Attachment A (Agency Specific Terms and Conditions for RFSP)_B-45866 12.19.docx
DOCX document 38 KB Posted
- Attached to
- SBE: Agency Payroll System State and local contract opportunity
- Solicitation number
- 25-586SBE-CHOPE-B-45866
- Issued by
- Illinois
About this file
This file is an Agency Specific Terms and Conditions document (Attachment A) for a contract with the Illinois State Board of Education (ISBE). The document outlines modifications and additions to Section 4 of a contract agreement, focusing heavily on data security, confidentiality, and handling requirements, particularly regarding student and educator data. No specific service descriptions, quantities, dates, or contract terms are provided in this document.
The document primarily details technical requirements for data protection, including insurance requirements ($1 million for Professional Liability and $2 million for Cyber Liability), liquidated damages of $1,333.33 per calendar day for missed deliverables, and provisions regarding student data protection under FERPA, ISSRA, and SOPPA. The document notes that approximately 0% of funds for the initial contract period will be from federal sources (Stevens Amendment disclosure). No other pricing or funding information is provided.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Agency Payroll System RFP FINAL.pdf | ||
| ipg-active-registered-vendor-disclosure-(formerly-forms-b)-v.23.1~14.docx | DOCX document | |
| vendor-disclosure-(formerly-forms-a)-v.24.1~15.docx | DOCX document | |
| c2d-vendor-guidance-v.24.4~2.pdf | ||
| Agency Payroll System RFP FINAL.docx | DOCX document | |
| Request for Proposal - Offer to the State of Illinois 10.2.24 v.25.1~2.pdf | ||
| U-Plan V.25.1~1.pdf | ||
| c2d-vendor-answer-sheet-v.24.4~2.docx | DOCX document | |
| B-45866 - ISBE Agency Payroll System Question and Answer Addendum 1_.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A Agency Specific Terms and Conditions Exceptions to SECTION 4 are as follows:
4.3: Current paragraph states “For purposes of this Section, subcontractors are those specifically hired to perform all or part of the work covered by the contract.” Please note that definition of “subcontractors” applies to the entirety of the contract.
4.9: In addition to the provisions contained therein, the vendor agrees to sign such documentation that may be reasonably requested by the State to insure that title is vested in the State.
4.10: The following provision is DELETED from the contract: “Neither Party shall be liable for incidental, special, consequential or punitive damages.”
4.11: In addition to the provisions contained therein, the Vendor agrees to provide: (d) a Professional Liability Insurance Policy with a limit of liability not less than $1,000,000 for each claim, and not less than $1,000,000 in the aggregate on an annual basis, for errors, omissions or negligent acts arising out of the performance of (or the failure to perform) professional services hereunder such as, but not limited to: systems analysis, system design, programming, data processing, consulting, system integration and information services. The Professional Liability coverage shall include contractual liability coverage in support of the Vendor’s indemnification agreements in favor of ISBE, shall be written on a “claims made” basis and must be maintained for a period of not less than three (3) years following the date of final payment to the Vendor for all such Services; (e) a Cyber Liability insurance Policy with limits of liability not less than Two Million and 00/100 Dollars ($2,000,000.00) per claim and Two Million and 00/100 Dollars ($2,000,000.00) in the aggregate covering claims involving privacy violations, information theft, failure of computer security, wrongful release of personal information, damage to or destruction of electronic information, and failure to prevent transmission of malicious code, including expenses for notification as required by local, state or federal guidelines. The Policy will be a claims-made program with any prior acts exclusion predating both the date of this Agreement and any earlier commencement of Services. Such coverage shall either be maintained continuously for a period of 2 years after expiration or termination of this Agreement or secure a 2-year extended reporting provision. The Vendor shall cause all of its subcontractors to purchase and maintain insurance coverages identical to those required of the Vendor hereunder. Insurance shall not limit Vendor’s obligation to indemnify, defend or settle any claims.
Additions to SECTION 4:
| 4.28. | PERFORMANCE OF THE SERVICES. The Vendor shall perform the Services (i) with a high degree of skill, care and diligence, (ii) in accordance with the highest professional standards, and (iii) in accordance with the schedule of deliverables set forth in the Proposal. The Vendor, and any subcontractors retained by the Vendor to perform Services under this Contract, shall not discuss the Services it is providing hereunder or engage in any public relations activities, including but not limited to, engaging the news media with regard to the Services, unless specifically requested or allowed to do so by ISBE. The Vendor shall provide all personnel, materials and equipment necessary to undertake the Services and to fulfill the purposes of this contract. The Vendor will use personnel suitably qualified and experienced to perform the Services in accordance with the requirements of this contract. Neither the Vendor nor its personnel or subcontractors shall be considered agents or employees of the Agency or the State. | ||
| 4.29. | VENDOR DEFAULT: The occurrence of any one or more of the following matters constitutes a default by the Vendor under this contract (a “Vendor Default”): | ||
| 4.29.1. | The Vendor becomes insolvent or generally fails to pay, or admits in writing its inability or unwillingness to pay, its debts as they become due; | ||
| 4.29.1.1. | The Vendor shall commence or consent to any case, proceeding or other action (a) seeking reorganization, arrangement, adjustment, liquidation, dissolution or composition of the Vendor or of the Vendor’s debts under any law relating to bankruptcy, insolvency, reorganization or relief of debts, or (b) seeking appointment of a receiver, trustee or similar official for the Vendor or for all or any part of the Vendor’s property; | ||
| 4.29.1.2. | Any case, proceeding or other action against the Vendor shall be commenced (a) seeking to have an order for relief entered against the Vendor as debtor, (b) seeking reorganization, arrangement, adjustment, liquidation, dissolution or composition of the Vendor or the Vendor’s debts under any law relating to bankruptcy, insolvency, reorganization or relief of debtors, or (c) seeking appointment of a receiver, trustee, or similar official for the Vendor or for all or any part of the Vendor’s property; | ||
| 4.29.1.3. | The breach of any representation, certification or warranty made by the Vendor herein or the Vendor’s failure to comply with any provision of this contract; or | ||
| 4.29.1.4. | The Vendor’s attempts to assign, convey or transfer this contract or any interest herein without the Agency’s prior written consent. | ||
| 4.29.2. | Upon the occurrence of a Vendor Default, the Agency may, without prejudice to any other right or remedy it may have under this contract or at law and/or in equity, terminate the contract and/or the Vendor’s right to perform Services under this contract. In either such case, the Agency may finish the Services by whatever method it may deem expedient. Any damages incurred by the Agency as a result of any such Vendor Default shall be borne by the Vendor at its sole cost and expense, shall not be payable as part of the contract amount, and shall be reimbursed to the Agency by the Vendor upon demand. | ||
| 4.29.3 | LIQUIDATED DAMAGES. The late delivery or untimely performance of the Services required under this Agreement by the Vendor will cause irreparable harm to the Agency in light of its obligations under state and federal law. As a result, the Agency shall have the right to assess liquidated damages as set forth in this Subsection if the Vendor fails to meet any of the following deliverable dates in accordance with the schedule for deliverables set forth in the Agreement: | ||
| 4.29.3.1. | If Vendor fails to meet any of the foregoing deliverable dates, the Vendor shall pay to the Agency liquidated damages of $1,333.33 per calendar day of delay for the shorter of either thirty (30) calendar days or until the deliverables are made in accordance with this Agreement; provided, however, that no liquidated damages will be assessed during the time after delivery by Vendor and while still under review by the Agency. Said amount is a good faith estimate of damages based on average salary, staff commitment and time allocation, to address the harm that the State will sustain by reason of said failure, repercussions of which will be suffered throughout the Agency. The parties mutually agree that this is a reasonable anticipated calculation of damages and is not intended as a penalty. The Agency may not collect liquidated damages and also claim damages for the same failure to meet the schedule. However, collecting liquidated damages or exercising the right to withhold payments does not prevent the Agency from claiming damages for subsequent failures to meet the time schedule. | ||
| 4.30. | STUDENT RECORDS. The Vendor will comply with the relevant requirements of the Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. 1232g), the Illinois School Student Records Act (ISSRA) (105 ILCS 10/1 et seq.), and the Student Online Personal Protection Act (SOPPA) (105 ILCS 85/1), regarding the confidentiality of student “education records” as defined in FERPA and “school student records” as defined in ISSRA, and “covered information” as defined in SOPPA. Any use of information contained in student education records to be released must be approved by the Agency. To protect the confidentiality of student education records, the Vendor will limit access to student education records to those employees who reasonably need access to them in order to perform their responsibilities under this contract. Any student records in the Vendor’s possession shall be returned when no longer needed for the purposes for which they were provided, or at the Agency’s request, they shall be permanently destroyed, and the Vendor shall provide written confirmation upon the destruction of student records. Student records shall not be archived, stored or retained in any manner and shall not be retained for any period longer than the Term of the contract. | ||
| 4.31. | REPORTING. During the Term, the Vendor will provide monthly progress reports due to the Agency on the 1st of each month. The Vendor will also provide a listing of the Services completed as an accompaniment to all invoices sent to the Agency for payment together with such other supporting documentation as the Agency may reasonably request. | ||
| 4.32. | KEY PERSONS. The Parties agree that availability of and performance of Services by, when assigned to perform such Services, Vendor’s staff is key to the satisfactory performance of this contract by the Vendor. The Vendor shall not substitute for key personnel assigned to the performance of this Contract without prior written approval from the Agency project manager except as follows: | ||
| a. | The Agency may request at any time the removal of (and the Vendor will remove) any individual performing Services if the Agency reasonably believes that individual is not qualified to perform the Services or tasks required of that individual. | ||
| b. | Should any of the said key individuals cease employment with the Vendor during the Term or become unavailable to perform the work assigned to them, the Vendor shall immediately notify the Agency in writing of such occurrence. The parties shall promptly confer and determine and provide for the basis upon which the Vendor shall assure satisfactory performance of the required work. They shall verify their understandings in writing and retain a record of such verification as part of the record of the Vendor’s performance of this contract. | ||
| 4.33. | WEBSITE INCORPORATION. The Agency expressly states that it will not be bound by any content on the Vendor’s website, even if the Vendor’s documentation specifically referenced that content and attempts to incorporate it into any other communication, unless the Agency has actual knowledge of such content and has expressly agreed to be bound by it in a written agreement that has been manually signed by an authorized representative of the Agency. | ||
| 4.34. | GENERAL PROVISIONS. | ||
| 4.34.1 | Entirety. This contract constitutes the entire agreement between the Parties with respect to the subject matter hereof, and supersedes any other negotiations, agreements or communications, whether written or oral, that have been made by either Party. The intent of the contract is to include items and services necessary for the proper execution and completion of the Services by the Vendor, including, without limitation, all such items and services which are consistent with, contemplated by, or reasonably inferable from the contract, whether or not such items and services are specifically mentioned herein. | ||
| 4.34.2 | Certifications and Assurances. | ||
| 4.34.2.1 | The Vendor agrees to comply with the provisions of the Illinois Procurement Code prohibiting conflicts of interest (30 ILCS 500/50-1-75) and all of the terms, conditions and provisions of those Sections apply to this contract the same as though they were incorporated and included herein. | ||
| 4.34.2.2 | Vendor certifies that during the last five (5) years no order, judgment or decree of any Federal authority has been issued barring, suspending, or otherwise limiting its right to contract with any governmental entity, including school districts, or to engage in any business practice or activity. Vendor further certifies that it will include this certification within every subcontract related to performance of this contract. | ||
| 4.34.3 | Counterparts. This contract may be executed in several counterparts, each of which shall be an original and all of which shall constitute one and the same instrument, binding on all Parties hereto, notwithstanding that all Parties are not signatories to the same counterpart. Signatures received by facsimile or signatures contained in a Portable Document Format (PDF) by any of the Parties shall have the same effect as original signatures. | ||
| 4.34.4 | Cumulative Rights. Except as otherwise provided in this contract, rights and remedies available to the Agency and/or the Vendor as set forth in this contract shall be cumulative with and in addition to, and not in limitation of, any other rights or remedies available to such Parties at law and/or in equity, and any specific right or remedy conferred upon or reserved to the Agency and/or the Vendor in any provision of this contract shall not preclude the concurrent or consecutive exercise of a right or remedy provided for in any other provision hereof. | ||
| 4.34.5 | Amendment. This agreement may only be amended in writing signed by both Parties. | ||
| 4.34.6 | Severability. In case any provision in this Agreement is held to be invalid, illegal or unenforceable, the validity, legality and enforceability of the remaining provisions shall be not affected. | ||
| 4.34.7 | Return of Property. Upon termination or expiration of the Term or at ISBE’s request, the Vendor shall immediately return all property to ISBE. | ||
| 4.34.8 | Stevens Amendment. Successful bidders will be subject to the provisions of Section 511 of P.L. 101-166 (the “Stevens Amendment”) due to the use of federal funds for this program. All announcements and other materials publicizing this program must include statements as to the amount and proportion of federal funding involved. Approximately 0% of funds for the initial contract period will be from federal sources. |
4.34.9 Internal Controls. If applicable and upon request, the Vendor shall provide the Agency, at no cost, with a copy of the most recent Annual Report or Form 10-K of itself or its holding company, its most recent audited internal control documents, including but not limited to Service Organization Control (“SOC”), SSAE 16, and SSAE 18 reports, which shall include the attestation of the company’s independent registered accounting firm regarding the company’s internal control over financial reporting.
| 4.35. | STUDENT DATA PROVISIONS: |
| 4.35.1 | In the delivery of the Services the Vendor may have access to information, including individually identifiable information, on students, including prior Illinois students ("Student Data"); educators, including educator licensure and service record data (“Educator Data”); programs; schools or institutions; and districts (collectively “Confidential Data”) necessary for required federal reporting, to audit and evaluate education programs and to perform studies for, or on behalf of, public elementary and secondary schools, all in a manner consistent with the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) ("FERPA"), the Illinois School Student Records Act (105 ILCS 10/1, et seq.) ("ISSRA"), the Illinois Freedom of Information Act (5 ILCS 140)(“FOIA”), the Privacy Act of 1974, 5 U.S.C. § 552a, and other applicable laws. |
4.34 4.35
4.35.2 The Confidential Data are and at all times will remain the sole property of ISBE. ISBE retains all right, title and interest in and to the Confidential Data and all copies thereof (including, without limitation, all copyrights, trade secrets, trademarks, patents, and other similar proprietary rights therein).
4.35.3 The term "individually identifiable information" means information that is identifiable to a particular individual, program, classroom, school, institution or district, including but not limited to the following: (a) a first and last name; (b) a home or other physical address, including street name and name of a city, town, or county; (c) an e-mail address; (d) a telephone number; (e) a social security, employer identification, student identification number, or biometric record; (f) test scores; or (g) clinical information, including any questionnaires, notes, or other documentation. Also includes other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty (34 C.F.R. § 99.3).
4.35.4 De-identified data” means data that does not identify a particular individual, program, classroom, school, institution or district and with respect to which there is no reasonable basis to believe the data can be used to identify a particular individual, program, classroom, school, institution or district. Personally identifiable information (“PII”) has been removed or obscured from the data in a way that minimizes the risk of unintended disclosure of the identity of individuals, programs, classrooms, schools, institutions or districts and information about them. (34 CFR § 99.31(b)(1)).
4.35.5 Vendor must ensure that any third-party Vendor of the Confidential Data working under or in collaboration with Vendor agrees by contractual terms to the provisions of this Agreement for the sharing, disclosure, re-disclosure, use, maintenance, security and destruction of the Confidential Data.
4.35.6 Injunctive Relief. Vendor agrees that an impending or existing violation of any provision of this Agreement would cause ISBE irreparable injury for which it would have no adequate remedy at law and that ISBE shall be entitled to seek immediate injunctive relief prohibiting such violation, in addition to any other rights and remedies available to it.
4.35.7 Prior to the publication of any data or results from research performed under this Agreement, Vendor must provide ISBE with a copy of any proposed publication that is based on Confidential Information specific to the State of Illinois, or any subgroup with the State of Illinois, or any subgroup (whether or not it is identified as including Illinois students) of size less than 30. ISBE shall have the right to review and comment on any portion of the publication prior to public dissemination. ISBE shall have the right to redact any inadvertent disclosures of individually identifiable information or Confidential Information. Any redactions by ISBE shall be final and Vendor agrees that the publication of any material redacted by ISBE shall be considered a material breach of this Agreement. ISBE reserves the right to demand that the Vendor include in any material to be publicly released a disclaimer to the effect that "Such material does not necessarily reflect the views of ISBE or its employees."
4.35.8 Data Access, Use and Security.
4.35.8.1 Restrictions on Vendor. The data access, use, and security restrictions set forth in this Section shall apply to the receipt, use, disclosure, and maintenance of Confidential Data by Vendor. Vendor agrees to the following:
A. Confidential Data may only be used for the purpose or purposes authorized pursuant to this Agreement.
B. Vendor will comply with all applicable laws, materials, regulations and all other State and Federal requirements with respect to the protection of privacy, security and dissemination of the shared data including but not limited to the relevant requirements of: including but not limited to the relevant requirements of: the Social Security Act (42 U.S.C. §§1320d-2 through 1320d-7); U.S.C. section 552(A)(Privacy Act of 1974, Public Law 93-579); Identity Protection Act (5 ILCS 179/1 et. seq.), FOIA (5 ILCS 140/7(1)(c); and PERA (105 ILCS 5/24A-7.1).
C. Vendor will comply with the relevant requirements of FERPA (20 U.S.C. § 1232g) and ISSRA (105 ILCS 10/1 et seq.), regarding the confidentiality of Student Data, and specifically “education records” as defined in FERPA and “school student records” as defined in ISSRA. Any use of information contained in student education records to be released must be approved by ISBE. To protect the confidentiality of student education records, Vendor will limit access to student education records to those employees who reasonably need access to them in order to perform their responsibilities under this Agreement.
D. Vendor shall abide by and be bound by the requirements of the U.S. Department of Education, Family Policy Compliance Office’s Guidance for Reasonable Methods and Written Agreements issued pursuant to the requirements of the Family Educational Rights and Privacy Act (“Guidance”). The Guidance is available at: http://www2.ed.gov/policy/gen/guid/fpco/pdf/reasonablemtd_agreement.pdf E. Vendor will comply with PERA’s confidentiality requirements regarding individual educator information (105 ILCS 5/24A-1 et seq.). The disclosure of educator or public school teacher, principal and superintendent performance evaluations is expressly prohibited under Section 24A-7.1 (105 ILCS 5/24A-7.1). Vendor will ensure that results from any analysis or evaluation of educator data will be published in a manner that protects the privacy and confidentiality of the individuals involved and that no educator, teacher or administrator can be personally identified from publicly reported aggregate data (Section 24A-20(a)(1)).
F. Vendor will follow ISBE’s confidentiality requirements for all ISBE data, pursuant to the Data Processing Confidentiality Act (30 ILCS 585/0.01 et seq.). Information obtained from any individual shall comply with the following terms and conditions, which include, but are not limited to:
| • | Be confidential; |
| • | Not be published or open to public inspection; |
| • | Not be used directly in any court in any pending action or proceeding; and |
| • | Not be admissible in evidence in any action or proceeding. |
All records and other information maintained by ISBE regarding any person are confidential and shall be protected from unauthorized use and/or disclosure under this Agreement. Any dissemination or use of the Confidential Data for other than the primary purpose of this Agreement without the express written authority of ISBE is specifically prohibited. Confidential Data released under this Agreement are solely for the use of Vendor and are to be used only for the specific purposes as described in the Specifications.
G. In the event that any Confidential Data is required to be disclosed in response to a valid order of a court of competent jurisdiction or other governmental body of the United States or any political subdivisions thereof, Vendor shall first (a) notify ISBE of the order and provide a complete copy of such order to ISBE and (b) permit ISBE to seek an appropriate protective order. Vendor shall fully cooperate with ISBE if ISBE wishes to apply to such court for a protective order. Vendor shall only disclose the Confidential Data to the extent necessary and for the purposes of the court or other governmental body. Furthermore, Vendor must comply with the notice requirements of FERPA (34 C.F.R. § 99.31(a)(9)(ii) when and if it is required to disclose any Student Data in accordance with a lawfully issued subpoena or court order. 34 C.F.R. § 99.33(b)(2).
H. Vendor must create and maintain a record of any disclosure of Confidential Data made to any other person or entity pursuant to this Agreement. The record of disclosure must record the name of any additional person or organization receiving the Confidential Data and their legitimate interest under 34 C.F.R. § 99.31 in requesting or obtaining the Confidential Data The record must also describe the Confidential Data included within the disclosure by class, school, district, or other appropriate grouping. Upon ISBE’s request, Vendor must provide a copy of the record of further disclosures to ISBE. 34 C.F.R. § 99.32(b)(2)(i) and (ii).
I. Nothing in this Agreement may be construed to allow Vendor to maintain, use, disclose, or share the Confidential Data in a manner not allowed by State or federal law or regulation, including but not limited to FERPA (20 U.S.C. § 1232g) and ISSRA (105 ILCS 10/1, et seq.).
J. Vendor will not share Confidential Data with anyone, except those employees, contractors, subcontractors and agents of Vendor with a legitimate interest in the Confidential Data for Audit, Evaluation, or Research and the relevant requirements of 34 C.F.R. § 99.32(a) applicable to the Confidential Data.
K. Vendor will instruct all persons having access to Confidential Data on the use and confidentiality restrictions set forth in this Agreement and sanctions for unauthorized disclosure and shall require all employees, contractors, subcontractors, or agents of any kind to undertake the same obligations as Vendor hereunder and comply with all applicable provisions of FERPA and other State and federal laws with respect to the Confidential Data. Vendor shall produce a written acknowledgement from all such persons verifying that the instruction required under this Section has occurred.
L. Vendor will not disclose any individually identifiable information or Confidential Data under this Agreement in a manner which could identify an individual student, person, program, school, institution, or district except as authorized by ISBE and applicable law. Disclosure includes, without limitation, disclosure of information, research, or analysis in a manner that permits the personal identification of parents and students, as such terms are defined in the FERPA regulations (34 C.F.R Part 99), or individual identification of a person, program, school, institution, or district; and includes, de-identified or aggregate data in cell sizes of less than ten (10) for each category or subcategory of data, and de-identified or aggregate data in cell sizes of more than ten (10) for each category or subcategory that, when disaggregated could lead to indirect disclosure through the disclosure, through the cumulative effects of disclosures, or when combined with other data element(s) in the public domain.
M. Vendor may not re-disclose Student Data to any other person or entity unless permitted or required by law and approved in advance under an amendment to this Agreement. Re-disclosure of Student Data includes, without limitation, disclosure of information, research, or analysis in a manner that permits the personal identification of parents and students, as such terms are defined in the FERPA regulations (34 C.F.R. Part 99); and includes, de-identified or aggregate data in cell sizes of less than ten (10) for each category or subcategory of data, and de-identified or aggregate data in cell sizes of more than ten (10) for each category or subcategory that, when disaggregated could lead to indirect disclosure through the disclosure, through the cumulative effects of disclosures, or when combined with other data element(s) in the public domain.
N. Vendor will apply data disclosure avoidance techniques such as cell suppression, complementary suppression, blurring and perturbation as appropriate, in order to further minimize re-identification risks associated with possible future efforts to compare and link the Confidential Data with other data sets. Care will be taken when utilizing cell suppression alone to employ additional methods to ensure that sensitive student counts cannot be found through the use of available percentages or data in other related tables or sources. Data users will refer to the best practices outlined by the National Center for Education Statistics Statewide Longitudinal Data Systems in Technical Brief 3, “Statistical Methods for Protecting Personally Identifiable Information in Aggregate Reporting” (NCES 2011-603), to minimize, to the greatest extent possible, the risk that individuals could be identified. Furthermore, Vendor agrees not to attempt to re--‐identify de-¬‐identified Confidential Data and not to transfer de-‐identified Confidential Data to any Authorizer User unless that Authorized User agrees not to attempt re-¬‐identification.
O. Vendor certifies that it has the capacity to restrict access to the Confidential Data and maintain the security of electronic information, as more fully set forth below. Vendor shall develop, implement, maintain and use appropriate administrative, technical and physical security measures to preserve the confidentiality, integrity and availability of all electronically maintained or transmitted Confidential Data received from, or on behalf of, ISBE. Vendor acknowledges that the use of unsecured telecommunications, including the Internet or email, to transmit individually identifiable or deducible information derived from this Agreement is strictly prohibited.
P. Vendor agrees that all data transferred pursuant to this agreement will be through encrypted transmission mechanisms. These may include but not be limited to secure FTP or web sites using SSL protocols. These measures will be extended by contract to all employees, contractors, subcontractors, or agents that will receive Confidential Data provided by this Agreement and used by Vendor.
Q. Vendor will not provide any of the Confidential Data obtained pursuant to this Agreement to any party ineligible to receive data protected by FERPA or prohibited from receiving data from any entity by virtue of a finding under subsections 99.67(c), (d) or (e) of Title 34 of the Code of Federal Regulations. 34 C.F.R. § 99.67 (c), (d) and (e).
R. Vendor agrees to fully report to ISBE as reasonable practicable, which in no event shall be longer than 48 hours of discovery of any infraction of the confidentiality provisions and any use or disclosure of Confidential Data not authorized by this Agreement or in writing by ISBE. Vendor’s report shall identify: (i) the nature of the unauthorized use or disclosure; (ii) the Confidential Data used or disclosed; (iii) who made the unauthorized use and/or received the unauthorized disclosure; (iv) what Vendor has done or shall do to mitigate any deleterious effect of the unauthorized use or disclosure; and (v) what corrective action Vendor has taken or shall take to prevent future similar unauthorized use and/or disclosure. Vendor shall provide such other information, including a written report, as reasonably requested by ISBE.
S. Vendor agrees that Confidential Data shall not be archived or sent to a records center.
T. Vendor agrees to secure any and all data received pursuant to this Agreement and agrees to establish, secure and retain records of access and use of all Confidential Data received pursuant to this Agreement. Upon reasonable notice and during normal business hours, Vendor agrees to allow ISBE on-site inspection and access to all relevant data files and servers to verify data security and usage, as well as audit access, throughout the Term of this Agreement and for a period of three (3) years following the end of the Term. The three (3) year period shall be extended for the duration of any audit in progress during the Term. No fees shall be assessed for such access, audit, or review, and Vendor agrees to cooperate with ISBE’s reasonable efforts to verify data security and usage.
U. Any breach of the security of any Confidential Data provided to any person or entity under this Agreement shall be subject to the terms and provisions of the Personal Information Protection Act (815 ILCS 530/1, et seq.).
V. Vendor represents and agrees that any and all approvals for the research to be conducted using the Confidential Data, where required by law, from the Vendor or the Vendor's Institutional Review Board ("IRB") have been obtained. ISBE may request a copy of any review completed by Vendor or the Vendor's IRB related to the Confidential Data; and Vendor shall provide ISBE with a copy of the requested review within ten (10) working days of ISBE's written request.
W. Vendor may not assign its obligations under this Agreement, or any part of its interest in this Agreement, without the prior written consent of ISBE. Any assignment made without said consent shall be null and void.
X. Vendor recognizes and agrees that the Confidential Data it obtains under this Agreement is the property of ISBE and shall be disposed of or returned to ISBE within ten (10) days, upon ISBE’s request. All Confidential Data received pursuant to this Agreement shall be disposed of upon termination, cancellation, expiration, or other conclusion of this Agreement. Disposal means the return of the Confidential Data to ISBE or destruction of the Confidential Data in a means outlined herein below, as directed by ISBE, including purging of all copies from the Vendor’s computer systems. Upon disposal of the Confidential Data, Vendor shall provide ISBE with written certification. Vendor agrees to require all employees, contractors, subcontractors, or agents of any kind to comply with this provision.
4.35.9 Protection of Data
4.35.9.1 All Confidential Data shall be stored in a secure environment physically located in the continental United States with access limited to the least number of staff needed to complete the purpose of this Agreement. Only one complete copy of the Confidential Data is permitted to be maintained by Vendor; however, time-delimited temporary data analysis files may be created. Any temporary data file(s) and subsets of the original data set will be considered Confidential Data and subject to the terms and conditions of this agreement. Vendor agrees to store data on one or more of the following media and protect the data as described:
| A. | Data stored on local workstation hard disks. Access to the data will be restricted to authorized users by requiring logon to the local workstation using a unique user ID and complex password or other authentication mechanisms which provide equal or greater security, such as biometrics or smart cards. If the workstation is located in an unsecured physical location the hard drive must have encryption to protect the Confidential Data in the event the device is stolen. |
| B. | Data stored on hard disks mounted on network servers and made available through shared folders. Access to the data will be restricted to authorized users through the use of access control lists which will grant access only after the authorized user has authenticated to the network using a unique user ID and complex password or other authentication mechanisms which provide equal or greater security, such as biometrics or smart cards. Data on disks mounted to such servers must be located in an area which is accessible only to authorized personnel, with access controlled through use of a key, card key, combination lock, or comparable mechanism. Backup copies for DR purposes must be encrypted if recorded to removable media. |
| C. | Paper documents. Any paper records must be protected by storing the records in a secure area which is only accessible to authorized individuals. When not in use, such records must be stored in a locked container, such as a file cabinet, locking drawer, or safe, to which only authorized persons have access. |
| D. | Access via remote terminal/workstation over the Public Internet. Vendor must request authorization from ISBE for remote data access at the time of access. Vendor shall ensure safeguards are protocols are in place to secure the receipt and transmission of data. |
| E. | Confidential Data shall not be stored by Vendor on portable devices or media which include but are not limited to laptops, tablets, handhelds/PDAs, Ultramobile PCs, optical discs, CDs, DVDs, Blu-Rays, removable storage and flash memory devices unless specifically requested by the Vendor and authorized within this Agreement. The request must include methods for encrypting the data, controlling access to the data and physically protecting the device(s) containing the data. |
4.35.10 Data Segregation
4.35.10.1 Confidential Data must be segregated or otherwise distinguishable from non- Confidential Data. This is to ensure that when no longer needed by the Vendor, all Confidential Data can be identified for return or destruction. It also aids in determining whether Confidential Data has or may have been compromised in the event of a security breach.
4.35.10.2 Confidential Data shall be stored in one of the following methods:
A. Confidential Data will be kept on media (e.g. hard disk, optical disc, tape, etc.) which will contain no non- Confidential Data; or B. Confidential Data will be stored in a logical container on electronic media, such as a partition or folder dedicated to confidential data; or, C. Confidential Data will be stored in a database which will contain no non-Confidential Data; or, D. Confidential Data will be stored within a database and will be distinguishable from non- Confidential Data by the value of a specific field or fields within database records; or E. When it is not feasible or practical to segregate Confidential Data from non- Confidential Data, then both the confidential data and the non-confidential data with which it is commingled must be protected as described in this Agreement.
F. If the Vendor or its agents detect a compromise or potential compromise in the IT security for this data such that personal information may have been accessed or disclosed without proper authorization, Vendor shall give notice to ISBE in accordance with this Agreement.
4.35.11 Disposition of Data.
4.35.11.1 Upon termination of the agreement, Vendor shall dispose of the data received along with backup copies and any temporary or permanent work files that contain confidential data and provide written notification of disposal. Failure to do so may prevent data sharing agreements with the organization in the future.
4.35.11.2 Upon the destruction of the confidential data, the Vendor shall verify the disposition, in writing, and submit it to the ISBE authorized representative within fifteen (15) days of the date of disposal.
4.35.11.3 Acceptable destruction methods for various types of media include:
A. For paper documents containing confidential or sensitive information, a contract with a recycling firm to recycle confidential documents is acceptable, provided the contract ensures that the confidentiality of the data will be protected. Such documents may also be destroyed by on-site shredding, pulping, or incineration.
B. For paper documents containing Confidential Data requiring special handling, recycling is not an option. These documents must be destroyed by on-site shredding, pulping, or incineration.
C. If confidential or sensitive information has been contained on optical discs (e.g. CDs, DVDs, Blu-ray), the data Vendor shall either destroy by incineration the disc(s), shredding the discs, or completely deface the readable surface with a coarse abrasive.
D. If confidential or sensitive information has been stored on magnetic tape(s), the data Vendor shall destroy the data by degaussing, incinerating or crosscut shredding.
E. If data has been stored on server or workstation data hard drives or similar media, the data Vendor shall destroy the data by using a “wipe” utility which will overwrite the data at least three (3) times using either random or single character data, degaussing sufficiently to ensure that the data cannot be reconstructed, or physically destroying disk(s).
F. If data has been stored on removable media (e.g. floppies, USB flash drives, portable hard disks, or similar disks), the data Vendor shall destroy the data by using a “wipe” utility which will overwrite the data at least three (3) times using either random or single character data, degaussing sufficiently to ensure that the data cannot be reconstructed, or physically destroying disk(s).
4.35.12. The terms and provisions of this contract shall apply to the use of Confidential Data received by Vendor for so long as Vendor retains the data and shall survive the expiration or earlier termination of this Agreement.
File details come from the government source that posted it. Updated .