Appendix 4: IT security measures Sample Clauses

Appendix 4: IT security measures. For the specific data processing, a level of protection is guaranteed suitable for the risks to the rights and freedoms of the natural persons affected by the processing. For this purpose, the protection objectives of Art. 32 para. 1 GDPR, such as confidentiality, integrity and availability of the systems and services, as well as their resilience in regard to the type, scope, circumstances and purpose of the processing, are considered in such a way that the risk is mitigated by means of suitable technical and organisational measures. The service provider has defined the security objectives, an IT security process and IT security management in its IT security concept to ensure the protection of Personal Data through appropriate technical and organisational measures. According to the specifications from the IT security concept, the risks associated with data processing were determined as well as a determination of the potential effects on the Data Subjects and the probability of occurrence. The determination of the technical measures to ensure data security takes place – as shown in the IT security concept – in consideration of the state of the art as well as the implementation costs. The ongoing guarantee of the requirements resulting from statutory provisions, e.g. GDPR, is ensured by the “IT security management”, where, in addition to the clear definitions and functions as well as tasks and responsibilities including, but not limited to, the implemented technical and organisational measures set forth below in this Appendix in accordance with Art. 32 GDPR, are implemented and continuously monitored and checked in the context of security checks. The measures described below represent the selection of the technical and organisational measures (“XXX”) to guarantee data security according to Art. 32 GDPR, suitable for the risk determined, taking into consideration the protection objectives according to the state of the art. The following protective level concept was used as a basis: Protection level Personal data for example (for individual data; for cumulative data, if necessary, higher protection level attached!) Severity of possible damage A have been made freely accessible by the Data Subject telephone directory, freely accessible website, freely accessible social media Minor B the improper handling of which does not lead to any particular adverse effects, but which were not made freely accessible by the person concerned Restricted access public files, lan...

Related to Appendix 4: IT security measures

  • Security Measures Lessee hereby acknowledges that the rental payable to Lessor hereunder does not include the cost of guard service or other security measures, and that Lessor shall have no obligation whatsoever to provide same. Lessee assumes all responsibility for the protection of the Premises, Lessee, its agents and invitees and their property from the acts of third parties.

  • Safety Measures Awarded vendor shall take all reasonable precautions for the safety of employees on the worksite, and shall erect and properly maintain all necessary safeguards for protection of workers and the public. Awarded vendor shall post warning signs against all hazards created by the operation and work in progress. Proper precautions shall be taken pursuant to state law and standard practices to protect workers, general public and existing structures from injury or damage.

  • Interim Measures 6.1 The Parties acknowledge that the British Columbia Claims Task Force made the following recommendation concerning Interim Measures:

  • Protective Measures We have implemented and will maintain appropriate technical and organisational measures in relation to the Services taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the likelihood and severity of risk to the rights and freedoms of data subjects. This includes measures relating to the physical security of Our facilities used to deliver them, measures to control access rights to Our assets and relevant networks, and processes for testing these measures. In accordance with Our obligations under applicable law, We may undertake digital forensic investigations in relation to the use of the Services and Subscriptions. You are responsible for using, and ensuring that your Users use, the controls and advice provided by the Services correctly and consistently.

  • Non-tariff Measures 1. A Party shall not adopt or maintain any non-tariff measures on the importation of any good of the other Party or on the exportation of any good destined for the territory of the other Party except in accordance with its WTO rights and obligations or in accordance with other provisions of this Agreement. 2. Each Party shall ensure its non-tariff measures permitted in paragraph 1 are not prepared, adopted or applied with a view to, or with the effect of, creating unnecessary obstacles to trade between the Parties.

  • Safeguard Measures Neither Party shall take safeguard action against services and service suppliers of the other Party from the date of entry into force of this Agreement. Neither Party shall initiate or continue any safeguard investigations in respect of services and service suppliers of the other Party.

  • Bilateral Safeguard Measures 1. Where, as a result of the reduction or elimination of a customs duty under this Agreement, any product originating in a Party is being imported into the territory of another Party in such increased quantities, in absolute terms or relative to domestic production, and under such conditions as to constitute a substantial cause of serious injury or threat thereof to the domestic industry of like or directly competitive products in the territory of the importing Party, the importing Party may take bilateral safeguard measures to the minimum extent necessary to remedy or prevent the injury, subject to the provisions of paragraphs 2 to 10. 2. Bilateral safeguard measures shall only be taken upon clear evidence that increased imports have caused or are threatening to cause serious injury pursuant to an investigation in accordance with the procedures laid down in the WTO Agreement on Safeguards. 3. The Party intending to take a bilateral safeguard measure under this Article shall immediately, and in any case before taking a measure, make notification to the other Parties and the Joint Committee. The notification shall contain all pertinent information, which shall include evidence of serious injury or threat thereof caused by increased imports, a precise description of the product involved and the proposed measure, as well as the proposed date of introduction, expected duration and timetable for the progressive removal of the measure. A Party that may be affected by the measure shall be offered compensation in the form of substantially equivalent trade liberalisation in relation to the imports from any such Party. 4. If the conditions set out in paragraph 1 are met, the importing Party may take measures consisting in increasing the rate of customs duty for the product to a level not to exceed the lesser of: (a) the MFN rate of duty applied at the time the action is taken; or (b) the MFN rate of duty applied on the day immediately preceding the date of the entry into force of this Agreement. 5. Bilateral safeguard measures shall be taken for a period not exceeding one year. In very exceptional circumstances, after review by the Joint Committee, measures may be taken up to a total maximum period of three years. No measure shall be applied to the import of a product which has previously been subject to such a measure. 6. The Joint Committee shall within 30 days from the date of notification examine the information provided under paragraph 3 in order to facilitate a mutually acceptable resolution of the matter. In the absence of such resolution, the importing Party may adopt a measure pursuant to paragraph 4 to remedy the problem, and, in the absence of mutually agreed compensation, the Party against whose product the measure is taken may take compensatory action. The bilateral safeguard measure and the compensatory action shall be immediately notified to the other Parties and the Joint Committee. In the selection of the bilateral safeguard measure and the compensatory action, priority must be given to the measure which least disturbs the functioning of this Agreement. The compensatory action shall normally consist of suspension of concessions having substantially equivalent trade effects or concessions substantially equivalent to the value of the additional duties expected to result from the bilateral safeguard measure. The Party taking compensatory action shall apply the action only for the minimum period necessary to achieve the substantially equivalent trade effects and in any event, only while the measure under paragraph 4 is being applied. 7. Upon the termination of the measure, the rate of customs duty shall be the rate which would have been in effect but for the measure. 8. In critical circumstances, where delay would cause damage which would be difficult to repair, a Party may take a provisional emergency measure pursuant to a preliminary determination that there is clear evidence that increased imports constitute a substantial cause of serious injury, or threat thereof, to the domestic industry. The Party intending to take such a measure shall immediately notify the other Parties and the Joint Committee thereof. Within 30 days of the date of the notification, the procedures set out in paragraphs 2 to 6, including for compensatory action, shall be initiated. Any compensation shall be based on the total period of application of the provisional emergency measure and of the emergency measure. 9. Any provisional measure shall be terminated within 200 days at the latest. The period of application of any such provisional measure shall be counted as part of the duration of the measure set out in paragraph 5 and any extension thereof. Any tariff increases shall be promptly refunded if the investigation described in paragraph 2 does not result in a finding that the conditions of paragraph 1 are met. 10. Five years after the date of entry into force of this Agreement, the Parties shall review in the Joint Committee whether there is need to maintain the possibility to take safeguard measures between them. If the Parties decide, after the first review, to maintain such possibility, they shall thereafter conduct biennial reviews of this matter in the Joint Committee.

  • Global Safeguard Measures Each Party retains its rights and obligations under Article XIX of the GATT 1994 and the WTO Agreement on Safeguards. In taking measures under these WTO provisions, a Party shall, consistent with WTO law and jurisprudence and in accordance with its domestic legislation, exclude imports of an originating product from one or several Parties if such imports do not in and of themselves cause or threaten to cause serious injury.

  • Technical Safeguards 1. USAC and DSS will process the data matched and any data created by the match under the immediate supervision and control of authorized personnel to protect the confidentiality of the data, so unauthorized persons cannot retrieve any data by computer, remote terminal, or other means. 2. USAC and DSS will strictly limit authorization to these electronic data areas necessary for the authorized user to perform their official duties. All data in transit will be encrypted using algorithms that meet the requirements of the Federal Information Processing Standard (FIPS) Publication 140-2 or 140-3 (when applicable). 3. Authorized system users will be identified by User ID and password, and individually tracked to safeguard against the unauthorized access and use of the system. System logs of all user actions will be saved, tracked and monitored periodically. 4. USAC will transmit data to DSS via encrypted secure file delivery system. For each request, a response will be sent back to USAC to indicate success or failure of transmission.

  • Security Safeguards Contractor shall maintain a comprehensive security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of District Data. Contractor shall store and process District Data in accordance with industry standards and best practices, including implementing appropriate administrative, physical, and technical safeguards that are no less rigorous than those outlined in CIS Critical Security Controls (CIS Controls), as amended, to secure such data from unauthorized access, disclosure, alteration, and use. Contractor shall ensure that all such safeguards, including the manner in which District Data is collected, accessed, used, stored, processed, disposed of and disclosed, comply with all applicable federal and state data protection and privacy laws, regulations and directives, including without limitation the Act, as well as the terms and conditions of this Addendum. Without limiting the foregoing, and unless expressly agreed to the contrary in writing, Contractor warrants that all electronic District Data will be encrypted in transmission and at rest in accordance with NIST Special Publication 800-57, as amended, or such other standard as the District’s Chief Privacy Officer or designee may agree to in writing. Contractor shall also encrypt any backup, backup media, removable media, tape, or other copies. In addition, Contractor shall fully encrypt disks and storage for all laptops and mobile devices.