Attachment 9 AD-503.pdf

PDF 152 KB Posted

Attached to
SCDMV CUSTOMER MANAGEMENT SOLUTION State and local contract opportunity
Solicitation number
5400020925
Issued by
South Carolina

About this file

This is a confidentiality and information security policy document from the South Carolina Department of Motor Vehicles (SCDMV) that establishes guidelines for the protection of sensitive and personally identifiable information (PII). The policy applies to all SCDMV employees, contractors, vendors, third parties, and volunteers who are authorized to access SCDMV data or facilities. Personnel are prohibited from accessing, using, or disclosing confidential or restricted information except as required for job duties, and are required to maintain confidentiality regarding Human Resources matters, restricted information subject to confidentiality agreements, and PII protected by state and federal disclosure laws. All employees must block out Social Security numbers and other non-essential PII when transmitting customer-related information, and verbal or written disclosure of restricted information to unauthorized individuals, including family members, friends, and other employees without a need-to-know basis, is strictly prohibited. Copying or removal of restricted information from premises without written authorization from a Director or Executive Director is not permitted, and only the SCDMV Executive Director has authority to authorize release of restricted data.

All SCDMV personnel must sign applicable acknowledgement of non-disclosure and due diligence forms prior to being granted access to SCDMV data or facilities. SCDMV employees are required to sign Form AD-503A annually during performance evaluations, while temporary employees must sign by February 17 annually. Contractors, vendors, and third parties must sign Form AD-503B prior to network access or unescorted facility access and re-sign annually at the beginning of each calendar year and upon termination of services. New personnel receive training on disclosure and confidentiality responsibilities during orientation. Violations of this policy may result in investigations under Policy AD-800 and corrective action up to and including termination under HR-202 Progressive Corrective Action Disciplinary Policy. The policy became effective April 30, 2018, and references related policies including AD-551 Information Security, AD-502 Personally Identifiable Information, and AD-900 Access to, Sale of and Release of Information.

View the file

Other files for this state and local contract opportunity

Other files attached to SCDMV CUSTOMER MANAGEMENT SOLUTION, newest first.
File Type Posted
Attachment 11 Software Table.docx DOCX document
Attachment 5 AD-502.pdf PDF
Attachment 1 MVN Diagram.pdf PDF
Attachment 12 Eligibility Check For Appointments-Revised.docx DOCX document
Attachment 8 AD-551.pdf PDF
Attachment 4 Customer Lookup Business Specifications.docx DOCX document
Attachment 6 NIST.pdf PDF
Amendment No.1.docx DOCX document
Attachment 7 AD-504.pdf PDF
Attachment 3 Card Design Standard.pdf PDF
Attachment 2 Web Services.docx DOCX document
Notice of Extension Of Award Posting #1.doc DOC document
Attachment 13 Customer_Queue Table Data Requirements.txt TXT text file
Attachment 10.doc DOC document
Attachment 12 Eligibility Check For Appointments.docx DOCX document
Solicitation.docx DOCX document
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

South Carolina Department of Motor Vehicles

POLICY AD-503 CONFIDENTIALITY OF INFORMATION

THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY. THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, IN WHOLE OR IN PART. NO PROMISES OR ASSURANCES, WHETHER WRITTEN OR ORAL, WHICH ARE CONTRARY TO OR

INCONSISTENT WITH THE TERMS OF THIS PARAGRAPH CREATE ANY CONTRACT OF EMPLOYMENT.

SECTION OF LAW: S. C. Code of Laws §30-2-10, 30-4-160, and 30-4-165

LEGAL AUTHORITY: State Human Resources Regulations

REQUIRED ACTION

All employees are responsible for reading and following this policy.

Supervisors/Managers are responsible to have every employee and new hire read this policy and electronically acknowledge it in PowerDMS. Supervisors/Managers must maintain acknowledgement reports for their area.

DEFINITIONS

Confidential: Sensitive information that is used or held by an agency. Considerable loss or harm could occur as a result of unauthorized access, use, or disclosure of this information. Refer to the SC Department of Administration Data Classification Schema.

Data: Any information that is stored in SCDMV systems for supporting SCDMV operations. The format of the data can be structured as in a database, unstructured as in email, or a collection of data items such as an image library. Data is information about something, someone, or someplace.

Data Owner: For the purpose of this policy, the data owner is the Director or designee who has the ability to create, edit, modify, share and restrict access to the data. The data owner has the ability to assign, share or surrender all of these privileges to a third party.

Personally Identifiable Information (PII): Refer to Policy AD-502 Personally Identifiable Information for this definition.

Personnel: All individuals employed by SCDMV and contractors/vendors/third parties/volunteers who are authorized to perform services or do jobs for SCDMV plus any third party, including a state agency, who is authorized access to SCDMV provided data.

Restricted: Highly sensitive information that is used or held by an agency. Statutory or regulatory penalties, notification provisions, or other mandates could result if the information is accessed, used or disclosed in an unauthorized manner. Refer to the SC Department of Administration Data Classification Schema.

GUIDELINES

A. PERSONNEL RESPONSIBILITIES

1. Any personnel with access to Social Security Administration (SSA) provided data must read and comply with the SCDMV Social Security Administration Information Exchange Agreement.

2. All personnel are expected to maintain confidentiality at all times, whether dealing with actual records, projects or conversations, and abide by contractual confidentiality agreements. Situations in violation of this policy include, but are not limited to the following:

a. sharing of information relative to confidential Human Resources matters;

b. breach of confidentiality obligations regarding the disclosure of restricted/confidential information that is subject to a duly signed confidentiality or research agreement; and

c. discarding restricted/confidential documents in non-secured trash (secured shredder bins must be used).

3. Personnel must not access, request, acquire or examine restricted/confidential information unless there is a need to do so in the normal course of their job duties. Casual or curious browsing is prohibited.

4. Confidential/Restricted information must not be stored on non-Agency owned devices unless specifically approved by the Executive Director. Requests must be coordinated and approved by the sponsoring directorate and the Privacy Officer prior to submission to the Executive Director for final approval.

5. SCDMV information is for state business use only. SCDMV personnel may not access, use, or modify any SCDMV information to achieve private or personal gain.

6. PII may not be released to anyone who has contacted the department on behalf of an employee or customer such as a brother, sister, parent, child, employer, etc. unless SCDMV has received a Power of Attorney or other consent signed and executed by the employee or customer.

7. If at any time an employee is not sure of the identity of a person who has contacted the agency, the employee should request assistance from his supervisor prior to releasing restricted/confidential information.

8. An individual’s PII is protected by state and federal disclosure laws and must not be disclosed except in accordance with federal and state law. Employees must block out the SSN and any other PII not officially required by the requestor when sending customer related information regardless of method of transmittal (digital, paper, etc.).

https://powerdms.com/link/IDS/document/?id=1225588 http://intrwebsvr2/DMVFORMS/SSAinformationexchangeagreement.pdf

9. Written and/or verbal disclosure of restricted/confidential information to unauthorized individuals, including but not limited to, family members, friends, and/or even other employees who do not have a “need to know” is prohibited.

(NOTE: This includes law enforcement if it is not in the course of the law enforcement officer’s job duties.)

10. Copying of restricted/confidential information for personal use or removal of such information from the premises without written authorization from a Director or the Executive Director is prohibited. Copying of restricted/confidential information must be necessary only to perform assigned work.

11. SCDMV will approve the release of any restricted/confidential information in accordance with SCDMV Policy AD-900 Access to, Sale of and Release of Information. Only the SCDMV Executive Director has authority to authorize release of SCDMV Restricted data.

12. Retention and disposal of restricted/confidential information must be done in accordance with the General Records Retention Schedules approved by the South Carolina Department of Archives and History.

B. HUMAN RESOURCES RESPONSIBILITIES

To protect the PII and restricted/confidential information of all employees, Human Resources will:

1. Identify file folders containing PII or restricted/confidential information and provide a list of those folders to the CIO and ISO, plus a list of personnel authorized access for each folder. The CIO will create access permissions for each folder limiting and restricting access to those folders to only those authorized HR personnel and one IT administrator.

2. Avoid printing, filing, or faxing PII or restricted/confidential information.

3. Properly secure documents that must be printed, faxed, or filed that may contain PII such as SSNs, addresses, birth dates and phone numbers by:

a. Immediately collecting printed information from shared printers, faxes, and photocopiers or using secure access codes.

b. Keeping documents containing PII or confidential data in locked files, sealed containers, or other limited badge access secured areas.

c. Restricting entry/access to areas where PII, confidential, or restricted information is not secure.

d. Removing PII, confidential, and restricted information from desk tops and secured when not in use.

e. Shredding, properly discarding, or archiving paper containing PII, confidential, or restricted information in accordance with retention timeframes.

f. Redacting PII, confidential, or restricted information from documents before mailing or faxing.

4. Never disclose employee PII or restricted/confidential information to anyone outside the agency or to other employees without a valid need to know (other than the employee) without a release of information.

C. CONFIDENTIALITY STATEMENT ACKNOWLEDGEMENT

1. All SCDMV personnel will sign the applicable SCDMV Acknowledgement of Non-Disclosure and Due Diligence form prior to being granted access to SCDMV’s data or data network.

a. SCDMV Employees: On an annual basis, all employees will be required to read this policy and sign Form AD-

503A Employee Acknowledgement of Duty of Non-Disclosure and Due Diligence during the employee’s performance evaluation. All temporary employees will be required to read this policy and sign Form AD-503A on or before February 17 on an annual basis. A signed copy of the employee’s Form AD-503A will be maintained in the employee’s Human Resources file.

b. SCDMV contractors, non-paid work experience personnel, vendors and other third parties will sign Form AD- 503B Contract Personnel Acknowledgement of Duty of Non-Disclosure and Due Diligence prior to being granted access to the SCDMV network or unescorted access to SCDMV facilities. They will read this policy and re-sign the AD-503B at the beginning of each calendar year and upon termination of their employment/services to SCDMV. In some instances, as agreed upon by the Chief Procurement Officer, the Information Security Officer, and a department attorney, a contractor/vendor representative may sign a Confidentiality Statement/Non-disclosure agreement for his company provided that company requires each of its employees to sign a Confidentiality Statement/Non-disclosure Agreement with the company. SCDMV Member Services users effectively sign a Confidentiality Agreement each time they use the service by electronically acknowledging a use agreement built into Member Services.

1) Contractors and Vendors: Signed copies of the NDA will be sent to and maintained by the Procurement Office.

2) Cleaning Crew: Facilities Management will maintain cleaning crew signed copies of the NDA.

3) Other Third Parties: Signed NDAs will be maintained by the sponsoring data owner.

2. All SCDMV employees will sign AD-503A upon termination of their employment. This requirement includes those retiring or transferring to other state agencies.

D. DISCLOSURE TRAINING

https://powerdms.com/link/IDS/document/?id=1225263 https://powerdms.com/link/IDS/document/?id=1225263 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224307 https://powerdms.com/link/IDS/document/?id=1224307 https://powerdms.com/link/IDS/document/?id=1224307 https://powerdms.com/link/IDS/document/?id=1224305

1. All new personnel will receive training on disclosure and confidentiality responsibilities as part of new employee orientation. Employees will be required to sign SCDMV Form AD-503A.

2. Contractors, non-paid work experience personnel, vendors and other third parties will receive training from their parent organizations or, in some cases, SCDMV on disclosure and confidentiality responsibilities as part of employee orientation. These personnel will be required to sign AD-503B unless specifically exempted by the provisions in paragraph C.1.b.

E. CORRECTIVE ACTION:

1. Personnel violating this policy may be investigated in accordance with Policy AD-800, Investigations and Internal Affairs and/or Policy AD-806, Internal Audits.

2. Personnel violating this policy may be subject to corrective action up to and including termination in accordance with HR-202 Progressive Corrective Action Disciplinary Policy.

CONTACT/TELEPHONE: Human Resources (803) 896-9975

APPROVED BY:

DMV Executive Director

ATTACHMENTS: Policy AD-551 Information Security, Policy AD-502 Personally Identifiable Information, Policy AD-900

Access to, Sale of and Release of Information, Form AD-503A Employee Acknowledgement of Duty of Non-Disclosure and Due Diligence, Form AD-503B Contract Personnel Acknowledgement of Duty of Non-Disclosure and Due Diligence, Social Security Administration Information Exchange Agreement.

EFFECTIVE DATE: April 30, 2018 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224307 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1225606 https://powerdms.com/link/IDS/document/?id=1225588 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224305 https://powerdms.com/link/IDS/document/?id=1224307

File details come from the government source that posted it. Updated .