Northrop Grumman Online Privacy Notice
Suppliers and Subcontractors
Effective March 10, 2025
Last Updated March 10, 2025
This Privacy Notice (“Notice”) is a supplement to the Northrop Grumman Privacy Notice and applies to suppliers and subcontractors that provide goods and or services to Northrop Grumman and its affiliates.
This Notice describes the types of Personal Information we may collect, how we use the information, with whom we share it and the choices available to individuals regarding our use of the information.
This Notice uses certain terms that have the meaning given to them in the California privacy laws.
Information We Collect/Obtain
Through your interaction with Northrop Grumman as a supplier or subcontractor, we may collect the following categories of Personal Information about you:
- Contact Information, including name, alias, email address, phone number, company name, company address
- Identifying Information, including national origin, citizenship, date of birth, place of birth, gender, military and veteran status
- Government Identification Information, including Social Security number, federal tax ID number, driver’s license number, passport number, state identification card number
- Financial Information, including bank account number, debit card number, bankruptcy information, and other similar information
- Employment Information, including work location, period of work, compensation information, work history, salary history, work authorization information, previous affiliation with Northrop Grumman, information about security clearances, civil and criminal court history
- Education Information, including résumé or C.V., education history, skills, certifications, and other professional information
- Inferences: inferences drawn from any of the information identified above to create a profile about you reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes
- Log-in Credentials, including username, password, time and date of login
Of the Personal Information collected, we may collect the following categories of sensitive Personal Information which may have special protections under the laws of your region:
- Government Identification Information, including Social Security number, federal tax ID number, driver’s license number, passport number, state identification card number
- Financial information, including bank account number, credit card number, debit card number, and other similar information
- Log-in Credentials; (such as username, password, time and date of login)
Where we process Personal Information regarded as 'special' in certain jurisdictions, we only process the Personal Information where necessary for compliance with employment, social security, or social protection laws. We will seek your explicit consent in writing, and you have the right to withdraw this consent at any time by contacting us as indicated in the 'How to Contact Us' section below.
How We Use the Information About You
We may use the above categories of Personal Information and sensitive Personal Information for certain business and/or commercial purposes, including as described in the below table. We may use your Personal Information in other ways for which we provide specific notice at the time of collection.
Purposes |
Categories of Personal Information |
Legal Basis |
To facilitate and administer our relationship with suppliers and subcontractors |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for the performance of the contract that governs the relationship |
To facilitate payment for goods and services |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Log-in Credentials |
Necessary for the performance of the contract that governs the relationship |
To conduct due diligence, including vetting individuals associated with suppliers or subcontractors where relevant and appropriate |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Necessary for our legitimate interests |
To undertake checks and maintain records that our suppliers and subcontractors are suitably qualified and experienced |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Necessary for our legitimate interests |
To provide you with support and to respond to your requests or inquiries, including to investigate and address any concerns |
Contact Information; Identifying Information; Government Identification Information; Employment Information; Log-in Credentials |
Necessary for the performance of the contract that governs the relationship |
To operate, evaluate and improve our business |
Contact Information; Identifying Information;; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for our legitimate interests |
Perform data analyses (including anonymization and aggregation of personal information) |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Necessary for our legitimate interests |
To protect against, identify and prevent cybersecurity and other security events, espionage, fraud and other unlawful activity, claims and other liabilities; and prosecuting those responsible |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for our legitimate interests |
To comply with Northrop Grumman policies |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for our legitimate interests |
To comply with and enforce applicable legal requirements, contractual obligations, relevant industry standards |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for us to comply with a legal obligation |
To respond to law enforcement requests |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for us to comply with a legal obligation |
To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us is among the assets transferred |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Necessary for our legitimate interests |
Prior Collection, Use and Disclosure of Personal Information
We may have collected and used your Personal Information, as described in “Information We Collect” and “How We Use the Information We Collect” sections above, during the 12-month period prior to the effective date of this Notice.
For Personal Information collected during such timeframe, we describe below:
the categories of sources from which we may have obtained the Personal Information,
- the categories of Personal Information we may have disclosed for a business purpose and the categories of recipients to whom we may have disclosed such information, and
- the categories of Personal Information we may have sold or shared to a third party, if any.Sources of Personal Information
We may have obtained Personal Information about you from various sources, including as described below.
Categories of Sources of Data Collection |
Categories of Personal Information |
Directly from you (such as when you provide identifiers to gain access to one of our facilities) |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Log-in Credentials |
Our subsidiaries |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Vendors who provide services on our behalf |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Log-in Credentials |
Our customers and business partners (such as subcontractors and suppliers) |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Log-in Credentials |
Government agencies, law enforcement, courts and regulators |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Cybersecurity information sharing resources |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Social networking services |
Contact Information; Identifying Information; Employment Information; Education Information |
Public databases |
Contact Information; Identifying Information; Employment Information; Education Information |
Disclosure of Personal Information for a Business Purpose
We may have disclosed certain categories of Personal Information to certain categories of recipients for a business purpose, including as described below.
Categories of Persons |
Categories of Personal Information |
Our subsidiaries |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Vendors who provide services on our behalf |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Our customers and business partners (such as subcontractors and suppliers) |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Participants in cyber security information resources (when related to a cyber threat indicator) |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences |
Government agencies, law enforcement, courts and regulators |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
Other parties in the event of a corporate transaction, such as an acquisition |
Contact Information; Identifying Information; Government Identification Information; Financial Information; Employment Information; Education Information; Inferences; Log-in Credentials |
For a list of relevant service providers, please contact us using one of the means identified in the “How To Contact Us” section below
Sale or Sharing of Personal Information
Except as described in this Notice, we do not sell or otherwise disclose Personal Information we collect about you to third parties or in exchange for monetary or other valuable consideration. We may also share Personal Information with service providers who perform services on our behalf based on our instructions. We may share certain Personal Information with our affiliates for the purposes described in this Notice.
Your Rights and Choices
Please refer to the “Your Rights and Choices” section of the Northrop Grumman Privacy Notice for an explanation of the rights and choices you have under applicable laws regarding your personal information.
Data Transfers
Please refer to the “Data Transfers” section of the Northrop Grumman Privacy Notice for information related to the cross-border transfer of personal information to regions other than the region in which the information was collected/obtained.
How We Protect Personal Information
Please refer to the “How We Protect Personal Information” section of the Northrop Grumman Privacy Notice for a description of the measures we undertake to protect your personal information.
Data Retention
Please refer to the “Data Retention” section of the Northrop Grumman Privacy Notice for more information on how long your data may be kept.
Links To Other Websites
Please refer to the “Links To Other Websites” section of the Northrop Grumman Privacy Notice for more information.
Updates To Our Notice
Please refer to the “Updates To Our Notice” section of the Northrop Grumman Privacy Notice for more information.
How To Contact Us
Please refer to the “How To Contact Us” section of the Northrop Grumman Privacy Notice for more information.
Subsidiaries/Affiliates
Please refer to the “Subsidiaries/Affiliates” section of the Northrop Grumman Privacy Notice for more information.