Laserfiche WebLink
Prudential <br />D. Information Security Program <br />Services Agreement <br />Provided by Prudential Retirement <br />Insurance and Annuity Company <br />Prudential states that (i) its treatment of Personal Information is in compliance with applicable laws <br />and regulations with respect to privacy and data security, and (ii) it has implemented and currently <br />maintains an effective written information security program including administrative, technical, and <br />physical safeguards and other security measures necessary to (a) ensure the security and personality <br />of Personal Information; (b) protect against any foreseeable threats or hazards to the security or <br />integrity of Personal Information; and (c) protect against unauthorized access to, destruction, <br />modification, disclosure or use of Personal Information that could result in substantial harm or <br />inconvenience to Plan Sponsor, or to any person who may be identified by Personal Information. <br />Without limiting Prudential's obligations under this exhibit, Prudential shall protect and maintain the <br />confidentiality and security of any Personal Information provided to or created by Prudential related to <br />the Services by or on behalf of Plan Sponsor in the manner provided for under, and otherwise in <br />compliance with any applicable domestic laws, regulations, and rules related to the collection, <br />storage, handling, processing, and transfer of Personal Information, including information regarding <br />individuals. <br />E. Remediation <br />Prudential shall notify Plan Sponsor, without unreasonable delay, upon confirming that an <br />unauthorized access or disclosure, unauthorized, unlawful or accidental loss, misuse, destruction, <br />acquisition of, or damage to Personal Information while under the responsibility or in the possession <br />of Prudential (a "Security Incident") has occurred. Thereafter, Prudential shall: <br />a) promptly furnish to Plan Sponsor details of the Security Incident; <br />b) conduct an investigation into the Security Incident; <br />c) take appropriate action to prevent a recurrence of any Security Incident; <br />d) determine whether notice is to be provided to any individuals, regulators, consumer reporting <br />agencies, or others under applicable law or regulation; <br />e) draft the contents of each such notice; and <br />f) offer remediation to affected persons consisting of two years of credit monitoring services if <br />such Security Incident poses a significant risk of identity theft and is required by law or <br />regulation. Any such notice or remediation shall be at Prudential's sole cost and expense. <br />19 <br />