Data Privacy & Cybersecurity Sample Clauses

Data Privacy & Cybersecurity. Except as has not had, and would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect: (a) the IT Assets operate and perform in a manner that permits the Company and its Subsidiaries to conduct their respective businesses as currently conducted; (b) the Company and its Subsidiaries have taken all actions, consistent with current industry standards of similarly sized companies in the consumer packaged goods industry, to protect the confidentiality, integrity and security of the IT Assets (and all information and transactions stored or contained therein or transmitted thereby) against any unauthorized use, access, interruption, modification or corruption, including the implementation of (i) data backup, (ii) disaster avoidance and recovery, (iii) business continuity and (iv) encryption and other security procedures, protocols and technologies; (c) there has been no breach, or unauthorized use, access, interruption, modification, corruption or other compromise, of any of the IT Assets (or any information or transactions stored or contained therein or transmitted thereby); (d) the Company and its Subsidiaries have at all times complied, and are currently in compliance, with all Applicable Data Protection Requirements; (e) no Action is pending or, to the Knowledge of the Company, threatened against the Company or any of its Subsidiaries by any Person alleging a violation of any Applicable Data Protection Requirement; (f) the Company and its Subsidiaries have implemented and maintain commercially reasonable technical and organizational measures, in accordance with industry standards of similarly sized companies in the consumer packaged goods industry, to protect all Personal Information in its possession or control against a breach, or unauthorized use, access, exfiltration, destruction, alteration, disclosure, loss, theft, interruption, modification or corruption thereof (each, a “Data Breach”); (g) the Company and its Subsidiaries have used commercially reasonable efforts to ensure that all service providers, data processors and other third parties that process any Personal Information on behalf of the Company or any of its Subsidiaries are bound by valid, written and enforceable agreements including any terms required by Applicable Data Protection Laws and requiring such third parties to comply with Applicable Data Protection Laws and to maintain the privacy, security and confidentiality of such Personal Info...
AutoNDA by SimpleDocs
Data Privacy & Cybersecurity. (a) Except as would not be material to the Company Group, taken as a whole, (i) each member of the Company Group is, and at all times since January 1, 2021, has been, in compliance with all Privacy Obligations; (ii) the Company and the Company Subsidiaries have used commercially reasonable efforts to ensure that all service providers, data processors and other third parties that process any Personally Identifiable Information on behalf of the Company or any of the Company Subsidiaries are bound by written agreements including any terms required by applicable Privacy Laws and requiring such third parties to comply with applicable Privacy Laws and (iii) neither the execution of this Agreement by the Company nor the consummation of the Transactions will result in a breach or violation of any Privacy Obligation by the Company or any Company Subsidiary. Except as would not be material to the Company Group, taken as a whole, neither the Company nor any Company Subsidiary has received any written or, to the Knowledge of the Company, threatened notices or complaints from any person or Governmental Authority alleging, or been subject to any audits or investigations concerning, and no Action is pending or, to the Knowledge of the Company, threatened alleging any failure to comply with any Privacy Obligations. (b) Except as would be material to the Company Group, taken as a whole, (i) the Systems operate and perform in accordance with their written documentation and functional specifications and, since January 1, 2021, otherwise have not malfunctioned, failed or experienced any breakdowns that resulted in continued substandard performance, or that caused disruption to or interruption of the business of the Company or any Company Subsidiary; (ii) each member of the Company Group has implemented and maintains commercially reasonable backup and data recovery, disaster recovery, encryption and business continuity policies, plans, procedures, facilities, and other reasonable technical and organizational measures, designed to prevent any failure, malfunction, breakdown, performance reduction, loss, theft, interruption, or unauthorized access, use, exfiltration, destruction, alteration, disclosure, modification, corruption, intrusion, breach of any security, or other adverse event affecting any Systems owned or controlled by, or, to the extent used in the operation of the business of the Company Group, licensed or leased to, the Company or any Company Subsidiary or any sens...
Data Privacy & Cybersecurity. (a) The Company complies in material respects with, and has for the past four (4) years complied in material respects with: (i) all Privacy Laws, (ii) all Privacy Policies applicable to the Company and (iii) all contractual commitments, including any terms of use, that the Company has entered into with respect to the Processing of Personal Information (collectively, the “Data Protection Requirements”). To the Company’s knowledge, its material vendors, processors, or other third parties that have been engaged by Company to Process Personal Information collected by and/or Processed by or for the Company (collectively, “Data Partners”) comply in material respects with, and have for the past four (4) years complied in material respects with all Privacy Laws applicable to their Processing of Personal Information on behalf of the Company. Where required by Privacy Policies and/or any applicable Privacy Laws, the Company has at all times presented a Privacy Policy to individuals prior to the collection of any Personal Information from such individuals, and all Privacy Policies are and have at all times been materially accurate, consistent and complete and have not been misleading or deceptive (including by omission). (b) The execution, delivery, and performance of this Agreement and the Transaction Documents and the transactions contemplated hereby and thereby do not and will not (i) conflict with or result in a violation or breach of any Data Protection Requirements; (ii) require the consent of or provision of notice to any material number of Persons concerning such Persons’ Personal Information; (iii) give rise to any material right of termination or other right to materially impair or limit Buyer’s or the Company’s rights to own and Process any Personal Information used in or materially necessary for the operation of the Company’s businesses; or (iv) otherwise materially impact the transfer of Personal Information to Buyer, except, in the case of clauses (iii) and (iv), to the extent resulting from the identity of Buyer or facts or attributes of Buyer, its Subsidiaries or their respective businesses. (c) The Company routinely (i) engages in due diligence of its Data Partners before allowing them to access, receive, or Process Personal Information and (ii) audits such Data Partners’ compliance with their commitments with respect to the Data Protection Requirements. The Company has valid and enforceable agreements in place with all Data partners that comply in a...
Data Privacy & Cybersecurity. Each Party shall comply and shall ensure that its Personnel and other Representatives comply with, the provisions of any Data Protection Laws applicable to their conduct under or in connection with this Agreement. To the extent required under applicable Data Protection Laws with respect to the transfer of personal data, the Parties shall enter into (or to the extent required by such Data Protection Laws, cause their respective Affiliates to enter into) such other agreements as may be required by the applicable Data Protection Laws. Each Party shall implement adequate policies and commercially reasonable security measures regarding the integrity and availability of the information technology and software applications owned, operated, or outsourced by that Party, and the data and Intellectual Property thereon. In case one Party or its Affiliates experiences any of the following events, it shall, as soon as such Party is aware, use reasonable efforts to notify the other Party within thirty-six (36) hours of: a confirmed data breach involving the unauthorized access to or accidental or illicit destruction, loss, change, communication, or dissemination of information related to an identified or identifiable natural person provided by the other Party or its Affiliates or Intellectual Property; or any order issued by a judicial or administrative authority regarding data exchanged between the Parties under this Agreement. Each Party shall use reasonable efforts to notify the other Party within thirty-six (36) hours of receiving: data subject requests related to an identified or identifiable natural person provided by the other Party or its Affiliates, such as access, rectification and deletion requests; and any complaint regarding the processing of data related to an identified or identifiable natural person provided by the other Party or its Affiliates, including allegations that the processing operations violate data subject rights.
Data Privacy & Cybersecurity. (a) The Companies and their Affiliates have and, to Cinergy’s Knowledge, with respect to the Processing of Personal Data on the Companies’ behalf, their respective Data Processors have, since the Lookback Date, complied in all respects with all applicable Company Privacy Policies and Privacy Laws. To the extent required by Privacy Laws or Company Privacy Policies, (i) Personal Data is Processed by the Companies, their Affiliates and their respective Data Processors in an encrypted manner, and (ii) Personal Data is securely deleted or destroyed by the Companies, their Affiliates and their respective Data Processors. Neither the execution, delivery or performance of this Agreement nor any of the other Transaction Documents, nor the consummation of any of the Transactions violate any Privacy Laws or Company Privacy Policies. Where any Company or any of its Affiliates uses a Data Processor to Process Personal Data, the Data Processor has provided guarantees, warranties or covenants in relation to Processing of Personal Data, confidentiality, security measures and has agreed to comply with those obligations in a manner sufficient for the Companies’ and their Affiliates’ compliance with Privacy Laws. (b) The Companies and their Affiliates have established an Information Security Program, and since the Lookback Date there have been no violations of the then-current Information Security Program. The Companies and their Affiliates have tested their respective Information Security Programs on a no less than annual basis and remediated all critical, high and medium risks and vulnerabilities. The IT Systems currently owned or controlled by the Companies and their Affiliates are in good working condition, operate and perform as necessary to conduct the business of the Companies and, to Cinergy’s Knowledge, do not contain any Malicious Code. All Company Data will continue to be available for Processing by the Companies and their Affiliates immediately following each Closing on substantially the same terms and conditions as existed immediately before such Closing. None of the Companies or their Affiliates is in breach or default of any contractual obligation relating to its IT Systems or to Company Data and none of them transfers Personal Data internationally except where such transfers comply with Privacy Laws and Company Privacy Policies. (c) Since the Lookback Date, the Companies and their Affiliates and, to Cinergy’s Knowledge, their respective Data Processors, have ...

Related to Data Privacy & Cybersecurity

  • Data Privacy Participant hereby explicitly and unambiguously consents to the collection, use and transfer, in electronic or other form, of Participant’s personal data as described in this Award Agreement and any other Restricted Stock Unit grant materials by and among, as applicable, the Service Recipients for the exclusive purpose of implementing, administering and managing Participant’s participation in the Plan. Participant understands that the Company and the Service Recipient may hold certain personal information about Participant, including, but not limited to, Participant’s name, home address and telephone number, date of birth, social insurance number or other identification number, salary, nationality, job title, any Shares or directorships held in the Company, details of all Restricted Stock Units or any other entitlement to Shares awarded, canceled, exercised, vested, unvested or outstanding in Participant’s favor (“Data”), for the exclusive purpose of implementing, administering and managing the Plan. Participant understands that Data may be transferred to a stock plan service provider, as may be selected by the Company in the future, assisting the Company with the implementation, administration and management of the Plan. Participant understands that the recipients of the Data may be located in the United States or elsewhere, and that the recipients’ country of operation (e.g., the United States) may have different data privacy laws and protections than Participant’s country. Participant understands that if he or she resides outside the United States, he or she may request a list with the names and addresses of any potential recipients of the Data by contacting his or her local human resources representative. Participant authorizes the Company, any stock plan service provider selected by the Company and any other possible recipients which may assist the Company (presently or in the future) with implementing, administering and managing the Plan to receive, possess, use, retain and transfer the Data, in electronic or other form, for the sole purpose of implementing, administering and managing his or her participation in the Plan. Participant understands that Data will be held only as long as is necessary to implement, administer and manage Participant’s participation in the Plan. Participant understands if he or she resides outside the United States, he or she may, at any time, view Data, request additional information about the storage and processing of Data, require any necessary amendments to Data or refuse or withdraw the consents herein, in any case without cost, by contacting in writing his or her local human resources representative. Further, Participant understands that he or she is providing the consents herein on a purely voluntary basis. If Participant does not consent, or if Participant later seeks to revoke his or her consent, his or her status as a Service Provider and career with the Service Recipient will not be adversely affected. The only adverse consequence of refusing or withdrawing Participant’s consent is that the Company would not be able to grant Participant Restricted Stock Units or other equity awards or administer or maintain such awards. Therefore, Participant understands that refusing or withdrawing his or her consent may affect Participant’s ability to participate in the Plan. For more information on the consequences of Participant’s refusal to consent or withdrawal of consent, Participant understands that he or she may contact his or her local human resources representative.

  • Data Privacy and Security Bank will implement and maintain a written information security program, in compliance with all federal, state and local laws and regulations (including any similar international laws) applicable to Bank, that contains reasonable and appropriate security measures designed to safeguard the personal information of the Funds' shareholders, employees, trustees and/or officers that Bank or any Subcustodian receives, stores, maintains, processes, transmits or otherwise accesses in connection with the provision of services hereunder. In this regard, Bank will establish and maintain policies, procedures, and technical, physical, and administrative safeguards, designed to (i) ensure the security and confidentiality of all personal information and any other confidential information that Bank receives, stores, maintains, processes or otherwise accesses in connection with the provision of services hereunder, (ii) protect against any reasonably foreseeable threats or hazards to the security or integrity of personal information or other confidential information, (iii) protect against unauthorized access to or use of personal information or other confidential information, (iv) maintain reasonable procedures to detect and respond to any internal or external security breaches, and (v) ensure appropriate disposal of personal information or other confidential information. Bank will monitor and review its information security program and revise it, as necessary and in its sole discretion, to ensure it appropriately addresses any applicable legal and regulatory requirements. Bank shall periodically test and review its information security program. Bank shall respond to Customer's reasonable requests for information concerning Bank's information security program and, upon request, Bank will provide a copy of its applicable policies and procedures, or in Bank's discretion, summaries thereof, to Customer, to the extent Bank is able to do so without divulging information Bank reasonably believes to be proprietary or Bank confidential information. Upon reasonable request, Bank shall discuss with Customer the information security program of Bank. Bank also agrees, upon reasonable request, to complete any security questionnaire provided by Customer to the extent Bank is able to do so without divulging sensitive, proprietary, or Bank confidential information and return it in a commercially reasonable period of time (or provide an alternative response that reasonably addresses the points included in the questionnaire). Customer acknowledges that certain information provided by Bank, including internal policies and procedures, may be proprietary to Bank, and agrees to protect the confidentiality of all such materials it receives from Bank. Bank agrees to resolve promptly any applicable control deficiencies that come to its attention that do not meet the standards established by federal and state privacy and data security laws, rules, regulations, and/or generally accepted industry standards related to Bank's information security program. Bank shall: (i) promptly notify Customer of any confirmed unauthorized access to personal information or other confidential information of Customer ("Breach of Security"); (ii) promptly furnish to Customer appropriate details of such Breach of Security and assist Customer in assessing the Breach of Security to the extent it is not privileged information or part of an investigation; (iii) reasonably cooperate with Customer in any litigation and investigation of third parties reasonably deemed necessary by Customer to protect its proprietary and other rights; (iv) use reasonable precautions to prevent a recurrence of a Breach of Security; and (v) take all reasonable and appropriate action to mitigate any potential harm related to a Breach of Security, including any reasonable steps requested by Customer that are practicable for Bank to implement. Nothing in the immediately preceding sentence shall obligate Bank to provide Customer with information regarding any of Bank's other customers or clients that are affected by a Breach of Security, nor shall the immediately preceding sentence limit Bank's ability to take any actions that Bank believes are appropriate to remediate any Breach of Security unless such actions would prejudice or otherwise limit Customer's ability to bring its own claims or actions against third parties related to the Breach of Security. If Bank discovers or becomes aware of a suspected data or security breach that may involve an improper access, use, disclosure, or alteration of personal information or other confidential information of Customer, Bank shall, except to the extent prohibited by Applicable Law or directed otherwise by a governmental authority not to do so, promptly notify Customer that it is investigating a potential breach and keep Customer informed as reasonably practicable of material developments relating to the investigation until Bank either confirms that such a breach has occurred (in which case the first sentence of this paragraph will apply) or confirms that no data or security breach involving personal information or other confidential information of Customer has occurred. For these purposes, "personal information" shall mean (i) an individual's name (first initial and last name or first name and last name), address or telephone number plus (a) social security number, (b) driver's license number, (c) state identification card number, (d) debit or credit card number, (e) financial account 22 number, (f) passport number, or (g) personal identification number or password that would permit access to a person's account or (ii) any combination of the foregoing that would allow a person to log onto or access an individual's account. This provision will survive termination or expiration of the Agreement for so long as Bank or any Subcustodian continues to possess or have access to personal information related to Customer. Notwithstanding the foregoing "personal information" shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.

  • Cybersecurity; Data Protection To the Company’s knowledge, the Company and its subsidiaries’ information technology assets and equipment, computers, systems, networks, hardware, software, websites, applications, and databases (collectively, “IT Systems”) are adequate for, and operate and perform in all material respects as required in connection with the operation of the business of the Company and its subsidiaries as currently conducted, free and clear of all material bugs, errors, defects, Trojan horses, time bombs, malware and other corruptants. The Company and its subsidiaries have implemented and maintained commercially reasonable controls, policies, procedures, and safeguards to maintain and protect their material confidential information and the integrity, continuous operation, redundancy and security of all IT Systems and data (including all personal, personally identifiable, sensitive, confidential or regulated data (collectively, the “Personal Data”)) used in connection with their businesses, and there have been no breaches, violations, outages or unauthorized uses of or accesses to same, except for those that have been remedied without cost or liability or the duty to notify any other person, nor any incidents under internal review or investigations relating to the same, except in each case as would not reasonably be expected to have a Material Adverse Effect. The Company and its subsidiaries are presently in material compliance with all applicable laws or statutes and all judgments, orders, rules and regulations of any court or arbitrator or governmental or regulatory authority, internal policies and contractual obligations relating to the privacy and security of IT Systems and Personal Data and to the protection of such IT Systems and Personal Data from unauthorized use, access, misappropriation or modification.

  • Employee Data Privacy Pursuant to applicable personal data protection laws, the Company hereby notifies you of the following in relation to your personal data and the collection, use, processing and transfer (collectively, the “Use”) of such data in relation to the Company’s grant of the RSUs and your participation in the Plan. The Use of your personal data is necessary for the Company’s administration of the Plan and your participation in the Plan. Your denial and/or objection to the Use of personal data may affect your participation in the Plan. As such, you voluntarily acknowledge, consent and agree (where required by applicable law) to the Use of personal data as described in this Paragraph 8. The Company and the Employer hold certain personal information about you, which may include your name, home address and telephone number, date of birth, social security number or other employee identification number, salary, nationality, job title, any Shares held by you, details of all RSUs or any other entitlement to Shares awarded in your favor, for the purpose of managing and administering the Plan (“Data”). The Data may be provided by you or collected, where lawful, from the Company, Affiliates or third parties, and the Company or Employer will process the Data for the exclusive purpose of implementing, administering and managing your participation in the Plan. The data processing will take place through electronic and non-electronic means according to logics and procedures strictly correlated to the purposes for which Data are collected and with confidentiality and security provisions as set forth by applicable laws and regulations in your country of residence (and country of employment, if different). Data processing operations will be performed minimizing the use of personal and identification data when such data are unnecessary for the processing purposes sought. Data will be accessible within the Company’s organization only by those persons requiring access for purposes of the implementation, administration and operation of the Plan and for your participation in the Plan. The Company and the Employer will transfer Data amongst themselves as necessary for the purpose of implementation, administration and management of your participation in the Plan, and the Company and the Employer may each further transfer Data to any third parties assisting the Company in the implementation, administration and management of the Plan. These recipients may be located in the European Economic Area, or elsewhere throughout the world, such as the United States. You hereby authorize them to receive, possess, use, retain and transfer the Data, in electronic or other form, for purposes of implementing, administering and managing your participation in the Plan, including any requisite transfer of such Data as may be required for the administration of the Plan and/or the subsequent holding of Shares on your behalf to a broker or other third party with whom you may elect to deposit any Shares acquired pursuant to the Plan. You may, at any time, exercise your rights provided under applicable personal data protection laws, which may include the right to (a) obtain confirmation as to the existence of the Data, (b) verify the content, origin and accuracy of the Data, (c) request the integration, update, amendment, deletion, or blockage (for breach of applicable laws) of the Data, and (d) oppose, for legal reasons, the Use of the Data that is not necessary or required for the implementation, administration and/or operation of the Plan and your participation in the Plan. You may seek to exercise these rights by contacting your Employer’s human resources manager or Invesco, Ltd., Manager, Executive Compensation, 0000 Xxxxxxxxx Xxxxxx, XX, Xxxxxxx, Xxxxxxx 00000.

  • Data Privacy Consent In order to administer the Plan and this Agreement and to implement or structure future equity grants, the Company, its subsidiaries and affiliates and certain agents thereof (together, the “Relevant Companies”) may process any and all personal or professional data, including but not limited to Social Security or other identification number, home address and telephone number, date of birth and other information that is necessary or desirable for the administration of the Plan and/or this Agreement (the “Relevant Information”). By entering into this Agreement, the Grantee (i) authorizes the Company to collect, process, register and transfer to the Relevant Companies all Relevant Information; (ii) waives any privacy rights the Grantee may have with respect to the Relevant Information; (iii) authorizes the Relevant Companies to store and transmit such information in electronic form; and (iv) authorizes the transfer of the Relevant Information to any jurisdiction in which the Relevant Companies consider appropriate. The Grantee shall have access to, and the right to change, the Relevant Information. Relevant Information will only be used in accordance with applicable law.

  • Data Privacy and Security Laws The Company is, and at all prior times was, in material compliance with all applicable state and federal data privacy and security laws and regulations in the United States, including, without limitation, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) as amended by the Health Information Technology for Economic and Clinical Health Act, and all applicable provincial and federal data privacy and security laws and regulations in Canada, including without limitation the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) (“PIPEDA”); and the Company has taken commercially reasonable actions to prepare to comply with, and have been and currently are in compliance with, the European Union General Data Protection Regulation (“GDPR”) (EU 2016/679) (collectively, the “Privacy Laws”). To ensure compliance with the Privacy Laws, the Company has in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling, and analysis of Personal Data (the “Policies”). “Personal Data” means (i) a natural person’s name, street address, telephone number, e-mail address, photograph, social security number or tax identification number, driver’s license number, passport number, credit card number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) Protected Health Information as defined by HIPAA; (iv) “personal information”, “personal health information”. and “business contact information” as defined by PIPEDA; (v) “personal data” as defined by GDPR; and (vi) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual orientation. The Company has at all times made all disclosures to users or customers required by applicable laws and regulatory rules or requirements, and none of such disclosures made or contained in any Policy have, to the knowledge of the Company, been inaccurate or in violation of any applicable laws and regulatory rules or requirements in any material respect. The Company further certifies: (i) it has not received notice of any actual or potential liability under or relating to, or actual or potential violation of, any of the Privacy Laws, and has no knowledge of any event or condition that would reasonably be expected to result in any such notice; (ii) is currently conducting or paying for, in whole or in part, any investigation, remediation, or other corrective action pursuant to any Privacy Law; or (iii) is a party to any order, decree, or agreement that imposes any obligation or liability under any Privacy Law.

  • DATA PROTECTION AND PRIVACY 14.1 In addition to Supplier’s obligations under Sections 6, 9, 10, and 15, Supplier will comply with this Section 14 when processing Accenture Personal Data. "Accenture Personal Data" means personal data owned, licensed, or otherwise controlled or processed by Accenture including personal data processed by Accenture on behalf of its clients. “Accenture Data” means all information, data and intellectual property of Accenture or its clients or other suppliers, collected, stored, hosted, processed, received and/or generated by Supplier in connection with providing the Deliverables to Accenture, including Accenture Personal Data.

  • Cybersecurity (i)(x) There has been no security breach or other compromise of or relating to any of the Company’s or any Subsidiary’s information technology and computer systems, networks, hardware, software, data (including the data of its respective customers, employees, suppliers, vendors and any third party data maintained by or on behalf of it), equipment or technology (collectively, “IT Systems and Data”) and (y) the Company and the Subsidiaries have not been notified of, and has no knowledge of any event or condition that would reasonably be expected to result in, any security breach or other compromise to its IT Systems and Data; (ii) the Company and the Subsidiaries are presently in compliance with all applicable laws or statutes and all judgments, orders, rules and regulations of any court or arbitrator or governmental or regulatory authority, internal policies and contractual obligations relating to the privacy and security of IT Systems and Data and to the protection of such IT Systems and Data from unauthorized use, access, misappropriation or modification, except as would not, individually or in the aggregate, have a Material Adverse Effect; (iii) the Company and the Subsidiaries have implemented and maintained commercially reasonable safeguards to maintain and protect its material confidential information and the integrity, continuous operation, redundancy and security of all IT Systems and Data; and (iv) the Company and the Subsidiaries have implemented backup and disaster recovery technology consistent with industry standards and practices.

  • Data Security and Privacy Plan As more fully described herein, throughout the term of the Subscription Agreement, Vendor will have a Data Security and Privacy Plan in place to protect the confidentiality, privacy and security of the Protected Data it receives from the District. Vendor’s Plan for protecting the District’s Protected Data includes, but is not limited to, its agreement to comply with the terms of the District’s Bill of Rights for Data Security and Privacy, a copy of which is set forth below and has been signed by the Vendor. Additional components of Vendor’s Data Security and Privacy Plan for protection of the District’s Protected Data throughout the term of the Subscription Agreement are as follows: (a) Vendor will implement all state, federal, and local data security and privacy requirements including those contained within the Subscription Agreement and this Data Sharing and Confidentiality Agreement, consistent with the District’s data security and privacy policy. (b) Vendor will have specific administrative, operational and technical safeguards and practices in place to protect Protected Data that it receives from the District under the Subscription Agreement. (c) Vendor will comply with all obligations contained within the section set forth in this Exhibit below entitled “Supplemental Information about a Subscription Agreement between [Xxxxx-Fultonville Central School District] and [Vendor Name].” Vendor’s obligations described within this section include, but are not limited to: (i) its obligation to require subcontractors or other authorized persons or entities to whom it may disclose Protected Data (if any) to execute written agreements acknowledging that the data protection obligations imposed on Vendor by state and federal law and the Subscription Agreement shall apply to the subcontractor, and (ii) its obligation to follow certain procedures for the return, transition, deletion and/or destruction of Protected Data upon termination, expiration or assignment (to the extent authorized) of the Subscription Agreement. (d) Vendor has provided or will provide training on the federal and state laws governing confidentiality of Protected Data for any of its officers or employees (or officers or employees of any of its subcontractors or assignees) who will have access to Protected Data, prior to their receiving access. (e) Vendor will manage data security and privacy incidents that implicate Protected Data and will develop and implement plans to identify breaches and unauthorized disclosures. Vendor will provide prompt notification to the District of any breaches or unauthorized disclosures of Protected Data in accordance with the provisions of Section 5 of this Data Sharing and Confidentiality Agreement.

  • NIST Cybersecurity Framework The U.S. Department of Commerce National Institute for Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity Version 1.1.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!