Laserfiche WebLink
Prudential <br />D. Information Security Program <br />Services Agreement <br />Provided by Prudential Retirement <br />Insurance and Annuity Company <br />Prudential states that (i) its treatment of Personal Information is in compliance with applicable laws and <br />regulations with respect to privacy and data security, and (ii) it has implemented and currently maintains <br />an effective written information security program including administrative, technical, and physical <br />safeguards and other security measures necessary to (a) ensure the security and personality of <br />Personal Information; (b) protect against any foreseeable threats or hazards to the security or integrity <br />of Personal Information; and (c) protect against unauthorized access to, destruction, modification, <br />disclosure or use of Personal Information that could result in substantial harm or inconvenience to Plan <br />Sponsor, or to any person who may be identified by Personal Information. Without limiting Prudential's <br />obligations under this exhibit, Prudential shall protect and maintain the confidentiality and security of <br />any Personal Information provided to or created by Prudential related to the Services by or on behalf <br />of Plan Sponsor in the manner provided for under, and otherwise in compliance with any applicable <br />domestic laws, regulations, and rules related to the collection, storage, handling, processing, and <br />b� ren• n� Pn.r J.n�l Ln Fn•m Blinn ,CI[.1{nn inf�.m �lir.n rCcn^. n.rJinr in�n•irV,,nlr <br />E. Remediation <br />Prudential shall notify Plan Sponsor, without unreasonable delay, upon confirming that an unauthorized <br />access or disclosure, unauthorized, unlawful or accidental loss, misuse, destruction, acquisition of, or <br />damage to Personal Information while under the responsibility or in the possession of Prudential (a <br />"Security Incident) has occurred. Thereafter, Prudential shall; <br />a) promptly furnish to Plan Sponsor details of the Security Incident; <br />b) conduct an investigation into the Security Incident; <br />c) take appropriate action to prevent a recurrence of any Security Incident; <br />d) determine whether notice is to be provided to any individuals, regulators, consumer reporting <br />agencies, or others under applicable law or regulation; <br />e) draft the contents of each such notice; and <br />f) offer remediation to affected persons consisting of two years of credit monitoring services if <br />such Security Incident poses a significant risk of identity theft and is required by law or <br />regulation. Any such notice or remediation shall be at Prudential's sole cost and expense. <br />20 <br />2501-25 <br />