Business Associate Privacy Policy


This Business Associate Privacy Policy (the “Policy”) describes how M3 MI/Kantar Media Healthcare Research (KMHR) uses Personal Data relating to the personnel or representatives (“Representatives”) of our clients, suppliers and other entities with whom we have entered, or may enter, business transactions (“Business Associates”). This Policy describes how we may obtain Representatives’ personal data, the types of personal data we may obtain, how we use, share and protect the personal data, the rights of Representatives with respect to their personal data, and how to contact us about our privacy practices.

We may revise this Privacy Policy at any time, without notice to you. You are responsible for reviewing it regularly. Your access of the Sites following the posting of changes means you agree to abide by those changes.

This Policy was last revised on December 7, 2023. 

About M3 MI/KMHR

M3 MI/ M3 MI/KMHR provides pharma and healthcare brands, and their research, advertising and media partners, with syndicated data and insights to support their marketing decisions.   Our data is sourced from proprietary surveys of consumers and healthcare professionals, 3rd party data, and advertising and media data collected by us and our suppliers.

This Privacy Policy relates to the products and services offered by M3 MI/KMHR.

M3 MI/KMHR is part of the M3 Group, including M3 Global Research, the leader in global healthcare data collection.

M3 Global Research is the trading name for the market research activities provided by M3 USA Corporation and its affiliates, including M3 (EU) Ltd, Qualitative and Quantitative Fieldwork Services AB (QQFS), Ekas Marketing Research Services (Ekas), M-Panels Research Services Private Limited (m360 Research), pharma-insight GmbH, All Global and Michael Allen Company.

The types of personal data we may obtain and process:

M3 MI/KMHR obtains personal data of Representatives that is disclosed or otherwise processed by M3 MI/KMHR upon entering into and performing agreements, communicating with Business Associates in relation to agreements and making and receiving payments under agreements. We also may obtain Representatives’ personal data from public sources in anticipation of a prospective business relationship. 

We use a variety of public sources to collate information about potential Business Associates we believe may be suitable for our services. We may also receive a referral from one of your colleagues and process that information in a similar way. Personal data is any information that allows an individual (in this case, the Representative) to be identified.

We may process the following types of personal data about Representatives:

  • Names, postal or e-mail addresses, fax numbers, and phone numbers
  • Employment information (e.g., job titles) relating to Representatives
  • Communication preferences

As a matter of practice, we will not collect any sensitive (special category) personal data relating to Representatives. To the extent that there is a need for us to process sensitive personal data, we will obtain the Representative’s prior written consent.   

Purpose and legal basis for processing your personal data:

This data is used to manage our contact with you, so that, for example, multiple attempts to contact you regarding the same services are eliminated or you are not re-contacted after informing us you are not interested in our services. We also use it as we generate lists of potential Business Associates to contact.  

We process personal data on the basis of our legitimate interest (i.e., we have a valid business reason) and we have carefully balanced your individual rights against this need.

We will only process your personal data for the purpose it was first collected. If we process the personal data for a new purpose, we will ensure it is either compatible with your original purpose or gain your consent.

How we use the Personal Data we obtain:

We may use the personal data we obtain about Representatives to: 

  • Manage our existing and prospective Business Associates relationships;
  • Communicate with Representatives for marketing, newsletters and company updates (for example, concerning services we offer or intend to offer in connection with our services);
  • Perform accounting, auditing, billing, and collection activities;
  • Safeguard and defend M3 MI/KMHR interests; and
  • Comply with applicable legal requirements, industry standards and our policies.

How we may share Personal Data:

M3 MI/KMHR does not sell, rent, or trade Representatives’ personal data. We may share your personal data only with: 

  • Affiliates of M3 to whom it is reasonably necessary or desirable for M3 MI/KMHR to disclose the personal data;
  • Service providers that M3 MI/KMHR has retained to perform services on its behalf, such as, but not limited to, IT service providers. Service providers are not permitted to use the personal data for their own purposes and are prohibited from onward transfer of the personal data without our written consent in each instance;
  • Law enforcement and other government authorities if required by law or reasonably necessary to protect the rights, property, and safety of others or ourselves. This includes lawful requests by public authorities, including to meet national security or law enforcement requirements; and

Links to other websites:

Our website may contain links to other websites. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting other websites and these other websites are not governed by this privacy policy. You should exercise caution and look at the privacy statement applicable to the website in question.

International Data Transfers:

Within M3 MI/KMHR:

M3 MI/KMHR endeavours to apply suitable safeguards to protect the privacy and security of your personal data and to use it only in ways that are consistent with your relationship with M3 MI/KMHR and the practices described in this Privacy Policy. Because of the global nature of our business, there may be times when we need to transfer your Personal Data to a country outside of the country you reside.

M3 MI/KMHR and M3 Global Research use cloud and physical servers in the UK, EU, USA, India and Australia.  UK and EU Personal Data will only be stored and processed in UK, EU or USA.

Standard Contractual Clauses:

For transfers outside of the EEA and UK, M3 MI/KMHR uses EU Standard Contractual Clauses or UK International Data Transfer Agreements to additionally safeguard data from the EEA and UK to countries outside of these locations.

Suppliers and contractors:

As laid out in this Privacy Policy, we may from time to time share limited information with carefully selected partners. This may involve transferring your personal data to countries outside the EEA, the UK, or Switzerland and is done within the legal restrictions of the General Data Protection Regulations (GDPR), and with M3 MI/KMHR remaining in contractual control of the data including standard EU data protection clauses.

How we protect Personal Data:

We maintain appropriate technical and organizational security safeguards designed to protect Representatives’ personal data against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure, or use. We update and test our security technology on an ongoing basis. We limit access to your personal data to those employees who need access to provide benefits or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your personal data.

How long we retain Personal Data:

We store Representatives’ personal data for as long as necessary to fulfil the purposes for which we collect the data (see “How We Use the Personal Data We Obtain“), except if required otherwise by law. Your personal data may be kept for 10 years after the working relationship has ceased. 

Changes and updates to the Privacy Policy:

As our organization, membership and benefits change from time to time, this Privacy Policy and our Terms of Use is expected to change as well. We reserve the right to amend the Privacy Policy and Terms of Use at any time, for any reason, without notice to you, other than the posting of the amended Privacy Policy and Terms of Use at this Site. We may e-mail periodic reminders of our policy and terms and will e-mail Representatives of material changes to it, but you should check our Site frequently to see the current Privacy Policy and Terms of Use that are in effect and any changes that may have been made to them.

Your Rights:

The European Union’s General Data Protection Regulation, the UK Data Protection Act, the California Consumer Privacy Act, as well as other countries and US State privacy laws provide certain rights for EEA, UK, U.S. and Swiss data subjects. Explanations of them (in English) are available at (i) the EU GDPR (ii) the website of the United Kingdom’s Information Commissioner’s Office (iii)  the website of the State of California Department of Justice,(iv) the website of the Swiss Federal Data Protection and Information Commissioner office and (v) Law Committees for each US State.

Additional information for California residents can be found in our California Privacy Policy.

If you wish to confirm that M3 MI/KMHR is processing your personal data, or to have access to the personal data M3 MI/KMHR may have about you, please contact our Data Protection Officer.

You may request information about:

  • the purpose of the processing;
  • the legal basis for that processing;
  • the categories of personal data and the data subject concerned;
  • information on the type or identity of third parties to which your data may be disclosed to and the protection provided;
  • the source of the personal information (if you didn’t provide it directly to us); and
  • how long it will be stored.


You have a right to:

  • access your personal data
  • have inaccurate personal data rectified
  • request erasure of personal data
  • restrict the processing of your personal data
  • object to the processing your personal data
  • data portability
  • opt out of data being transferred to a third party, unless there is a legal reason to do so (see “How we may share Personal Data”)
  • opt out of direct marketing


To exercise your rights, you can write the Data Protection Officer at

Reasonable access to your personal data will be provided at no cost to you upon your request. M3 MI/KMHR will provide the information to you within the legal time frame. If for some reason access is denied, M3 MI/KMHR will provide an explanation as to why access has been denied

Contact Information:

M3 MI/KMHR has appointed an internal data protection officer for you to contact if you have any questions, requests on your personal data, concerns or complaints please send an email to