imgpsh_mobile_save.jpg

Privacy Policy

This Privacy Policy applies to  Cipla Limited together with its subsidiaries, affiliates, and group Companies (“Cipla”, “we”, “our”, or “us”), in connection with our personal data processing activities. We are committed to respecting your privacy and safeguarding your personal data when you interact with us.

This Privacy Policy explains how and why we collect, use, disclose, store, and protect personal data when you access or use our websites, digital platforms, online services, and related interactions ( “Services”). It also describes the categories of personal data we process, the purposes and legal bases for such processing, the circumstances in which we may share personal data, the safeguards we implement, and the rights available to individuals under applicable data protection laws.

This Privacy Policy is intended to comply with applicable data protection laws, including the European Union General Data Protection Regulation (EU GDPR), the United Kingdom GDPR (UK GDPR), the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), the Washington My Health My Data Act (MHMDA), and the Digital Personal Data Protection Act (DPDPA), 2023 (including applicable rules) in India, as well as other relevant applicable laws.

Scope 

This Privacy Policy applies to  the processing of personal data by Cipla and covers information relating only to identified or identifiable individuals in connection with the following interactions:

  1. Visiting or interacting with our websites
  2. Submitting information through online forms, portals, or enquiry channels
  3. Registering for Services, programs, or communications
  4. Using features that involve cookies or similar technologies
  5. Communicating with us through digital channels, including email or online support

Accessing or using our website constitutes your acknowledgement of an agreement to this Privacy Policy and the applicable Terms of Use.

This Privacy Policy applies to all pages hosted on Cipla’s websites. It does not apply to third-party websites that may be accessible through links on our platforms. Such third-party websites operate under their own privacy policies, and Cipla does not assume responsibility for the processing of personal data by such entities.
Cipla maintains official pages and profiles on certain social media platforms, including LinkedIn, Instagram, Facebook, and X (formerly Twitter).

In relation to statistical and aggregated page insights or analytics provided by LinkedIn in connection with Cipla’s Company Page, Cipla and LinkedIn act as joint controllers for the limited processing of such data, in accordance with LinkedIn’s Page Insights Joint Controller Addendum, which forms part of LinkedIn’s user agreements.

For all other processing activities carried out on these platforms, the respective social media provider acts as an independent data controller. Users are encouraged to review the privacy policies of these platforms to understand how their personal data is processed.

Territorial Applicability

This Privacy Policy applies to the processing of personal data by Cipla across the jurisdictions in which Cipla operates, as well as to individuals who access or use our Services from different locations.

While data protection laws may vary by jurisdiction, Cipla applies consistent privacy principles across its operations and implements additional measures where necessary to comply with applicable local legal and regulatory requirements.

Personal Data We Collect & Process

We may collect and process personal data about you depending on how you access or use our Services. The personal data we collect falls into the following categories: 

a.) Information You Provide Directly

You may provide personal data to us when you:

  1. Visit our website or social media pages and register for Services, programs, or communications or subscribe to updates or newsletters 
  2. Apply for job opportunities through our online application portals 
  3. Submit enquiries, requests, or feedback through online forms, email, or customer support channels  
  4. Visit Cipla facilities or premises as a guest, vendor, or third-party service provider, and access our systems or guest Wi-Fi networks
  5. Engage with us as a supplier, vendor, or business partner, including through a Chatbot that allows users or visitors to ask questions and receive automated responses. This processing is based on our legitimate interests and, where required, your consent.  The Chatbot collects and processes interaction data, including chat content and timestamps, for the purpose of responding to your queries. You are advised not to share sensitive personal data in the chat.  
  6. Report an adverse event or product related issues. 

Personal data for the above purposes may include your name, contact details (such as email address and phone number), professional and employment-related information, health-related information (where relevant, for example in connection with adverse event reporting), product usage information and any other information you choose to provide voluntarily. 

In connection with adverse event reporting and product safety monitoring, such data is processed for purposes including monitoring the safety and quality of our products, investigating and responding to adverse events and product complaints, complying with applicable regulatory and legal reporting obligations, and reporting to health authorities and regulatory bodies, where required. 

b.) Information Collected Indirectly (Automatically or through Cookies and Similar Technologies)

When you access or use our Services, certain personal data may be collected automatically through technical means including through the use of cookies and similar tracking technologies. This data helps us understand how our Services are used and improve user experience.

Such personal data may include:

  1. Internet protocol (IP) address
  2. Browser type, approximate location, device type and operating system
  3. Pages visited, links clicked, and time spent on the website
  4. Date and time of visits and referring URLs
  5. Information about your device, preferences, and interactions with the website.

Aggregate and anonymized statistical data (such as page views and engagement metrics, including those provided through our social media platforms such as LinkedIn).

Where required under applicable law, we obtain your consent before placing or using cookies and similar tracking technologies, except where such cookies are strictly necessary for the functioning of the website. Further details regarding our use of cookies and how you can manage your preferences are provided in the Cookies & Tracking section of this Privacy Policy.

c.) Information from Other Sources

In certain circumstances, we may receive personal data  about you from third-party sources, including analytics providers, technology partners, business partners, recruitment agencies, and publicly available sources, where such collection is permitted under applicable law. 

We collect and process such personal data in a manner that is proportionate, relevant, and limited to what is necessary for the purposes described in this Privacy Policy. We ensure that such third parties are authorized to share your personal data with us and that appropriate safeguards are in place to protect such data in accordance with applicable data protection laws.

Sharing and Disclosure of Personal Data

We may share your personal data with third parties only where necessary for the purposes described in this Privacy Policy and in accordance with applicable data protection laws.

  1. Service providers and Business Partners
    We may share personal data with trusted third party service providers and partners who support the operation of our website, provide technical, analytical or communication services, or assist with other business or operational functions. Such third parties are contractually obligated to process personal data only on our documented instructions, and to implement appropriate confidentiality and security measures.
  2. Cipla Affiliates and Group Companies
    We may share personal data with Cipla’s subsidiaries, affiliates, and group companies for purposes such as internal administration, operational support, business management, and other legitimate business purposes, in accordance with this Privacy Policy and applicable data protection laws.
  3. Legal and Regulatory Disclosures
    We may process and disclose your personal data to third parties, including legal advisors and regulatory authorities, where necessary to:
    1. Comply with applicable laws, regulations, court orders, or governmental requests.
    2. Establish, exercise, or defend legal claims.
    3. Protect the rights, property, or safety of Cipla, its employees, users, or third parties.
    4. Detect, investigate, and prevent fraud, cybercrime, or other unlawful or unethical activities.
  4. Business Transfers
    Your personal data may be transferred to a third party in connection with a merger, acquisition, restructuring, financing, sale of assets, or other similar business transaction. In such cases, appropriate safeguards will be implemented to ensure that your personal data remains protected in accordance with applicable laws.
  5. Lawful Basis for Sharing
    Where required under applicable law, our sharing of personal data is based on lawful grounds such as compliance with legal obligations, performance of a contract, or our legitimate interests, provided that such interests are not overridden by your rights and interests. In cases where required, we will obtain your consent prior to sharing your personal data.

Cookies and Similar Technologies

We use cookies and similar technologies to enhance your experience, improve the functionality of our website, and understand how visitors interact with our digital platforms.

  1. What are cookies?
    Cookies are small text files consisting of letters and numbers that are placed on your device (such as a computer, tablet, or mobile device) when you visit a website. Cookies enable the website to recognize your device and store certain information about your preferences or past interactions.
  2. Types of Cookies We Use
    We may use the following categories of cookies on our website:
    1. Strictly Necessary cookies: These cookies are essential for the operation of the website and enable core functionalities such as security, network management, and accessibility. These cookies cannot be disabled.
    2. Functional cookies: These cookies enable enhanced functionality and personalization, such as remembering your preferences.
    3. Analytics and Performance cookies: These cookies help us understand how visitors use our website, allowing us to improve performance and user experience.
    4. Advertising or Targeting cookies: Where used, to deliver relevant content and communication. We do not knowingly use such cookies to track or profile children.
  3. How we use Cookies
    We use cookies to:
    1. Ensure the security and proper functioning of the website.
    2. Enable essential features and Services.
    3. Analyse usage patterns and improve website performance.
    4. Enhance user experience and usability.
  4. Your choices and controls
    Where required under applicable law, we obtain your consent before placing or using cookies, except for cookies that are strictly necessary for the functioning of the website. You can manage your cookie preferences through the cookie banner, preference settings, or other tools available on the website. You may also manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of the website.
  5. Third party cookies
    Some cookies may be placed by third party service providers who assist us in operating, analysing, and improving our Services. These third parties are permitted to use the information collected through such cookies only for the purposes specified by us and in accordance with applicable data protection laws.

International Data Transfers

In certain circumstances, your personal data may be transferred to, stored, and processed in jurisdictions outside your country of residence, including in countries where Cipla or its service providers operate.

Where such transfers occur, we ensure that appropriate safeguards are implemented to protect your personal data in accordance with applicable data protection laws. These safeguards may include the use of standard contractual clauses, intra-group data transfer agreements, or other legally recognized transfer mechanisms.

Where required under applicable law, we will obtain your consent prior to transferring your personal data outside your jurisdiction.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet applicable legal, regulatory, or reporting requirements.

In determining the appropriate retention period, we consider factors such as the nature, sensitivity, and purpose of the personal data, as well as applicable legal obligations. Once personal data is no longer required, it is securely deleted, anonymized, or, where appropriate, archived in accordance with applicable data protection law.

Data Security:

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. Such measures include, where appropriate

  1. Access controls and authentication mechanisms
  2. Encryption and data protection safeguards
  3. System and network security monitoring
  4. Regular security assessments and audits
  5. Employee training and awareness program

We continuously review and enhance our security practices to address emerging risks and ensure the ongoing confidentiality, integrity, and availability of personal data. While we take reasonable steps to protect personal data using commercially acceptable security measures, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

User Rights

Subject to applicable data protection laws, you have certain rights in relation to your personal data. These may include the right to access, correct, or delete your personal data; restrict or object to its processing; and the right not to be subject to decisions based solely on automated processing where such decisions significantly affect you.

Where applicable, you may also have the right to data portability, the right to withdraw consent at any time, the right to opt out of the sale or sharing of your personal data, and the right to not be discriminated against for exercising your rights. Under the Digital Personal Data Protection Act, 2023, you may also have the right to nominate an individual to exercise your rights in the event of your death or incapacity and to seek grievance redressal.

These rights are not absolute and may be subject to limitations under applicable law.

Where processing is based on your consent, you may withdraw such consent at any time. Withdrawal does not affect the lawfulness of processing carried out before such withdrawal.

To exercise your rights, you may contact us at globalprivacy@cipla.com. We may request additional information to verify your identity before processing your request. We will respond within the timelines prescribed under applicable law.

If you are not satisfied with our response, you may file a complaint with your national supervisory authority.

Children and Vulnerable Individuals’ Privacy

We are committed to protecting the privacy of children and vulnerable individuals who may require enhanced safeguards when their personal data is processed. For the purposes of this Privacy Policy, a child includes individuals under the age of 13, or such other age as defined under applicable law.

We collect and process personal data relating to children and vulnerable individuals only where legally permitted and for legitimate, specific purposes, and take reasonable steps to minimise such collection. Where required under applicable law, we obtain verifiable consent from a parent, lawful guardian, or authorised representative prior to such processing.

We implement appropriate technical and organisational safeguards to ensure that such data is processed securely, fairly, and responsibly, and is protected against misuse, harm, or exploitation. We do not knowingly use such data for profiling, behavioural tracking, or targeted communications where restricted under applicable laws. 

If you believe that personal data relating to a child or vulnerable individual has been collected or processed without proper authorisation, please contact us at globalprivacy@cipla.com so that we can take appropriate action. Where required by applicable law, additional rights and protections may apply to children’s data, including the right to access, correction, erasure, and withdrawal of consent through a parent or lawful guardian.

Changes to This Policy

Cipla reserves the right to modify this Privacy Policy from time to time without prior notice. The updated version will be posted on this website with a revised effective date. We encourage you to review this Privacy policy periodically.

Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, you may contact us at:

Cipla Limited
Cipla House, Peninsula Business Park, 
Ganpatrao Kadam Marg, Lower Parel, 
Mumbai – 400013, India
Email: globalprivacy@cipla.com
We will respond to your request within the timelines prescribed under applicable data protection laws.
Last updated: July 08th, 2026