Skip to main content

Privacy Statement (January 2022–today)

This privacy statement does not apply to situations where we have notified you that an alternative privacy statement applies. Effective date of this privacy statement: January 2022.

Medtronic’s mission is to contribute to human welfare by the application of biomedical engineering in the research, design, manufacture, and sale of instruments or appliances that alleviate pain, restore health, and extend life.

Medtronic MiniMed Inc. and Medtronic affiliated companies (together, “we” or “Medtronic”) offer diabetes therapy management solutions, which consist of a range of medical devices (including insulin pumps, continuous glucose monitor and Smart insulin Pen), device management software (including CareLink™ Personal) and associated services (including product support, education and online ordering platform), that are all part of the Medtronic Diabetes integrated ecosystem operated by or on behalf of Medtronic (“Medtronic Diabetes Management Solutions” or “Solutions”).

This privacy statement describes how your personal data, including health-related data, is collected and further processed by Medtronic in connection with your use of Medtronic Diabetes Management Solutions, which rights you have and how to contact us about this privacy statement or to exercise your rights. Except as otherwise described in this privacy statement, the Medtronic affiliate listed in your country (i.e. Medtronic Ltd.) is responsible for the processing of your personal data through the Solutions.

If you choose to share your personal data with healthcare professionals in context of your medical treatment or other parties external to Medtronic, they will be solely responsible for their own use, or further processing, of your personal data.

For the purpose of this privacy statement, “you” means any individual that uses Medtronic direct-to-consumer Solutions or whose behalf the Solutions are used, as applicable.

We obtain personal data in various ways: when you directly provide information to us; when medical device data is uploaded from a medical device (e.g., pump, CGM, Smart Insulin Pen) into Medtronic device management software (e.g., Carelink Personal) or when otherwise using automated means, including cookies and similar technologies. For more information on the cookies and similar technologies we use on your Solution, see its Cookie Policy.

The personal data you provide to us depends on your use of our Solutions. When contacting Medtronic customer and product support (e.g., by phone, email, chatbot) and/or when registering to a device management software and/or associated service, some of your personal data is necessary to allow us to provide you with that Solution. In such case, the following types of personal data we obtain include:

  • your contact information and/or account details (such as your first and last name, home address, country, phone number, date of birth or age, Medtronic account credentials (i.e., username and password),
  • information about your healthcare provider(s), healthcare organization and health insurance company,
  • information relevant to the performance of a contract with us (such as your credit card details (only in relation to any of your orders on an online ordering platform where available in your country), order and shipment information),
  • Information about your food consumptions or your personal preferences (such as your lifestyle, habits, interests and hobbies) you choose to provide to us,
  • other personal data contained in content you submit on the Solution(s) (such as your request for technical support).

At the time when the collection of your personal data is necessary, we will inform you whether the provision of the above information is optional or mandatory for us to provide the Solution you requested. Where the collection is mandatory, we may not be able to provide you with the Solution you requested if you choose not to provide that information to us.

In addition, we may obtain health-related data associated to your Medtronic therapy, including your type of diabetes, Medtronic device information (such as the type of device used and its serial number) and compatible medical device data uploaded to Medtronic device management software (e.g., CareLink™ Personal). We will process health-related data only with your explicit consent or in order to meet Medtronic’s legal and regulatory obligations as a manufacturer of medical devices, as explained below.

Medtronic will process your personal data (including health-related data) only as relevant to the Solution(s) for which you provided the data and for the specific purposes, and based on the legal grounds, outlined below. Please note that one or more purposes may apply simultaneously, depending on the Solution(s) you have registered for or requested. Please refer to the service description of the Solution(s) for more information on their functionalities.

(Explicit) Consent

Processing of health-related data

With your explicit consent, we will process your health-related data for the following specific purposes:

  • To create your CareLink™ Personal account in order to upload your device data and to generate your CareLink™ Personal reports;
  • To aggregate health-related data in a way that does not directly identify anyone. We will use this information to create internal reports to further research and develop new products and services for Diabetes Management and improve existing products and services, and/or to develop materials presented at conferences and to health care providers and public authorities to demonstrate product performance or enable Medtronic to improve training, education and support programs.

Marketing communications

In accordance with the laws applicable in your country, we may also ask you to “opt-in” or consent to receive communications regarding products and services that we believe may be of interest to you including:

  • To receive newsletters;
  • To receive educational material;
  • To receive updates about Medtronic products and service innovation;
  • To participate in surveys.

If at any time you decide not to receive any marketing communication for all or one of the specific topics listed above, you will be given the possibility to opt-out following the procedure provided in any relevant message you receive from us. Alternatively, you can write to us at ‘Medtronic Ltd, Building 9, Croxley Green Business Park, Hatters Lane, Watford, WD18 8WW’ or contact us on rs.ukdiabetesproductsupport@medtronic.com or rs.privacyeurope@medtronic.com

Legitimate interest

We will also process personal data, based on our legitimate interests to support the following activities or purposes:

  • To respond to your requests or queries and provide you with technical support, including technical training, you seek in relation to Medtronic Diabetes Management Solutions;
  • To communicate with you and send you (urgent) communications of an operational nature (e.g., planned outages or updates) about our Solutions;
  • To send alerts to care partners you have chosen to share with via CareLink™ Connect
  • To manage and maintain your personal data associated with the Medtronic Diabetes Management Solution(s) you use;
  • To make your personal data (such as your credentials, contact information and/or preferences) available across the Medtronic Diabetes services you use, in order to facilitate and personalize your customer journey with Medtronic, where relevant;
  • To provide the product services requested on your behalf by your health care provider where applicable;
  • To aggregate personal data to a level where you are no longer directly identifiable. Such information is used to create statistics in order to gain a better understanding of the quality and performance of our services;
  • To prevent and detect fraud and other criminal activities, and to comply and enforce our policies and the Terms of Use of the relevant Solution(s) as necessary for the establishment, exercise, or defense of our legal rights.

Contract

Depending on the services available in your country, we will process your personal data as necessary to perform our contractual obligations or to take steps at your request, before entering a contract for the following purposes:

  • To process, ship and deliver the product(s) you ordered on our online ordering platform, in relation to your diabetes therapy.
  • To negotiate and agree on the contract terms applicable to specific Medtronic Diabetes services, to send you relevant (non-marketing) communications and to perform the essential elements of the services you requested.

Legal obligation

In addition, Medtronic will process personal data (including health-related data) to comply with its legal obligations and as necessary for reasons of public interest in the area of health, including:

  • To comply with post-market surveillance and vigilance reporting obligations under applicable medical device regulations;
  • To comply with requests from competent authorities;

Medtronic does not disclose your personal data (including health-related data) with third parties except as described in this privacy statement.

In the ordinary course of business, we may share your personal data (including personal health-related data) with third-party service providers to perform services on our behalf and only based on our documented instructions, including:

  • Information Technology and hosting services;
  • Postal services, couriers or other freight services to ship the products ordered in relation to your diabetes therapy management,
  • Customer support and communication services, such as to send you marketing communication you have signed up for, as well as urgent (non-marketing) communication about Medtronic products and services,
  • Consulting services regarding product and/or service development, security and technical strategy,
  • Survey management solutions to manage surveys we may invite you to participate to,
  • Legal and professional services to receive legal advice and manage legal disputes, where applicable.

Where our service providers need to have access to your personal data, we will (1) select providers who respect your privacy and comply with applicable data protection laws; (2) only give them access to the information they need to perform their services; (3) ensure that they will only use the information for the purposes agreed in our contract with them and protect that information in accordance with applicable data protection laws.

We may also share your personal data (including health-related data) with our Medtronic affiliates as described below.

Medtronic MiniMed Inc. (18000 Devonshire Street, Northridge, CA 91325, United States of America)Legal manufacturer of Medtronic medical devices used in connection with diabetes therapy management. Medtronic MiniMed Inc. is responsible for processing your personal data as described above in connection with the following activities:
  • To comply with legal requirements, such as vigilance reporting, post-market surveillance, and correspondence with competent authorities;
  • To provide advanced technical assistance as requested by Medtronic local affiliate(s);
  • To support its research and development activities on the Solutions by means of internal statistical reports based on aggregated data.
Medtronic International Trading sàrl (Route du Molliau 31, 1131 Tolochenaz, Switzerland)Responsible for the import and distribution in Europe, Middle East and Africa (EMEA) of products manufactured by Medtronic MiniMed Inc. and for the processing of your personal data in connection with the following activities:
  • To develop its research and development activities on diabetes therapy management solutions, as well as its marketing activities in the EMEA region by means of internal statistical reports based on aggregated data.
Medtronic local affiliate in your countryMedtronic local affiliate is responsible for the processing of your personal data in connection with the following activities:
  • Local activities carried out in relation with the Solutions and services in the concerned country, including registration with local authorities, technical assistance and escalation to Medtronic MiniMed Inc. as needed;
  • To comply with contractual arrangements executed with you and/or, where applicable, with local institutions which may be associated to your diabetes therapy (e.g. hospitals, health insurance companies);
  • To support local marketing activities by means of internal statistical reports based on aggregated data.
Medtronic Customer & Product Support in your countryProcesses your personal data for technical support provided on behalf of Medtronic local affiliate and escalation to Medtronic MiniMed Inc. as needed.
Medtronic Bakken Research Centre BV (the Netherlands)Processes your personal data on behalf of Medtronic MiniMed Inc. and Medtronic International Trading sàrl to create statistical reports.
Medtronic BV (the Netherlands)Authorized representative of Medtronic MiniMed Inc. in the European Union under the European regulation on medical devices. Medtronic B.V. processes your personal data on behalf of Medtronic MiniMed Inc. to comply with legal obligations under applicable medical device regulations, especially for post-market surveillance and vigilance reporting purposes.

Medtronic maintains appropriate technical and organizational measures designed to protect your personal data against accidental, unlawful or unauthorized destruction, loss, alteration, disclosure, or access.

Your personal data (including health-related data) is stored on servers located in the European Economic Area (“EEA”) but we may also transfer your information to Medtronic affiliates and/or third-party service providers located outside of the EEA as described above, including in the United States of America that has not been recognized by the European Commission as providing an adequate level of data protection.

Where there is a need to transfer your personal data to Medtronic affiliates or to third-party service providers, we will ensure that there are appropriate safeguards in place to protect your personal data as required by applicable laws. When your personal data need to be transferred outside the EEA, United Kingdom or Switzerland, we will implement appropriate safeguards to ensure an adequate level of data protection, including executing data transfers agreements based on the European Commission’s Standard Contractual Clauses.

We also reserve the right to transfer personal data we have about you in the event we sell or transfer all or portion of our business or assets. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use the personal data you have provided to us in a manner consistent with this privacy statement. Following such sale or transfer, you may contact the entity to which we transferred your personal data with any inquiries concerning the processing of that personal information.

Your personal data will only be retained by Medtronic for so long as necessary and relevant to fulfill the purpose(s) set out herein and may be retained beyond the duration of your business relationship with Medtronic if required to enable us to fulfill such purposes as to comply with legal requirements, including compliance and record retention regulations.

Subject to applicable laws, you have the following rights with respect to the processing of your personal data as described in this privacy statement:

  • to receive access to your personal data;
  • to withdraw your consent at any time and without giving reasons, in case our processing of your personal data is based on your consent. However, this will not affect the lawfulness of data that have been processed before you withdrew consent;
  • to have any inaccurate or incomplete personal data about you corrected or completed. If you use a device management software or associated service, you may be able to correct your information directly within your account. Alternatively, you can contact us as explained below. Please be informed that we can ask you to demonstrate that the personal data you want to correct is indeed erroneous;
  • to obtain the personal data you provided to us - based on your consent or as needed by us to perform a contract with you - in a way that is accessible and machine-readable and to request us to transfer such data to another organization;
  • to ask for the deletion of your personal data that is being processed or retained by us. Personal data may be retained in exceptional cases exclusively if required to enable us to comply with legal requirements, including compliance and record retention regulations;
  • to restrict the processing of your personal data if and when (a) you contest the accuracy of the data, (b) the processing is illegitimate and you request the restriction of its use instead of its deletion (c) your personal data is no longer needed for the purposes which are outlined above, but you need it in judicial proceedings;
  • to object to the processing of your personal data based on our legitimate interests.

If you wish to exercise any of your rights, obtain a copy of the safeguards implemented by Medtronic, or if you have any questions about the processing of your personal data (including health-related data) in accordance with this privacy statement, you can contact us or our Data Protection Officer at the following e-mail address: rs.privacyeurope@medtronic.com. Subject to applicable law, you may lodge a complaint with a data protection authority, in particular in the country of your habitual residence, if you are not satisfied by our response or if you consider your privacy rights have been breached.

This privacy statement will be reviewed and updated periodically to reflect changes to our personal data practices or relevant laws. We will post a notice on the Solutions to notify you of any significant changes and indicate at the top of this privacy statement when it was most recently updated.