Laserfiche WebLink
1. Inappropriate use or unauthorized disclosure of DOR consumers' personal <br />information by the Contractor or the Contractor's assignees. Disclosure <br />methods include, but are not limited to, electronic, paper, and verbal. <br />2. Unauthorized access to DOR consumers' personal information. Information <br />can be held in medium that includes, but is not limited to, electronic and <br />paper. <br />3. Loss or theft of information technology (IT) equipment, electronic <br />devices/media, paper media, or data containing DOR consumers' personal <br />information. IT equipment and electronic devices/media include, but are not <br />limited to, computers (e.g., laptop and desktop, netbooks, tablets), <br />smartphones, cell phones, CDs, DVDs, USB flash drives, servers, printers, <br />peripherals, assistive technology devices (e.g., notetakers, videophones), <br />and copiers. Data can be held in medium that includes, but is not limited to, <br />electronic and paper. <br />F. Contractor agrees to provide annual security and privacy training for all <br />individuals who have access to personal, confidential, or sensitive information <br />relating to the performance of this agreement. <br />G. Contractor agrees to obtain and maintain acknowledgements from all individuals <br />to evidence their understanding of the consequences of violating California <br />privacy laws and the contractor's information privacy and security policies. <br />H. For contractors that do not have a security program that includes annual security <br />and privacy training, a self -training manual is available on the DOR website <br />under the "Providers" tab in the "Becoming a Service Provider" section under <br />"Annual Security and Privacy Training for VR Service Providers." The self - <br />training manual is named "Protecting Privacy in State Government' and can be <br />downloaded at the following link: <br />hftps://www.dor.ca.gov/Home/SecudtVandPrivacV. <br />Additional training and awareness tools are available at the California Office of <br />Information Security (OIS) website and the California Office of Privacy <br />Protection (COPP) website. The COPP created the self -training manual, <br />"Protecting Privacy in State Government" that DOR revised to meet its business <br />needs. <br />Audit and Review Requirements <br />General Audit and Review Requirements <br />A. The Contractor shall submit to the State such reports, accounts, and records <br />deemed necessary by the State to discharge its obligation under State and <br />Exhibit D 4 <br />