Effective date: 1st April 2026
1. Overview
This Privacy Notice explains how Abbott processes personal data when you use our websites, create and manage an account, purchase products, contact our customer support channels, or use our digital applications. It also describes the use of cookies and similar technologies on our websites.
2. Controller Information
Depending on the processing activity, the controllers within the meaning of UK GDPR / EU GDPR are Abbott Laboratories Limited (Abbott House, Vanwall Business Park, Maidenhead, Berkshire SL6 4XE, UK). Country-specific controllers and representatives apply where required by local law.
3. How Abbott Processes Your Personal Data
This table offers an overview of the personal data Abbott processes, for what purpose and the legal requirement we have to fulfil to do so. This is not an exhaustive list and only some part will apply to you, depending on the type of user, the applicable affiliate or Abbott business and the processed information.
3.1 Provision of Products and Services
| Purpose for collection/use | Categories of personal data | Lawful basis |
| Provision of user accounts | Name, contact details, login credentials, account activity, purchase history | Performance of a contract |
| Process and fulfil orders; send transactional messages | Address, payment and financial information, order and shipping information | Performance of a contract; legal obligations (e.g., tax and accounting) |
| Provide information about products and services, including software updates, training and special offers | Contact details; preferences; subscription settings | Consent where required; otherwise, legitimate interests in keeping users informed |
3.2 Customer support, complaint handling, and service improvement
| Purpose for collection/use | Categories of personal data | Lawful basis |
| Respond to inquiries via phone, email, social media or online chat | Name, address, date of birth, country of residence, email, phone; whether contacting on behalf of a user; account information; device details; communication record | Legitimate interests (customer support); performance of a contract as applicable; consent |
| User-generated content | Comments on our products and services, like complaints, responses to our newsletters and product information, reviews and ratings. We also collect feedback through user surveys and facilitate user ratings and reviews on some of our services. | Legitimate interests (customer support); performance of a contract as applicable |
| Support for app-related issues | Mobile device information, including operating system; app usage details as relevant | Legitimate interests (troubleshooting and service improvement) |
| Handle sensor complaints and warranty cases; provide complaint number | Device identifiers, error/issue descriptions, shipping address details | Legal obligation; performance of a contract |
| To enhance customer experience, we may combine data held across Abbott systems to facilitate a unified view of your account and to improve resolution speed and accuracy | Account data, purchase history, prior interactions and outcomes; contact frequency and nature | Legitimate interests |
| Integrate web shop data with customer service interactions to improve resolution speed and accuracy | Summaries of prior interactions and outcomes; contact frequency and nature | Legitimate interests (service efficiency and accuracy) |
| Operate the webshop and online support forms | Name, phone number, device model, email address, shipping address, device type and app used, operating system, sensor error details | Performance of a contract; legal obligations |
| Issue complaint numbers; assess warranty; contact by phone if needed | Contact details; case metadata | Legal obligations |
| Immediately transfer answers to our quality management system | Support form submissions | Legal obligations; legitimate interests (quality and safety) |
| Systematically use contact details to improve user experience (e.g., pre-filling forms when logged in) | Contact and account identifiers | Performance of a contract |
| Process health-related information submitted via websites or support channels | Health data and other special categories provided by you | Explicit consent where required; legal obligations; vital interests in limited cases |
3.3 Marketing, and Personalised Communications
| Purpose for collection/use | Categories of personal data | Lawful basis |
| Deliver communications via letter, SMS, telephone, or in‑app messages (e.g., LibreView or FreeStyle Libre app) | Contact and channel preferences; limited engagement metadata | Consent; legitimate interests (service communications) |
| Personalise website/app content and communications based on your preferences and interactions | Demographics (e.g., age, gender), insurance details, diabetes type, sensor type, pump connectivity, glucose values or alerts, dietary information (if entered), sensor status, prior customer service contacts, order/shipping/delivery data | Consent where required by law |
| Send targeted reminders and recommendations to help product use and health outcomes | Contact details; usage patterns; sensor lifecycle status | Consent (for marketing); legitimate interests for service messages |
3.4 Fraud prevention and security
| Purpose for collection/use | Categories of personal data | Lawful basis |
| Safeguard users and Abbott from fraud (e.g., screen interactions for common fraudulent behaviours) | Identifiers, transaction metadata, behavioural patterns as relevant | Legitimate interests (fraud prevention) |
3.5 Website analytics and cookies
| Purpose for collection/use | Categories of personal data | Lawful basis |
| Collect technical and web browsing information through cookies and similar technologies | Browser type and language, operating system, IP address, referrer URLs, pages viewed, ads and links clicked | Consent where required; legitimate interests (site performance and audience measurement) |
For details, see the separate Cookies Policy available on our website.
4. Sharing of personal data
We may share personal data with contracted service providers who support us in delivering our products and services, such as customer support providers, logistics partners, payment service providers or fraud-prevention services. In doing so, we limit the disclosure to only the personal data that is necessary to deliver the service. Such processing may be based on the performance of a contract, our legitimate interests, or compliance with legal obligations.
In addition, we may share personal data with Abbott affiliates and partners in the context of joint marketing activities or joint programs, where this is required for the registration and execution of the respective activity. In these cases, processing is based on consent where legally required or on our legitimate interests.
Personal data may also be disclosed in connection with corporate transactions, such as the sale or transfer of a product line or business unit, limited to customer and account data relevant to the transferred business, and based on legitimate interests or legal obligations.
Furthermore, we may disclose personal data to public authorities, law enforcement agencies, legal advisers or auditors where this is necessary to comply with legal obligations, to respond to lawful requests, or to establish, exercise or defend legal claims.
5. How long will Abbott keep my personal data?
We will keep your personal data in our records for as long as necessary for the purposes described in this Privacy Policy or otherwise authorised by law. This includes providing you with a service you have requested from us or complying with applicable legal, regulatory, tax, accounting, or reporting requirements. It also includes keeping your personal data for so long as there is any possibility that you or we may wish to bring a legal claim, or where we are required to keep your personal data for legal or regulatory reasons. We may also retain your personal data where such retention is necessary to protect your interests or the interests of another natural person. Where information is used for more than one purpose, we will retain it until the purpose with the latest period expires. Where we no longer require your personal data for any of the purposes described in this Privacy Policy, your personal data will be deleted from our systems and will no longer be available to us. In general, we may apply the following criteria:
- Data is retained for the duration of our professional or contractual relationship with you.
- Data is retained as long as you do not withdraw your consent or object to the processing, where applicable.
- Data is retained for the period required by applicable laws and regulations.
- Data may be retained for the duration of applicable statutes of limitation to defend against legal claims or audits.
If you wish to receive further information regarding our record retention procedures, please contact us using the contact details provided under the “How can I contact Abbott?” section below.
6. Does Abbott transfer personal data to different jurisdictions?
Abbott may transfer your personal data to other jurisdictions different from the country where you are based. These countries may include the United States, where Abbott is headquartered, and other countries that may not guarantee the same level of protection of personal data as the one in which you reside.
To safeguard your personal data, we will only make such transfers as necessary to use your personal data as described in this policy and only transfer your personal data as permitted by applicable data protection laws and relying on existing transfer mechanisms or safeguards, such as Standard Contractual Clauses, Adequacy decisions, explicit consent or Binding Corporate Rules. Some Abbott affiliates and group companies are certified under the EU-US/UK-US/Swiss-US Data Privacy Frameworks, which provide a comparable level of safeguards to your personal data.
7. What are your Privacy Rights?
The applicable data protection law grants you comprehensive data protection rights to your personal data. Some or all of the following rights may be granted by the laws of your country or region:
The right to request the erasure of your personal data;
The right to rectify any wrong or incomplete personal data that Abbott holds about you;
The right to object or opt-out at any time of processing activities based on legitimate interest (e.g., on some occasions, opt-out from receiving marketing material from us). This will usually be noted and accessible at the bottom of any email you receive from us.
The right to request access to the personal data that Abbott holds about you;
The right, in some cases, to limit the processing of your personal data, where applicable.
The right not to be subjected to solely automated decision-making, where applicable.
Where you have provided your personal data to us with your consent or as part of a contract, the right to the portability of that personal data to another person or, if it’s technically feasible for us to do so, to another company;
The right to lodge a complaint with your national data protection supervisory authority. You may find the contact details of the competent supervisory authority for EEA Member States with the associated contact details under the following link: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en ; or for Switzerland: https://www.edoeb.admin.ch/edoeb/en/home.html ; or for the UK: https://ico.org.uk.
Please note that these rights could be rejected or limited according to the applicable data protection regulations or may depend on additional requirements. You can exercise your rights by contacting Abbott as described below.
8. How does Abbott protect the privacy of children?
Abbott is committed to protecting the privacy of children. We collect and process personal data of minors only where this is necessary for the use of our products or services and solely in accordance with applicable data protection laws. Where legally required, we obtain verifiable consent from a parent or legal guardian before collecting or using personal data of a child.
Abbott does not knowingly allow children to order products or use online services that are not intended for them. Personal data of minor users is processed only for the specified purposes, in a secure manner, and with appropriate safeguards in place.
If you are a parent or legal guardian and believe that your child has provided personal data to Abbott without the required consent, please contact us at the email address below. We will promptly review the matter and take appropriate action.
9. How does Abbott keep personal data secure?
It is Abbott’s practice to apply appropriate security measures to the processing of personal data. However, the confidentiality of personal data transmitted over the Internet cannot be guaranteed. Personal data can be accessed by a restricted number of Abbott employees. We train our employees about the importance of privacy and how to handle and manage customer data appropriately and securely. We urge you to exercise caution when transmitting personal data over the Internet, especially personal data related to your health. Abbott cannot guarantee that unauthorized third parties will not gain access to your personal data; therefore, when submitting personal data to Abbott Websites, you must weigh both the benefits and the risks.
We may provide links to websites and other third-party content that are not owned or operated by Abbott. You should check the privacy policies of any third-party sites different from this one before submitting personal data.
10. How can I contact Abbott?
If you have questions about the use, amendment, or deletion of personal data that you have provided to us, or if you would like to opt out of future communications, please contact us at ADChelpuk@abbott.com or by mail:
Abbott Laboratories Limited
Abbott House
Vanwall Business Park
Maidenhead
Berkshire
SL6 4XE
EU Data Protection Officer (EU DPO): EU-dpo@abbott.com
Further information: https://www.abbott.com/eu-dpo.html
11. How will I know whether Abbott has updated this Policy?
Without prejudice to your rights under applicable law, Abbott reserves the right to amend this Privacy Policy without prior notice to reflect technological advancements, legal and regulatory changes and good business practices. In certain jurisdictions, registered users will be notified by email of any changes and relevant information will be posted on the Abbott Website.
If Abbott changes its privacy practices, an updated version of this Privacy Policy will reflect those changes, and we will notify you of such changes by updating the effective date at the top of this Privacy Policy.