Laserfiche WebLink
requirements must be included in the subcontracts: <br />(1). All client information submitted over the Internet to the subcontractor's databases must be <br />protected, at a minimum, by 128 -bit Secure Socket Layer (SSL) encryption. Clients' social security <br />numbers must be stored in a separate database within the subcontractor's network of Servers, and <br />protected by a firewall and a secondary database server firewall or AESI data encryption. If a <br />subcontractor receives client social security numbers or other confidential information in the course of <br />business, for example a resume - distribution service that provides enrollment in CalJOSS, Social security <br />numbers must be destroyed within two days after the client registers for CalJGSS. If a subcontractor <br />obtains confidential information as an agent of the subgrantee, the subcontract must specifically state <br />the purpose for the data collection and the tern of records retention must be Stated, and directly <br />related, to the purpose and use of the information. In accordance with Uniform Guidance 2 CFR Part 200 <br />and DOL Exceptions 2 CFA Part 2900, social security numbers and other client specific information shall <br />not be retained for more than three years after a client completes services. The aubgrantee should <br />extend this period, only if any litigation, claim, negotiation, audit, or other action involving the <br />records has been started before the end of the three -year retention period. In this came tae records <br />should be maintained until completion of the action and resolution of all issues arising from it, or <br />until the close of the three -year retention period, whichever is later. Uniform Guidance 2 CFR Part 200 <br />and DOL Exceptions 2 CPR Part 2900. <br />W. Client information (personal information that identifies a client such as name and social security <br />number) and /or demographic information of a client (such as wage history, address, and previous <br />employment) shall not be used as a basis for commercial solicitation during the time the client or agency <br />is using the subcontractor's Services. Client information and /or demographic information Shall not be <br />used for any purposes other than those specific program purposes set forth in the subcontract. <br />(3). An AJCC client must still be given the option to use the AJCC's services, including Cd1JOSS, even if <br />he or she chooses not to use any services of she subcontractor. This option shall be prominently, <br />clearly and immediately communicated to the client upon registration within the AJCC or for CdlJOHS, the <br />subcontractor's resume- distribution services, or any other services subcontractor offers to the client or <br />the A,CCC Operator. <br />(4). The subcontractor must clearly disclose all of its potential and intended uses of the client's <br />personal and /or demographic information for the services the client seeks and for any other services the <br />subcontractor offers. The subcontractor shall not use a client's personal and /or demographic information <br />without the client's prior permission. A link to the subcontractor's Privacy Policy shall appear <br />prominently on the registration Screens that list the potential and intended uses of the client's <br />personal and/or demographic information. <br />(5). when the "pass- through• entity modifies State automated systems such as the State CalJGSS System, it <br />shall provide reasonable notice of such changes to the Subgrantee. The Subgrantee shall be responsible <br />to communicate such changes to the AJCC Operator(6) in the local area. <br />m). Each party Shall designate an employee who shall be responsible for overall security and <br />confidentiality of its data and information systems and each party shall notify the other of any changes <br />in that designation. As of this date, the fallowing are those individuals: <br />FOR THE "PASS - THROUGH" ENTITY <br />Name: Jaime Gutierrez <br />Title: Section Manager <br />Address: P.O. Sox 826680, MIC 50 <br />Sacramento, CA 942BO -0001 <br />Telephone: (916) 654 -9699 <br />Fax: (916) 654 -9586 <br />FOR THE 3USGRANTEE <br />Deborah Sanchez <br />Title: Economic Development Specialist III <br />Telephone: (714) 565 -2621 <br />Fax` (714) 565 -2602 <br />21. Signatures <br />This subgrant agreement is of no force and effect until signed by both of the parties hereto. Subgrantee <br />will not commence performance prier to the beginning of this subgrant agreement. <br />Page 13 of 13 <br />55F -18 <br />