knowledge, agents and contractors has committed any prohibited act, made any statement of material fact or made any material omissions that would reasonably be expected to provide a basis for FDA to invoke the FDA Application Integrity Policy or for any other governmental agency to invoke a similar policy. The Company and its subsidiaries have filed, maintained, and submitted all reports, documents, forms, notices, applications, records, submissions and supplements or amendments as required by any applicable law or regulations, and all such reports, documents, forms, notices, applications, records, submissions and supplements or amendments were complete and accurate on the date filed in all material respects (or were corrected or supplemented by a subsequent submission). Neither the Company, its subsidiaries nor any of their respective employees, officers, directors, and to the Company’s knowledge, agents and contractors has made any materially false statements on, or material omissions from, any notifications, applications, approvals, reports and other submissions required to be submitted to FDA or any other governmental entity. The manufacturing facilities and operations of the Company and its subsidiaries and, to the Company’s knowledge, their respective manufacturers and suppliers, are and have been in compliance in all material respects with all applicable laws, regulations, and requirements, including applicable Health Care Laws.
(xx)Cybersecurity. The Company and its subsidiaries’ information technology assets and equipment, computers, systems, networks, hardware, software, websites, applications, and databases (collectively, “IT Systems”) are adequate for, and operate and perform in all material respects as required in connection with the operation of the business of the Company and its subsidiaries as currently conducted. The Company and its subsidiaries have implemented and maintained commercially reasonable physical, technical and administrative controls, policies, procedures, and safeguards to maintain and protect their material confidential information and the integrity, continuity of operation, redundancy and security of all IT Systems and data, including “Personal Data,” used in connection with their businesses. “Personal Data” means (i) a natural person’s name, street address, telephone number, e-mail address, photograph, social security number or tax identification number, driver’s license number, passport number, credit card number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) “personal data” as defined by GDPR; (iv) any information which would qualify as “protected health information” under HIPAA; and (v) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual orientation. There have been no breaches, violations, outages or unauthorized uses of or accesses to same. The Company and its subsidiaries are presently in compliance in all material respects with and have at all prior times complied in all material respects with all applicable laws or statutes and all judgments, orders, rules and regulations of any court or arbitrator or governmental or regulatory authority, internal policies and contractual obligations relating to the privacy and security of IT Systems and Personal Data and to the protection of such IT Systems and Personal Data from unauthorized use, access, misappropriation or modification.
(yy)Compliance with Data Privacy Laws. The Company and its subsidiaries are, and at all prior times were, in compliance in all material respects with all applicable state and federal data privacy and security laws and regulations, including without limitation HIPAA, as well as all applicable privacy, data protection and data security laws and regulations from all jurisdictions outside of the United States, including, without limitation, the European Union General Data Protection Regulation (EU 2016/679) (“GDPR”) (collectively, the “Privacy Laws”), the Policies (as defined below) and all applicable contractual obligations concerning the processing of any Personal Data and privacy, data protection and/or data security obligations (collectively, “Privacy Requirements”). The Company and its subsidiaries have in place, comply with, and take appropriate steps reasonably designed to comply in all respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling, and analysis of Personal Data (the “Policies”). The Company and its subsidiaries have at all times made all disclosures to individuals required by applicable Privacy Laws and