Right of Review and Audit. Upon written request by the EA, Contractor shall provide the EA with copies of its policies and summaries of related procedures that pertain to the protection of PII. It may be made available in a form that does not violate Contractor’s own information security policies, confidentiality obligations, and applicable laws. In addition, Contractor may be required to undergo an audit of its privacy and security safeguards, measures and controls as it pertains to alignment with the requirements of New York State laws and regulations, the EA’s policies applicable to Contractor attached to this DPA, and alignment with the NIST Cybersecurity Framework performed by an independent third party at Contractor’s expense, and provide the audit report to the EA. Contractor may provide the EA with a recent industry standard independent audit report on Contractor’s privacy and security practices as an alternative to undergoing an audit.
Appears in 1 contract
Samples: Data Privacy Agreement
Right of Review and Audit. Upon written request by the EA, Contractor shall provide the EA with copies of its policies and summaries of related procedures that pertain to the protection of PII. It may be made available in a form that does not violate Contractor’s own information security policies, confidentiality obligations, and applicable laws. In addition, Contractor may be required to undergo an audit no more than one (1) time per calendar year of its privacy and security safeguards, measures and controls as it pertains to alignment with the requirements of New York State laws and regulations, the EA’s policies applicable to Contractor attached to this DPAContractor, and alignment with the NIST Cybersecurity Framework performed by an independent third party at ContractorEA’s expense, and provide the audit report to the EA. Contractor may provide the EA with a recent industry standard independent audit report on Contractor’s privacy and security practices as an alternative to undergoing an audit.
Appears in 1 contract
Samples: Data Privacy Agreement
Right of Review and Audit. Upon written request by the EA, Contractor shall provide provides the EA with copies of its policies and summaries of related procedures that pertain to the protection of PIIPII at xxxxx://xxxxxx.xxx/trust/security/practices. It may be is made available in a form that does not violate Contractor’s own information security policies, confidentiality obligations, and applicable laws. In addition, Contractor may be required to undergo an audit of its privacy and security safeguards, measures and controls as it pertains to alignment with the requirements of New York State laws and regulations, the EA’s policies applicable to Contractor attached to this DPAContractor, and alignment with the NIST Cybersecurity Framework performed by an independent third party at Contractor’s expense, and provide the audit report to the EA. Contractor may provide the EA with a recent industry standard independent audit report on Contractor’s privacy and security practices as an alternative to undergoing an audit.
Appears in 1 contract
Samples: Data Privacy Agreement
Right of Review and Audit. Upon written request by the EA, Contractor shall provide the EA with copies of its policies and summaries of related procedures that pertain to the protection of PII. It may be made available in a form that does not violate Contractor’s own information security policies, confidentiality obligations, and applicable laws. In addition, no more than once a year, Contractor may be required to undergo an audit of its privacy and security safeguards, measures and controls as it pertains to alignment with the requirements of New York State laws and regulations, the EA’s policies applicable to Contractor attached to this DPAContractor, and alignment with the NIST Cybersecurity Framework performed by an independent third party at ContractorEA’s expense, and provide the audit report to the EA. Contractor may provide the EA with a recent industry standard independent audit report on Contractor’s privacy and security practices as an alternative to undergoing an audit.
Appears in 1 contract
Samples: Data Privacy Agreement
Right of Review and Audit. Upon written request by the EA, Contractor shall provide the EA with copies of its policies and summaries of related procedures that pertain to the protection of PII. It may be made available in a form that does not violate Contractor’s own information security policies, confidentiality obligations, and applicable laws. In additionthe event of a data breach, Contractor contractor may be required to undergo an audit of its privacy and security safeguards, measures and controls as it pertains to alignment with the requirements of New York State laws and regulations, the EA’s policies applicable to Contractor attached to this DPAContractor, and alignment with the NIST Cybersecurity Framework performed by an independent third party at Contractor’s expense, and provide the audit report to the EA. Contractor may provide the EA with a recent industry standard independent audit report on Contractor’s privacy and security practices as an alternative to undergoing an audit.
Appears in 1 contract
Samples: Data Privacy Agreement