Laserfiche WebLink
Exhibit C <br />Confidentiality Requirements <br />The State of California and the Subrecipient will exchange various kinds of information <br />pursuant to this subgrant agreement. That information will include data, applications, <br />program files, and databases. These data and information are confidential when they define <br />an individual or an employing unit or when the disclosure is restricted or prohibited by any <br />provision of law. Confidential information requires special precautions to protect it from <br />unauthorized use, access, disclosure, modification, and destruction. The sources of <br />information may include, but are not limited to, the EDD, the California Department of <br />Social Services, the California Department of Education, the California Department of <br />Corrections and Rehabilitation, the County Welfare Department(s), the County IV-D Directors <br />Office of Child Support, the Office of the District Attorney, the California Department of <br />Mental Health, the California Office of Community Colleges and the Department of Alcohol and <br />Drug Programs. <br />The Pass -through Entity and Subrecipient agree that: <br />a. Each party shall keep all information that is exchanged between them in the strictest <br />confidence and make such information available to their own employees only on a <br />"need -to -know" basis. <br />b. Each party shall provide security sufficient to ensure protection of confidential <br />information from improper use and disclosures, including sufficient administrative, <br />physical, and technical safeguards to protect this information from reasonable <br />unanticipated threats to the security or confidentiality of the Information. <br />c. The Subrecipient agrees that information obtained under this subgrant agreement will <br />not be reproduced, published, sold or released in original or in any other form for <br />any purpose other than those specifically identified in this agreement. <br />1. Aggregate Summaries: All reports and/or publications developed by the <br />Subrecipient based on data obtained under this agreement shall contain <br />confidential data In aggregated or statistical summary form only. "Aggregated" <br />refers to a data output that does not allow identification of an individual or <br />employer unit. <br />2. Publication: Prior to publication, Subrecipient shall carefully analyze <br />aggregated data outputs to ensure the identity of individuals and/or employer <br />units cannot be inferred pursuant to California Unemployment Insurance Code <br />Section 1094(c). Personal identifiers must be removed. Geographic identifiers <br />should be specified only in large areas and as needed, and variables should be <br />recorded in order to protect confidentiality. <br />3. Minimum Data Cell Size: The minimum data cell size or derivation thereof shall <br />be three participants for any data table released to outside parties or to the <br />public. <br />d. Each party agrees that no disaggregate data, identifying individuals or employers, <br />shall be released to outside parties or the public. <br />e. The Subrecipient shall notify Pass -through Entity's Information Security Office of <br />any actual or attempted information security incidents, within 24 hours of initial <br />detection, by telephone at (916) 654-6231. Information security incidents include, <br />but are not limited to, any event (intentional or unintentional), that causes the <br />loss, damage, or destruction, or unauthorized access, use, modification, or <br />disclosure of information assets. <br />The Subrecipient shall cooperate with the Pass -through Entity in any investigation <br />of security Incidents. The system or device affected by an information security <br />incident and containing confidential data obtained in the administration of this <br />program shall be immediately removed from operation upon confidential data exposure <br />or a known security breach. It shall remain removed from operation until correction <br />and mitigation measures are applied. If the Subrecipient learns of a breach in the <br />security of the system which contains confidential data obtained under this <br />Subgrant, then the Subrecipient must provide notification to individuals pursuant <br />to California Civil Code Section 1798.82. <br />Page 14 of 16 <br />