Disclosure, Transfer and Processing ‘The Personal Information of the Data Subjects will be provided by one Party’ to the other Party through electronic upload. The Parties undertake to ensure the secuity of the Personal Information of Data Subjects while in transit or while being transmitted through the channels or media authorized under this Agreement. Each Party shall process Personal Information of Data Subjects disclosed or transferred 10 it pursuant to this Agreement in accordance with the methods and other terms and conditions of its privacy notice, statement or policy that apply to its processing of such personal information (-Privaey Policy). Each Party shall ensure that the relevant Data Subjects are informed or provided a copy or access to its Privaey Poli Designated Data Center Location for ZPC: Singapore Designated Data Center Location for Counterparty: During the term of this Agreement, the Parties agree that the Personal Information of Data Subjects disclosed, shared or transferred pursuant to this Agreement will be housed in the relevant Designated Data Center Location set forth above, unless the Parties otherwise expressly agree in writing, Safeguards for Data Privacy and Security Each Party shall establish reasonable and appropriate safeguards and security measures to ensure the confidentiality, integrity and security of the Personal Information of Data Subjects shared or disclosed by the other Party pursuant to this Agreement, It shall be responsible in preventing the unauthorized access and use of such Personal Information in its custody. It is likewise prohibited from further sharing or disclosing such Personal Information to any unauthorized party, including its affiliates. without the prior written consent of the other Party or the Data Subjects, as appropriate. Each Party shall implement and maintain a security program in accordance with industry standards, which shall include security measures intended to protect the Personal Information of Data Subjects against accidental or unlawful destruction, alteration, closure or unauthorized or unlawful processing. Each Party shall regularly monitor its compliance with these security measures. In the event that there is a breach in its data security, it shall notify the Data Protection Officer or any other appropriate officer of the other Party in writing, immediately after discovery of such data breach or upon reasonable belief that a data breach has occurred. Both Parties shall use encryption method which meets the most appropriate standard recognized by the information and communications technology industry, such as Advanced Encryption Standard with a key size of 256 bits (A The foregoing obligations and undertakings of each Party shall continue and shall survive the termination of this Agreement for as long as such Party processes, uses or stores Personal Information of Data Subjects shared and disclosed by the other Party. Data Breach Management Each Party shall regularly monitor its compliance with the security measun provided in Section 7 of this Agreement, In the event that there is a breach in its data security affecting Personal Information of the Data Subjects. it shall notify the Data Protection Officer or any other appropriate officer of the other Party in writin immediately afier discovery of such data breach or upon reasonable belief that such data breach has occurred. The following must be included in such written notice if known at the time of notice: * General circumstances, nature of the data breach, and Personal Information of Data Subjects possibly involved: * Number and/or identities of Data Subjects affected; Steps taken to reduce the harm or negative consequenees of the data breach: ‘The representatives of the affected Party for the purpose of addressing the data breach and their contact details: and + Any assistance to be provided to th ullfected Data Subjects, The notice contemplated above shall be delivered by the affected Party to the other Party immediately and in no event later than Qventy (24) hours after the oceurrenc of such data breach and shall not be delayed for investigation purposes. Each Party shall cooperate fully with the other in investigating and responding to each suecessfil data breach affecting Personal Information of Data Subjects. Retention, Destruction, or Disposal of Personal Information Unless applicable laws or regulations allow or require a longer period for retention, the Personal Information subject of this Agreement shall be kept and retained by the Parties for so long as may be necessary for the implementation or delivery of the relevant Services or afier [INSERT] years from the termination of this Agreement, whichever comes later, Upon termination of this Agreement, each Party shall. upon instruction of the other Party, destroy, delete or return to the latter all Personal Information of Data Subjects that the former received from the latter within thirty (30) days from the effective date of termination, unless the former is mandated or permitted by maintain a copy thereof for a longer period, plicable law to Personal Information of Data Subjects in the custody of a Party that requir. disposal shall be disposed of and/or discarded by such Party in a secure manner that would prevent further proc unauthorized acc losure to any other person or entity 10. Other Obligations of the Parties (a) Each Party shall comply with all applicable data privacy laws and regulations in the Philippines, including the Data Privacy Act. (b) Each Party shall ensure that access to Personal Information of Data Subj shared and disclosed by the other Party pursuant to this Agreement is limited only to its personnel, employees. agents, or representatives who need acce: for the fulfillment of the purposes set forth in Section | of this Agreement (c) Each Party shall require that each person entrusted by it with the processing of Personal Information of Data Subjects hereunder has undertaken to comply With the principle of data seerecy and has been duly instructed about the applicable data protection law, Such persi have a. confidentiality agreement with such Party with terms that are consistent with and not le (d) Whenever requested in writing, ach Party shall make available to the other Party all information necessary to demonstrate its compliance with the obligations hereunder and those laid down in the Data Privacy Act, its IRR and other -gulations issued by the NPC. (c) Whenever requested in writing by the other Party, each Party shall assist the other Party in fulfilling its obligation to respond to requests from Data Subj relative to the exercise of their rights pertaining to their Personal Information disclosed, shared or transferred to it pursuant to this Agreement. 11. Indemnification and Limitation of Liabi Each Party hereby agrees to indemnify and hold the other Party. its directors, officers, employees and personnel harmless from any damages, loss, liability, ot costs (including reasonable attorney's fees and the costs of enforcing this indemnity) arising out of or resulting from any negligence or breach of its obligations under or in connection with this Agreement, including any breach of applicable mandatory statutory obligations relating to the processing, use and storage of the Personal Information of Data Subjects disclosed, shared or transferred to it pursuant to this Agreement. 12. 13. Notwithstanding any other provision in this Agreement, neither Party shall, to the maximum extent permitted under applicable law. be made liable to the other Party under is Agreement for any punitive, exemplary, indirect, incidental, special or consequential damages, whether foreseeable or unforeseeable and whether based upon lost goodwill, lost revenue, income or profits, loss of use of money. work stoppage, impairment of other assets, or otherwise and whether arising out of breach of warranty, breach of contract, strict liability in tort, negligence, misrepresentation or otherwise. ights of Data Subjects Both Parties undertake to respect and uphold the rights of Data Subjects as led under the Data Privacy Act, its IRR and other issuances related thereto, ssuances of the NPC. provi includin, For purposes of inquities, requests or complaints that may be filed by the Data Subjects, the NPC or any other concerned persons. the personal information controllers under this Agreement are each of the Parties. A Data Subject may exercise any of his/her rights as a data subject in accordance with applicable laws and regulations, Each Party undertakes to promptly provide the necessary information, request or complaint forms and guidance to any Data Subject who may wish to exercise his/her rights in relation to any Personal Information subject of this Agreement. Onward Disclosure Onward disclosure of any Personal Information shared by a Party (“Disclosing Party") to the other Party (“Receiving Party”) under this Agreement is permitted only with the explicit consent of the Disclosing Party. A Receiving Party may further disclos the Personal Information to third parties only to the extent and only for such purposes permitted by the Main Agreement and this Agreement. A Receiving Party agrees that any use of Personal Information other than that provided in the Main Agreement or this Agreement is strietly prohibited. A Disclosing Party will treat any such prohibited disclosure as a data breach under the terms of the Main Agreement or this Agreement. A Disclosing Party agrees to permit omvard sharing to the relevant personal formation processors of the Receiving Party mentioned in Section 2 of this Agreement and to the named third parties listed in Annex A which have been validly appointed by the Receiving Party as its service providers, A Receiving Party and the permitted third parties appointed by it receiving Personal Information subject of this Agreement must execute an agreement with terms and conditions similar or at par to those provided in this Agreement. 14. 16. sing Party retains the right to seek assurances that the standards pro} herein are in place amongst any third parties to whom Personal Information i pursuant to this Agreement or the Main Agreement. Designated Data Protection Officers; Obtaining Copies of this Agreement The Parties confirm that for the purpose of this Agreement. their designated Data Protection Officers are as follows: For ZP Name: Diwata De Leon Contact No.: +632 8908, Email: DDeLcon@zuell ma.com For Counterparty Name’ Richelle R. Llosala Contact No.: 0922-8985811 Email: llosala@consolidatedpaper.net A Data Subject may obtain a copy of this Agreement by filing a request therefor with any of the above designated Data Protection Officer. provided that upon agreement of both Parties. any detail or information that constitute trade or industrial secrets or confidential and proprietary business information or that could endanger either Party's computer network or system. or expose to harm the integrity, availability or confidentiality of the Personal Information under its control or custody shall be red! in the copy that shall be provided to the requesting Data Subject. Periodic Review This Agreement shall be reviewed by both Parties on time upon request of either Party. The Parties hereby a contents or at any NPC to review the weest oF require any the Parties shall execute an amendment or addendum within ifieen (13) days from notice from the NPC containing its observations and suggestions or requirements or within such longer period as may be allowed by the NPC or applicable law in order to be compliant with the provisions of the Data Privacy Act. Notwithstanding any provision herein to the contrary, this Agreement shall not apply to Personal Information of Data Subjects which ate collected and processed by a Party independent of the other Party even if they are the same with the Personal Information subsequently shared to it by the other Party. Such Personal Information of Data Subjects which are collected and processed by a Party independent of the other Party shall not be deemed Personal Information of Data Subjects disclosed, shared, or transferred to it pursuant to this Agreement. 17. Miscellaneous (a) Either Party may not a hereunder in whole or sign this Agreement nor any of its rights and obligations part without the prior written consent of the other Party. (b) This Agreement shall be governed by the laws of the Republic of the Philippines. (c) In the event of inconsistencies between the provisions of this Agreement and any other contracts/agreements between the Parties, the provisions of this Agreement hall prevail with respect to all matters pertaining to Personal Information of the Data Subjects disclosed, shared or transferred pursuant to this Agreement (d) Any provision or stipulation in this Agreement which may be declared void or unenforceable by final judgment of a competent court shall not affect the validity ot enforceability of the other provisions or stipulations not affected by such declaration, IN WITNESS WHEREOF. the Parti the place above written. have executed this Agreement as of the date and at ZUELLIG PHARMA CONSOLIDATED PAPER CORPORATION PROD! DANILO J. CAHOY Name} JOHNNY O.SY ion: President & General Manager Positidh: President Witnesses: ZUELLIG PHARMA CORPORATION —_ CONSOLIDATED PAPER PRODUCTS INC. Name: Diwata De Leon Position: Data Privacy Officer Date: ACKNOWLEDGM! Republic of the Philippines) City of )ss. BEFORE ME, a Notary Public in and for the . this day of. __. personally appeared: NAME ID noJ/Validity/Place of Iss ZUELLIG PHARMA CORPORATION By: Name CONSOLIDATED PAPER PRODUCTS INC. By: Name:JOHNNY 0. SY known to me and to me known to be the same persons who executed the above DATA SHARING AGREEMENT, consisting of (_) pages, including this page where this Acknowledgment appears, acknowledged to me that the same is their own fiee and voluntary act and deed as well as the voluntary act and deed of the entities/corporations herein represented IN WITNESS WHEREOF, I have hereunto set my hand the day. year and place above written, NOTARY PUBLIC Series of 20__ 10 crn A B. Annex A. Permitted Service Providers Appointed by the Parties sellig Pharma Corporation: 1 For Counterparty 12

You might also like