PROTECTION OF INFORMATION Data Protection Sample Clauses

PROTECTION OF INFORMATION Data Protection. 6.1 The Parties acknowledge their respective obligations arising under Data Protection Legislation and must assist each other as necessary to enable each other to comply with these obligations. For the purposes of this Contract [the Council is the Controller and the Provider is the Processor] OR [the Provider is Controller]. OR [the Parties are joint Controllers, see Legal Services for alternative DP clauses] 6.2 Notwithstanding the general obligations of clause 6, the Provider shall; a) provide the Council with such information as the Council may require to satisfy itself that the Provider is complying with its obligations under the DPA 2018 promptly and in any event within 5 working days; b) promptly notify the Council of any breach of the security measures required to be put in place pursuant to this clause 6.2 c) ensure it does not knowingly or negligently do or omit to do anything which places the Council in breach of any of its obligations under the DPA 2018; d) notify the Council when any Data Subject Request is received relating to data for which the Council is the Controller 6.3 The Provider must: a) nominate an Information Governance Lead, to be responsible for information governance; b) where relevant nominate a Caldicott Guardian; c) ensure that the Council is kept informed at all times of the identities of the Information Governance Lead and, where relevant, the Caldicott Guardian; 6.4 Where the Schedule 6 / Specification states specific obligations relating to the processing of data, the Parties acknowledge that: a) in relation to Personal Data collected and processed by the Provider for the purpose of delivering the Goods the Provider will be sole Controller; and b) in relation to Personal Data provided by the Council to the Provider for the purpose of delivering the Goods the Council will be the sole Controller and the Provider will be the Processor; and c) in relation to Personal Data required by the Council for the purposes of quality assurance, performance management and contract management, the Council and the Provider will be joint Controllers. 6.5 The Provider must ensure that all Personal Data processed by the Provider in the course of supplying the Goods is processed in accordance with the relevant Partiesjoint obligations under the DPA 2018. 6.6 The Provider’s obligations in relation to Personal Data processed by the Provider in the course of delivering the Goods include: a) maintaining and operating policies relating to confiden...
AutoNDA by SimpleDocs
PROTECTION OF INFORMATION Data Protection. 15.1 The Parties acknowledge that for the purposes of the Data Protection Legislation, the Council and the Provider are each a Controller.

Related to PROTECTION OF INFORMATION Data Protection

  • Protection of Information E1 Data Protection Xxx X0 Official Secrets Acts 1911, 1989, Section 182 of the Finance Xxx 0000 E3 Confidentiality E4 Freedom of Information E5 Security of Confidential Information E6 Publicity, Media and Official Enquiries E7 Security E8 Intellectual Property Rights and Assigned Deliverables E9 Audit and the National Audit Office

  • Use and Protection of Information Recipient agrees to protect such Information of the Discloser provided to Recipient from whatever source from distribution, disclosure or dissemination to anyone except employees of Recipient with a need to know such Information solely in conjunction with Recipient’s analysis of the Information and for no other purpose except as authorized herein or as otherwise authorized in writing by the Discloser. Recipient will not make any copies of the Information inspected by it.

  • Retention of Information You acknowledge and accept that the Bank will be required under the China Connect Rules to keep records in relation to Northbound trading for a period of not less than 20 years.

  • Preservation of Information The Trustee shall preserve, in as current a form as is reasonably practicable, the names and addresses of Certificateholders contained in the most recent list furnished to the Trustee as provided in Section 7.14, and the names and addresses of Certificateholders received by the Trustee in its capacity as Registrar, if so acting. The Trustee may destroy any list furnished to it as provided in Section 7.14, upon receipt of a new list so furnished.

  • Dissemination of Information The Borrower authorizes each Lender to disclose to any Participant or Purchaser or any other Person acquiring an interest in the Loan Documents by operation of law (each a "Transferee") and any prospective Transferee any and all information in such Lender's possession concerning the creditworthiness of the Borrower and its Subsidiaries, including without limitation any information contained in any Reports; provided that each Transferee and prospective Transferee agrees to be bound by Section 9.11 of this Agreement.

  • Collection of Information You authorize us to access and download information from your Meter or from your PC Postage account. We may disclose this information to the USPS or other authorized governmental entity. We won’t share with any third parties (except the USPS or other governmental entity) individually identifiable information that we obtain about you in this manner unless required to by law or court order. We may elect to share aggregate data about our clients’ postage usage with third parties.

  • Accessibility of Information Technology Contractor represents and warrants that any software/ hardware/ communications system/ equipment (collectively “technology”), if any, provided under this Agreement adheres to the standards and/or specifications as may be set forth in the Section 508 of the Rehabilitation Act of 1973 standards guide and is fully compliant with WCAG 2.0 AA standards for accessibility and compliant with any applicable FCC regulations. Technology that will be used on a mobile device must also be navigable with Voiceover on iOS devices in addition to meeting WCAG 2.0 level AA. If portions of the technology or user experience are alleged to be non-compliant or non- accessible at any point, District will provide Contractor with notice of such allegation and Contractor shall use its best efforts to make the technology compliant and accessible. If a state or federal department, office or regulatory agency, or if any other third party administrative agency or organization (“Claimants”), make a claim, allegation, initiates legal or regulatory process, or if a court finds or otherwise determines that technology is non-compliant or non-accessible, Contractor shall indemnify, defend and hold harmless the District from and against any and all such claims, allegations, liabilities, damages, penalties, fees, costs (including but not limited to reasonable attorneys’ fees), arising out of or related to Xxxxxxxxx’ claims. Contractor shall also fully indemnify District for the full cost of any user accommodation that is found to be necessary due to an identifiable lack of accessibility in the Contractor’s technology. If necessary, an independent 3rd party accessibility firm using POUR standards (Perceivable, Operable, Understandable and Robust) may be used to validate the accessibility of the technology.

  • Security of Information Unless otherwise specifically authorized by the DOH Chief Information Security Officer, Contractor receiving confidential information under this contract assures that: • Encryption is selected and applied using industry standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program against all information stored locally and off-site. Information must be encrypted both in-transit and at rest and applied in such a way that it renders data unusable to anyone but authorized personnel, and the confidential process, encryption key or other means to decipher the information is protected from unauthorized access. • It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer (OCIO) policy 141, Securing Information Technology Assets, available at: xxxxx://xxxx.xx.xxx/policy/securing-information-technology-assets. • It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH Chief Information Security Officer. • DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. • It has implemented physical, electronic and administrative safeguards that are consistent with OCIO security standard 141.10 and ISB IT guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: o Documented access authorization and change control procedures; o Card key systems that restrict, monitor and log access; o Locked racks for the storage of servers that contain Confidential Information or use AES encryption (key lengths of 256 bits or greater) to protect confidential data at rest, standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CMVP); o Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; o Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; o Complex passwords that are systematically enforced and password expiration not to exceed 120 days, dependent user authentication types as defined in OCIO security standards; o Strong multi-factor authentication mechanisms that assure the identity of individuals who access Confidential Information; o Account lock-out after 5 failed authentication attempts for a minimum of 15 minutes, or for Confidential Information, until administrator reset; o AES encryption (using key lengths 128 bits or greater) session for all data transmissions, standard algorithms validated by NIST CMVP; o Firewall rules and network address translation that isolate database servers from web servers and public networks; o Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; o Log management and intrusion detection/prevention systems; o A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.

  • Designation of Information Xxxxx shall clearly identify any portions of its submissions that it believes are trade secrets, or information that is commercial or financial and privileged or confidential, and therefore potentially exempt from disclosure under the Freedom of Information Act (FOIA), 5 U.S.C. § 552. Xxxxx shall refrain from identifying any information as exempt from disclosure if that information does not meet the criteria for exemption from disclosure under FOIA.

  • Verification of Information The Seller authorizes the Listing Brokerage to obtain any information affecting the Property from any regulatory authorities, governments, mortgagees or others and the Seller agrees to execute and deliver such further authorizations in this regard as may be reasonably required. The Seller hereby appoints the Listing Brokerage or the Listing Brokerage’s authorized representative as the Seller’s attorney to execute such documentation as may be necessary to effect obtaining any information as aforesaid. The Seller hereby authorizes, instructs and directs the above noted regulatory authorities, governments, mortgagees or others to release any and all information to the Listing Brokerage.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!