Data Privacy and Security Requirements Sample Clauses

Data Privacy and Security Requirements. (a) The Group Companies are and, since December 31, 2016, have been in material compliance with all Data Privacy and Security Requirements. Except as set forth on Section 3.21 to the Company Schedules and to the knowledge of the Company, there have been no Security Incidents since December 31, 2018 with respect to any Company IT Systems, Business Data, or Company Products or otherwise related to the Business. No Group Company has since December 31, 2018 received any written notice from any Person, been required by applicable Law or Contract to give any notice to any Person, or been subject to any Proceeding, in each case with respect to any Security Incident or otherwise with respect to any breach or purported breach of any Data Privacy and Security Requirements. The Group Companies have implemented and maintain commercially reasonable security, disaster recovery and business continuity plans, procedures and facilities, including by implementing systems and procedures to encrypt the transmission of material Business Data on or from Company IT Systems. Since December 31, 2018, there has not been any material failure with respect to any of the Company IT Systems that has not been remedied or replaced in all material respects. The Group Companies have taken commercially reasonable steps intended to ensure that the Company IT Systems do not contain, and, to the knowledge of the Company, the Company IT Systems do not contain, any material unauthorized feature (including any worm, bomb, Trojan Horse, backdoor, clock, timer or other disabling device, code, design or routine) or material defects, technical concerns or problems that would cause any Company IT System to be erased, inoperable or otherwise incapable of being used, or any computer code designed to disrupt, disable or harm in any manner the operation of any Software or hardware, either automatically, with the passage of time or upon command, or otherwise that would prevent the same from performing substantially in accordance with their user specifications or functionality descriptions. (b) The Group Companies (i) engage and have engaged in Processing only with respect to such Data as they are authorized to so engage (or to cause such Processing, as applicable) by Law and, in the case of Data obtained from third parties, Contract, and (ii) have implemented reasonable safeguards designed to prevent unauthorized use or disclosure of such Data. The Group Companies have, with respect to all such Data that is...
AutoNDA by SimpleDocs
Data Privacy and Security Requirements. In connection with its receipt, use, and disclosure of Confidential Data received from NYSDOL pursuant to this MOU, the Data Requestor shall:
Data Privacy and Security Requirements. (a) The Group Companies are and, since December 31, 2018, have been in compliance in all material respects with all Data Privacy and Security Requirements. There have been no material security incidents since December 31, 2018 with respect to any Company IT Systems, Business Data, or Company Products or otherwise related to the Business. No Group Company has since December 31, 2018 received any notice from any Person, been required to give any notice to any Person, or been subject to any Proceeding, in each case with respect to any security incident or otherwise with respect to any breach or purported breach of any Data Privacy and Security Requirements by any Group Company. The Group Companies have implemented and maintain commercially reasonable security, disaster recovery and business continuity plans, procedures and facilities and have employed commercially reasonable efforts to protect the confidentiality, integrity and security of the Company IT Systems. The Group Companies take and have at all times taken commercially reasonable steps to prevent the introduction of any virus, worm, Trojan horse or similar disabling code or program (“Malicious Code”) or any computer code designed to disrupt, disable or harm in any manner the operation of any software or hardware, either automatically, with the passage of time or upon command, or otherwise that would prevent the same from performing substantially in accordance with their user specifications or functionality descriptions (collectively, “Contaminants”) into the Company IT Systems. The Company IT Systems are sufficient in capacity, functionality and operation for the operation of the Business. Since December 31, 2018, there has not been any failure with respect to any of the Company IT Systems that has not been remedied or replaced in all material respects. (b) The Group Companies have implemented commercially reasonable safeguards designed to prevent unauthorized use or disclosure of confidential data and Personal Information in their possession and control. Except as would not be material to the Group Companies, taken as a whole, the Group Companies have rights necessary to Process Personal Information in the conduct of the Business as currently conducted. (c) The Group Companies have all contractual rights necessary to process Business Data in the conduct of the Business as currently conducted. (d) No Group Company is in material breach of any agreement pursuant to which a Group Company licenses, acqu...
Data Privacy and Security Requirements. 1. CONFIDENTIALITY AND SECURE COMMUNICATIONS A. CONTRACTOR shall comply with all applicable federal and state laws and regulations pertaining to the confidentiality of individually identifiable protected health information (PHI) or personally identifiable information (PII) including, but not limited to, requirements of the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the California Welfare and Institutions Code regarding confidentiality of client information and records and all relevant County policies and procedures. B. CONTRACTOR will comply with all COUNTY policies and procedures related to confidentiality, privacy, and secure communications. C. CONTRACTOR shall not use or disclose PHI or PII other than as permitted or required by law. 2. ELECTRONIC PRIVACY AND SECURITY A. CONTRACTOR shall have a secure email system and send any email containing PII or PHI in a secure and encrypted manner. CONTRACTOR’s email transmissions shall display a warning banner stating that data is confidential, systems activities are monitored and logged for administrative and security purposes, systems use is for authorized users only, and that users are directed to log off the system if they do not agree with these requirements. B. CONTRACTOR shall institute compliant password management policies and procedures, which shall include but not be limited to procedures for creating, changing, and safeguarding passwords. CONTRACTOR shall establish guidelines for creating passwords and ensuring that passwords expire and are changed at least once every 90 days. C. Any Electronic Health Records (EHRs) maintained by CONTRACTOR that contain PHI or PII for clients served through this Agreement shall contain a warning banner regarding the PHI or PII contained within the EHR. CONTRACTOR’s that utilize an EHR shall maintain all parts of the clinical record that are not stored in the EHR, including but not limited to the following examples of client signed documents: discharge plans, informing materials, and health questionnaire. D. CONTRACTOR entering data into any county electronic systems shall ensure that staff are trained to enter and maintain data within this system. 3. BUSINESS ASSOCIATE AGREEMENT (BAA) A. CONTRACTOR may perform or assist COUNTY in the performance of certain health care administrative duties that involve the use and/or disclosure of client identifying information as define...
Data Privacy and Security Requirements. Globalstar will comply with the data privacy and security procedures set forth in Attachment 2.7.
Data Privacy and Security Requirements. Contractor agrees to comply with all of the provision in Attachment C, Data Privacy and Security Requirements.
Data Privacy and Security Requirements. 3.1 CONFIDENTIALITY AND SECURE COMMUNICATIONS A. Contractor shall comply with all applicable Federal and State laws and regulations pertaining to the confidentiality of individually identifiable protected health information (PHI) or personally identifiable information (PII) including, but not limited to, requirements of the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the California Welfare and Institutions Code regarding confidentiality of client information and records and all relevant County policies and procedures. B. Contractor will comply with all County policies and procedures related to confidentiality, privacy, and secure communications. C. Contractor shall have all employees acknowledge an Oath of Confidentiality mirroring that of County, including confidentiality and disclosure requirements, as well as sanctions related to non-compliance. D. Contractor shall not use or disclose PHI or PII other than as permitted or required by law.
AutoNDA by SimpleDocs
Data Privacy and Security Requirements 

Related to Data Privacy and Security Requirements

  • Data Privacy and Security Bank will implement and maintain a written information security program, in compliance with all federal, state and local laws and regulations (including any similar international laws) applicable to Bank, that contains reasonable and appropriate security measures designed to safeguard the personal information of the Funds' shareholders, employees, trustees and/or officers that Bank or any Subcustodian receives, stores, maintains, processes, transmits or otherwise accesses in connection with the provision of services hereunder. In this regard, Bank will establish and maintain policies, procedures, and technical, physical, and administrative safeguards, designed to (i) ensure the security and confidentiality of all personal information and any other confidential information that Bank receives, stores, maintains, processes or otherwise accesses in connection with the provision of services hereunder, (ii) protect against any reasonably foreseeable threats or hazards to the security or integrity of personal information or other confidential information, (iii) protect against unauthorized access to or use of personal information or other confidential information, (iv) maintain reasonable procedures to detect and respond to any internal or external security breaches, and (v) ensure appropriate disposal of personal information or other confidential information. Bank will monitor and review its information security program and revise it, as necessary and in its sole discretion, to ensure it appropriately addresses any applicable legal and regulatory requirements. Bank shall periodically test and review its information security program. Bank shall respond to Customer's reasonable requests for information concerning Bank's information security program and, upon request, Bank will provide a copy of its applicable policies and procedures, or in Bank's discretion, summaries thereof, to Customer, to the extent Bank is able to do so without divulging information Bank reasonably believes to be proprietary or Bank confidential information. Upon reasonable request, Bank shall discuss with Customer the information security program of Bank. Bank also agrees, upon reasonable request, to complete any security questionnaire provided by Customer to the extent Bank is able to do so without divulging sensitive, proprietary, or Bank confidential information and return it in a commercially reasonable period of time (or provide an alternative response that reasonably addresses the points included in the questionnaire). Customer acknowledges that certain information provided by Bank, including internal policies and procedures, may be proprietary to Bank, and agrees to protect the confidentiality of all such materials it receives from Bank. Bank agrees to resolve promptly any applicable control deficiencies that come to its attention that do not meet the standards established by federal and state privacy and data security laws, rules, regulations, and/or generally accepted industry standards related to Bank's information security program. Bank shall: (i) promptly notify Customer of any confirmed unauthorized access to personal information or other confidential information of Customer ("Breach of Security"); (ii) promptly furnish to Customer appropriate details of such Breach of Security and assist Customer in assessing the Breach of Security to the extent it is not privileged information or part of an investigation; (iii) reasonably cooperate with Customer in any litigation and investigation of third parties reasonably deemed necessary by Customer to protect its proprietary and other rights; (iv) use reasonable precautions to prevent a recurrence of a Breach of Security; and (v) take all reasonable and appropriate action to mitigate any potential harm related to a Breach of Security, including any reasonable steps requested by Customer that are practicable for Bank to implement. Nothing in the immediately preceding sentence shall obligate Bank to provide Customer with information regarding any of Bank's other customers or clients that are affected by a Breach of Security, nor shall the immediately preceding sentence limit Bank's ability to take any actions that Bank believes are appropriate to remediate any Breach of Security unless such actions would prejudice or otherwise limit Customer's ability to bring its own claims or actions against third parties related to the Breach of Security. If Bank discovers or becomes aware of a suspected data or security breach that may involve an improper access, use, disclosure, or alteration of personal information or other confidential information of Customer, Bank shall, except to the extent prohibited by Applicable Law or directed otherwise by a governmental authority not to do so, promptly notify Customer that it is investigating a potential breach and keep Customer informed as reasonably practicable of material developments relating to the investigation until Bank either confirms that such a breach has occurred (in which case the first sentence of this paragraph will apply) or confirms that no data or security breach involving personal information or other confidential information of Customer has occurred. For these purposes, "personal information" shall mean (i) an individual's name (first initial and last name or first name and last name), address or telephone number plus (a) social security number, (b) driver's license number, (c) state identification card number, (d) debit or credit card number, (e) financial account 22 number, (f) passport number, or (g) personal identification number or password that would permit access to a person's account or (ii) any combination of the foregoing that would allow a person to log onto or access an individual's account. This provision will survive termination or expiration of the Agreement for so long as Bank or any Subcustodian continues to possess or have access to personal information related to Customer. Notwithstanding the foregoing "personal information" shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.

  • Data Privacy and Security Laws The Company is, and at all prior times was, in material compliance with all applicable state and federal data privacy and security laws and regulations in the United States, including, without limitation, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) as amended by the Health Information Technology for Economic and Clinical Health Act, and all applicable provincial and federal data privacy and security laws and regulations in Canada, including without limitation the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) (“PIPEDA”); and the Company has taken commercially reasonable actions to prepare to comply with, and have been and currently are in compliance with, the European Union General Data Protection Regulation (“GDPR”) (EU 2016/679) (collectively, the “Privacy Laws”). To ensure compliance with the Privacy Laws, the Company has in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling, and analysis of Personal Data (the “Policies”). “Personal Data” means (i) a natural person’s name, street address, telephone number, e-mail address, photograph, social security number or tax identification number, driver’s license number, passport number, credit card number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) Protected Health Information as defined by HIPAA; (iv) “personal information”, “personal health information”. and “business contact information” as defined by PIPEDA; (v) “personal data” as defined by GDPR; and (vi) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual orientation. The Company has at all times made all disclosures to users or customers required by applicable laws and regulatory rules or requirements, and none of such disclosures made or contained in any Policy have, to the knowledge of the Company, been inaccurate or in violation of any applicable laws and regulatory rules or requirements in any material respect. The Company further certifies: (i) it has not received notice of any actual or potential liability under or relating to, or actual or potential violation of, any of the Privacy Laws, and has no knowledge of any event or condition that would reasonably be expected to result in any such notice; (ii) is currently conducting or paying for, in whole or in part, any investigation, remediation, or other corrective action pursuant to any Privacy Law; or (iii) is a party to any order, decree, or agreement that imposes any obligation or liability under any Privacy Law.

  • Data Security Requirements Without limiting Contractor’s obligation of confidentiality as further described in this Contract, Contractor must establish, maintain, and enforce a data privacy program and an information and cyber security program, including safety, physical, and technical security and resiliency policies and procedures, that comply with the requirements set forth in this Contract and, to the extent such programs are consistent with and not less protective than the requirements set forth in this Contract and are at least equal to applicable best industry practices and standards (NIST 800-53).

  • Privacy and Security (a) Each of the Company and its Subsidiaries complies (and requires and monitors the compliance of applicable third parties) in all material respects with all applicable Laws relating to privacy or data security, and reputable industry practice, standards, self-governing rules and policies and their own published, posted and internal agreements and policies (which are in conformance with reputable industry practice) (all of the foregoing collectively, “Privacy Laws”) with respect to: (i) personally identifiable information (including name, address, telephone number, electronic mail address, social security number, bank account number or credit card number), sensitive personal information and any special categories of personal information regulated thereunder or covered thereby (“Personal Information”), whether any of same is accessed or used by the Company or any of its Subsidiaries or any of their respective business partners; and (ii) non-personally identifiable information, whether any of same is accessed or used by the Company or any of its Subsidiaries or any of their respective business partners. (b) Neither the Company nor any of its Subsidiaries uses, collects, or receives any Personal Information or sensitive non-personally identifiable information and does not become aware of the identity or location of, or identify or locate, any particular Person as a result of any receipt of such Personal Information, in a manner which would materially breach or violate any Privacy Laws and materially and adversely impact the business of the Company and its Subsidiaries, taken as a whole. (c) To the Company’s knowledge, Persons with which the Company or any of its Subsidiaries have contractual relationships have not breached any agreements or any Privacy Laws pertaining to Personal Information and to non-personally identifiable information. (d) To the Company’s knowledge, the Company and its Subsidiaries take all commercially reasonable steps to protect the operation, confidentiality, integrity and security of their respective business systems and websites and all information and transactions stored or contained therein or transmitted thereby against any unauthorized or improper use, access, transmittal, interruption, modification or corruption, and there have been no material breaches of same. Without limiting the generality of the foregoing, each of the Company and its Subsidiaries (i) uses industry standard encryption technology and (ii) has implemented a comprehensive security plan that (1) identifies internal and external risks to the security of the Company’s or its Subsidiaries’ confidential information and Personal Information and (2) implements, monitors and improves adequate and effective safeguards to control those risks.

  • PERSONAL INFORMATION PRIVACY AND SECURITY CONTRACT 11 Any reference to statutory, regulatory, or contractual language herein shall be to such language as in 12 effect or as amended. 13 A. DEFINITIONS

  • Data Protection and Security A. In this Agreement the following terms shall have the meanings respectively ascribed to them:

  • Security Requirements 7.1 The Authority will review the Contractor’s Security Plan when submitted by the Contractor in accordance with the Schedule (Security Requirements and Plan) and at least annually thereafter.

  • DATA PROTECTION AND PRIVACY 14.1 In addition to Supplier’s obligations under Sections 6, 9, 10, and 15, Supplier will comply with this Section 14 when processing Accenture Personal Data. "Accenture Personal Data" means personal data owned, licensed, or otherwise controlled or processed by Accenture including personal data processed by Accenture on behalf of its clients. “Accenture Data” means all information, data and intellectual property of Accenture or its clients or other suppliers, collected, stored, hosted, processed, received and/or generated by Supplier in connection with providing the Deliverables to Accenture, including Accenture Personal Data.

  • Bill of Rights for Data Privacy and Security As required by Education Law Section 2-d, the Parents Bill of Rights for Data Privacy and Security and the supplemental information for the Service Agreement are included as Exhibit A and Exhibit B, respectively, and incorporated into this DPA. Contractor shall complete and sign Exhibit B and append it to this DPA. Pursuant to Education Law Section 2-d, the EA is required to post the completed Exhibit B on its website.

  • Privacy and Data Protection 8.1 The Receiving Party undertakes to comply with South Africa’s general privacy protection in terms Section 14 of the Xxxx of Rights in connection with this Bid and shall procure that its personnel shall observe the provisions of such Act [as applicable] or any amendments and re-enactments thereof and any regulations made pursuant thereto. 8.2 The Receiving Party warrants that it and its Agents have the appropriate technical and organisational measures in place against unauthorised or unlawful processing of data relating to the Bid and against accidental loss or destruction of, or damage to such data held or processed by them.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!