Tigermed Japan, Inc. (the “Company”) handles personal data of individuals in the European Economic Area (EEA) (*1), as defined in Section 1, in accordance with this policy.
Customers who use the Company’s services to process medical data containing personal data may be considered “Controllers” under the General Data Protection Regulation (EU) 2016/679 (the “GDPR” *2), while the Company may be considered a “Processor” under the GDPR’s extraterritorial scope. Accordingly, customers are responsible for complying with applicable laws and regulations, including the GDPR. The Company does not provide legal or audit advice and does not guarantee that their products or services comply with applicable laws and regulations.
1. Definition of Personal Data
“Personal data” means any information related to an identified or identifiable natural person. An “identifiable natural person” is a person who can be identified, directly or indirectly, for example through identifiers such as a name, identification number, location data, or online identifier, or through factors specific to the individual’s physical, physiological, genetic, mental, economic, cultural, or social identity.
2. Compliance with Applicable Laws and Regulations
When handling personal data, the Company complies with applicable Japanese laws and regulations, as well as the General Data Protection Regulation (GDPR) and applicable laws and regulations of EEA member states.
3. Cross-Border Transfer of Personal Data
On January 23, 2019, Japan received an adequacy decision under Article 45 of the GDPR, enabling the smooth transfer of personal data between Japan and the EU. Accordingly, Standard Contractual Clauses (SCCs) or other standard data protection clauses are not required for personal data transfers from the EEA to Japan. However, at a customer’s request, the Company may enter into such clauses before accepting such transfers. The Company handles personal data transferred to it in accordance with applicable data processing agreements and Japan’s Act on the Protection of Personal Information, including the Supplementary Rules applicable to personal data transferred from the EEA under the adequacy decision.
4. Management of Personal Data
The Company manages personal data in accordance with its Privacy Policy and Personal Information Handling Policy described below.
Notes
GDPR: General Data Protection Regulation
EEA: European Economic Area