knowledge that any such governmental authority is considering such action; (vi) has filed, obtained, maintained or submitted all material reports, documents, forms, notices, applications, records, claims, submissions and supplements or amendments as required by any Applicable Laws or Authorizations and that all such reports, documents, forms, notices, applications, records, claims, submissions and supplements or amendments were complete and correct in all material respects on the date filed (or were corrected or supplemented by a subsequent submission); and (vii) has not, either voluntarily or involuntarily, initiated, conducted, or issued or caused to be initiated, conducted or issued, any recall, market withdrawal or replacement, safety alert, “dear healthcare provider” letter, or other notice or action relating to the alleged lack of safety or efficacy of any product or any alleged product defect or violation and, to the Company’s knowledge, no third party has initiated, conducted or intends to initiate any such written notice or action.
(oo) Privacy Laws. The Company and its Subsidiaries are, and at all prior times were, in material compliance with all applicable data privacy and security laws and regulations, including, without limitation, to the extent applicable, if any, the Health Insurance Portability and Accountability Act (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (the “HITECH Act”) (42 U.S.C. Section 17921 et seq.); and the Company and its Subsidiaries have taken all necessary actions to comply in all material respects with the European Union General Data Protection Regulation (“GDPR”) (EU 2016/679) (collectively, “Privacy Laws”). To ensure compliance with the Privacy Laws, the Company and its Subsidiaries have in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling and analysis of Personal Data (the “Policies”). The Company provides accurate notice of its Policies to its customers, employees, third party vendors and representatives, as applicable. The Policies provide accurate and sufficient notice of the Company’s then-current privacy practices relating to its subject matter and such Policies do not contain any material omissions of the Company’s then-current privacy practices. “Personal Data” means: (i) a natural person’s name, street address, telephone number, email address, photograph, social security number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) Protected Health Information as defined by HIPAA; (iv) “personal data” as defined by GDPR; and (v) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual orientation. None of such disclosures made or contained in any of the Policies have been inaccurate, misleading, deceptive or in violation of any Privacy Laws or Policies in any material respect. The execution, delivery and performance of this Agreement or any other agreement referred to in this Agreement will not result in a material breach of any Privacy Laws or Policies. Neither the Company nor any Subsidiary: (y) has received notice of any actual or potential liability under or relating to, or actual or potential violation of, any of the Privacy Laws, and has no knowledge of any event or condition that would reasonably be expected to result in any such notice; or (z) is a party to any order, decree, or agreement that imposed any obligation or liability under any Privacy Law.
(pp) IT Systems. (i)(x) To the Company’s knowledge, there has been no material security breach, attack or other compromise of or relating to any of the Company’s and its Subsidiaries’ information technology and computer systems, networks, hardware, software, data (including the data of their respective customers, employees, suppliers, vendors and any third party data maintained by or on behalf of them), equipment or technology (“IT Systems and Data”), and (y) the Company and its Subsidiaries have not been notified of, and have no knowledge of any event or condition that would reasonably be expected to result in any security breach, attack or compromise to their IT Systems and Data, (ii) the Company and each Subsidiary has complied, and are presently in compliance with, all applicable laws, statutes or any judgment, order, rule or regulation of any court or arbitrator or governmental or regulatory authority and all industry guidelines, standards, internal policies and contractual obligations relating to the privacy and security of IT Systems and Data and to the protection of such IT Systems and Data from unauthorized use, access, misappropriation or modification and (iii) the Company and each Subsidiary has implemented backup and disaster recovery technology consistent with industry standards and practice.
(qq) Export and Import Laws. Each of the Company and the Subsidiaries, and, to the Company’s knowledge, each of their affiliates and any director, officer, agent or employee of, or other person associated with or acting on behalf of, the Company has acted at all times in compliance with applicable Export and Import Laws (as defined below) and there are no claims, complaints, charges, investigations or proceedings pending or expected or, to the knowledge of the Company, threatened between the Company or any of the Subsidiaries and any Governmental Authority under any Export or Import Laws. The term “Export and Import Laws” means the Arms Export Control Act, the International Traffic in Arms Regulations, the Export Administration Act of 1979, as amended, the Export
- 12 -