Laserfiche WebLink
subgrant agreement and any other terms of this subgrant agreement that may be <br />applicable. In addition, the following requirements must be included in <br />the subcontracts: <br />(1), All client information submitted over the internet to the subcontractor's <br />databases must be protected, at a minimum, by 128-bit Secure Socket Layer <br />(SSL) encryption. Clients' social security numbers must be stored in a <br />separate database within the subcontractor's network of servers, and <br />protected by a f rewall and a secondary database server firewall or <br />AES1 data encryption. If a subcontractor receives client social <br />security numbers or other confidential information in the course of <br />business, for example a resume -distribution service that provides <br />enrollment in CaIJOBS(SM), social security numbers must be destroyed <br />within two days after the client registers for CaIJOBS(SM). If a <br />subcontractor obtains confidential information as an agent of the <br />Subrecipient, the subcontract must specifically state the purpose <br />for the data collection and the term of records retention must be <br />stated, and directly related, to the purpose and use of the information. <br />Social security numbers and other client specific information shall <br />not be retained for more than three years after a client completes services. <br />The Subrecipient should extend this period, only if any litigation, <br />claim, negotiation, audit, or other action involving the records has <br />been started before the end of the three-year retention period. <br />In this case the records should be maintained until completion <br />of the action and resolution of all issues arising from it, or <br />until the close of the three-year retention period, whichever is later. <br />See 2 CFR 200.333. <br />(2). Client information (personal information that identifies a client such <br />as name and social security number) and/or demographic information <br />of a client (such as wage history, address, and previous employment) <br />shall not be used as a basis for commercial solicitation during the time <br />the client or agency is using the subcontractor's services. Client <br />information and/or demographic information shall not be used for any <br />purposes other than those specific program purposes set forth in <br />the subcontract. <br />(3). An AJCC client must still be given the option to use the AJCC's services, <br />including CaIJOBS(SM), even if he or she chooses not to use any services <br />of the subcontractor. This option shall be prominently, clearly and <br />immediately communicated to the client upon registration within the <br />AJCC or for CaIJOBS(SM), the subcontractor's resume -distribution services, <br />or any other services subcontractor offers to the client or the <br />AJCC Operator. <br />(4). The subcontractor must clearly disclose all of its potential and <br />intended uses of the client's personal and/or demographic information <br />for the services the client seeks and for any other services the <br />subcontractor offers. The subcontractor shall not use a client's <br />personal and/or demographic information without the client's prior <br />permission. A link to the subcontractor's Privacy Policy shall <br />appear prominently on the registration screens that list the <br />potential and intended uses of the client's personal and/or <br />demographic information. <br />(5). When the Pass -through Entity modifies State automated systems such <br />as the State CaIJOBS(SM) System, it shall provide reasonable notice of <br />such changes to the Subrecipient. The Subrecipient shall be responsible <br />to communicate such changes to the AJCC Operator(s) in the local area. <br />m). Each party shall designate an employee who shall be responsible for overall <br />security and confidentiality of its data and information systems and <br />each party shall notify the other of any changes in that designation. <br />As of this date, the following are those individuals: <br />Pagn 20 of 21 <br />