Laserfiche WebLink
a. Passwords and Employee Access: SAPL shall secure usernames, passwords, and any other <br />means of gaining access to student data. SAPL shall only provide access to student data to <br />employees or integrated library system provider such as TLC that is performing the services. <br />b. Destruction of Data: SAPL shall destroy or delete all student data obtained under the MOU <br />when it is no longer needed for the purpose for which it was obtained. <br />c. Security Protocols: Both parties agree to maintain security protocols that meet industry <br />standards in the transfer of transmission of any data, including ensuring that data may only <br />be viewed or access by parties legally allowed to do so. <br />2. Data Breach: In the event that student data is accessed or obtained by an unauthorized individual, <br />SAPL shall provide notification to SAUSD within a reasonable amount of time of the incident, and <br />not exceeding forty-eight (48) hours. Provider shall follow the following process: <br />a. The security breach notification shall be written in plain language, shall be titled "Notice of <br />Data Breach", and shall present the information described herein under the following <br />headings: "What Happened", "What Information Was Involved", "What We Are Doing", <br />"What You Can Do", and "For More Information". Additional information may be provided as <br />a supplement to the notice. <br />b. The security breach notification described above in section 2(a) shall include, at a minimum, <br />the following information: <br />The name and contact information of the reporting SAPL subject to thissection. <br />ii. A list of the types of personal information that were or are reasonably believed to <br />have been the subject of a breach. <br />iii. If the information is possible to determine at the time the notice is provided, then <br />either(1)the date of the breach, (2) the estimated date of the breach, or(3)the data <br />range within which the breach occurred. The notification shall also include the date <br />of the notice. <br />iv. Whether the notification was delayed as a result of a law enforcement investigation, <br />if that information is possible to determine at the time the notice is provided. <br />V. A general description of the breach incident, if that information is possible to <br />determine at the time the notice is provided. <br />c. At SAUSD's discretion, the security breach notification may also include any of the following: <br />Information about what the SAPL has done to protect individuals whose information <br />has been breached. <br />ii. Advice on steps that the person whose information has been breached may take to <br />protect himself or herself. <br />