Data privacy

Data protection policy of the Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis

The Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis handle personal data only within the limits of their purpose as set forth in law, the statutes and the regulations. A record is only kept of data required for the business activities of the Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis and for the proper fulfillment of the roles assigned to them.

No data are passed on for other purposes without the consent of the person concerned, unless this is required by the legal obligations to provide information or is necessary for the business activities of the Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis and is beneficial to the quality of service provided, for example as part of a data handling operation for security purposes (hosting).

The Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis only keep personal data for as long as they are legally required to do so, or insofar as this is of importance for the purpose for which the data have been recorded.

The Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis undertake to comply with the current data protection law, including the related data privacy policy, along with pertinent key directives, guidelines and regulations of the founding company, as well as for the purpose of ongoing development and improvement of the effectiveness of data protection.

The Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis take appropriate technical and organization security measures to provide effective protection of the data managed by them against unauthorized or unlawful access or accidental loss, destruction or damage.

The Pension Funds Novartis, Insurance Services Novartis and Management Pension Fund Novartis use a data protection management system, which they are continuously improving. The systems, processes and organization are subject to evaluation by an independent certification agency according to internationally recognized technical standards, in order to comply with the quality requirements of the GoodPriv@cy®/DPCO seal of approval for data protection.

Basel, 30 october 2009

Pension Funds Novartis

Dr. Markus Moser
Managing Director

Management Pension Fund Novartis

Marcel Schmidt
Managing Director