Privacy Policy for Medical-Device Vigilance
How OrganoGEN Limited collects, uses, and protects personal data submitted in incident and adverse-event reports relating to OrganoGEN-distributed medical devices, under EU Regulation 2017/745 (MDR) Article 87 and the EU General Data Protection Regulation (EU) 2016/679.
In Short
If you submit an incident or adverse-event report to OrganoGEN regarding one of our distributed medical devices, this policy describes the personal data we collect, how we share it with the manufacturer and the Cyprus competent authority, and how to exercise your rights. Note that OrganoGEN distributes medical devices (governed by EU MDR 2017/745), not medicinal products; the regulatory regime described here is therefore medical-device vigilance, not pharmacovigilance. This wording is provisional and is being reviewed by Cyprus-licensed legal counsel before final publication.
Reporting a serious incident
If you have witnessed a serious incident or adverse event involving an OrganoGEN-distributed medical device, please contact OrganoGEN without delay: info@organogenbiotech.com or +357 95 707111. Serious incidents must also be reported to the manufacturer and may be reportable to the Cyprus competent authority under EU MDR 2017/745 Article 87.
1. Scope
This policy applies if you submit, on your own behalf or on behalf of an organisation, an incident report, adverse-event report, near-miss report, complaint, or related correspondence relating to a medical device that has been placed on the market by OrganoGEN Limited (acting as the authorised representative or distributor under EU MDR 2017/745) or distributed in Cyprus by OrganoGEN.
This policy supplements the general Privacy Policy. For surgeon CRM and clinical-marketing activities, see the Healthcare Professionals Privacy Policy instead.
2. What personal data we collect
OrganoGEN collects only the personal data necessary to receive, document, and forward a medical-device vigilance report:
From the reporter (you)
- Name and professional role.
- Organisation (hospital, clinic, or pharmacy).
- Work address, email, and phone number for follow-up.
- The content of your report (incident description, device identifier or UDI, batch / lot number, date and place of incident, clinical outcome).
About the affected patient (where the report concerns a specific patient)
OrganoGEN collects only the minimum information necessary to characterise the incident, in keeping with the data-minimisation principle (Article 5(1)(c) GDPR):
- Initials or anonymised identifier (not full name unless statutorily required by the receiving authority).
- Gender, age or date of birth (where clinically relevant to the incident).
- Clinical information necessary to characterise the incident: indication for the device, the device implanted or used, the adverse event, treatment given, clinical outcome.
OrganoGEN does not routinely collect full patient names, national identifiers, or other directly identifying data for vigilance reports submitted by healthcare professionals. Where a patient self-reports directly to OrganoGEN, we collect only the minimum necessary contact information to acknowledge the report and direct the patient to their treating clinician.
3. How and why we use personal data
OrganoGEN uses vigilance-report personal data only to:
- Acknowledge receipt of your report.
- Document the report in OrganoGEN's vigilance file under EU MDR 2017/745 Article 87(2)(a) (distributor obligations).
- Forward the report to the relevant manufacturer ("the legal manufacturer") promptly, in the form required by the manufacturer's vigilance procedure.
- Report serious incidents to the Cyprus competent authority where required by EU MDR 2017/745 and Cyprus law.
- Contact you for clarification, follow-up information, or to communicate the outcome of the manufacturer's or competent authority's investigation.
- Maintain post-market surveillance records as required by EU MDR 2017/745 Article 83 and Annex III.
OrganoGEN does not use vigilance data for any other purpose, including marketing.
4. How we obtain your personal data
OrganoGEN receives vigilance personal data only when you (or your organisation) provide it to us, by email, phone, post, or in person.
5. Legal basis for processing
OrganoGEN relies on the following Article 6(1) GDPR bases, and on the special-category data conditions under Article 9(2) GDPR for the clinical health data that necessarily accompanies a vigilance report:
- Article 6(1)(c) legal obligation. The primary basis. EU MDR 2017/745 Articles 83 (post-market surveillance), 87 (vigilance reporting), and 93 (registration of devices and economic operators) impose legal obligations on OrganoGEN as a distributor or authorised representative to receive, document, and forward incident reports.
- Article 6(1)(c) + Article 9(2)(i) GDPR. For the special-category health data that necessarily accompanies a vigilance report, processing is "necessary for reasons of public interest in the area of public health" (Article 9(2)(i)), specifically "ensuring high standards of quality and safety of health care and of medicinal products or medical devices."
- Article 6(1)(f) legitimate interest. Secondary basis for post-market surveillance, where the legitimate interest is the safe distribution of CE-marked medical devices in Cyprus, balanced against the rights and freedoms of the data subject (and minimised by the data-minimisation principle in section 2 above).
6. Data retention
OrganoGEN retains vigilance reports for the period required by EU MDR 2017/745 and by the contractual agreement with the relevant manufacturer:
- For non-implantable devices: at least 10 years after the device covered by the report has been placed on the market.
- For implantable devices: at least 15 years after the device covered by the report has been placed on the market (EU MDR Article 10(8)).
- Longer retention may apply where required by the receiving competent authority or by the manufacturer's vigilance procedure.
7. Who has access to your personal data
OrganoGEN shares vigilance personal data only with:
- Authorised OrganoGEN personnel. Andreas Samourides as founder and quality manager, and any other authorised personnel acting under written confidentiality.
- The legal manufacturer of the device covered by the report. The manufacturer acts as a separate data controller (or, in some cases, a joint controller) for vigilance reports, under written agreements compliant with EU MDR 2017/745 and the GDPR.
- The Cyprus competent authority. Where the report meets the threshold for mandatory notification under EU MDR 2017/745 Article 87 and Cyprus implementing legislation, OrganoGEN will report it to the Cyprus competent authority for medical devices. Reports may include or be linked to entries in the European Database on Medical Devices (EUDAMED).
- Other competent authorities and Notified Bodies. Where the manufacturer or competent authority requires onward sharing, for example to the manufacturer's Notified Body for CE-mark certification follow-up.
- OrganoGEN's professional advisors. Cyprus-licensed legal and quality-management advisors, under written confidentiality obligations.
OrganoGEN does not share vigilance data with marketing, advertising, or other third parties unrelated to vigilance.
8. Transfer of personal data outside the EEA
OrganoGEN's primary processing is within the European Economic Area. Where the legal manufacturer is established outside the EEA (for example Aspire Medical Innovation in the United States, Tulip Medical in the United States, or Auxein Medical in India), OrganoGEN transfers vigilance reports to the manufacturer under one of the safeguards in Chapter V GDPR:
- European Commission adequacy decisions, where available for the destination country.
- Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR.
- Article 49 derogations where strictly necessary for public-health reasons (for example "necessary for important reasons of public interest", Article 49(1)(d)).
A list of recipient countries and applied safeguards is available on request to the privacy contact below.
9. How we protect your personal data
OrganoGEN applies the same technical and organisational measures described in section 10 of the general Privacy Policy. Vigilance files are stored in restricted-access folders, kept separate from general business correspondence, and access is limited to authorised personnel with a documented need to know.
10. Your rights under GDPR
Subject to the conditions set out in the GDPR, you have the right to access, rectification, restriction, objection, and complaint as described in sections 13 and 14 of the general Privacy Policy. Note the following specific limitations for vigilance data:
- Erasure may be limited. OrganoGEN may be unable to delete vigilance reports before the end of the statutory retention period (section 6 above) because the data is required by EU MDR 2017/745 for ongoing post-market surveillance.
- Objection may be limited. The legal basis for vigilance processing is principally Article 6(1)(c) (legal obligation) and Article 9(2)(i) (public interest in public health); these are not bases against which Article 21 GDPR objection applies.
To exercise any right or raise a concern, email info@organogenbiotech.com.
11. Status and contact
This wording is provisional and will be reviewed by Cyprus-licensed legal counsel (with specialist medical-device vigilance experience) before final publication.
OrganoGEN Limited · Souliou 12, Mesa Geitonia, Limassol 4000, Cyprus
Vigilance reports, privacy and general enquiries: info@organogenbiotech.com ·
Phone: +357 95 707111
Last revision date: 2026-05-13. Version: 1.0 (provisional, pre-counsel-review).
