Data Protection - GDPR-Aligned Practices

Data protection framework - GDPR-aligned principles, scope, security, rights, international transfers, breach notification.


Taj Pharma operates a data-protection framework aligned with GDPR principles and applicable local law (including the DPDP Act 2023 in India).

1. Principles #

  • Lawfulness, fairness, transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

2. Data Scope #

CategoryExamplesRetention
B2B contactsDistributor, tender, regulator contactsRelationship + 3-10 years
PharmacovigilanceICSR content10+ years
Website analyticsIP (anonymised where applicable), visitsUp to 24 months
Customer auditsAudit reports, CAPA10 years

3. Security Measures #

  • HTTPS/TLS in transit
  • Role-based access controls
  • Audit logging
  • Regular backup / DR testing
  • Vendor due diligence and DPAs
  • Staff training

4. Rights #

Access, rectification, erasure (where not required for regulatory retention), restriction, portability, objection. Email privacy@tajpharma.com.

5. International Transfers #

SCCs or equivalent safeguards.

6. Breach Notification #

Notification to supervisory authority and (where required) data subjects per applicable law timeframes.

7. Sub-Processors #

Vetted sub-processors under written agreements. Current list available to B2B customers on request.

8. Contact #

privacy@tajpharma.com