Laserfiche WebLink
3. Employee Obligation: SAPL shall require all employees who have access to student data <br /> to comply with all applicable provisions of this DSA with respect to the data shared <br /> under the MOU. <br /> 4. Disposition of Data: Upon written request,SAPL shall dispose or delete all student data <br /> obtained under the MOU when it is no longer needed for the purpose for which it was <br /> obtained. <br /> S. Advertising Prohibition: SAPL is prohibited from using or selling student data to market <br /> or advertise to students or families/guardians. <br /> ARTICLE V: DATA PROVISIONS <br /> 1. Data Security:The SAPL agrees to abide by and maintain adequate data security <br /> measures,,consistent with industry standards and technology use practices,to protect <br /> student data from unauthorized disclosure or acquisition by an unauthorized person. <br /> These measures shall include, but not limited to: <br /> a. Passwords and Employee Access: SAPL shall secure usernames, passwords, and <br /> any other means of gaining access to student data, SAPL shall only provide <br /> access to student data to employees or integrated library system provider such <br /> as TLC that is performing the services. <br /> b. Destruction of Data: SAPL shall destroy or delete all student data obtained under <br /> the MOU when it is no longer needed for the purpose for which it was obtained. <br /> c. Security Protocols: Both parties agree to maintain security protocols that meet <br /> industry standards in the transfer of transmission of any data, including ensuring <br /> that data may only be viewed or access by parties legally allowed to do so. <br /> 2. Data Breach: In the event that student data is accessed or obtained by an unauthorized <br /> individual,SAPL shall provide notification to SAUSD within a reasonable amount of time <br /> of the incident, and not exceeding forty-eight (48) hours after the SAPL is aware of the <br /> breach. Provider shall follow the following process: <br /> a. The security breach notification shall be written in plain language,shall be titled <br /> "Notice of Data Breach", and shall present the information described herein <br /> under the fallowing headings: "What Happened", "What Information Was <br /> Involved", "What We Are Doing", "What You Can Do", and "For More <br /> Information". Additional information may be provided as a supplement to the <br /> notice. <br /> Page 3 of 9 <br />