Test Purchase Agreement Data Protection & Information Security Addendum

Galleri Testing Agreement 

Data Protection & Information Security Addendum

 

Last Updated: June 8, 2026

This Data Protection and Information Security Addendum to the Galleri® Testing (“DPA”) is entered into by and between GRAIL, Inc. (“GRAIL”) and the legal entity defined as Customer in the Galleri® Testing Agreement (“Customer”), entered into by and between the Parties (the “Agreement”), and is hereby incorporated into and effective as of the effective date of the Agreement. Customer and GRAIL shall be referred to collectively as the “Parties,” and individually as a “Party.” Capitalized terms used but not defined in this DPA will have the meanings set forth in the Agreement. 

WHEREAS, Customer and GRAIL have entered into the Agreement pursuant to which Customer will make GRAIL’s Galleri® multi-cancer early detection test (the “Test”) available to eligible U.S-based individuals identified by the Customer (hereinafter “Eligible Participants”); 

WHEREAS, Customer may disclose certain personally identifiable information of Eligible Participants to GRAIL pursuant to the Agreement; and  

WHEREAS, the Parties wish to set forth in this DPA requirements applicable to such personally identifiable information.

NOW THEREFORE, the Parties agree as follows:

1. APPLICABILITY.  

1.1 This DPA applies to the extent Customer shares any Personal Information (as defined below) of Eligible Participants with GRAIL. The Parties acknowledge and agree that GRAIL is a Covered Entity as defined under HIPAA (as defined below) and that any personally identifiable information about an Eligible Participant that GRAIL receives directly from either (a) such Eligible Participant or (b) a healthcare professional who orders the Test for such Eligible Participant is PHI (as defined below) that is governed by HIPAA and subject to the terms of the Agreement.  

1.2 To the extent Customer makes the Test available to Eligible Participants as part of an employee welfare benefit plan that is subject to the Employer Retirement Income Security Act of 1974 (“ERISA”) that qualifies as a “Health Plan” (as defined under HIPAA) and exchanges PHI (as defined below) with GRAIL, either directly or through a third-party insurance administrator (“TPA”) in its capacity as a Health Plan, the terms of the ERISA Exhibit attached hereto as Exhibit A (“Exhibit A”) shall apply to such PHI.

2. DEFINITIONS

2.1 “Consumer” means a person who is subject to a relevant and applicable Data Privacy Law(s) and whose Personal Information has been supplied to GRAIL by Customer under the Agreement.

2.2 “Consumers’ Rights” means those rights of Consumers as set out in applicable Data Privacy Laws, including, without limitation, the right to know and the rights of access/portability and erasure.

2.3 “Cross-Context Behavioral Advertising” means the targeting of advertising to a Consumer based on the Consumer’s Personal Information obtained from the Consumer’s activity across businesses, distinctly-branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the Consumer intentionally interacts. 

2.4 “Data Privacy Laws” means all applicable federal, state, regional, and/or local laws, rules, and regulations relating to privacy, data protection, data security, breach notification or the Processing of Personal Information, including, without limitation, to the extent applicable, the California Consumer Privacy Act of 2018 (California Civil Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020, and any implementing regulations promulgated thereunder (“CCPA”) and any other applicable United States state or federal privacy laws, in each case as may be amended, replaced, or superseded from time to time. For the purposes of this DPA, the term Data Privacy Laws does not include HIPAA. 

2.5 “HIPAA” means the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5), and the regulations promulgated thereunder by the United States Department of Health and Human Services, including the Privacy, Security, Breach Notification and Enforcement Regulations at 45 CFR Parts 160 and 164. 

2.6 “Personal Information” means (i) any data or information (regardless of the medium in which it is contained and whether alone or in combination) that relates to an identified or identifiable person, or (ii) any other information constituting “Personal Information,” “Personal Data,” or similar terms under applicable Data Privacy Laws which Customer supplies to GRAIL and which GRAIL processes in fulfillment of its obligations under the Agreement. For the purposes of this DPA, “Personal Information” does not include PHI (as defined below). 

2.7 “Protected Health Information” or “PHI” has the meaning given to it under HIPAA.

2.8 “Security Incident” means the loss, or unlawful acquisition of Personal Information, or any other unlawful processing of Personal Information, whether in electronic, hard copy or other form, that compromises its security, confidentiality, availability, or integrity, including a “security breach” as defined under applicable Data Privacy Laws. Routine or otherwise trivial attempts to penetrate GRAIL’s network or systems that occur routine basis, such as scans and “pings,” will not be considered a “Security Incident.”

2.9 “Sell,” “Selling,” “Sale,” or “Sold” has the meaning set forth in applicable Data Privacy Laws, including, as defined by the CCPA, selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information by a business to a third party for monetary or other valuable consideration. 

2.10  “Share,” “Shared,” or “Sharing” has the meaning set forth in applicable Data Privacy Laws, including, as defined by the CCPA, sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information by a business to a third party for Cross-Context Behavioral Advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third-party for Cross-Context Behavioral Advertising for the benefit of a business in which no money is exchanged.

3. GENERAL OBLIGATIONS OF THE PARTIES

3.1 Compliance with Law. Each Party shall comply with all applicable federal, state, regional and/or local laws, rules, and regulations relating to the privacy, data security or the processing of Personal Information, including Data Privacy Laws, regardless of the medium in which such Personal Information is contained.

3.2 GRAIL Obligations

a. GRAIL shall perform an appropriate security and privacy risk assessment of any subcontractor or third-party that creates, maintains, or transmits Personal Information on behalf of GRAIL (“Subcontractor”), and shall ensure that any such Subcontractor agrees in writing to restrictions, conditions, and requirements that are at least as protective of Personal Information as those established in this DPA. 

b. GRAIL shall not Sell any Personal Information or use Personal Information for purposes of Cross-Context Behavioral Advertising. 

c. GRAIL shall maintain all necessary documentation to evidence its compliance with this DPA for a period of six (6) years after the expiration or termination of this Agreement or for such longer period as otherwise may be required by applicable Data Privacy Laws, whichever occurs latest. 

3.3 Customer Obligations

a. Customer hereby represents and warrants that it has obtained any and all necessary consents and authorizations and provided all necessary disclosures required by applicable Data Privacy Laws for GRAIL to process the Personal Information as required under the Agreement and/or this DPA. Customer shall not instruct GRAIL to process Personal Data for any purposes Customer knows, or reasonably should know, is in violation of applicable Data Privacy Laws.

b. Customer shall not disclose or otherwise make available to GRAIL any Sensitive Personal Information under the Agreement or this DPA without GRAIL’s prior written consent. For the purposes of this DPA, “Sensitive Personal Information” means Personal Information that reveals an individual’s social security, driver’s license, state identification card, or passport number; account log-in(s); financial account, debit card, or credit card number(s) whether or not in combination with any required security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious or philosophical beliefs; genetic data; biometric information; health information (including PHI); or sex life or sexual orientation.

c. Customer must notify GRAIL in writing it requires GRAIL to provide PHI on GRAIL invoices for charges associated with the Test. With respect to any such request, Customer hereby represents and warrants that (i) it cannot fulfil its payment obligations to GRAIL without the inclusion of such PHI on applicable invoices; (ii) it shall not use or disclose the PHI for any other purpose besides its performance of payment obligations to GRAIL under this Agreement (the “Purpose”); (iii) the requested PHI constitutes the minimum necessary required for Customer to fulfil the Purpose; (iv) Customer shall apply appropriate technical, organizational, and administrative safeguards to ensure the protection and security of such PHI in compliance with all applicable law and Customer policies.  For the avoidance of doubt, GRAIL’s permissible basis for sharing such PHI is to receive reimbursement for the provision of healthcare services provided under the Agreement, as is permitted under 45 CFR 164.506(c)(1). GRAIL reserves the right to deny a request to include PHI on invoices if GRAIL reasonably believes that such inclusion is not required for GRAIL to receive reimbursement.

4. SECURITY

4.1 GRAIL Security Standards. GRAIL has implemented, and shall maintain throughout the term of the Agreement, appropriate administrative, organizational, technical, and physical safeguard with respect the Personal Information designed to protect the security, confidentiality, integrity and availability of Personal Information that are consistent with industry best practices and any applicable Data Privacy Laws. GRAIL shall protect against reasonably anticipated threats to the security or integrity of Personal Information, including reasonably anticipated impermissible uses or disclosure of Personal Information, and shall mitigate, to the extent possible, any harmful effect that is known to GRAIL of such impermissible uses or disclosures. Without limiting the generality of the foregoing, GRAIL’s security procedures and practices shall include, at a minimum, the measures set forth in the GRAIL Security Addendum attached hereto as Exhibit B (“Exhibit B”).

4.2 Security Incidents. If GRAIL learns of a Security Incident that occurs on GRAIL’s systems or that is directly related to GRAIL’s processing of Personal Information under the Agreement that leads to the unlawful access to, exfiltration, theft, loss, alteration or disclosure of Personal Information transmitted, stored or otherwise processed by GRAIL or its Subcontractor, GRAIL shall notify Customer without unreasonable delay and shall cooperate with Customer’s efforts to respond to such Security Incidents.  Such notification shall include, at a minimum: (a) the nature of the Security Incident, including where possible, the categories and approximate number of Eligible Participants concerned and the categories and approximate number of Personal Information records concerned; (b) details of the likely consequences of the Security Incident; and (c) details of the measures taken or proposed to be taken by GRAIL to address the Security Incident, including, where appropriate, measures to mitigate its possible adverse effects. Upon Customer’s written request, GRAIL shall assist Customer with any notification that Customer is required to make to Eligible Participants and/or regulatory authorities. 

5. RIGHTS OF CONSUMERS. The terms of this Section 5 apply to the extent that an Eligible Participant meets the definition of a Consumer under Applicable Privacy Law.

5.1 As between Customer and GRAIL, Customer shall be responsible for providing Consumers with any privacy notice or any other disclosure required by applicable Data Privacy Laws with respect to the collection and processing of Personal Information under the Agreement, including any notice required under applicable Data Privacy Laws at the point of collection of a Consumer’s Personal Information. 

5.2 Taking into account the nature of the processing performed by GRAIL, GRAIL shall assist Customer through appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligations to respond to reasonable requests for exercising Consumers’ rights. 

5.3 Unless otherwise required by applicable Data Privacy Laws, GRAIL shall not respond to any requests or other communications that GRAIL receives from Consumers, without the prior written consent, and at the direction of Customer, except to acknowledge receipt of Consumer’s request and direct the Consumer to Customer.

5.4 GRAIL shall not, as a result of a Consumer’s exercise of Consumers’ Rights, deny goods or services to the Consumer, charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties; provide a different level or quality of goods or services to the Consumer; or suggest to the Consumer that any of the foregoing will result from the exercise of Consumer’s Rights.

6. RETURN OR DISPOSAL.  To the extent not otherwise prohibited by applicable Data Privacy Laws, at any time upon Customer’s written request, upon or upon the expiration or termination of the Agreement for any reason, GRAIL shall (and shall ensure that any Subcontractors shall), at Customer’s discretion, either return or securely delete or destroy all Personal Information processed under the Agreement. Notwithstanding the foregoing, GRAIL may retain copies of Personal Information as required to meet its legal, regulatory or professional obligations. The privacy and security provisions of this DPA shall continue to apply for as long as GRAIL retains the Personal Information 

7. GENERAL

7.1 Assignment.  Neither GRAIL nor any permitted Subcontractor shall be entitled to assign its rights or benefits or transfer its obligations or burdens under this DPA, whether in whole or in part, without the prior written consent of Customer.  Any assignment or other transfer in violation of the foregoing shall be null and void.

7.2 Survival.  GRAIL acknowledges and agrees that, notwithstanding the termination or expiry of the Agreement or this DPA for any reason, the obligations in this DPA shall continue for so long as any Personal Information remains in GRAIL’s custody or control, or GRAIL (or any permitted Subcontractor) otherwise processes Personal Information under or in connection with the Agreement or this DPA.

7.3 Conflicts. In the event of a conflict between this DPA and the Agreement, this DPA shall control with respect to the processing of Personal Information.   

7.4 Notices.  All notices provided by GRAIL under this DPA will be provided to Customer at the mailing address set forth in the Agreement


Exhibit A

ERISA EXHIBIT 

This Exhibit A applies to the extent Customer makes the Test available to Eligible Participants as part of an employee welfare benefit plan that is subject to the Employee Retirement income Security Act of 1974 (“ERISA”) and that qualifies as a health plan as defined under HIPAA (“Health Plan”). For the purposes of this Exhibit A, the term Customer includes, as applicable, the Customer’s Health Plan. Capitalized terms used and not otherwise defined in this Exhibit A shall have the meaning given to them in the Galleri® Testing Agreement Data Protection and Information Security Addendum (“DPA”) to which it is attached. 

For the purposes of this Exhibit A, the terms “Business Associate”, “Covered Entity,” “Healthcare Operations,” “Indirect Treatment Relationship,” “Payment,” and “Treatment” have the meanings given to them under HIPAA. 

1. RELATIONSHIP OF THE PARTIES 

a. The Parties acknowledge and agree that GRAIL is a Covered Entity healthcare provider that establishes an Indirect Treatment Relationship with Eligible Participants who receive the Test. The Parties acknowledge and agree that in the performance of its obligations under the Agreement, GRAIL does not serve as a Business Associate to Customer. In the event the services provided by GRAIL to Customer change such that GRAIL constitutes a Business Associate of Customer, the Parties hereby agree to enter into a Business Associate Agreement without unreasonable delay.  

b. Customer hereby represents and warrants that it (i) is offering the Test as part of an employee welfare benefit plan subject to ERISA and that qualifies as a Health Plan under HIPAA; and (ii) complies with the all applicable requirements under HIPAA including, without limitation, the requirements for group health plans set forth in 45 §164.504(f). 

2. USE AND DISCLOSURE OF PHI 

a. Absent an authorization collected in accordance with 45 CFR §164.508, any collection use or disclosure of PHI that occurs under the Agreement by either Party shall be exclusively for that Party’s Treatment, Payment, or Healthcare Operations (hereinafter, collectively, “TPO”) purposes as permissible under 45 CFR §164.506(c), or as is otherwise legally required under HIPAA. 

b. The Health Plan shall only request from GRAIL, and GRAIL shall only disclose to the Health Plan, the minimum necessary PHI required for the Health Plan to perform plan administrative functions (as defined in 45 CFR §164.504(a)), or to otherwise meets its legal obligations as a Health Plan.   Customer represents and warrants that (i) such PHI provided by GRAIL to Customer will be used solely for Health Plan activities or as otherwise required by applicable law, (ii) Customer will not use such PHI in any manner not in accordance with HIPAA and the restrictions established in the Health Plan documents as required by 45 CFR §164.504(f)(2); (iii) Customer will not use the PHI for the purposes of employment-related actions or decisions or in connection with any other benefit or employee benefit plan of Customer.

c. To the extent the Health Plan requests GRAIL to disclose PHI to the Customer’s third-party administrator (“TPA”) the Health Plan hereby represents and warrants that: (i) the request is for the minimum necessary PHI needed for the Health Plan or TPA to accomplish the TPO purposes for which it was requested; (ii) the TPA is a Business Associate of the Health Plan; and (iii) the Health Plan will prohibit the TPA from using or disclosing the PHI for any purpose other than the TPO purpose for which it was disclosed, without receiving the necessary authorizations, consents, and/or other applicable rights from the individuals to which the PHI pertains. 

3. SECURITY SAFEGUARDS AND COMPLIANCE WITH HIPAA SECURITY REGULATIONS.  GRAIL shall use appropriate administrative, technical, and organizational safeguards in compliance with the HIPAA Security Rule (45 CFR 164 Part C) to protect against unauthorized access, use or disclosure of PHI. Without limiting the foregoing, GRAIL shall protect PHI in compliance with Section 4 of the DPA (Security) and GRAIL’s Security Addendum attached hereto as Exhibit B. 

4. SURVIVAL. The obligations in this Exhibit A shall continue for so long as any PHI processed by GRAIL pursuant to the Agreement remains in GRAIL’s custody or control.

5. CONFLICT. In the event of any conflicts between this Exhibit A, the DPA, and the Agreement, this Exhibit A shall control with respect to the treatment of PHI. Any ambiguity in this Exhibit A shall be interpreted to permit and require compliance with HIPAA and any other applicable law.


EXHIBIT B

GRAIL Security Addendum

This GRAIL Security Addendum (hereinafter “Exhibit B”) is incorporated into and made a part of the Data Protection & Information Security Addendum (the “DPA”) to which it is attached. Capitalized terms used but not otherwise defined herein have the meanings given to them in the DPA. 

Without limiting GRAIL’s obligations under Section 4 of the DPA (Security) and Section 3 of Exhibit A (Security Safeguards and Compliance with HIPAA Security Regulations) this Exhibit B describes the minimum administrative, technical, physical, and organizational security measures (collectively, the “Information Security Program”) that GRAIL has implemented and will maintain to protect Personal Information and PHI that GRAIL processes under the DPA. As security threats change, GRAIL may update its Information Security Program to ensure Personal Information and PHI is appropriately protected. As such, GRAIL reserves the right to update this Exhibit B from time to time; provided, however, that GRAIL shall not reduce the level of security standards established in this Exhibit B.

1. Information Security Policies and Standards: GRAIL shall maintain written information security policies, standards, and procedures addressing administrative, organizational, technical, and physical safeguards reasonably designed to protect the confidentiality, integrity, and availability of Personal Information and PHI. 

2. Physical Security: GRAIL shall maintain commercially reasonable security systems at GRAIL corporate sites at which an information system that uses or stores Personal Data or PHI is located. 

3. Organizational Security: GRAIL shall maintain written information security policies and procedures addressing acceptable data use standards and incident response protocols. 

4. Network Security: GRAIL shall maintain commercially reasonable information security policies and procedures addressing network security. 

5. Virus and Malware Controls: GRAIL shall protect Personal Information and PHI from malicious code and will install and maintain anti-virus and malware protection software on GRAIL-managed devices that handle Personal Information and PHI. 

6. Personnel: GRAIL shall maintain an Information Security team that manages the Information Security Program. GRAIL shall maintain a security and privacy awareness program to train employees about their security and privacy obligations. Employees are required to follow established security policies and procedures.

7. Subcontractor Security. GRAIL shall only select and contract with Subcontractors that are capable of maintaining appropriate security safeguards that are no less onerous than those contained in the DPA and this Exhibit B. 

8. Disaster Recovery. GRAIL shall maintain disaster recovery plans that are kept up to date and revised on a regular basis.

9. Security Framework and certifications. GRAIL shall maintain a security framework that is aligned to information security established industry standards, such as ISO/IEC 27001, or an equivalent industry-recognized framework. GRAIL shall provide evidence of its then-current certifications upon Customer’s written request. 

  •