Laserfiche WebLink
12.5.2 Consultant, unless stipulated otherwise, shall promptly notify the <br />appropriate City Identified Contact within 24 hours or sooner by telephone, <br />unless shorter time is required by applicable law, if it confirms that there is, <br />or reasonably believes that there has been a Data Breach. Consultant <br />shall (1) cooperate with the City as reasonably requested by the City to <br />investigate and resolve the Data Breach, (2) promptly implement <br />necessary remedial measures, if necessary, and (3) document responsive <br />actions taken related to the Data Breach, including any post -incident <br />review of events and actions taken to make changes in business practices <br />in providing the Services, if necessary. <br />12.5.3 Unless otherwise stipulated, if a Data Breach is a direct result of <br />Consultant's breach of its contractual obligation to encrypt Personal Data <br />or otherwise prevent its release, Consultant shall bear the costs <br />associated with (1) the investigation and resolution of the Data Breach; (2) <br />notifications to individuals, regulators or others required by state law; (3) a <br />credit monitoring service required by state (or federal) law; (4) a website or <br />a toll-free number and call center for affected individuals required by state <br />law — all not to exceed the average per record per person cost calculated <br />for data breaches in the United States (currently $225 per record/person) <br />in the most recent Cost of Data Breach Study: Global Analysis published <br />by the Ponemon Institute at the time of the Data Breach; and (5) complete <br />all corrective actions as reasonably determined by Consultant based on <br />root cause. <br />12.6 Definitions. For purposes of this Agreement, the following definitions <br />apply: <br />12.6.1 "Data Breach" means the unauthorized access by a non -authorized <br />person/s that results in the use, disclosure or theft of City's unencrypted <br />Personal Data or Non -Public Data. <br />12.6.2 "Non -Public Data" means data, other than Personal Data, that is <br />not subject to distribution to the public as public information. It is deemed <br />to be sensitive and confidential by the City because it contains information <br />that is exempt by statute, ordinance or administrative rule from access by <br />the general public as public information. <br />12.6.3 "Participating Students" means students who use the Services <br />made available pursuant to this Agreement. <br />12.6.4 "Personal Data" means data that includes information relating to a <br />person that identifies the person by name and has any of the following <br />personally identifiable information (PII): government -issued identification <br />numbers (e.g., Social Security, driver's license, passport, library account <br />numbers); financial account information, including account number, credit <br />REV: 01-10-18 JS Page 8 of 18 <br />ATTY/AGR.2018.007/Brainfuse 2018 <br />